Click here to get back home

Strange appearances in Logs

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Strange appearances in Logs AL 12-21-2005
Posted by AL on December 21, 2005, 8:10 am
Please log in for more thread options
I have been receiving the following strange entries in the Security and
System logs.

Look to me like hacks or attempted hacks. Any comments?

I've ommited details for security reasons.

1st Entry: Always 4 attempts at log-ins.

Reason: Unknown user name or bad password
User Name: Administrator
Domain: <omitted>
Logon Type: 10
Logon Process: User32
Authentication Package: Negotiate
Workstation Name: <omitted>
Caller User Name: <omitted>$
Caller Domain: <omitted>
Caller Logon ID: (0x0,0x3E7)
Caller Process ID: 5840
Transited Services: -
Source Network Address: 12.36.212.13
Source Port: <omitted>

The second entry appears in the System log and relate to printing. I know
for certain there was no printing activity for normal users on the network at
this time.

Event Type:        Information
Event Source:        Print
Event Category:        None
Event ID:        42
Date:                19/12/2005
Time:                16:21:03
User:                NT AUTHORITY\SYSTEM
Computer:        <omited>
Description:
Printer Colour on reswks1 (from NAZGUL) in session 1 was successfully
unpublished.

There are a whole series of these entries in the system log over several
days relating to clearing the printing queue and changing printer properties
--
Al

Posted by ewiley on December 22, 2005, 4:39 pm
Please log in for more thread options
Generally I've seen the first error when you've got a printer mapped
from a computer not on the domain, or with a different set of
credentials than the user's normal ones. When the password of the
account changes, the mapping's credentials are not updated, and will
try to re-map the connection several times with it's stored credentials
before giving up. Try un-mapping all the printers and network
connections from the workstation and re-mapping them.

Your second issue is from Terminal service users. When a user connects
to a server, TS creates printer queues for each printer the user has on
their workstation. They will be un-set each time the user logs off. See
if these messages correspond to TS logon/logoffs and you'll probably
find the line-up.

--Karl


Posted by Steven L Umbach on December 23, 2005, 12:52 pm
Please log in for more thread options
Any time you see failed logons for the administrator account that can be
reason for concern. Type 10 logon is an attempt via Remote Desktop. If it
shows the source computer that may help in trying to track down what is
going on. Usually hack attempts will show many failed logons in rapid
succession. As far as changing printer properties see if a user name is
shown. --- Steve


http://www.windowsecurity.com/articles/Logon-Types.html --- explanation of
logon types.

>I have been receiving the following strange entries in the Security and
> System logs.
>
> Look to me like hacks or attempted hacks. Any comments?
>
> I've ommited details for security reasons.
>
> 1st Entry: Always 4 attempts at log-ins.
>
> Reason: Unknown user name or bad password
> User Name: Administrator
> Domain: <omitted>
> Logon Type: 10
> Logon Process: User32
> Authentication Package: Negotiate
> Workstation Name: <omitted>
> Caller User Name: <omitted>$
> Caller Domain: <omitted>
> Caller Logon ID: (0x0,0x3E7)
> Caller Process ID: 5840
> Transited Services: -
> Source Network Address: 12.36.212.13
> Source Port: <omitted>
>
> The second entry appears in the System log and relate to printing. I know
> for certain there was no printing activity for normal users on the network
> at
> this time.
>
> Event Type: Information
> Event Source: Print
> Event Category: None
> Event ID: 42
> Date: 19/12/2005
> Time: 16:21:03
> User: NT AUTHORITY\SYSTEM
> Computer: <omited>
> Description:
> Printer Colour on reswks1 (from NAZGUL) in session 1 was successfully
> unpublished.
>
> There are a whole series of these entries in the system log over several
> days relating to clearing the printing queue and changing printer
> properties
> --
> Al



Similar ThreadsPosted
Strange issue with ACL September 26, 2005, 7:21 pm
very very strange problem.. please help! February 24, 2007, 10:40 am
Strange Stuff June 19, 2008, 5:51 pm
strange file on c: root October 18, 2005, 11:04 am
NTFS Deny not Working STRANGE September 30, 2005, 4:40 am
Security Log Event has Strange Timestamp April 5, 2006, 2:20 pm
Rather strange issuance of Kerberos tickets July 9, 2006, 6:31 pm
Strange folder security problem October 4, 2006, 3:45 pm
Strange issue with password authentication January 18, 2007, 10:58 am
Strange; setting up CA for DC IPsec- how did the DCs autoenroll? January 12, 2008, 9:56 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap