RE: 25 logon attempts per minute for hours - what is going on?

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hello,

Thank you for posting.

Event 100 indicates that a user wants to logon to FTPSvc but fails due to a
wrong user name or bad password. The events are hackneyed. According to my
experience, two reasons may cause this high occurrence of Event 100:
1. Clients attempt to logon with the wrong user name or password
continually.
2. Your server has been attacked as Owen said.

You can perform the test mentioned by Owen. On the other hand, if the FTP
server is not necessary for you, I suggest you disable the FTP Publishing
Service on the server. It will prevent your server from FTP related
attacks. If you are using FTP service now, I need an MPS report for further
research. To collect the MPS report, please follow these steps:
1. Access the following URL:
<http://www.microsoft.com/downloads/details.aspx?familyid=cebf3c7c-7ca5-408f
-88b7-f9c79b7306c0&displaylang=en>
2. Download MPSRPT_Alliance_X86.EXE and execute the exe file.
3. Please send the result file (CAB file) to me at v-jochen@xxxxxxxxxxxxxx

Sincerely,
John Chen, MCSE, MCSA, MCDBA, MCSD
Microsoft Online Partner Support

Get Secure! - www.microsoft.com/security

=====================================================
When responding to posts, please "Reply to Group" via
your newsreader so that others may learn and benefit
from your issue.
=====================================================

This posting is provided "AS IS" with no warranties, and confers no rights.

.



Relevant Pages

  • Re: EventID 529 Logged 1723 Times in one Day!
    ... David @ Solsletta ... I see this on my machines that run an FTP server. ... Logon Process: IIS ...
    (microsoft.public.windows.server.sbs)
  • Re: Allow log on locally in Default Domain Controller Policy.
    ... > has a reason for local access to a DC. ... Even placing an FTP server on a DC, ... > you can still set up your permission to avoid giving local logon access to ...
    (microsoft.public.cert.exam.mcse)
  • Re: Allow log on locally in Default Domain Controller Policy.
    ... > Personally I suggest not using FTP on a DC at all, because IIS, like IE, ... > be useful unless you're doubling up server duties for lack of cash... ... >> There is one reason why a normal user needs logon locally permissions to ... >>>There is no reason that a normal user needs to logon to a Domain ...
    (microsoft.public.cert.exam.mcse)
  • Re: FTP Client Access Error using Web Proxy Client mode ISA 2000 Stand
    ... This looks like your ISA is already passing logon credentials for you. ... I have a Trouble when try to connect to any External FTP using WEb Browser ... Internet Security and Acceleration Server ...
    (microsoft.public.isa)
  • Re: Please help refresh my memory on AD DC
    ... When I boot my Laptop I reach the Logon screeen for XP Laptop and here ... admin account to be able to Login so I can control it from the DC. ... A domain user can by default logon to any domain computer, except Domain controllers. ... A Server has websites already hosted on it in a Workgroup and now I ...
    (microsoft.public.windows.server.active_directory)