Rogue Workstation?



I noticed the following entries in the Security log of one of my Windows
Domain Controllers this morning:


Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 681
Date: 5/9/2006
Time: 8:17:26 AM
User: NT AUTHORITY\SYSTEM
Computer: DC1
Description:
The logon to account: Administrator
by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
from workstation: OWNER-W5T0
failed. The error code was: 3221225578

Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 681
Date: 5/9/2006
Time: 8:17:25 AM
User: NT AUTHORITY\SYSTEM
Computer: DC1
Description:
The logon to account: Administrator
by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
from workstation: OWNER-W5T0
failed. The error code was: 3221225578



Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 5/9/2006
Time: 8:17:25 AM
User: NT AUTHORITY\SYSTEM
Computer: DC1
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: Administrator
Domain: OWNER-W5T0
Logon Type: 3
Logon Process: NtLmSsp
Authentication Package: NTLM
Workstation Name: OWNER-W5T0



The workstation name is not one of a known machine on my network, nor am I
able to ping or find any DNS info regarding this workstation.

My question is two-fold:

1. My domain name is corp.com. Why would my domain controller log an
invalid attempt to log onto the Administrator account for an unknown
domain(See event 529 below)?

2. What are the some methods to detect rogue machines on the network?

I am not using DHCP. All ip addresses are static.

Thank you.
.



Relevant Pages

  • Re: Help - RPC over http credential issue
    ... I am showing the following errors in my DC event security log: ... Event Type: Failure Audit ... Logon Failure: ...
    (microsoft.public.exchange.setup)
  • Re: Internet Explorer and Outlook Express problems after standby mode
    ... > Event Type: Failure Audit ... > Event Source: Security ... > Event Category: Account Logon ...
    (microsoft.public.windowsxp.perform_maintain)
  • Re: Security failures
    ... I send a copy of the text to the security people who contact the person at the noted workstation and tell them not to run scripts or programs which check every machine on every domain in the world. ... Event Type: Failure Audit ... An unexpected error occurred during logon ...
    (microsoft.public.win2000.general)
  • change administrator password
    ... the Security Event Viewer. ... Is there a procedure to follow when changing the administrator password, ... Event Type: Failure Audit ... Logon Failure: ...
    (microsoft.public.win2000.security)
  • Re: Cant delegate/share to a group
    ... Try changing the Distribution group to a security group. ... The client operation failed". ... > Event Type: Success Audit ... > Successful Network Logon: ...
    (microsoft.public.exchange2000.general)