Failed Logon Attempts



Hi All

Just seeking a little help on some security issues one of our servers
experienced last night. It appears as though they hit the "admin" account &
not the administrators & then hit the "Guest" account which was disabled
anyway. Only problem is i can not find their IP address through all of this
as there is no ISA installed. Is there any other way i can gain this
information from SBS 2003 or am i doomed until i can get the boss to see
things my way:)

Thanks in advance for any help

here is the log of the incident

Source Event ID Last Occurrence Total Occurrences

Security 680 3/18/2007 4:56 PM 5,385


Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon account: admin
Source Workstation: SERVER
Error Code: 0xC0000064
=====================================================================
Source Event ID Last Occurrence Total Occurrences

Security 680 3/18/2007 4:56 PM 5,385


Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon account: admin
Source Workstation: SERVER
Error Code: 0xC0000064


Source Event ID Last Occurrence Total Occurrences
Security 529 3/18/2007 4:56PM 3,391

Logon Failure:
Reason: Unknown user name or bad password
User Name: admin
Domain: (DOMAIN)
Logon Type: 8
Logon Process: IIS
Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Workstation Name: SERVER
Caller User Name: SERVER$
Caller Domain: DOMAIN
Caller Logon ID: (0x0,0x3E7)
Caller Process ID: 5688
Transited Services: -
Source Network Address: -
Source Port: -
================================================================================================
Source Event ID Last Occurrence Total Occurrences
Security 539 3/18/2007 4:33PM 1,993 *

Logon Failure:
Reason: Account locked out
User Name: guest
Domain: DOMAIN
Logon Type: 8
Logon Process: IIS
Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Workstation Name: SERVER
Caller User Name: SERVER$
Caller Domain: DOMAIN
Caller Logon ID: (0x0,0x3E7)
Caller Process ID: 5688
Transited Services: -
Source Network Address: -
Source Port: -
==============================================================================================
Security 531 3/18/2007 1:35 PM 1
Logon Failure:
Reason: Account currently disabled
User Name: guest
Domain: DOMAIN
Logon Type: 8
Logon Process: IIS
Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Workstation Name: SERVER
Caller User Name: SERVER$
Caller Domain: DOMAIN
Caller Logon ID: (0x0,0x3E7)
Caller Process ID: 5688
Transited Services: -
Source Network Address: -
Source Port: -



.



Relevant Pages

  • Re: Please help refresh my memory on AD DC
    ... When I boot my Laptop I reach the Logon screeen for XP Laptop and here ... admin account to be able to Login so I can control it from the DC. ... A domain user can by default logon to any domain computer, except Domain controllers. ... A Server has websites already hosted on it in a Workgroup and now I ...
    (microsoft.public.windows.server.active_directory)
  • Re: ISA SERVER NOT STARTING
    ... I delete the nat/basic firewall and stop and started the RRAS an tried to ... There were no critical events in the DNS Server Log in the last 24 hours. ... An error occurred during logon ... Caller User Name: - ...
    (microsoft.public.windows.server.sbs)
  • Re: Please help refresh my memory on AD DC
    ... When I boot my Laptop I reach the Logon screeen for XP Laptop and here I am ... administrator account. ... account to be able to Login so I can control it from the DC. ... A Server has websites already hosted on it in a Workgroup and now I join it ...
    (microsoft.public.windows.server.active_directory)
  • Re: Please help refresh my memory on AD DC
    ... "Meinolf Weber" wrote: ... They however cannot logon directly to the physical DC machine. ... NOT an admin account to be able to Login so I can control it from ... A Server has websites already hosted on it in a Workgroup and now ...
    (microsoft.public.windows.server.active_directory)
  • Re: Event ID 529
    ... First is a hardware firewall that sits on the perimeter of your network and requires that your users give user names and passwords, different from those for the network. ... Sometimes the Logon Type is different, also the User Name can be ... Computer: <SERVER NAME> ... Caller User Name: $ ...
    (microsoft.public.windows.server.sbs)