Results 1 to 6 of 6

Thread: Event Log: Failed Audit

  1. #1
    Tom Guest

    Event Log: Failed Audit

    Win2K3 SP1 SBS

    I am seeing several (!) Failed Audits in my Security Event Log. Most of
    them look like this:
    Logon failure:
    Reason: Unknown user name or bad password
    Username: Administrator
    Domain: MyIntranetDomainName
    Logon Type: 8
    Logon Process: IIS
    Authentication Package: Microsoft Authentication Package v1.0
    Workstation Name: MyServerWorkstation
    Caller Username: MyServerWorkstation$ [Note: $ at the end]
    Caller Domain: MyIntranetDomainName
    Caller LogonID: (0x0, 0x3E7)
    Caller ProcessID: 1276
    Transited Services: -
    Source Network address: -
    Source Port -

    Can someone explain what this means? If we're receiving attempts to access
    our system what counter measures should we take? We are up to date on ALL
    (including THE most recent) MS updates and we have a very long complex
    password.
    TIA

  2. #2
    Dave Patrick Guest

    Re: Event Log: Failed Audit

    These articles may help.

    http://support.microsoft.com/default...b;en-us;287537
    http://support.microsoft.com/default...b;en-us;326985

    --

    Regards,

    Dave Patrick ....Please no email replies - reply in newsgroup.
    Microsoft Certified Professional
    Microsoft MVP [Windows]
    http://www.microsoft.com/protect

    "Tom" wrote:
    | Win2K3 SP1 SBS
    |
    | I am seeing several (!) Failed Audits in my Security Event Log. Most of
    | them look like this:
    | Logon failure:
    | Reason: Unknown user name or bad password
    | Username: Administrator
    | Domain: MyIntranetDomainName
    | Logon Type: 8
    | Logon Process: IIS
    | Authentication Package: Microsoft Authentication Package v1.0
    | Workstation Name: MyServerWorkstation
    | Caller Username: MyServerWorkstation$ [Note: $ at the end]
    | Caller Domain: MyIntranetDomainName
    | Caller LogonID: (0x0, 0x3E7)
    | Caller ProcessID: 1276
    | Transited Services: -
    | Source Network address: -
    | Source Port -
    |
    | Can someone explain what this means? If we're receiving attempts to
    access
    | our system what counter measures should we take? We are up to date on ALL
    | (including THE most recent) MS updates and we have a very long complex
    | password.
    | TIA



  3. #3
    Kevin D. Goodknecht Sr. [MVP] Guest

    Re: Event Log: Failed Audit

    Tom wrote:
    > Win2K3 SP1 SBS
    >
    > I am seeing several (!) Failed Audits in my Security Event Log. Most
    > of them look like this:
    > Logon failure:
    > Reason: Unknown user name or bad password
    > Username: Administrator
    > Domain: MyIntranetDomainName
    > Logon Type: 8
    > Logon Process: IIS
    > Authentication Package: Microsoft Authentication Package v1.0
    > Workstation Name: MyServerWorkstation
    > Caller Username: MyServerWorkstation$ [Note: $ at the end]
    > Caller Domain: MyIntranetDomainName
    > Caller LogonID: (0x0, 0x3E7)
    > Caller ProcessID: 1276
    > Transited Services: -
    > Source Network address: -
    > Source Port -
    >
    > Can someone explain what this means? If we're receiving attempts to
    > access our system what counter measures should we take? We are up to
    > date on ALL (including THE most recent) MS updates and we have a very
    > long complex password.
    > TIA


    This is likely someone trying to gain access to the FTP server by trying to
    guess the username password, in this case it is the Built in Administrator.
    A check of the FTP server's logfiles will verify this.


    --
    Best regards,
    Kevin D. Goodknecht Sr. [MVP]
    Hope This Helps
    ===================================
    When responding to posts, please "Reply to Group"
    via your newsreader so that others may learn and
    benefit from your issue, to respond directly to
    me remove the nospam. from my email address.
    ===================================
    http://www.lonestaramerica.com/
    http://support.wftx.us/
    http://message.wftx.us/
    ===================================
    Use Outlook Express?... Get OE_Quotefix:
    It will strip signature out and more
    http://home.in.tum.de/~jain/software/oe-quotefix/
    ===================================
    Keep a back up of your OE settings and folders
    with OEBackup:
    http://www.oehelp.com/OEBackup/Default.aspx
    ===================================



  4. #4
    mrecomm101 Guest

    Re: Event Log: Failed Audit

    Kevin,

    I am experiencing the same issue. To troubleshoot, I stopped every website
    and every FTP site within my IIS (6.0) -- and I'm still getting the failed
    logon attempts. How can they be acheiving this when all sites are stopped,
    including AppPools?

    "Kevin D. Goodknecht Sr. [MVP]" wrote:

    > Tom wrote:
    > > Win2K3 SP1 SBS
    > >
    > > I am seeing several (!) Failed Audits in my Security Event Log. Most
    > > of them look like this:
    > > Logon failure:
    > > Reason: Unknown user name or bad password
    > > Username: Administrator
    > > Domain: MyIntranetDomainName
    > > Logon Type: 8
    > > Logon Process: IIS
    > > Authentication Package: Microsoft Authentication Package v1.0
    > > Workstation Name: MyServerWorkstation
    > > Caller Username: MyServerWorkstation$ [Note: $ at the end]
    > > Caller Domain: MyIntranetDomainName
    > > Caller LogonID: (0x0, 0x3E7)
    > > Caller ProcessID: 1276
    > > Transited Services: -
    > > Source Network address: -
    > > Source Port -
    > >
    > > Can someone explain what this means? If we're receiving attempts to
    > > access our system what counter measures should we take? We are up to
    > > date on ALL (including THE most recent) MS updates and we have a very
    > > long complex password.
    > > TIA

    >
    > This is likely someone trying to gain access to the FTP server by trying to
    > guess the username password, in this case it is the Built in Administrator.
    > A check of the FTP server's logfiles will verify this.
    >
    >
    > --
    > Best regards,
    > Kevin D. Goodknecht Sr. [MVP]
    > Hope This Helps
    > ===================================
    > When responding to posts, please "Reply to Group"
    > via your newsreader so that others may learn and
    > benefit from your issue, to respond directly to
    > me remove the nospam. from my email address.
    > ===================================
    > http://www.lonestaramerica.com/
    > http://support.wftx.us/
    > http://message.wftx.us/
    > ===================================
    > Use Outlook Express?... Get OE_Quotefix:
    > It will strip signature out and more
    > http://home.in.tum.de/~jain/software/oe-quotefix/
    > ===================================
    > Keep a back up of your OE settings and folders
    > with OEBackup:
    > http://www.oehelp.com/OEBackup/Default.aspx
    > ===================================
    >
    >
    >


  5. #5
    mrecomm101 Guest

    Re: Event Log: Failed Audit

    Sorry Kevin, it was a backlog of email notifications that was occuring. Still
    curious as to getting a straightforward answer on how to stop these types of
    attacks.

    "Kevin D. Goodknecht Sr. [MVP]" wrote:

    > Tom wrote:
    > > Win2K3 SP1 SBS
    > >
    > > I am seeing several (!) Failed Audits in my Security Event Log. Most
    > > of them look like this:
    > > Logon failure:
    > > Reason: Unknown user name or bad password
    > > Username: Administrator
    > > Domain: MyIntranetDomainName
    > > Logon Type: 8
    > > Logon Process: IIS
    > > Authentication Package: Microsoft Authentication Package v1.0
    > > Workstation Name: MyServerWorkstation
    > > Caller Username: MyServerWorkstation$ [Note: $ at the end]
    > > Caller Domain: MyIntranetDomainName
    > > Caller LogonID: (0x0, 0x3E7)
    > > Caller ProcessID: 1276
    > > Transited Services: -
    > > Source Network address: -
    > > Source Port -
    > >
    > > Can someone explain what this means? If we're receiving attempts to
    > > access our system what counter measures should we take? We are up to
    > > date on ALL (including THE most recent) MS updates and we have a very
    > > long complex password.
    > > TIA

    >
    > This is likely someone trying to gain access to the FTP server by trying to
    > guess the username password, in this case it is the Built in Administrator.
    > A check of the FTP server's logfiles will verify this.
    >
    >
    > --
    > Best regards,
    > Kevin D. Goodknecht Sr. [MVP]
    > Hope This Helps
    > ===================================
    > When responding to posts, please "Reply to Group"
    > via your newsreader so that others may learn and
    > benefit from your issue, to respond directly to
    > me remove the nospam. from my email address.
    > ===================================
    > http://www.lonestaramerica.com/
    > http://support.wftx.us/
    > http://message.wftx.us/
    > ===================================
    > Use Outlook Express?... Get OE_Quotefix:
    > It will strip signature out and more
    > http://home.in.tum.de/~jain/software/oe-quotefix/
    > ===================================
    > Keep a back up of your OE settings and folders
    > with OEBackup:
    > http://www.oehelp.com/OEBackup/Default.aspx
    > ===================================
    >
    >
    >


  6. #6
    mrecomm101 Guest

    Re: Event Log: Failed Audit

    Kevin,

    I found my security hole. All my FTP sites are "denied Access except these
    IPs...", except for one that was set to default "grant access to all". That
    weas the one being attacked.

    Hope this helps others. Thanks!

    "Kevin D. Goodknecht Sr. [MVP]" wrote:

    > Tom wrote:
    > > Win2K3 SP1 SBS
    > >
    > > I am seeing several (!) Failed Audits in my Security Event Log. Most
    > > of them look like this:
    > > Logon failure:
    > > Reason: Unknown user name or bad password
    > > Username: Administrator
    > > Domain: MyIntranetDomainName
    > > Logon Type: 8
    > > Logon Process: IIS
    > > Authentication Package: Microsoft Authentication Package v1.0
    > > Workstation Name: MyServerWorkstation
    > > Caller Username: MyServerWorkstation$ [Note: $ at the end]
    > > Caller Domain: MyIntranetDomainName
    > > Caller LogonID: (0x0, 0x3E7)
    > > Caller ProcessID: 1276
    > > Transited Services: -
    > > Source Network address: -
    > > Source Port -
    > >
    > > Can someone explain what this means? If we're receiving attempts to
    > > access our system what counter measures should we take? We are up to
    > > date on ALL (including THE most recent) MS updates and we have a very
    > > long complex password.
    > > TIA

    >
    > This is likely someone trying to gain access to the FTP server by trying to
    > guess the username password, in this case it is the Built in Administrator.
    > A check of the FTP server's logfiles will verify this.
    >
    >
    > --
    > Best regards,
    > Kevin D. Goodknecht Sr. [MVP]
    > Hope This Helps
    > ===================================
    > When responding to posts, please "Reply to Group"
    > via your newsreader so that others may learn and
    > benefit from your issue, to respond directly to
    > me remove the nospam. from my email address.
    > ===================================
    > http://www.lonestaramerica.com/
    > http://support.wftx.us/
    > http://message.wftx.us/
    > ===================================
    > Use Outlook Express?... Get OE_Quotefix:
    > It will strip signature out and more
    > http://home.in.tum.de/~jain/software/oe-quotefix/
    > ===================================
    > Keep a back up of your OE settings and folders
    > with OEBackup:
    > http://www.oehelp.com/OEBackup/Default.aspx
    > ===================================
    >
    >
    >


Similar Threads

  1. Replies: 5
    Last Post: 28-10-2010, 07:23 PM
  2. Security Failure Audit Account Logon Event ID 675
    By Itsme in forum Active Directory
    Replies: 1
    Last Post: 01-06-2009, 05:53 PM
  3. Failure Audit - Logon/Logoff - Event ID 529
    By Actionguy in forum Windows Security
    Replies: 2
    Last Post: 28-01-2009, 09:33 PM
  4. Replies: 4
    Last Post: 20-11-2008, 01:13 AM
  5. event: 566 Object Access Audit Failure
    By maratha in forum Active Directory
    Replies: 1
    Last Post: 14-02-2008, 05:04 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,752,124,199.53381 seconds with 16 queries