RE: ANONYMOUS LOGON
- From: "a" <a@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Tue, 5 Apr 2005 10:15:08 -0700
"pmsis" wrote:
> Hi ,
> I have disable the above anonymous logon, however i still detect from my
> security event log stating the account have sucessfully logon & logoff?Kindly
> advise on this. Will like to know also is my system have been compromised?
>
> Below is the information from the event log thanks!
>
> Event Type: Success Audit
> Event Source: Security
> Event Category: Logon/Logoff
> Event ID: 538
> Date: 4/6/2005
> Time: 12:22:41 AM
> User: NT AUTHORITY\ANONYMOUS LOGON
> Computer: PM
> Description:
> User Logoff:
> User Name: ANONYMOUS LOGON
> Domain: NT AUTHORITY
> Logon ID: (0x0,0x354F8D)
> Logon Type: 3
>
>
> For more information, see Help and Support Center at
> http://go.microsoft.com/fwlink/events.asp.
>
>
> Event Type: Success Audit
> Event Source: Security
> Event Category: Logon/Logoff
> Event ID: 540
> Date: 4/6/2005
> Time: 12:22:40 AM
> User: NT AUTHORITY\ANONYMOUS LOGON
> Computer: PM
> Description:
> Successful Network Logon:
> User Name:
> Domain:
> Logon ID: (0x0,0x354F8D)
> Logon Type: 3
> Logon Process: NtLmSsp
> Authentication Package: NTLM
> Workstation Name: USER-KGVRTDD2YP
> Logon GUID: -
> Caller User Name: -
> Caller Domain: -
> Caller Logon ID: -
> Caller Process ID: -
> Transited Services: -
> Source Network Address: 203.70.230.19
> Source Port: 0
>
>
> For more information, see Help and Support Center at
> http://go.microsoft.com/fwlink/events.asp.
>
.
- References:
- ANONYMOUS LOGON
- From: pmsis
- ANONYMOUS LOGON
- Prev by Date: ANONYMOUS LOGON
- Next by Date: Re: vpn configuration question
- Previous by thread: ANONYMOUS LOGON
- Index(es):
Relevant Pages
|
Loading