Re: Hundreds of failed login attempts



It could be a hack attempt or the administrator account has wrong
credentials and is trying to access the server for some legitimate purpose,
fails, and keeps retrying. Check the logon events for the source computer
and if it is on your network you need to see what is going on. If it is from
outside your network it probably is a hack attempt and you should check your
firewall logs to see if it is from the same source IP and block that IP in
your firewall. Also make sure the server has no unneeded services installed
or available to the internet such as file and print sharing possibly. You
can go to a self scan site such as http://scan.sygatetech.com/ to do some
basic firewall scans. The link below can help track down account lockout
issues/logon failures. --- Steve


http://www.microsoft.com/downloads/details.aspx?FamilyId=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&displaylang=en

"Selden" <seldenm@xxxxxxx> wrote in message
news:npmdnXT3S-7rgrHZRVn-ig@xxxxxxxxxxxxxxx
I'm seeing hundreds of failed login attempts for "administrator" on one of
my web servers.

The administrator account has a limit of 20 attempts, then a lockout for
30 minutes.

But the security event log shows these events occurring about 10 per
minute for hours at a time, with no break.

I'm pretty new to server administration, and I'm not sure what else to do
to limit these attempts.

Any suggestions would REALLY be appreciated!

---Selden McCabe




.



Relevant Pages

  • Re: Security - ciphers - autentification
    ... ABC, then my auth reply will be based also on this account, and I will have ... Or server auth string will be combined from accounts/time/.... ... this will make direct server hack hard. ... Hack firewall - there is nothing except ...
    (SecProg)
  • Re: Server Hacked Serv-U hidden files
    ... The server sits in a co-location datacentre. ... Unfortunately the server runs with only limited firewall (hardware) directly ... I do know that some script kiddies are responsible for the hack. ...
    (microsoft.public.windows.server.general)
  • Re: AD error
    ... I'm glad to know you could logon server and change user settings. ... Log on SBS server with original Administrator account. ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • RE: SBS_Database_Cleanup Failed
    ... Could you please let me know how I launch SQL Enterprise Manager. ... > Hi Alexander, ... > You can either manually rename the Administrator account on the computer ... > Administrator account names in the network (including the server). ...
    (microsoft.public.windows.server.sbs)
  • Re: iis lockdown & admin logout
    ... and I was told that if you used the administrator account as ... it would be good to "re-run" the IIS lockdown tool. ... revert settings to default settings before ... it's just running NT4 Server + latest IIS Lockdown ...
    (microsoft.public.inetserver.iis.security)