Re: Process running under Adminstrator account
- From: "Gregg Hill" <bogus@xxxxxxxxxxx>
- Date: Sun, 16 Sep 2007 12:32:10 -0700
Lanwench,
You mentioned the well-known SID issue in a reply to someone on 9/1/07 in
this same newsgroup ("Tracing a break-in attempt"). I asked some more
questions, but they got missed, so here they are again.
I did not realize the SID was all that was needed (or is it?). However,
let's say one has a terminal server with 3389 open to the Internet (I know a
VPN first or firewall authentication first would help). How does the hacker
try to get into the TS? Don't they just start with "administrator" and a
dictionary or other attack? In that case, would not the changing of the
admin name help?
How does the "well-known SID" factor into such an attack?
--
Gregg Hill
DISCLAIMER WARNING: the information contained in any reply I make is merely
an OPINION, one that I hope you will consider when you make a choice as to
what you will do on your systems or network.
**No recommendation is to be implied by my OPINION.**
There, that should cover it!
"Lanwench [MVP - Exchange]"
<lanwench@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:OslDm0G%23HHA.5980@xxxxxxxxxxxxxxxxxxxxxxx
Ryan <Ryan@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
I disabled the administrator account for security reasons. At the
same time the event log shows failed administrator logon attempts.
Attempts repeat every 2 till 5 hours. The calling process has PID 944
which I looked up as svchost process.
This refers to the following services:
svchost.exe 944 AeLookupSvc, AppMgmt, BITS, Browser,
CryptSvc, dmserver, EventSystem,
helpsvc,
lanmanserver, lanmanworkstation,
Netman,
Nla, RasMan, RemoteAccess, Schedule,
seclogon, SENS, ShellHWDetection,
winmgmt,
wuauserv
I can not find any service that starts with Administrator account.
Does someone have any suggestions?
As Susan said, you need to re-enable it.
I don't bother to rename the admin account anymore, either. Security by
obscurity = pretty useless, as anyone trying to hack into your server is
going after the well-known SID anyway.
.
- Follow-Ups:
- Re: Process running under Adminstrator account
- From: kj [SBS MVP]
- Re: Process running under Adminstrator account
- References:
- Re: Process running under Adminstrator account
- From: Lanwench [MVP - Exchange]
- Re: Process running under Adminstrator account
- Prev by Date: Re: e-mail are not sent with exchange
- Next by Date: Re: Opinions Blackberry vs. Treo
- Previous by thread: Re: Process running under Adminstrator account
- Next by thread: Re: Process running under Adminstrator account
- Index(es):
Relevant Pages
|
Loading