Security event 675

From: bjong (piaa)
Date: 03/22/04


Date: Mon, 22 Mar 2004 09:51:14 +0800

A customer is using MOM to track failed account logins, the following events
are captured by MOM in one of the DC DC0001 (happened to be the PDC for that
domain):

Severity: Error

Status: New

Source: Logon Failed: privileged accounts

Name: Privileged Account Logon Failed: admin

Description: Pre-authentication failed:

            User Name: admin

            User ID:
%{S-1-5-21-606747145-117609710-839522115-500}

            Service Name: krbtgt/domA

            Pre-Authentication Type: 0x2

            Failure Code: 0x18

            Client Address: 192.168.10.11
ß--------------------------------- this is another DC

Domain: OAHKEX

Agent: DC0001 ß----------------------------this is the PDC emulator

Time: 03/10/2004 17:47:27

Now what surprises the customer is that the client address (presumably the
computer that the account was trying to logon) is another DC 192.168.10.11.
which they confirm that no one attempted to login during that time. In my
memory when a password is entered and checked by the logon server, if the
password is wrong it will be passed to the PDC for validation, does the
above indicate such a case?

I tried to simulate such situation but found that a wrong password login
does not necessary generate the same 675 event in the PDC emulator, am I
missing something?

Thanks for any input.



Relevant Pages

  • Re: Andrew Haas
    ... >steal every penny my mom had (bought herself ... My brother is so deeply ... >on my moms account, and had access to her acct ... >>Mike C wrote: ...
    (rec.running)
  • Re: Andrew Haas
    ... steal every penny my mom had (bought herself ... on my moms account, and had access to her acct ... My poor brother takes this ... >Mike C wrote: ...
    (rec.running)
  • Re: Way to make passwd ignore case when logging in?
    ... Mom is the same as mom or MOM to make it as easy as possible for her. ... account to the other. ... Simply create a new entry in /etc/passwd in e.g all uppercase, ... it checks the username so this only applies to the ...
    (comp.os.linux.misc)
  • Re: OT: Thank you AS3...
    ... dad is in alot of pain and his spirit is way down. ... not including the bazzilion other drugs he is taking, but the morphine is ... ISFunds) we tried to have me put on their account but they needed both ... signatures and mom wasn't there at that time, but I have access to their ...
    (alt.support.stop-smoking)
  • Re: OT: Thank you AS3...
    ... He isn't eating properly mostly because he says food all taste bad to him. ... for instance his sister brought up a complete lobster dinner (salads rolls ... ISFunds) we tried to have me put on their account but they needed both ... signatures and mom wasn't there at that time, but I have access to their ...
    (alt.support.stop-smoking)

Quantcast