Re: am I being hacked or is something else going on?

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 05/22/04


Date: Sat, 22 May 2004 01:46:27 GMT

In event ID 529 the last line is the workstation that the bad logon attempt came from
but in your case it seems to be the computer that the event was logged on. I have
searched a bit and am not real sure about the " Logon Process: Advapi " as I
usually see ntlm or negotiate. Most of my search results mentioned OWA or Exchange
when Advapi was mentioned. --- Steve

"Gary Massengale" <garym_jnospam@hotmail.com> wrote in message
news:OP8VYkzPEHA.1340@TK2MSFTNGP12.phx.gbl...
> yes, it is on the local network. I have tested our firewall and cannot
> find any unnecessary ports open, and we have a coporate antivirus solution
> and the scans dont show infection on any of our PCs, and I will also try
> your suggestions also,thanks.
>
> One other thing, if it is somebody on our local network trying this, how can
> I track down which workstation this person is using?
>
> gary
>
>
>
> "Steven L Umbach" <n9rou@nospam-comcast.net> wrote in message
> news:LLbrc.87773$iF6.7516024@attbi_s02...
> > Are you on a local network with other computers? Type 3 logon means
> someone is trying
> > to gain access from the network. Do you have any holes open in your
> firewall to offer
> > services to internet users such as a web server? I would suggest running
> Microsoft
> > Baseline Security Analyzer on your computer to check for vulnerabilities
> including
> > unneeded services and scan your firewall from a self scan site such as
> > http://scan.sygatetech.com/ to make sure it is not misconfigured and
> disable file and
> > print sharing if you are not offering shares to other computers on a
> network. Be
> > sure to do a full virus scan with latest definitions if you have not done
> that
> > yet. --- Steve
> >
> > http://www.microsoft.com/technet/security/tools/mbsahome.mspx
> > http://www.microsoft.com/security/protect/
> >
> > "Gary Massengale" <garym_jnospam@hotmail.com> wrote in message
> > news:OveepMpPEHA.556@tk2msftngp13.phx.gbl...
> > > event viewer is showing unsuccesful login attemps, sometimes user name
> is "
> > > server ", sometimes " abc ", sometimes " data ". I have current
> antivirus,
> > > and a firewall running, so I am curious as to what is causing these
> attempts
> > > at 2 AM in the morning.
> > >
> > > Below is what I keep seeing:
> > >
> > >
> > > Event Type: Failure Audit
> > >
> > > Event Source: Security
> > >
> > > Event Category: Logon/Logoff
> > >
> > > Event ID: 529
> > >
> > > Date: 5/20/2004
> > >
> > > Time: 2:04:10 AM
> > >
> > > User: NT AUTHORITY\SYSTEM
> > >
> > > Computer: MYSERVERNAME
> > >
> > > Description:
> > >
> > > Logon Failure:
> > >
> > > Reason: Unknown user name or bad
> password
> > >
> > > User Name: server
> > >
> > > Domain:
> > >
> > > Logon Type: 3
> > >
> > > Logon Process: Advapi
> > >
> > > Authentication Package:
> > > MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
> > >
> > > Workstation Name: MYSERVERNAME
> > >
> > >
> >
> >
>
>



Relevant Pages

  • Re: Clean Uninstall of ISA Server 2004
    ... and the target is another workstation on the local network. ... So I know it isn't the Hardware firewall because it is outside my local ... So when I run the CEIWW I can just click somewhere to disable the ISA ...
    (microsoft.public.windows.server.sbs)
  • [hardware] gigabit firewall
    ... I need some help finding the right hardware for a gigabit firewall. ... mixed 100/1000 MBit backbone ... in the local network ... I just measured the current packets/sec and packet sizes on ...
    (comp.security.firewalls)
  • Re: Local Network or Internet?
    ... You shouldn't make any changes in your router, since its firewall is ... designed to keep the Internet out, not the local network. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Problem when join computer to domain
    ... If that DC that you say is in the local network close to the workstation, and the workstation is using some other DC, this generally means that your sites and services aren't properly configured, make sure that the client machine use that server in the preferred DNS settings, and that the Site where the server and machine belongs have the correct subnet assigned. ... I know that this port is closed betwen some location but on all my remote location I have DC which is DNS server and GC. ...
    (microsoft.public.windows.server.active_directory)
  • Is SP2 a Disaster for XP and Local Networks?
    ... not a smooth transition with respect to my local network and firewall capabilities. ... firewall, Norton's Nav, Mozilla browser/mailer, spybot and flying along pretty well. ... reach my other two computers on my local network. ... Wayne T. Watson (Watson Adventures, Prop., Nevada City, CA) ...
    (microsoft.public.windowsxp.network_web)

Loading