Go Back   TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: , ,

Sponsored Links



account lockout hack?

Active Directory


Reply
 
Thread Tools Search this Thread
  #1  
Old 08-04-2009
Brian MXP
 
Posts: n/a
account lockout hack?

Howdy-

Has anyone ever heard of a hack/malware that would lock out user accounts in AD
(presumably via bad logon attempts - wasn't auditing for that prior to the event)?

What's interesting is that the accounts that were locked were all common first names
(Dave, Matt, John, Sally, Stacey, Emily, etc.) and not oddly spelled (role accounts) or
exotic/foreign-type names...

TIA,
BM
Reply With Quote
  #2  
Old 08-04-2009
Florian Frommherz [MVP]
 
Posts: n/a
Re: account lockout hack?

Brian,

Brian MXP wrote:
> Has anyone ever heard of a hack/malware that would lock out user
> accounts in AD (presumably via bad logon attempts - wasn't auditing for
> that prior to the event)?
>
> What's interesting is that the accounts that were locked were all common
> first names (Dave, Matt, John, Sally, Stacey, Emily, etc.) and not oddly
> spelled (role accounts) or exotic/foreign-type names...


I think Conficker malware used to do this. Enable auditing of account
logon events on your DCs to check where those logon attempts originate
from and check the machines in question.

Cheers,
Florian
--
Microsoft MVP - Group Policy
eMail: prename [at] frickelsoft [dot] net.
blog: http://www.frickelsoft.net/blog.
Maillist (german): http://frickelsoft.net/cms/index.php?page=mailingliste
Reply With Quote
  #3  
Old 08-04-2009
Brian MXP
 
Posts: n/a
Re: account lockout hack?

Thanks, Florian. That hypothesis would make sense, as the event happened last week (3/31
- or 4/1 somewhere else : ) during the supposed Conficker flare-up.

I've since set auditing failed logon attempts on the DCs in question & we haven't seen a
re-occurrence, but the fact that the locked out accounts were common English first names
seemed to be too coincidental and wasn't sure if this was a known threat. Other than
identifying systems infected with Conficker, any other advice you may have?

Thanks,
Brian

Florian Frommherz [MVP] wrote:
> Brian,
>
> Brian MXP wrote:
>> Has anyone ever heard of a hack/malware that would lock out user
>> accounts in AD (presumably via bad logon attempts - wasn't auditing
>> for that prior to the event)?
>>
>> What's interesting is that the accounts that were locked were all
>> common first names (Dave, Matt, John, Sally, Stacey, Emily, etc.) and
>> not oddly spelled (role accounts) or exotic/foreign-type names...

>
> I think Conficker malware used to do this. Enable auditing of account
> logon events on your DCs to check where those logon attempts originate
> from and check the machines in question.
>
> Cheers,
> Florian

Reply With Quote
  #4  
Old 08-04-2009
Florian Frommherz [MVP]
 
Posts: n/a
Re: account lockout hack?

Brian,

Brian MXP wrote:
> and wasn't sure if this was a known threat. Other than identifying
> systems infected with Conficker, any other advice you may have?


Out of my pocket, no. It all boils down to see where those bad attempts
come from. Based on that, you can go on researching whether there is a
service with bad credentials trying to start or any rogue software
trying to do authentication on - but that is all really vague.

Cheers,
Florian
--
Microsoft MVP - Group Policy
eMail: prename [at] frickelsoft [dot] net.
blog: http://www.frickelsoft.net/blog.
Maillist (german): http://frickelsoft.net/cms/index.php?page=mailingliste
Reply With Quote
  #5  
Old 08-04-2009
Isaac Oben [MCITP,MCSE]
 
Posts: n/a
Re: account lockout hack?

Hello Brian MXP,

Turn on auditing and filter the security log for Event ID 680. This will
give you the users with account lockout and the source, look for a parttern
to help troubleshoot.

--
Isaac Oben [MCTIP:EA, MCSE]
"Brian MXP" <brian@nospam.mit.edu> wrote in message
news:uYM3k9EuJHA.4452@TK2MSFTNGP04.phx.gbl...
> Howdy-
>
> Has anyone ever heard of a hack/malware that would lock out user accounts
> in AD (presumably via bad logon attempts - wasn't auditing for that prior
> to the event)?
>
> What's interesting is that the accounts that were locked were all common
> first names (Dave, Matt, John, Sally, Stacey, Emily, etc.) and not oddly
> spelled (role accounts) or exotic/foreign-type names...
>
> TIA,
> BM


Reply With Quote
  #6  
Old 09-04-2009
samanderson123 via WinServerKB.com
 
Posts: n/a
Re: account lockout hack?

Brian MXP wrote:
>Howdy-
>
>Has anyone ever heard of a hack/malware that would lock out user accounts in AD
>(presumably via bad logon attempts - wasn't auditing for that prior to the event)?
>
>What's interesting is that the accounts that were locked were all common first names
>(Dave, Matt, John, Sally, Stacey, Emily, etc.) and not oddly spelled (role accounts) or
>exotic/foreign-type names...
>
>TIA,
>BM


Soulution: If you are administrator using domain. then never user watch wich
one user lock. if you face this type of problem then scan dial-a-fix and
trojon removal tool.

--
Message posted via WinServerKB.com
http://www.winserverkb.com/Uwe/Forum...er-ad/200904/1

Reply With Quote
  #7  
Old 09-04-2009
Meinolf Weber [MVP-DS]
 
Posts: n/a
Re: account lockout hack?

Hello Brian,

If you need more info about Conficker check this website:
http://www.confickerworkinggroup.org/wiki/

Also a test for local machines and networks are available.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Thanks, Florian. That hypothesis would make sense, as the event
> happened last week (3/31 - or 4/1 somewhere else : ) during the
> supposed Conficker flare-up.
>
> I've since set auditing failed logon attempts on the DCs in question &
> we haven't seen a re-occurrence, but the fact that the locked out
> accounts were common English first names seemed to be too coincidental
> and wasn't sure if this was a known threat. Other than identifying
> systems infected with Conficker, any other advice you may have?
>
> Thanks,
> Brian
> Florian Frommherz [MVP] wrote:
>
>> Brian,
>>
>> Brian MXP wrote:
>>
>>> Has anyone ever heard of a hack/malware that would lock out user
>>> accounts in AD (presumably via bad logon attempts - wasn't auditing
>>> for that prior to the event)?
>>>
>>> What's interesting is that the accounts that were locked were all
>>> common first names (Dave, Matt, John, Sally, Stacey, Emily, etc.)
>>> and not oddly spelled (role accounts) or exotic/foreign-type
>>> names...
>>>

>> I think Conficker malware used to do this. Enable auditing of account
>> logon events on your DCs to check where those logon attempts
>> originate from and check the machines in question.
>>
>> Cheers,
>> Florian



Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "account lockout hack?"
Thread Thread Starter Forum Replies Last Post
What is Account Lockout Policy unlimitedtech Networking & Security 1 31-07-2009 10:35 PM
W2K3 AD Account Lockout HulloSon Active Directory 3 29-05-2009 06:06 PM
User Account Lockout josephr38@hotmail.com Active Directory 6 17-03-2009 10:06 PM
Question on Account Lockout - Urgent Abhi Window 2000 Help 2 06-08-2007 01:42 PM
Event ID 529 and 675 W/O Account Lockout or Errors on account used for backups Wad4ipod Small Business Server 3 18-04-2007 10:47 PM


All times are GMT +5.5. The time now is 12:06 PM.