Re: account names exposed!

From: Jeff Cochran (jcochran.nospam_at_naplesgov.com)
Date: 03/09/04


Date: Mon, 08 Mar 2004 23:14:57 GMT

On Mon, 8 Mar 2004 17:03:30 -0500, "Calvin Lai"
<clai[at]qdata[dot]com> wrote:

>I have a computer w/ IPSec set on 135-139 plus FTP and Terminal Service as
>blocked (except from a certain users w/ sepcific IP) already. However, I
>still see a lot of attempts by those intruders from time to time in my even
>log. The thing that concern me most is that they somehow able to fetch the
>account names of my computer. Does anyone know where I should go for more
>info this problem?

Check your event logs, your firewall logs and so on. And stop ytrying
to "block" ports you don't want people accessing. Lock everything and
open only what you need.

Jeff



Relevant Pages

  • Re: Check logs for Intrusion
    ... The Security logs states unknown username ... >I search the IIS logs for this intruders IP address? ... The IIS logs are text files, any search function that works on text ...
    (microsoft.public.inetserver.iis.security)
  • Re: MM2 crashing
    ... No error is the system logs, for the app events, security, or system. ... Let me take a min to explain the crash. ... When MM2 or Media Player or Notepad ... MM2 and Media player both lock up ...
    (microsoft.public.windowsxp.moviemaker)
  • Re: File Locks...
    ... E.G. firewalls logs can be "copied" while in use when using ... You could autostart a wbem script to monitor file change in a dir ... > remove a file lock condition. ...
    (microsoft.public.scripting.wsh)
  • Re: Very good break in
    ... IIS is not running on this machine. ... netBIOS ports are blocked at the edge. ... of course there are no iis logs. ... just installing patches is not enough to secure a computer... ...
    (microsoft.public.win2000.security)
  • Re: possible rooted systems
    ... Check the firewall logs for outbound and inbound connections on non standard ... Once you do that check standard ports. ... Either way check the logs on the firewall for abnormal usage (you should know ...
    (Security-Basics)