Click here to get back home

Seeing Null Share Connection in Eventviewer

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Seeing Null Share Connection in Eventviewer Will 02-13-2007
Get Chitika Premium
Posted by Will on February 13, 2007, 4:27 am
Please log in for more thread options
Having been hacked by a NetBIOS trojan on some unsecured Windows 2000
machines lately, I decided to role play the intruder and see how the events
show up in the event viewer. One thing that really perplexes me is why
does a null connection to IPC$ not show up in event viewer as Anonymous
Logon? I was issuing the command against my own system:

net use * \<ip.here>\ipc$ "" /user:""

The only way I could get an anonymous logon message to show up in the
Windows 2000 event viewer was to follow a successful null connection with an
actual mount of a file system. If I mounted c$ as administrator, only at
that point do I then see the anonymous logon from the prior null connection.

It's not real comforting to know that by the time I see the anonymous
connection in the eventviewer I'm already hacked. Nor is it too good to
know that someone might be trying to access the system by a null connection
on an unsecured host, and that activity is not showing up.

Is the above behavior the way this is supposed to work? Is there anything
I can do to get the IPC$ null connection mounts to show right away in
eventviewer?

--
Will



Similar ThreadsPosted
Windows Explorer changes user account during connection to share folder February 15, 2006, 5:49 am
Null Sessions July 13, 2007, 4:00 pm
Preventing RDT connection from outside March 5, 2007, 12:51 pm
terminal service connection September 14, 2006, 6:08 am
Computers Losing Connection ??? January 11, 2007, 10:47 am
Remote Web Connection / Logon To Restrictions December 10, 2005, 1:56 pm
Remote Desktop Connection IP address June 30, 2006, 2:34 pm
IPsec connection can no be established from BOTH endpoints July 17, 2006, 1:22 pm
Connection to a service under Windows 2003 November 4, 2006, 5:08 pm
Trying to set port for Remote Desktop Connection on Win2K3 July 21, 2005, 10:33 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap