Click here to get back home

Services Security Failure Audit

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Services Security Failure Audit Ralish 10-29-2005
Get Chitika Premium
Posted by Ralish on October 29, 2005, 2:09 pm
Please log in for more thread options
Hello,

Yesterday I was reading through the Security Logs in Event Viewer on a
Windows Server 2003 Domain Controller when I noticed the following event:

Event Type: Failure Audit
Event Source: Security
Event Category: Object Access
Event ID: 560
Date: 29/10/2005
Time: 1:20:08 PM
User: NT AUTHORITY\NETWORK SERVICE
Computer: <cut>
Description:
Object Open:
Object Server: SC Manager
Object Type: SC_MANAGER OBJECT
Object Name: ServicesActive
Handle ID: -
Operation ID:
Process ID: 528
Image File Name: C:\WINDOWS\system32\services.exe
Primary User Name: <cut>$ (Machine Logon)
Primary Domain: <cut>
Primary Logon ID: (0x0,0x3E7)
Client User Name: NETWORK SERVICE
Client Domain: NT AUTHORITY
Client Logon ID: (0x0,0x3E4)
Accesses: READ_CONTROL
Connect to service controller
Lock service database for exclusive access

Privileges: -
Restricted Sid Count: 0
Access Mask: 0x20009

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

A quick bit of experimentation revealed that this Failure Audit occurs only
once every reboot, relatively early in the Windows boot-up process.

Can anyone provide any advice on the cause of this failure audit, and any
likely repercussions from it? I have yet to notice any negative effects from
this error, but it would still be nice to know the reason behind this event.

Thanks in advance,

Ralish




Posted by Steven L Umbach on October 30, 2005, 9:05 pm
Please log in for more thread options
Object access errors like that can be hard to track down and usually can be
ignored if everything is working well. Also look in the system and
application logs to see if there are any other warning or error messages
that show about the same timestamp that may give a clue. I have seen that
Event ID when an account tries access the operating system in such a way
that requires administrator access but fails.--- Steve


> Hello,
>
> Yesterday I was reading through the Security Logs in Event Viewer on a
> Windows Server 2003 Domain Controller when I noticed the following event:
>
> Event Type: Failure Audit
> Event Source: Security
> Event Category: Object Access
> Event ID: 560
> Date: 29/10/2005
> Time: 1:20:08 PM
> User: NT AUTHORITY\NETWORK SERVICE
> Computer: <cut>
> Description:
> Object Open:
> Object Server: SC Manager
> Object Type: SC_MANAGER OBJECT
> Object Name: ServicesActive
> Handle ID: -
> Operation ID:
> Process ID: 528
> Image File Name: C:\WINDOWS\system32\services.exe
> Primary User Name: <cut>$ (Machine Logon)
> Primary Domain: <cut>
> Primary Logon ID: (0x0,0x3E7)
> Client User Name: NETWORK SERVICE
> Client Domain: NT AUTHORITY
> Client Logon ID: (0x0,0x3E4)
> Accesses: READ_CONTROL
> Connect to service controller
> Lock service database for exclusive access
>
> Privileges: -
> Restricted Sid Count: 0
> Access Mask: 0x20009
>
> For more information, see Help and Support Center at
> http://go.microsoft.com/fwlink/events.asp.
>
> A quick bit of experimentation revealed that this Failure Audit occurs
> only once every reboot, relatively early in the Windows boot-up process.
>
> Can anyone provide any advice on the cause of this failure audit, and any
> likely repercussions from it? I have yet to notice any negative effects
> from this error, but it would still be nice to know the reason behind this
> event.
>
> Thanks in advance,
>
> Ralish
>




Posted by Roger Abell [MVP] on October 31, 2005, 1:41 am
Please log in for more thread options

> Object access errors like that can be hard to track down and usually can
> be ignored if everything is working well. Also look in the system and
> application logs to see if there are any other warning or error messages
> that show about the same timestamp that may give a clue. I have seen that
> Event ID when an account tries access the operating system in such a way
> that requires administrator access but fails.--- Steve
>

Agreed, but in case of message shown it is the machine$ account,
which runs as System, and that is hidden member of Administrators.
I assume that the SCM is impersonating an account used as a service
account, but the account does not have correct permissions on its service.

>
>> Hello,
>>
>> Yesterday I was reading through the Security Logs in Event Viewer on a
>> Windows Server 2003 Domain Controller when I noticed the following event:
>>
>> Event Type: Failure Audit
>> Event Source: Security
>> Event Category: Object Access
>> Event ID: 560
>> Date: 29/10/2005
>> Time: 1:20:08 PM
>> User: NT AUTHORITY\NETWORK SERVICE
>> Computer: <cut>
>> Description:
>> Object Open:
>> Object Server: SC Manager
>> Object Type: SC_MANAGER OBJECT
>> Object Name: ServicesActive
>> Handle ID: -
>> Operation ID:
>> Process ID: 528
>> Image File Name: C:\WINDOWS\system32\services.exe
>> Primary User Name: <cut>$ (Machine Logon)
>> Primary Domain: <cut>
>> Primary Logon ID: (0x0,0x3E7)
>> Client User Name: NETWORK SERVICE
>> Client Domain: NT AUTHORITY
>> Client Logon ID: (0x0,0x3E4)
>> Accesses: READ_CONTROL
>> Connect to service controller
>> Lock service database for exclusive access
>>
>> Privileges: -
>> Restricted Sid Count: 0
>> Access Mask: 0x20009
>>
>> For more information, see Help and Support Center at
>> http://go.microsoft.com/fwlink/events.asp.
>>
>> A quick bit of experimentation revealed that this Failure Audit occurs
>> only once every reboot, relatively early in the Windows boot-up process.
>>
>> Can anyone provide any advice on the cause of this failure audit, and any
>> likely repercussions from it? I have yet to notice any negative effects
>> from this error, but it would still be nice to know the reason behind
>> this event.
>>
>> Thanks in advance,
>>
>> Ralish
>>
>
>




Similar ThreadsPosted
Sourcing security failure audit id: 529 Windows server 2003 March 7, 2007, 9:14 am
673 Failure Audit appears several times per day December 10, 2005, 11:46 pm
Object Access Failure Audit June 12, 2006, 10:37 am
Meaning of This Failure Audit EventID 560 March 17, 2007, 2:23 am
Audit windows services in member server October 11, 2006, 2:26 am
MSDTC Security Log Failure Audits October 29, 2005, 6:41 pm
Security Failure Audits - hackers? March 16, 2006, 5:28 am
Security Configuration Wizard: Catastrophic Failure October 7, 2005, 8:30 am
Audit Policy (security logs) August 20, 2007, 10:18 pm
Help Needed in interpreting Security Audit Logs December 27, 2006, 10:36 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap