How do I tell if an attack is from an internal or external source

From: Steve Everington (steve.nospam_at_pannellsigns.co.uk)
Date: 03/30/05


Date: Wed, 30 Mar 2005 11:05:02 +0100

Hello

I have been getting a series of (a few hundred) failed login attempts in the
early hours of the morning (a series of 529 & 681 login failure security
events). The 529 entry has a login in type of 3, which I believe is a
network login and the workstation name is the server's name.

Is there a way of telling whether the events are being caused by attempted
logins on my VPN or by a trojan/virus running on my server or some other
source?

Thanks

Steve Everington



Relevant Pages

  • Re: Why?
    ... Back when I first tried using it KDM presented a login ... Text entry box labelled 'Password' ... the original XDM is very 'no frills' and assumes you need to log ...
    (Debian-User)
  • Re: Windows logs me off as soon as I try to logon
    ... The winlogon registry key has the correct entry. ... >> touchpad and following the reboot windows stopped letting me login. ... >> safe mode. ...
    (microsoft.public.windowsxp.general)
  • Re: Windows logs me off as soon as I try to logon
    ... The winlogon registry key has the correct entry. ... I get to the welcome screen and login as usual then following entry of the Username and password the Logging off screen appears with the logging off music and I am returned to the welcome screen. ... I am able to login to safe mode. ...
    (microsoft.public.windowsxp.general)
  • self inflicted
    ... I have an unusual situation dealing with forms authentication, ... I set things up this way so I can use a common login page, ... the page_load event of the entry pages, but removing ... ..ASPXAUTH cookie on the entry page and if it is present I ...
    (microsoft.public.dotnet.framework.aspnet)
  • self-inflicted authentication issue
    ... I have an unusual situation dealing with forms authentication, ... In theses pages I setup site ... I set things up this way so I can use a common login page, ... the page_load event of the entry pages, but removing ...
    (microsoft.public.dotnet.languages.vb)