Re: Determine attacker IP?

Tech-Archive recommends: Fix windows errors by optimizing your registry



AllenM wrote:
Wrong. Although attackers do tend to use bizzare account names their
favorites are accounts that "do" exist such as "administrator"
"guest". They usually try to get in through the FTP port so if your
SBS server isn't a FTP server (and it shouldn't be) then you should
just disable FTP. Also the best way to stop this is to rename the
administrator account and disable the guest account.

The "best way" is have solid password policies (& human procedures),
complex, and changed often coupled with monitoring dillegence.

Guest should be disabled by default and shouldn't be enabled. Renaming
administrator offers little (but some) protections. Third party products
that install using a default service account should be much more of a
concern.

There are other effective hardening methods, but for SBS, this and a good
firewall with only required open ports should suffice.


ork.org> wrote in message
news:O19JXZ9nIHA.4832@xxxxxxxxxxxxxxxxxxxxxxx
Some persistent soul or drone attempted to log into my server
Administrator account. He/it tried about 30 times over two days at
4:40 in the morning. Is there an easy way to determine his IP
address and block or report it. I guess I'm dreaming about the
reporting part. SBS R2 Premium, ISA 2004 SP3. I get about one or two
break-in
attempts a month. Not bad. Usually, attackers try bizarre account
names that don't exist. Naturally, I have S7r0onN6Gg passwords/pass
phrases. Jim G

--
/kj


.



Relevant Pages

  • Re: Determine attacker IP?
    ... Although attackers do tend to use bizzare account names their ... usually try to get in through the FTP port so if your SBS server isn't a FTP ...
    (microsoft.public.windows.server.sbs)
  • Re: Help: Seeting Guest privilege for FTP login
    ... > I cannot set guest privileges for Guest Login for FTP. ... There's no 'guest' account in SUN's ...
    (comp.sys.sun.admin)
  • Re: Help with Guest account
    ... Account and created a new User Account. ... Same thing in the Guest ... problem accessing the internet with it as it uses that same network ... enable the Guest Account is "an" administrator account. ...
    (microsoft.public.windowsxp.security_admin)
  • RE: Bypass Traverse Checking?
    ... Authenticated Users, because they are significantly different (different ... account without that SID in its token would not be able to access the ... you are affecting Anonymous Logon and the _builtin_ Guest ... account. ...
    (Focus-Microsoft)
  • Re: Office 2004 Mainstream Support Has Been Extended two years!
    ... Further research indicates that it affects systems where the the Guest ... Phillip: I should have done a bit more research :-) ... concept of a "Guest" account. ... John McGhie, Microsoft MVP, Consultant Technical ...
    (microsoft.public.mac.office.word)