Re: IP of machine locking account?



i always thought that exposing domain machines directly to the internet was
a really bad idea. lock the whole network behind a firewall and provide vpn
access in to users who need it from outside.

meanwhile, rename the account or delete it if you aren't using it.

"just bob" <kilbyfan@xxxxxxx> wrote in message
news:47d922f1$0$36379$742ec2ed@xxxxxxxxxxxxxxxxx
Someone is trying to hack one of our (formerly) admin accounts in AD on
Server 2003 using a bad password and causing the account to lock and the
event viewer shows the login attempt coming from a machine with a name
which is not on our network.

This has been happening every day at a different time of day and every
time the machine name is different. The only constant is the account being
attacked is the same every time. It would really help if there was a way
to get the IP address and not just the name of the machine. I have looked
in our DNS and DHCP database and found no machines we do not recognize.

Thank you in advance if you have a suggestion for me.

-Bob



.



Relevant Pages

  • Re: Possible inside security breach
    ... By default "authenticated users" can add up to ten workstations to a domain which ... means that ANYONE that know a logon/password for a domain account can add a ... ipsec policy to use for network communications restricted to only domain ... > who connect via a VPN. ...
    (microsoft.public.win2000.security)
  • VPN/LAN Troubleshootin
    ... Some of you might remember how I had a problem with a VPN ... share requiring the person to enter a password and the ... There was a tip to just create the same account with the ... same passwords from every user on the network on the host ...
    (microsoft.public.windowsxp.security_admin)
  • Re: How to Change Win 2000 Cached Account Password?
    ... I have never read or figured a way to change cached credentials without ... You could configure vpn account password to not expire. ... You could also use security policy user right assignment for allow/deny network ...
    (microsoft.public.win2000.security)
  • Re: Restricting VPN access
    ... I think you have to create a firewall rule on ISA where the source is the ... VPN CLient network, and the destination is your machine (an object you ... users(even adding deny access to the account we want to restrict). ... I've tried having the vpn user log out and back in to see if that helped. ...
    (microsoft.public.isa.vpn)
  • VPN Security, locking out non domain members
    ... most valuable being time).I need to lock out or block non ms domain ... members from my network. ... The non domain members must be blocked (corporate ... Home user>cisco vpn concentrator>simple IP address pool ...
    (microsoft.public.security)