RE: Event ID 529



ISA is part of the Premium install. I was asking only because it generally
represents a good security practice whether novice or not. The likelihood
is that you already have a good security solution in place. I hate ISA
because it shuts down everything I want except VPN. The VPN still works
nicely though. I think perhaps this is for the better because what I
understand about security fits in a thimble.
--
Regards,
Jamie


"Scott" wrote:

No ISA here.
We're just a small humble office. I installed SBS2003 mainly for the
exchange feature and remote access capability. Perhaps a bit of overkill, but
the install was easy, it seems to be runnning smoothly and I don't have
enough time ear-marked as the designated IT person :-)


"thejamie" wrote:

Here is what it looks like locally: (I reinstalled the server about 4 days
ago after a problem that resulted from installing SQL Server 2005 or I would
give you an offsite copy as well.) I don't believe it is cause for concern.
Still, it doesn't hurt to be concerned. Are you running ISA?

Logon Failure:
Reason: Unknown user name or bad password
User Name: MYLOGONNAME
Domain: MYDOMAIN
Logon Type: 3
Logon Process: IAS
Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Workstation Name:
Caller User Name: MYSVRNAME$
Caller Domain: MYDOMAIN
Caller Logon ID: (0x0,0x3E7)
Caller Process ID: 996
Transited Services: -
Source Network Address: -
Source Port: -

--
Regards,
Jamie


"Scott" wrote:

Thanks Jamie, I'll try that at home tonight to see what happens.
Yet I'm still a bit confused. We're a 4 person office. No one here would
have the means to attempt a log in from an odd domain name outside the
network. Was this an attempted security breach?

"thejamie" wrote:

You get one of these for each time a user incorrectly types in their pasword
or at least if they do this over a VPN (I am not using it internally - mostly
via VPN). Try it. Go someplace outside of your network, login but use the
wrong password. The system will record and report your attempt.
--
Regards,
Jamie


"Scott" wrote:

Received the following error message. We're a small office so I know this was
not generated internally. I have no idea who the user and domain are. Can
someone please explain what happened here?

Logon Failure:
Reason: Unknown user name or bad password
User Name: LEHNT02$
Domain: LEOHK
Logon Type: 3
Logon Process: NtLmSsp
Authentication Package: NTLM
Workstation Name: LEHNT02
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: -
Source Port: -

.



Relevant Pages

  • Re: Update Post Regarding Logon events after Trend 3.5 Upgrade
    ... Trend Response: ... Security Server on my server but the file TMVS.exe was available so I was ... After doing an upgrade from CSM 3.0 to CSM 3.5 I've been seeing Logon ... Caller User Name: SBS$ ...
    (microsoft.public.windows.server.sbs)
  • Re: Login Errors Seem to indicate we are being hacked?
    ... I've got ISA configured so it only allows SMTP and RWW, and I use RWWGuard for RWW security, so I'm confident that in my case it can't be anything but SMTP. ... Logon Failure: ... Caller User Name: SERVER01$ ... Ie what is a logon type 3 and what do the caller Login ...
    (microsoft.public.windows.server.sbs)
  • Re: slow iis 6.0 performance
    ... If yes, the security has ... compatible web farm Session replacement for Asp and Asp.Net ... > Logon Failure: ... > Caller User Name: - ...
    (microsoft.public.inetserver.iis)
  • Re: Stop illegal login attempts?
    ... How can I stop illegal login attempts to my SBS box Exchange server? ... I had a guy last night try for over 3 hours to guess my username/password which generated over 610 security errors in the security event log. ... Logon Failure: ... Caller User Name: WX98$ ...
    (microsoft.public.windows.server.sbs)
  • RE: Event ID 529
    ... the install was easy, it seems to be runnning smoothly and I don't have ... Logon Failure: ... Caller User Name: MYSVRNAME$ ... Source Network Address: - ...
    (microsoft.public.windows.server.sbs)