Advertisement

03.22.2008 at 02:59PM PDT, ID: 23261953 | Points: 125
[x]
Attachment Details

How do I stop an intruder from bouncing around my network like this?

Asked by chrisdhicks in SBS Small Business Server, MS Internet Security & Accel, MS Forefront

Tags: Failure Audit 529

How do I stop an intruder from bouncing around my network like it was a ping pong game? I have ISA and SBS server 2003. I thought it was protected from these kinds of multiple attempts. Ive gone thru my logs and there are THOUSANDS of these attempts to gain access. The latest it seems to be from the source of an internal machine on the network but this is not the case. I scanned the particular machine for spyware and nothing. It doesnt seem to matter because if I turn off the machine he comes from and that is not listed. I also blocked via ISA hundreds of thousands of IPs from China, Russia and so on but this particular intruder I cannot stop. HOW DO I FIND ANS STOP???
Event Type:      Failure Audit
Event Source:      Security
Event Category:      Logon/Logoff
Event ID:      529
Date:            3/21/2008
Time:            11:50:20 AM
User:            NT AUTHORITY\SYSTEM
Computer:      MX-MAIL-SERVER
Description:
Logon Failure:
       Reason:            Unknown user name or bad password
       User Name:      kaitlin
       Domain:            SFMX
       Logon Type:      3
       Logon Process:      NtLmSsp
       Authentication Package:      NTLM
       Workstation Name:      OPS-MANAGER
       Caller User Name:      -
       Caller Domain:      -
       Caller Logon ID:      -
       Caller Process ID:      -
       Transited Services:      -
       Source Network Address:      192.168.1.50
       Source Port:      0


For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Event Type:      Failure Audit
Event Source:      Security
Event Category:      Logon/Logoff
Event ID:      529
Date:            3/21/2008
Time:            11:50:20 AM
User:            NT AUTHORITY\SYSTEM
Computer:      MX-MAIL-SERVER
Description:
Logon Failure:
       Reason:            Unknown user name or bad password
       User Name:      administrator
       Domain:            SFMX
       Logon Type:      3
       Logon Process:      NtLmSsp
       Authentication Package:      NTLM
       Workstation Name:      -
       Caller User Name:      -
       Caller Domain:      -
       Caller Logon ID:      -
       Caller Process ID:      -
       Transited Services:      -
       Source Network Address:      -
       Source Port:      -


For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Start Free Trial
 
Loading Advertisement...
 
[+][-]03.22.2008 at 05:39PM PDT, ID: 21188230

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.22.2008 at 06:38PM PDT, ID: 21188332

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.23.2008 at 04:11AM PDT, ID: 21189231

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.23.2008 at 03:29PM PDT, ID: 21190991

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.23.2008 at 05:47PM PDT, ID: 21191265

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.24.2008 at 12:47AM PDT, ID: 21192339

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.24.2008 at 12:49AM PDT, ID: 21192344

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.01.2008 at 07:33PM PDT, ID: 21259758

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.02.2008 at 04:37AM PDT, ID: 21261869

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.02.2008 at 04:39AM PDT, ID: 21261885

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.05.2008 at 05:37PM PDT, ID: 21290202

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]09.05.2008 at 02:39PM PDT, ID: 22404075

Experts Exchange has a courteous staff of administrators who help members get the most out of the website by means of administrative comments like this one.

Start your 7-day free trial to view this Administrative Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628