Re: Block clients from accessing domain controllers

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Rob McShinsky (Anonymous_at_List.com)
Date: 04/13/04


Date: Tue, 13 Apr 2004 12:32:18 -0400

A little too dirty. That would shutdown the other 5000 people who do not
have the virus on their machine.

"paisher" <anonymous@discussions.microsoft.com> wrote in message
news:1761801c42169$45817050$a001280a@phx.gbl...
>
>>-----Original Message-----
>>I am looking for a quick and dirty way to block
> identified clients both
>>inside and outside the domain from making logon attempts
> to the domain
>>controller. We have had some internal problems with
> variant of the Gaobot
>>virus which try feverishly to use its list of username
> and passwords against
>>the domain controller. We have seen upwards of 200000
> failed logon attempts
>>in 15 minutes. This is causing a type of denial of
> service situation where
>>the domain controllers at out main site are getting
> loaded so much that
>>logon requests are being sent to DC's at different AD
> sites across slower
>>links. Any thoughts would be helpful.
>>
>>Rob McShinsky
>>
>>
>>.
>>Close port 88? Disable or stop the authentication
> service.



Relevant Pages

  • Re: Block clients from accessing domain controllers
    ... Just the problem machines. ... > You said dirty... ... stop the net logon service and/or KDC. ... >> the domain controller. ...
    (microsoft.public.win2000.active_directory)
  • Re: Block clients from accessing domain controllers
    ... You said dirty... ... stop the net logon service and/or KDC. ... "Rob McShinsky" wrote in message ... > the domain controller. ...
    (microsoft.public.win2000.active_directory)
  • Re: Auditing User logon/logoff events.
    ... u say in the document like i enabled "Account logon events" only in domain ... Then i am getting 672,673 event ids in my domain controllers event viewer. ... can see this log in domain controller security log. ...
    (microsoft.public.win2000.security)
  • Re: remote desktop rights on domain controller
    ... First of for domain controllers user rights must be configured in Domain ... Controller Security Policy - not local policy. ... The user right for logon ... Group on the domain controller if using Windows 2003. ...
    (microsoft.public.windows.server.security)
  • Re: How to remove a cached password?
    ... See if another domain user can logon to it or not, ... a domain controller is that it has incorrect dns settings. ... The login used on the laptop is the same ...
    (microsoft.public.windowsxp.security_admin)