Re: EventID 529 Logged 1723 Times in one Day!



Forgot. No - no source IP.
--
David @ Solsletta


"Cris Hanna [SBS-MVP]" wrote:

with all those different names, appears to be a hack attack
when you look at the event do you see an IP are they consistent?

have you gone to www.grc.com and run Shields Up to see what's open?
Is port 80 open?
Is port 21 open for FTP?

Are you running Std. or Premium?
If Std. what are you doing for a firewall?
"David" <David@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:5B853CCB-3DB3-41A5-A7BB-7EA41680AB2B@xxxxxxxxxxxxxxxx
This is appearing in the logswith varying User Names:

Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 14/09/2007
Time: 02:18:30
User: NT AUTHORITY\SYSTEM
Computer: MAC
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: pop
Domain: MACPROSOL
Logon Type: 8
Logon Process: IIS
Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Workstation Name: MAC
Caller User Name: MAC$
Caller Domain: MACPROSOL
Caller Logon ID: (0x0,0x3E7)
Caller Process ID: 2144
Transited Services: -
Source Network Address: -
Source Port: -

The events are logged consistently but are intermittent. Generally
occurring every 2 seconds for several hours with one user name then
ceasing
for a few hours or days before starting with another user name.
Examples of
names are: pop, dns, test123, admin, administrator.

Hack attempt and apart from turning off remote access any ideas?
--
David @ Solsletta

.



Relevant Pages

  • Re: EventID 529 Logged 1723 Times in one Day!
    ... appears to be a hack attack ... when you look at the event do you see an IP are they consistent? ... Logon Failure: ... Caller Domain: MACPROSOL ...
    (microsoft.public.windows.server.sbs)
  • Re: You are not authorized to view this page
    ... Here is the record from the Sytem Log for Kerberos ... AUTHORITY\SYSTEM BAY18 "Logon Failure: ... Logon Process: Kerberos ... Caller User Name: - ...
    (microsoft.public.inetserver.iis.security)
  • Re: You are not authorized to view this page
    ... IIS and Kerberos Part 2 - What are Service Principal Names? ... on logon session ... 30/04/2007 12:04:47 PM Security Failure Audit Logon/Logoff 529 NT AUTHORITY\SYSTEM BAY18 "Logon Failure: ... Caller User Name: - ...
    (microsoft.public.inetserver.iis.security)
  • Re: You are not authorized to view this page
    ... Kerberos authN is failing for some reason, ... 30/04/2007 12:04:47 PM Security Failure Audit Logon/Logoff 529 NT AUTHORITY\SYSTEM BAY18 "Logon Failure: ... Logon Type: 3 ... Caller User Name: - ...
    (microsoft.public.inetserver.iis.security)
  • Re: You are not authorized to view this page
    ... AUTHORITY\SYSTEM BAY18 "Logon Failure: ... Logon Process: Kerberos ... Caller User Name: - ...
    (microsoft.public.inetserver.iis.security)