It is a computer unknown to me
Main Topics
Browse All TopicsOur sbs server is on the internet. For protection ISA 2004 is installed and is running. Anonymous access has been disabled in the gpo the anonymous account has been renamed as well, just in case.
However, we keep getting these:
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 540
Date: 5/8/2007
Time: 9:47:40 PM
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: happy
Description:
Successful Network Logon:
User Name:
Domain:
Logon ID: (0x0,0x100B7AB)
Logon Type: 3
Logon Process: NtLmSsp
Authentication Package: NTLM
Workstation Name: DHWEB1
Logon GUID: -
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: 65.210.203.90
Source Port: 0
Not a lot and generally from the same ip address: and a few minutes later is the corresponding 538 logout which matches the login ID.
The server is standalone environment (colo server) so there is no lan machines. All IPs are external.
I have searched everywhere and there has been no specific yes or no you are being hacked if you see the above. I think we are, but how do i stop it using ISA 2004?
Please help
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Then do you have any web applications that are open to the Internet? Because anonymous authentication doesn't get anyone into much of anything... but if you have an ASP web site that is set to allow for anonymous authentication, then it's quite possible that someone is looking at it... but that doesn't mean at all that you are being hacked.
Jeff
TechSoEasy
Business Accounts
Answer for Membership
by: r-kPosted on 2007-05-09 at 09:33:10ID: 19058350
Is 65.210.203.90 your server address, or some computer known to you? It seems to be in the Dallas area.
echnet/pro dtechnol/w indows2000 serv/ maint ain/monito r/logonoff .mspx
Event ID 540 is discussed in this link:
http://www.microsoft.com/t