Re: Audit Object Access Problem

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 01/24/05


Date: Mon, 24 Jan 2005 15:32:47 -0600

You will normally get some events even if you do not have any auditing
enabled. You might want to use the free tool dumpsec from SomarSoft to see
if any folder/files are indeed enabled for auditing, possibly from a time in
the past and forgotten about or via Group Policy file system. Also check the
security option on those computers in Local Security Policy to make sure
that "audit access of global system objects" is not enabled. If it is
undefined set it to disabled. --- Steve

http://www.somarsoft.com/ -- link to Dumpsec

"JayJ" <jmcinnes@mighty.co.za> wrote in message
news:1106571141.143914.189390@f14g2000cwb.googlegroups.com...
> Good day everyone
>
> I am having a problem with Windows 2000 (and XP) and active directory.
> I want to enable the GPO setting "audit object access" and then specify
> files and folders on workstations and servers that inherit this setting
> from the GPO.
>
> When I enable the above setting, I get thousands of entries in the
> event logs every minute, even though there are no files or folders with
> auditing enabled on any of the workstations/servers yet.
>
> Here is a sample:
> ---------------------
> Object Open:
> Object Server: Security
> Object Type: File
> Object Name: \Device\{29633AC7-C9B6-407B-8FE3-D079B0304CA3}
> New Handle ID: 1516
> Operation ID: {0,150820847}
> Process ID: 1512
> Primary User Name: xyzuser
> Primary Domain: XYZDMN
> Primary Logon ID: (0x0,0x53A05)
> Client User Name: -
> Client Domain: -
> Client Logon ID: -
> Accesses READ_CONTROL
> SYNCHRONIZE
> ReadData (or ListDirectory)
> WriteData (or AddFile)
> AppendData (or AddSubdirectory or CreatePipeInstance)
> ReadEA
> WriteEA
> ReadAttributes
> WriteAttributes
>
> Privileges -
> ----------------------
> and another:
> ----------------------
> Handle Closed:
> Object Server: Security
> Handle ID: 1760
> Process ID: 1284
> ----------------------
>
>
> Even if I reset the auditing on the root of all drives (and set it to
> propagate), I still get many thousands of these entries. If I disable
> auditing of object access, I get no entries in the security event log
> at all.
>
> I don't think this is by design because I haven't seen this before. The
> event logs fill up in a couple of minutes even if I set them to 100
> MBytes.
>
> Any ideas?
>
> Jason
>



Relevant Pages

  • Re: audit user activity
    ... you can set filter to view the Security log for a particular user. ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ... Right-click Small Business Server Auditing Policy and click Edit. ...
    (microsoft.public.windows.server.sbs)
  • Re: Pen-testing Internships?
    ... I know that Wells Fargo has a program for IT auditing where they go to ... > very good resource for learning and collaboration among IT Security ... Cenzic has the most comprehensive solutions to meet your application security penetration testing and vulnerability management needs. ... You have an option to go with a managed service or an enterprise software. ...
    (Pen-Test)
  • RE: Sharing Folder and Files
    ... you need to enable Local Security Auditing and then auditing on your ... The audited entries can be viewed under Event Viewer --> Security. ... --> Enable auditing on your folders. ...
    (microsoft.public.win2000.file_system)
  • Re: Audit Failures/READ_CONTROL SYNCHRONIZE
    ... am I trying to use auditing for something it was not ... >: If you're using Windows 2000 then you're going to see a lot of yucky events>: like this. ... Access failures often occur normally, Explorer in particular>: often tries to open files with maximum privilege,>: and then use the failure as a UI cue- it will display the file differently. ... >: For instance, if you don't have Full Control on a file, Explorer will notice>: and disable parts of the security dialog. ...
    (comp.os.ms-windows.nt.admin.security)
  • Re: How to trace a deleted file on a server by a user
    ... If you didn't have security auditing enabled, ... want to audit every single file operation. ... MCSE, CCEA, Microsoft MVP - Terminal Server ...
    (microsoft.public.win2000.termserv.apps)