Re: Yikes! Is this a security issue I need to worry about?
- From: "Paul Shapiro" <paul@xxxxxxxxxxxxxxxxxxxxxxx>
- Date: Sun, 20 Apr 2008 12:16:03 -0400
I looked into similar events on a client's system this morning. I think the break-in attempt is trying to authenticate during an SMTP connection, looking for a valid username/password. The user names tried were things like admin, root, test, info, sales, guest, etc. Enabling SMTP logging should verify the details. I just enabled the logging this morning, so I don't yet have proof this is the source, but I found a number of similar reports when searching. Those reports indicated that ADVAPI is the logon process used to validate smtp authentication requests.
"tcv" <thecomputervalet@xxxxxxxxx> wrote in message news:97bb4817-e0bd-490b-919b-4bbf0842afc8@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
On Apr 19, 7:40 pm, Susan Bradley <sbrad...@xxxxxxxxxxx> wrote:Bill Sanderson wrote:
> I don't have a lot of depth in this stuff, but here's what I'm reading:
> Logon type 3 is a logon across a network.
> Advapi indicates a logon handled though IIS.
> So--IIS is active on this box?
> Is the IP dynamic, or fixed?
> "tcv" <thecomputerva...@xxxxxxxxxxx> wrote in message
>news:Xns9A856049E1EA5thecomputervaletgeem@xxxxxxxxxxxxxxxx
>> I found this occurring 60+ times last night. The server is publicly
>> accessable through LogMeIn. It also is behind a SonicWall that has VPN
>> setup with Radius Authentication.
>> Reason: Unknown user name or bad password
>> User Name: !@#$
>> Domain:
>> Logon Type: 3
>> Logon Process: Advapi
>> Authentication Package: Negotiate
>> Workstation Name: SERVER
>> Caller User Name: SERVER$
>> Caller Domain: [REDACTED]
>> Caller Logon ID: (0x0,0x3E7)
>> Caller Process ID: 1508
>> Transited Services: -
>> Source Network Address: -
>> Source Port: -
>> Cheers,
>> m
It's an SBS box... of course IIS is working :-)
What ports do you have open? If 25 it's just someone banging on the port.
Yes, 25 is open. Why would it say advapi and not, say, SMTP?
I also misstated the original attempts. It was 160+
.
- Follow-Ups:
- Re: Yikes! Is this a security issue I need to worry about?
- From: tatat
- Re: Yikes! Is this a security issue I need to worry about?
- From: Bill Sanderson
- Re: Yikes! Is this a security issue I need to worry about?
- References:
- Yikes! Is this a security issue I need to worry about?
- From: tcv
- Re: Yikes! Is this a security issue I need to worry about?
- From: Bill Sanderson
- Re: Yikes! Is this a security issue I need to worry about?
- From: Susan Bradley
- Re: Yikes! Is this a security issue I need to worry about?
- From: tcv
- Yikes! Is this a security issue I need to worry about?
- Prev by Date: Re: Exchange problems After changing FireWall Harware
- Next by Date: Re: Client Connectivity in SBS 2003 issue
- Previous by thread: Re: Yikes! Is this a security issue I need to worry about?
- Next by thread: Re: Yikes! Is this a security issue I need to worry about?
- Index(es):
Relevant Pages
|