Re: Event Viewer: Security: Failure Audit: Username/Password question

From: Jerry zhao (v-jerryz_at_online.microsoft.com)
Date: 01/21/05


Date: Fri, 21 Jan 2005 08:57:42 GMT

Hi Bryce,
 
Thanks for your posting. Also thanks for Marina's update.
 
Actually, you can not see the password that has been attempted just like
Marina mentioned. Generally, password is sensitive personal information.
Even the domain administrator who can view the account information of every
user in the domain can not view the Password of the users. That's a by
design feature to protect user privacy.
 
You may have interest in details of Event 529:
Product: Windows Operating System
ID: 529
Source: Security
Version: 5.0
Component: Security Event Log
Symbolic Name: SE_AUDITID_UNKNOWN_USER_OR_PWD
Message: Logon Failure:
Reason: Unknown user name or bad password
User Name: %1
Domain: %2
Logon Type: %3
Logon Process: %4
Authentication Package: %5
Workstation Name: %6
    
Explanation
This event record indicates an attempt to log on using an unknown user
account or a valid user account but with an incorrect password. An
unexpected increase in the number of these audits could represent an
attempt by someone to find user accounts and passwords (such as a
"dictionary" attack, in which a list of words is used by a program to
attempt entry).
 
   
User Action
The person with administrative rights for the computer should establish a
threshold limit for attempted log ons. Attempts in excess of the limit
should be investigated as a possible attempt to break into the computer.
 
Meanwhile, you may want to disables a user account if an incorrect password
is entered a specified number of times over a specified period. These
policy settings help you to prevent attackers from guessing users'
passwords, and they decrease the likelihood of successful attacks on your
network. For more information about this, please refer:
 
To apply or modify account lockout policy
http://www.microsoft.com/resources/documentation/WindowsServ/2003/standard/p
roddocs/en-us/Default.asp?url=/resources/documentation/WindowsServ/2003/stan
dard/proddocs/en-us/password_lockout.asp
 
FOR YOUR INFORMATION:
 
You can check any Events from the Microsofte web site:
http://www.microsoft.com/technet/support/ee/search.aspx?DisplayName=Windows%
20Server%202003&ProdName=Windows%20Operating%20System&MajorMinor=5.2&LCID=10
33
 
I hope the above information helps.
 
Please feel free to let me know if you have any questions or if you need
further assistance.

Have a nice day!

Best regards,

Jerry Zhao (MSFT)

Microsoft Online Partner Support

Get Secure! - www.microsoft.com/security

=====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.



Relevant Pages

  • Re: AUTO LOGON and cross-posting
    ... single message to a handful of relevant groups all at once) and multiposting ... (which means posting individually to several groups and is not recommended), ... I would like to have a domain user account logon at boot ...
    (microsoft.public.win2000.security)
  • Re: MMC can not open <Snap-in Name> ERROR
    ... I understand the issue to be: Most .msc files are not able to be opened ... Suggestion 1. ... This issue may also cause by corrupted user account, ... This posting is provided "AS IS" with no warranties, ...
    (microsoft.public.windows.server.sbs)
  • RE: large fonts, background colours dont load in ie6sp1, xp2
    ... Does the problem occur if you create a new user account and login using the ... Internet Explorer. ... Select the Internet Options item. ... This posting is provided "AS IS" with no warranties, ...
    (microsoft.public.windows.inetexplorer.ie6.setup)
  • Re: How to determine SMTP(s)
    ... You need to create yourself user account. ... >This posting is provided "AS IS" with no warranties, ... >Keep an eye on the product lifecycle for Visual FoxPro here: ...
    (microsoft.public.fox.programmer.exchange)
  • Re: Cannot access WinXP machine on the network
    ... I try to resolve it by creating a user account on ... Pamuditha, ... There are many possible causes for the "access restriction massage". ... BTW, posting your email address openly will get you more unwanted email, than ...
    (microsoft.public.windowsxp.network_web)