Re: Event ID 538 Logon Type 3 NT AUTHORITY/ANONYMOUS LOGON

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 03/12/05


Date: Fri, 11 Mar 2005 21:42:55 -0600

It is common to see those Events on computers using Windows networking and
that have file and print sharing and Client for Microsoft networks enabled.
Those often are null sessions used by the computer browser service. While
null sessions can be used to enumerate users, groups, and shares you can
mitigate the risk by using a firewall to prevent internet access to null
sessions, enforcing strong passwords on your network, and making sure your
share/folder permissions only allow authorized users access.

There are things you can do to reduce there occurrence as ling as the
changes do not interfere with your network access for users. For instance
disabling netbios over tcp/ip, disabling the computer browser service, and
configuring the security option for "additional restrictions for anonymous
access" to be " no access without explicit anonymous permissions". If you
disable netbios over tcp/ip on a computer it will no longer show in or be
able to use My Network Places but access to shares can still be done via
fully qualified domain name or possibly even netbios name as long as dns can
resolve the non FQDN by appending parent suffix to the request. The link
below explains anonymous access more and the security option to restrict it
along with possible consequences of doing such. --- Steve

http://support.microsoft.com/?kbid=246261

"/.dz" </.dz@discussions.microsoft.com> wrote in message
news:480AE832-9FE3-4740-A265-6F6CA5A898FD@microsoft.com...
> The security event log on our W2K, SP4 server has hundreds of the above
> messages in it. There are no associated 'logon' events, just the 'logoff'
> events.
>
> File and Print sharing is enabled on this server.
>
> There are several published file shares (all hidden); and there are
> individuals who are authorized to use those shares. The security log does
> contain 540/538 'pairs' that reflect the credentials of these known users
> (user/domain). (These are also 'Logon Type 3') But the number of 538 NT
> AUTHORITY/ANONYMOUS LOGON events absolutely dwarfs the number of "known
> user"
> logon/logoff events.
>
> The server itself is not a domain controller. It was until recently a
> member of a NT domain, and now is under AD (I don't know how to state that
> with any accuracy). 'Known user' logon/logoff events are present for
> both
> the 'older' NT domain, and the newer 'AD' whatever).
>
> I've scoured newsgroups and the MS web site without any luck whatsoever.
> Any feedback would be greatly appreciated.
>



Relevant Pages

  • Fwd: CERT Advisory CA-2003-08 Increased Activity Targeting Windows Shares
    ... poorly protected file shares. ... Intruders have been able to leverage poorly ... The network scanning associated with this activity is widespread but ... W32/Deloder attempts to compromise the Administrator ...
    (Bugtraq)
  • [Full-Disclosure] Fwd: CERT Advisory CA-2003-08 Increased Activity Targeting Windows Shares
    ... CERT Advisory CA-2003-08 Increased Activity Targeting Windows Shares ... The network scanning associated with this activity is widespread but ... W32/Deloder attempts to compromise the Administrator ...
    (Full-Disclosure)
  • Home networking - very strange issue - pls help!
    ... I am trying to get a home network going with 2 Windows XP Pro SP2 machines. ... I have a laptop and a desktop that i am trying to share files across. ... I have enabled Simple file sharing. ... When i do a net share i can see all the shares plus C$, ...
    (microsoft.public.windowsxp.general)
  • Re: Logon Failure: The used has not been granted the requested lo
    ... Use the command net share on the XP Home computer to see if the shares ... trying to access via UNC has everyone permissions ... > shares in My Network Places or under Windows explorer. ... one XP home and one XP pro. ...
    (microsoft.public.windowsxp.security_admin)
  • RE: Internet security on "hotspots"
    ... there's a setting in the security policy under Network Access where ... Now if we're talking shares, anonymous never did have access in most cases, ... Disabling the guest account - it's been disabled by default since NT 3.5, ...
    (Focus-Microsoft)