Re: Hacking attempts?



JEC wrote:
FWIW - the only ports that open on both of these boxes are 25, 443,
4125, and 3389.



OWA also runs on 443 as does HTTP/RPC, but I believe the logon Type:3 as you
are seeing *is* RWW.

You can use the IIS logs to track down the ip address(es) that are
attempting unauthorized login. IIS logs are timestamped UTC though as I
remember. You'll need to adjust to correlate to your event logs.

"JEC" <thejohncarlson@xxxxxxxxxxxxxxxxxxx> wrote in message
news:612C1FD7-5FB3-48C6-B8D0-B7B9321C6AF1@xxxxxxxxxxxxxxxx
Here is an example:

Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 5/9/2007
Time: 10:16:22 AM
User: NT AUTHORITY\SYSTEM
Computer: SERVER
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: mindy
Domain:
Logon Type: 3
Logon Process: Advapi
Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Workstation Name: SERVER
Caller User Name: SERVER$
Caller Domain: DOMAIN
Caller Logon ID: (0x0,0x3E7)
Caller Process ID: 436
Transited Services: -
Source Network Address: -
Source Port: -


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.


The caller process is what gives it away. It is inetinfo.exe. The
only externally exposed IIS is the RWW.


"Steve" <newsgroup@xxxxxxxxxx> wrote in message
news:OYoNTQokHHA.5024@xxxxxxxxxxxxxxxxxxxxxxx
How are you determining that these are RWW login attempts? What is
the actual security event being logged?

"JEC" <thejohncarlson@xxxxxxxxxxxxxxxxxxx> wrote in message
news:9852BEC9-023D-48CE-BE82-5AC1744D3081@xxxxxxxxxxxxxxxx
I am a computer consultant who manages a dozen SBS 2003 networks.
About a week ago, I received my daily report and noticed there had
been 1700 failed login attempts on this server. Upon examining the
security logs, I discovered that there were 9 login attempts a
second, trying to login to the RWW with random user names. It did
not appear that any were successful.

Yesterday afternoon, it happened to another one of my customers.
1100 login attempts to the RWW in a very short amount of time. All
with random user names. Again it appeared none were successful.

Has anyone else seen anything like this happening?

My servers are completely patched, and all users have very strong
passwords. Anyone else have any suggestions of steps I should take
to prevent this?

Is there a way to limit the number of login attempts to the RWW?

Any help is greatly appreciated.

--
/kj


.



Relevant Pages

  • Re: Login Errors Seem to indicate we are being hacked?
    ... I've got ISA configured so it only allows SMTP and RWW, and I use RWWGuard for RWW security, so I'm confident that in my case it can't be anything but SMTP. ... Logon Failure: ... Caller User Name: SERVER01$ ... Ie what is a logon type 3 and what do the caller Login ...
    (microsoft.public.windows.server.sbs)
  • Re: Event ID 529, NTLMSSP error from a foreign computer
    ... I'd be looking internal...an unsecured wireless access point, or somebody plugging a laptop into an unsecured port, etc. ... Logon Failure: ... Caller User Name: - ... what kind of login attempt would it be? ...
    (microsoft.public.windows.server.sbs)
  • Re: Failed logons from inetinfo.exe Ev.ID 529
    ... Well, considering webmaster, admin1, and root are all non-standard windows accounts, someone is definitely bouncing attempts off IIS. ... it isn't RWW because of how RWW handles its application pool. ... Logon Failure: ... Caller User Name: servername$ ...
    (microsoft.public.windows.server.sbs)
  • Re: Hacking attempts?
    ... Event Source: Security ... Logon Failure: ... Caller User Name: SERVER$ ... Upon examining the security logs, I discovered that there were 9 login attempts a second, trying to login to the RWW with random user names. ...
    (microsoft.public.windows.server.sbs)
  • Re: Hacking attempts?
    ... Event Source: Security ... Logon Failure: ... Caller User Name: SERVER$ ... Upon examining the security logs, I discovered that there were 9 login attempts a second, trying to login to the RWW with random user names. ...
    (microsoft.public.windows.server.sbs)

Loading