Seeing Null Share Connection in Eventviewer



Having been hacked by a NetBIOS trojan on some unsecured Windows 2000
machines lately, I decided to role play the intruder and see how the events
show up in the event viewer. One thing that really perplexes me is why
does a null connection to IPC$ not show up in event viewer as Anonymous
Logon? I was issuing the command against my own system:

net use * \\<ip.here>\ipc$ "" /user:""

The only way I could get an anonymous logon message to show up in the
Windows 2000 event viewer was to follow a successful null connection with an
actual mount of a file system. If I mounted c$ as administrator, only at
that point do I then see the anonymous logon from the prior null connection.

It's not real comforting to know that by the time I see the anonymous
connection in the eventviewer I'm already hacked. Nor is it too good to
know that someone might be trying to access the system by a null connection
on an unsecured host, and that activity is not showing up.

Is the above behavior the way this is supposed to work? Is there anything
I can do to get the IPC$ null connection mounts to show right away in
eventviewer?

--
Will


.



Relevant Pages

  • RE: Strange Control Panel Problems -- HELP!
    ... Then a box pops up telling me that I don't currently have a connection ... that when I attempt to look at network connections ... Have a look in the Event Viewer for any error message may help us to ...
    (microsoft.public.windowsxp.perform_maintain)
  • Re: Xbox 360 Extender Frustrating Problem
    ... Please post the exact text of the message you see in Event Viewer. ... This posting is provided "AS IS" with no warranties, and confers no rights. ... however when I end a connection of either it will not ...
    (microsoft.public.windows.mediacenter)
  • Re: Performance on laptop crawling, but task manager says everythings fine. Help...
    ... What appears in Event Viewer? ... Wireless network connections: The connection to our wifi network ... window. ...
    (microsoft.public.windowsxp.perform_maintain)
  • Re: Problem connecting Xbox 360 to Media Center PC
    ... I checked the event viewer and each log, Application, Security, System and ... connection is trying to run when your user logs in. ... In the error log, see if there is mention of the app... ... Windows Media Center-based PC has disconnected this device." ...
    (microsoft.public.windows.mediacenter)
  • Re: Connect Limit Reached
    ... > The TCP/IP stack in Windows XP with Service Pack 2 installed limits ... Had exactly the same error report in Event Viewer myself after a recent ... re-install of XP Pro with SP2. ... At the same time my ADSL modem was dropping it's connection frequently so i ...
    (microsoft.public.windowsxp.network_web)