Re: Sucsss Audit - have I been hacked ?

From: Colin Nash [MVP] (x_at_x)
Date: 08/28/04

  • Next message: Lanwench [MVP - Exchange]: "Re: Sucsss Audit - have I been hacked ?"
    Date: Fri, 27 Aug 2004 20:43:58 -0400
    
    

    "Jay B" <hidden@noemail.com> wrote in message
    news:l4jvi0lu0d74r03bio3tqp8lulo3htlupm@4ax.com...
    > I'm a security neophyte... I need some advice here as to whether I
    > found something bad in the Security Log.
    >
    > My server was in a location where it was not physically secure.
    > When I got back to it today, I took a look in the Event Logs to see
    > what might have been happening while I was gone. In the Security Log
    > I found only _one_ event "Success Audit". What worries me is that
    > the detail shows "The audit log was cleared"... the event ran
    > as primary user "System", client user "administrator".
    >
    > Is this a "normal" event? I admit to know nothing at all about
    > security audit process. Does this indicate that the audit log was
    > manually cleared by someone or is it the normal output of the
    > system audit process ?
    >
    > Thanks,
    > Jay

    It looks like someone who knows the password to the built-in "Administrator"
    account cleared the log. Was the date during the timeframe that you were
    away? Do you have any auditing enabled? If not, its normal for the
    security log to be empty.


  • Next message: Lanwench [MVP - Exchange]: "Re: Sucsss Audit - have I been hacked ?"

    Relevant Pages

    • Sucsss Audit - have I been hacked ?
      ... found something bad in the Security Log. ... I found only _one_ event "Success Audit". ... security audit process. ... manually cleared by someone or is it the normal output of the ...
      (microsoft.public.win2000.security)
    • Re: Sucsss Audit - have I been hacked ?
      ... Jay B wrote: ... I need some advice here as to whether I ... > found something bad in the Security Log. ... > security audit process. ...
      (microsoft.public.win2000.security)
    • Re: Losing access to a shared folder
      ... I see no failures in the security log. ... Both shares are on the same file server. ... domain controllers as preferred and secondary dens servers. ...
      (microsoft.public.windowsxp.security_admin)
    • Re: "Access Is Denied" when XPPro Client tries to Join Domain
      ... I didn't see an error in the security log when I received "Access is ... >> I added SBS2003 server and ran it through it config, ... >> domain users or administrators, and didn't assign a computer to them. ... and it had several folders being shared with the other PCs ...
      (microsoft.public.windows.server.sbs)
    • Re: dns server unable to open active directory
      ... Systems Administrator ... The Security Log is set to maximum size of 512 kb, ... Event Source: DNS ... The DNS server was unable to open the Active Directory. ...
      (microsoft.public.windows.server.active_directory)