Re: Event ID 529 Question



Teneo,

Neat idea, I'll have a look at that and report back my findings, certainly does seem better than routing through the logs looking for a needle in a haystack.

Siv

"Teneo" <not@xxxxxxxx> wrote in message news:%232v7TdzdIHA.1168@xxxxxxxxxxxxxxxxxxxxxxx
Cool

May find the following useful to email you an alert instead of having to
manually check the logs..(assuming you have configured monitoring and reporting)
http://msmvps.com/blogs/bradley/archive/2005/01/31/34556.aspx


"Siv" <g@xxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:0B89A668-2D1D-4161-BEAE-1366EDF86F57@xxxxxxxxxxxxxxxx
Teneo,
Cheers, now I have found it and turned all logging tick boxes on.
Let's see what we find in a day or so.
Thanks for this.

Siv

"Teneo" <not@xxxxxxxx> wrote in message news:%23mwg6zydIHA.4260@xxxxxxxxxxxxxxxxxxxxxxx
Hi Siv

Main Server, Protocols, SMTP, here you find default smtp virtual server, right mouse click, properties and at the bottom click enable logging, then properties and advanced..


"Siv" <g@xxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:69D97E88-4C21-4A4A-A8F5-627AFB4D9F8C@xxxxxxxxxxxxxxxx
Teneo,

If I go into exchange do I click on the main server name or the SMTP Connector as I can't find the Advanced tab that you are talking about? I can see the "Diagnostic Logging tab" and the "Monitoring" tab neither seems to sound like what you are talking about.

If I go into the SMTP Connector and right-click that and go "Properties" I do get an "Advanced" tab but that has all the "send HELO instead of EHLO" type stuff which again doesn't look like what you are talking about?

Please advise, I am confused about where you are going to turn the logging on.

Thanks for your advice.

Siv

"Teneo" <not@xxxxxxxx> wrote in message news:%23YKTSzudIHA.4144@xxxxxxxxxxxxxxxxxxxxxxx
Hi Siv

we are seeing these also. Im pretty sure its to do with hacking attempt on port 25

Switch on logging on your default smtp server, need to click properties / advanced to tick options require ( I tick them all...lol )

Then in windows\system32\logfiles will see SMTPSVC1

Here you can look up the time and see the IP and if have ISA can block the IP.

Hope it helps.




"Siv" <g@xxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:F2B333D5-B641-4F6C-8337-1E8897B03974@xxxxxxxxxxxxxxxx
Just lately I have been seeing this in the event logs:

Logon Failure:
Reason: Unknown user name or bad password
User Name: Mickey
Domain:
Logon Type: 3
Logon Process: Advapi
Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Workstation Name: SERVER01
Caller User Name: SERVER01$
Caller Domain: DIRECT
Caller Logon ID: (0x0,0x3E7)
Caller Process ID: 1608
Transited Services: -
Source Network Address: -
Source Port: -

There is no "Mickey" user on our network, so it worries me that we have a hacker trying to get in using brute force logins as this occurred 45 times. Usually when you get this you see a source port and source IP Address, but these are not listed? We use wireless networking as well as the wired network so it is possible that someone could be attempting to login from outside the building using wireless, could this be why there is no IP or Port listed?

Any help/advice gratefully accepted.


Siv









.



Relevant Pages

  • RE: Message Delivery Failure on Incoming
    ... We are SMTP. ... Logging enabled as detailed. ... start the service StiSvc with arguments "" in order to run the server: ... see Help and Support Center at ...
    (microsoft.public.windows.server.sbs)
  • Re: ASP.Net V 2.0 problems with sending email
    ... Presumably it is trying to deliver it from the web server, ... parties smtp server. ... I suggest you try turn on the network Tracing asMischa has suggested. ... Microsoft MSDN Online Support Lead ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: ASP.Net V 2.0 problems with sending email
    ... Presumably it is trying to deliver it from the web server, ... parties smtp server. ... I suggest you try turn on the network Tracing asMischa has suggested. ... Microsoft MSDN Online Support Lead ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Login Errors Seem to indicate we are being hacked?
    ... As an example, my Sonicwall keeps a log that I can read from the regular UI, as well as having the ability to report to a syslog server or e-mail out the log info. ... thing on the box using that authentication package. ... The SMTP or IIS logs should answer everything. ... I'm not familiar with that particular router or its logging capabilities, ...
    (microsoft.public.windows.server.sbs)
  • Re: Login Errors Seem to indicate we are being hacked?
    ... I have turned on diagnostic logging on SMTP. ... we could turn something off on our own SMTP server to stop the devils from ... Caller User Name: SERVER01$ ...
    (microsoft.public.windows.server.sbs)