Re: Thousands of security failure events created by inetinfo.exe

Tech-Archive recommends: Speed Up your PC by fixing your registry



This is originating from the IIS. Do you have exposed your webserver and
NTLM authentication enabled?

--
Claus
"12gauge" <12gauge@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:C93899F6-0163-4C01-A7DD-56239FBBE312@xxxxxxxxxxxxxxxx
Hello all,

When I check my SBS 2003 Server Performance Report, it says I have over
9,000 critical errors in the event log. When I check the Security log, I
get
thousands of the following error:

Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 8/13/2007
Time: 9:52:53 AM
User: NT AUTHORITY\SYSTEM
Computer: ALPHA
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: Administrator
Domain: TECHDYNAMICS
Logon Type: 8
Logon Process: IIS
Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Workstation Name: ALPHA
Caller User Name: ALPHA$
Caller Domain: TECHDYNAMICS
Caller Logon ID: (0x0,0x3E7)
Caller Process ID: 5820
Transited Services: -
Source Network Address: -
Source Port: -


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

When I look at Process ID 5820 in Task Manager, it is listed as
inetinfo.exe. Another important thing to note is that the events are
occurring at 9pm and 9am every day for about 52 minutes, then they quit
until
the next 9pm or 9am. Also, when I look at the IIS Admin service, it is set
to
logon as the local system account.

Any ideas?

Thanks,

Steve


.



Relevant Pages

  • IIS, Trend, Exhaustion, Permissions, Heelp!!!
    ... passwords using IIS and adsutil as in List 2. ... Logon Failure: ... Caller User Name: NETWORK SERVICE ... To reset the password for the IUSR_ComputerName account, ...
    (microsoft.public.windows.server.sbs)
  • Re: security logon failures?
    ... Both the boxes are running Web Edition and the only services running are IIS ... An error occurred during logon ... Caller User Name: - ...
    (microsoft.public.inetserver.iis.security)
  • Re: Failed Logon Attempts
    ... You would have to review your IIS logs to get this info. ... Logon account: admin ... Source Workstation: SERVER ... Caller User Name: SERVER$ ...
    (microsoft.public.windows.server.sbs)
  • Re: what hits once per minute?
    ... What's IIS doing that would require a login? ... runs under an account for which you changed the password. ... logon type 8- cleartext? ... > Caller User Name: 'server name'$ ...
    (microsoft.public.windows.server.sbs)
  • Re: KDC Event ID 7 and Wins startup errors.
    ... Event Type: Information ... Event Source: USER32 ... Logon Failure: ... Caller User Name: $ ...
    (microsoft.public.windows.server.sbs)