Re: Thousands of logon failures in the Security Log

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Robarb wrote:
Every morning, my Security log is full of unsuccessful login attempts
with user names like 'Administrator' and 'Admin' as well as common
names like 'Mike', 'Bob', etc. I realize these are attempts to break
into my system, and some mornings there are over 2000 attempts on
'Administrator' alone.

I have set my account lockout thresholds very low (as has been
described in other TechNet discussions) and I still often wake up to
a security log reporting thousands of "Unknown user name or bad
password" errors. Any ideas why the lockout isn't working? What
should I do? All help is appreciated.

Thanks,

Rob

Lockouts will not stop logging of the attempted login. The logon type and
process name can be used to help determine what method is being used to
attempt access.

If you are able to determine the source (IP) you may be able to block them
and or report them to authorities. Also review any open ports and close any
not absolutely necessary. Some routers/firewalls are able to open ports only
for specific hours of operation.

--
/kj


.



Relevant Pages

  • Re: Thousands of logon failures in the Security Log
    ... 2000 attempts on 'Administrator' alone. ... I have set my account lockout thresholds very low (as has been ... a security log reporting thousands of "Unknown user name or bad ... are able to open ports only for specific hours of operation. ...
    (microsoft.public.windows.server.sbs)
  • Re: Lost Administrator password
    ... the above logs are related to user logons and the ... associated logging being turned on. ... Administrator was blank and the password reset as well (not sure if the ... Domain Password & Lockout Policies ...
    (microsoft.public.windows.server.sbs)
  • Admin Account locked out every hour.
    ... The lockout originates from the domain controller DC1. ... None seem to using the Administrator account. ... Client Address: 127.0.0.1 ...
    (microsoft.public.windows.server.active_directory)
  • Question regarding Group Policy
    ... I am an administrator of a small company. ... I like to setup a security policy ... lockout for 10 minutes. ...
    (microsoft.public.win2000.group_policy)
  • Security network audit
    ... administrator) for currently security status. ... on all computers, check for open ports, check network traffic ... through critical ports.. ...
    (microsoft.public.windows.server.general)