Sucsss Audit - have I been hacked ?

From: Jay B (hidden_at_noemail.com)
Date: 08/28/04


Date: Sat, 28 Aug 2004 00:17:07 GMT

I'm a security neophyte... I need some advice here as to whether I
found something bad in the Security Log.

My server was in a location where it was not physically secure.
When I got back to it today, I took a look in the Event Logs to see
what might have been happening while I was gone. In the Security Log
I found only _one_ event "Success Audit". What worries me is that
the detail shows "The audit log was cleared"... the event ran
as primary user "System", client user "administrator".

Is this a "normal" event? I admit to know nothing at all about
security audit process. Does this indicate that the audit log was
manually cleared by someone or is it the normal output of the
system audit process ?

Thanks,
Jay



Relevant Pages

  • Re: Ghost in the Recycle Bin
    ... Audit account logon events ... Prevent local guests group from accessing application log ... Prevent local guests group from accessing security log ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: administrator sign on
    ... I dont' think Windows audits this by default. ... Event log in the Security log, in the Computer Management MMC. ... also audit success of, say, logon events, and probably also system events, ...
    (microsoft.public.security)
  • Re: Audit the administrator account?
    ... In a Windows NT domain, the security log of the PDC can be configured to ... "Audit these events" and turn on auditing for "User and Group Management"... ... Event Log for the PDC for event ID 628. ...
    (microsoft.public.win2000.security)
  • Re: Audit problem
    ... I already enabled the suditing ... fail audit options. ... Then, try to check your security log, ... >> I enable object access audit setting and apply all audit ...
    (microsoft.public.win2000.security)
  • Re: DC Policy: just want to audit files, not set security
    ... definition to deliver only Audit SACL to some storage ... > to audit everything. ... Just enabling auditing of object access will generate ... > lot of events in the security log. ...
    (microsoft.public.windows.server.security)