Click here to get back home

Administrator account disabled but still get "incorrect password" errors in Event log

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Administrator account disabled but still get "incorrect password" errors in Event log John Kotuby 05-04-2008
Posted by John Kotuby on May 4, 2008, 2:11 pm
Please log in for more thread options
Hi all,

I have disabled the Administrator account on a standalone remote Web server
that we lease from a hosting company. There have been occasional failed
attempts at logon by, I presume, a hacker. I have also disabled Teminal
Services login for that account so I am not sure how the hacker is even
getting to the point of attempted login. The IIS server does use Windows
Authentication, however, and I am reading up on security for IIS. I am a
mere programmer that has been thrown into the role of also securing the
server that our application runs on.

Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon account: administrator
Source Workstation: 51WEB-83
Error Code: 0xC000006A

What I don't understand, besides the source of the attempts themselves, is
that the error message being generated indicates an "incorrect password"
instead of a "disabled account".

Would this be expected as some sort of error hierarchy? If the hacker gets
the password wrong then the "incorrect password" code is generated and if by
chance the correct password is entered then the "disabled account" code
would be thrown?

Thanks for any clarification on this issue. In Computer Management/Users the
Red X of a disabled account clearly shows up on the built-in administrator
account. That was why I questioned the actual error message in the Security
tab of the event viewer.

Thanks to all...



Similar ThreadsPosted
Administrator account disabled but still get "incorrect password" errors in Event log May 4, 2008, 2:12 pm
event log errors January 27, 2006, 3:08 pm
continuing errors in event viewr June 2, 2006, 12:35 am
Multiple Event ID 529 Errors in Server 2003 April 10, 2006, 1:34 pm
Unable to resolve SPNEGO Event ID 40961 errors November 25, 2007, 12:54 pm
server2008 password expiration disabled? February 28, 2008, 7:00 pm
PCs still function on domain with computer account disabled June 14, 2006, 3:51 pm
Main Administrator account doesn't have Administrator groups right March 1, 2006, 2:35 pm
Security configuration wizard: Parameter incorrect error September 26, 2007, 7:11 am
connect to event log on a non admin account? December 7, 2005, 4:23 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap