Click here to get back home

Security Failure Audits - hackers?

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Security Failure Audits - hackers? Leo 03-16-2006
Posted by Leo on March 16, 2006, 5:28 am
Please log in for more thread options
I have a web server hosting various commercial websites. I was looking at the
event log when I noticed several Security Failure Audits from a few different
IP addresses and domains that look like this:

Logon Failure:
        Reason:                Unknown user name or bad password
        User Name:        admin
        Domain:                HIGGINS
        Logon Type:        3
        Logon Process:        NtLmSsp
        Authentication Package:        NTLM
        Workstation Name:        HIGGINS
        Caller User Name:        -
        Caller Domain:        -
        Caller Logon ID:        -
        Caller Process ID:        -
        Transited Services:        -
        Source Network Address:        ***.***.***.***
        Source Port:        0

and this:

Logon attempt by:        MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon account:        admin
Source Workstation:        HIGGINS
Error Code:        0xC0000064

To me this looks like some people are trying guess the administrator
username and password. What is the best practice way of dealing with this?
The Administrator account has been renamed and there is no Guest account,
what else can I do? Is it possible to block these IP addresses? Any
suggestions would be appreciated.

Posted by Roger Abell [MVP] on March 16, 2006, 8:52 am
Please log in for more thread options
You are being probed.

If you shut down access from external IPs except to the
required (tcp 80/443, etc) then you only need to guard
the few authentication methods available that are needed
for the web owners content management and if applicable
Windows account restricted browsing areas.

Those will still get probed.

When I have such probe pests, ones that are persistent,
I put their IP in a deny filter in IPsec rules, where I name
the filters by month and then occassionally delete the filters
from older months to let them out of banishment.


>I have a web server hosting various commercial websites. I was looking at
>the
> event log when I noticed several Security Failure Audits from a few
> different
> IP addresses and domains that look like this:
>
> Logon Failure:
> Reason: Unknown user name or bad password
> User Name: admin
> Domain: HIGGINS
> Logon Type: 3
> Logon Process: NtLmSsp
> Authentication Package: NTLM
> Workstation Name: HIGGINS
> Caller User Name: -
> Caller Domain: -
> Caller Logon ID: -
> Caller Process ID: -
> Transited Services: -
> Source Network Address: ***.***.***.***
> Source Port: 0
>
> and this:
>
> Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
> Logon account: admin
> Source Workstation: HIGGINS
> Error Code: 0xC0000064
>
> To me this looks like some people are trying guess the administrator
> username and password. What is the best practice way of dealing with this?
> The Administrator account has been renamed and there is no Guest account,
> what else can I do? Is it possible to block these IP addresses? Any
> suggestions would be appreciated.



Similar ThreadsPosted
MSDTC Security Log Failure Audits October 29, 2005, 6:41 pm
Failure audits for object access on logon scripts and startup scripts, but clients still run them fine. February 27, 2008, 7:40 am
Silencing Security Audits of Memory Mapped Files? March 11, 2007, 5:15 pm
Services Security Failure Audit October 29, 2005, 2:09 pm
Security Configuration Wizard: Catastrophic Failure October 7, 2005, 8:30 am
Sourcing security failure audit id: 529 Windows server 2003 March 7, 2007, 9:14 am
hackers need answer quick November 15, 2006, 10:53 am
Secure your Oracle database from hackers April 15, 2008, 1:47 am
673 Failure Audit appears several times per day December 10, 2005, 11:46 pm
Object Access Failure Audit June 12, 2006, 10:37 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap