Anonymous logons in event viewer question.....

From: Max Burke (mlvburke_at_%$%#@.nz)
Date: 10/18/03


Date: Sat, 18 Oct 2003 22:02:15 +1300

I have the following appearing regularly in the event viewer security
log; I have been trying to track down why and what (if anything) I can
or need to do about this anonymous logon.....

So far all the web sites (including Microsoft's) only talk about Win 2K,
NT, and XP Professional....
None of them mention XP Home at all except for vague references about it
can be caused by having the welcome screen enabled, and that this was
fixed in XP SP1. My computer is fully up to date with all updates and
patches.

There are some other vague references (mostly talking about Win2K again)
that it also can/does happen with LAN connected computers (I have an old
486 running Win95a connected through a LAN to this computer) and that
it's some sort of system logon event that allows LAN connections to
work.....

[ XXXXXX = computer name, logon names, etc]

Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 540
Date: 18/10/2003
Time: 6:24:27 p.m.
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: XXXXXXXXX
Description:
Successful Network Logon:
User Name:
Domain:
Logon ID: (0x0,0x11ED0)
Logon Type: 3
Logon Process: NtLmSsp
Authentication Package: NTLM
Workstation Name:
Logon GUID: {00000000-0000-0000-0000-000000000000}

On a related note I'm also seeing every so often:

Event Type: Failure Audit
Event Source: Security
Event Category: Account Management
Event ID: 627
Date: 18/10/2003
Time: 8:57:51 p.m.
User: XXXXXXXX\XXXX
Computer: XXXXXXX
Description:
Change Password Attempt:
Target Account Name: HelpAssistant
Target Domain: XXXXXXX
Target Account ID: XXXXXXX\HelpAssistant
Caller User Name: XXXXXXX
Caller Domain: XXXXXXXXX
Caller Logon ID: (0x0,0xC55E)
Privileges: -

This failure happens for all registered user accounts;

Me. (my logon)
The hidden admistrator account.
The help assistant account.
The hidden support account.
The guest account.

Most often it's when the computer is turned on or rebooted, but
occasionally after the computer has been running for several hours. Most
of the time I'm not connected to the internet when it happens. Also I am
the only one who has physical access to both computers. (They're sitting
next to each other on my desk)

I have Zone alarm installed on my system, and also have ICF running; I
run PC-cillian 2002 and keep up to date their virus def files. I have
turned off all unneeded services, MBSA report no unnecessary services
are running. I do regularly scans (weekly using Ad-Aware and Spybot
S&D) and run Trojan scanners once a week as well.....

Again I haven't been able to find out anything helpful on any websites,
mostly they talk about Win2K, and XP Professional and about setting
security policies for logons which cant be done in XP Home.....

Is there anything I can do to track down what this audit failure means
and what I need to do (if anything) to stop the attempted password
changes from happening....

One last question;
When the guest account is turned of in Control Panel / User Accounts /
Guest account [off] why does it still show as logging on in the security
event viewer log?

-- 
mlvburke@#%&*.net.nz
Replace the obvious with paradise to email me.
See Found Images at:
http://homepages.paradise.net.nz/~mlvburke/


Relevant Pages

  • [EC-SA-01.2003] Windows XP "welcome screen" exposes the names of all the members of the l
    ... logon screen with what is called "Welcome Screen". ... (including the original administrator account, ... Using the "welcome screen" actually disables / ignores the security ...
    (Bugtraq)
  • Re: ATTN : Microsoft - Security Event 529....Second Request for help....
    ... According to the events, the logon ... failure is from the local machine account. ... disconnected from the network. ... Security Event ID 529 is a failure audit for logon/logoff. ...
    (microsoft.public.windows.server.sbs)
  • RE: Event ID 529 on cleint workstation
    ... Security Event ID 529 is a failure audit for logon/logoff. ... "logon events" generate the events on domain controllers for domain account ... The Event 529 was caused by the machine account password not being ... I suggest that you re-join the client to ...
    (microsoft.public.windows.server.sbs)
  • Re: Is it really true that NTFS is secure?
    ... The account Group got put back in the Administrator group again. ... Event Source: Security ... The logon to account: Administrator ...
    (microsoft.public.security)
  • Risks Digest 25.73
    ... German electronic health card system failure ... Risks of the Cloud: Liquid Motors ... Oakland 2010, IEEE Symposium on Security and Privacy, CFP ... A friend's facebook account was hacked recently (a neat little short-term ...
    (comp.risks)