Is someone hacking our server?

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: MBD (MBD_at_discussions.microsoft.com)
Date: 03/06/05


Date: Sun, 6 Mar 2005 08:57:01 -0800

This morning (and every so often) I read this in the security log:

Logon Failure:
         Reason: Unknown user name or bad password
         User Name: connect
         Domain:
         Logon Type: 3
         Logon Process: Advapi
         Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
         Workstation Name: SBSSERVER
         Caller User Name: HILLSIDESERVER$
         Caller Domain: OURDOMAIN
         Caller Logon ID: (0x0,0x3E7)
         Caller Process ID: 1632
         Transited Services: -
         Source Network Address: -
         Source Port: -

There was no one in the building when this event occurred. Our firewall
blocks everything except port 25 (SMTP mail). Was this a hacking attempt?
Was it from the outside or inside?

Thanks,
MBD



Relevant Pages

  • Re: critical errors in security log
    ... Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net ... I always get to see that there are critical errors in security log. ... it said Logon failure: ...
    (microsoft.public.windows.server.sbs)
  • Re: EMail/Security problem...
    ... Because they are pop3 users with email addresses different from user names, ... I've sent a larger security log, Jill doesn't have her email setup to auto ... does the security log have just logon failure one time? ... from your newsreader: microsoft.private.directaccess.partnerfeedback. ...
    (microsoft.public.windows.server.sbs)
  • Errors!
    ... I am having an error come up in my security log. ... It happens twice every ... It is event ID 529 and is Logon Failure: Unkown user name or bad ...
    (microsoft.public.windows.server.security)
  • Event ID 537
    ... like some others experienced flooding of the security log with event ... Logon Failure: ... It is in some comments related to running in mixed mode, ...
    (microsoft.public.security)