audit

From: DC Gringo (dcgringo_at_visiontechnology.net)
Date: 11/16/04


Date: Tue, 16 Nov 2004 12:24:38 -0500

I audit to logons...can someone tell me what they mean?

Event Type: Success Audit
Event Source: Security
Event Category: Privilege Use
Event ID: 576
Date: 11/15/2004
Time: 5:02:22 PM
User: domain\user1
Computer: machinename
Description:
Special privileges assigned to new logon:
  User Name:
  Domain:
  Logon ID: (0x0,0xE15B34)
  Privileges: SeChangeNotifyPrivilege
   SeBackupPrivilege
   SeRestorePrivilege
   SeDebugPrivilege

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Success Audit
Event Source: Security
Event Category: Privilege Use
Event ID: 578
Date: 11/15/2004
Time: 5:02:22 PM
User: domain/user1
Computer: CIL-132
Description:
Privileged object operation:
  Object Server: SC Manager
  Object Handle: -312443664
  Process ID: 1068
  Primary User Name: machinename$
  Primary Domain: domainname
  Primary Logon ID: (0x0,0x3E7)
  Client User Name: dheckel
  Client Domain: domainname
  Client Logon ID: (0x0,0xE15B34)
  Privileges: SeTakeOwnershipPrivilege

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

-- 
_____
DC G


Relevant Pages

  • Re: APACHE$PRIVILEDGED
    ... The primary security on OpenVMS and on most other multi-processing operating systems is implemented via the memory management system and via what VAX calls the change-mode routines, via the Alpha SRM PALcode change-mode equivalent, or via what the IA-32 and IA-32e architectures refer to as the call gate. ... With OpenVMS constructs including device drivers )and user-written system services (UWSS; also known as privileged shareable images), these constructs operate in inner processor modes. ... One of the more hazardous situations for system security is a mixed environment; where there are resources shared between trusted and untrusted environments. ... Not only will the operation that requires privileges now be permitted, but other and potentially unintended operations can also be permitted. ...
    (comp.os.vms)
  • [UNIX] Bugzilla Multiple Vulnerabilities (SQL Injections, Privileges Escalation, Information Leak)
    ... Get your security news from a reliable source. ... user may retain privileges that should have been removed, ... Reference: ... secure bug, you can access the summary of that bug even if you do not have ...
    (Securiteam)
  • Re: Happy 10 years of continuous virus free computing on OpenVMS alpha 7.1
    ... OpenVMS provides an inherent security advantage over all the other ... advantage of OpenVMS brings it much closer to such a goal than any OS ... attaining higher mode privileges or services for which a process was ... currently used University-level texts on OS Design. ...
    (comp.os.vms)
  • Re: Microsoft finally acknowledges the security drumbeats
    ... not part of the operating system. ... If the security problems go ... > IIS full administrator privileges. ... If processes like IIS running with admin priveleges is the ...
    (comp.security.misc)
  • Re: Microsoft finally acknowledges the security drumbeats
    ... not part of the operating system. ... If the security problems go ... > IIS full administrator privileges. ... If processes like IIS running with admin priveleges is the ...
    (comp.security.unix)