Re: Security Event Log madness.

From: Nunya Beeswax (no email)
Date: 04/28/05


Date: 28 Apr 2005 15:22:02 -0500


     I know that it was her username that deleted the files. But, she
was logged onto two computers at the same time. She claims that a
friend was using one of the computers logged in under her username
(students have been told repeatedly not to do that) and that the
friend was supposed to log her off. So, even though I know it was her
username, I need to know the computer it was done on. There is a
camera that shows these computers. So, if I know what computer she
or her friend, was on, they can't deny it. Right now, they can blame
it on each other.

On Thu, 28 Apr 2005 14:11:07 +0100, andy smart
<anonymus@discussions.microsoft.com> wrote:

>Nunya Beeswax wrote:
>> We've had a student in our school system delete a ton of files on
>> a server that were wide-open to students. The permissions allowed
>> students to delete files because Microsoft Office files need 'Delete'
>> permissions or they'll create the filename but the file will be empty.
>> The students have their own individual folder for saving files that
>> only they can access but most of the teachers had them using the
>> 'open' folder. I recovered everything from our backup, but we don't
>> want to let this slide.
>> Anyway, I know the username of the student that deleted the
>> files. But, I need to determine the computer they did it from. I
>> know it's one of two computers. I have the security logs from both
>> domain controllers, the file server the files were deleted from and
>> the computers she logged in on. I see clearly in the log from the
>> file server that she deleted the files. But, it doesn't tell me what
>> computer the delete command was executed from. I don't see anything
>> in ANY of the other security logs that tells me what computer the
>> delete command came from.
>> I see events 540 & 576 in the log of one of the domain
>> controllers involving this user, but the 'Workstation Name' field is
>> blank in the 540 events. Surely to God above there is some way to
>> find out what computer she actually used, but I don't see anything in
>> any of these logs that tells me.
>> I need to know what computer she deleted the files from. Also,
>> if someone can point me to a good book or online resource that tells
>> me how to make sense of the event logs I would REALLY appreciate it.
>> Any light you can shed on this would be GREATLY appreciated.
>
>Do you know when the files were deleted? If so you could run the
>eventcomb tool (free from somewhere on microsoft.com) to run over the
>event logs which should tell you which machine they were on.
>
>BTW, why do you need to know which workstation it was? If you got her
>bang to rights why do you need to know where it was done from.



Relevant Pages

  • Re: Security Event Log madness.
    ... >If the students have been instructed not to share usernames and passwords, ... If her username and password were compromised by the other ... >> was logged onto two computers at the same time. ... >> friend was supposed to log her off. ...
    (microsoft.public.win2000.security)
  • Re: Proof of personal Internet Usage
    ... internet and a printout of all the sites that she visited. ... The only way it would continue to show on server logs would be if that ... websites take between 5 and 10 seconds to load. ... To hit the 17 hour limit, your friend would have had to download around 6000 ...
    (uk.legal)
  • Re: event id 675
    ... workstation and uses a valid domain account name but enters a bad ... Failure Code 24.By reviewing each of your DC Security logs ... providing the username and domain name, ... address of the system from which the logon attempt originated. ...
    (microsoft.public.win2000.security)
  • RE: Run Advertised Programs is empty
    ... the SID, not the username, but any special characters in this username? ... Also I have found that when this troubling account logs in there are errors ... Is it a clew that Add New Programs also is empty? ... The other machine he logs in to is also in the collection. ...
    (microsoft.public.sms.misc)
  • Office 2007 Enterprise Deployment - Name and Initials Prompt
    ... We're preparing Office 2007 Enterprise for deployment in our student labs ... student logs into a new machine somewhere they will see this dialog. ... inserted in the PIDKEY, USERNAME, USERINITIALS, and COMPANYNAME fields). ... I've also attempted using a capture of the changes made to the registry from ...
    (microsoft.public.office.setup)