Am I seeing an attempted security breach?

From: Daren Addison (DarenAddison_at_discussions.microsoft.com)
Date: 01/17/05


Date: Mon, 17 Jan 2005 01:37:03 -0800

I have posted below the event that concerns me.
I have this message logged daily over the past week (as far back as I have
checked so far). The strange thing is that the time stamp is identical
everyday,
at 13:33.

Logon Failure:
  Reason: Unknown user name or bad password
  User Name: <myname>
  Domain: <domain name>
  Logon Type: 4
  Logon Process: Advapi
  Authentication Package: Negotiate
  Workstation Name: <sbs server>
  Caller User Name: <server name$>
  Caller Domain: <domain name>
  Caller Logon ID: (0x0,0x3E7)
  Caller Process ID: 1292
  Transited Services: -
  Source Network Address: -
  Source Port: -

Any advice would be welcomed.

Running SBS2003 std. Using Intelligent Gateway 1800 office portal, which has
built in firewall. Using NAT config.
Server has 2NICs.



Relevant Pages

  • Re: ISA SERVER NOT STARTING
    ... I delete the nat/basic firewall and stop and started the RRAS an tried to ... There were no critical events in the DNS Server Log in the last 24 hours. ... An error occurred during logon ... Caller User Name: - ...
    (microsoft.public.windows.server.sbs)
  • Re: Event ID 529
    ... First is a hardware firewall that sits on the perimeter of your network and requires that your users give user names and passwords, different from those for the network. ... Sometimes the Logon Type is different, also the User Name can be ... Computer: <SERVER NAME> ... Caller User Name: $ ...
    (microsoft.public.windows.server.sbs)
  • Re: Another security question/issue.
    ... Time to audit your server and workstations with AV, Malware, and installed ... Logon Process: Advapi ... Caller User Name: servername$ ... Source Port: - ...
    (microsoft.public.windows.server.sbs)
  • Re: Logon 529 Errors
    ... Default SMTP Virtual Server properties-Access tab-Relay ... Connection filtering is different from what inna is attempting, ... These are almost surely SMTP logon attempts, ... Caller User Name: DELLSERVER$ ...
    (microsoft.public.windows.server.sbs)
  • Re: Logon 529 Errors
    ... connection has been found on the black list, my DNS server ... Connection filtering is different from what inna is attempting, ... These are almost surely SMTP logon attempts, ... Caller User Name: DELLSERVER$ ...
    (microsoft.public.windows.server.sbs)