Question

Explaining Failure Audits

Asked by: skbohler

Last night I got a ton of Audit Failure event log entries.

How can I tell the type of access they're attempting from looking at the entry?

Example:

EVENT # 14330
EVENT LOG Security
EVENT TYPE Audit Failure
SOURCE Security
CATEGORY Account Logon
EVENT ID 681
USERNAME NT AUTHORITY\SYSTEM
COMPUTERNAME   IPDAEW0061MIA
TIME 1/4/2004 7:40:07 PM
MESSAGE The logon to account: anyone
by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
from workstation: IPDAEW0061MIA
failed. The error code was: 3221225572
 
EVENT # 14418
EVENT LOG Security
EVENT TYPE Audit Failure
SOURCE Security
CATEGORY Account Logon
EVENT ID 681
USERNAME NT AUTHORITY\SYSTEM
COMPUTERNAME   IPDAEW0061MIA
TIME 1/4/2004 7:40:17 PM
MESSAGE The logon to account: test
by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
from workstation: IPDAEW0061MIA
failed. The error code was: 3221225572

Are these people trying to access via FTP, Frontpage, direct login, Terminal Services, etc.?

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2004-01-05 at 05:22:09ID20840915
Tags

microsoft_authentication_package_v1_0

Topics

Windows Network Security

,

Operating Systems Network Security

Participating Experts
3
Points
125
Comments
23

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Auditing Policy
    Good Day, I have turned on Auditing for the everyone group on a specific file on a server. The right is list folder/read data and failed is checked. I then go to events viewer, security and i see failures from users who have access to the specific folder. Here is the data th...
  2. Audit
    Hi Please can anyone tell me how i can have the trace for any files or folders been deleted by user in network i am using windows 2000 server and i want to have a trace for any file deleted by user ,like this i can know who delete a specific file or folder.. how i can set ...
  3. Audit Failure 565
    This event shows up in our event logs about 3 to 4 times a second as an audit failure. If anyone has any insight on this it would be very helpful. If you need further information please ask and thanks for your help! EVENT LOG Security EVENT TYPE Audit Failure SOURCE Se...
  4. Failure Audits with "Aloha" as the username.
    I have two clients that have Server 2003 that are getting the following Failure Audit in the security logs: Event Type: Failure Audit Event Source: Security Event Category: Account Logon Event ID: 672 Date: 11/19/2008 Time: 6:22:56 PM User: NT AUTHO...
  5. Windows 2003 Audit polidy success/failure audits - s…
    I have enabled audit logs on a folder, and tested it out. I added "domain users" as the group to audit thinking that this would include everyone in the domain. Well when I open the folder being audited it creates 8 logs in the security folder. This just seems lik...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: LucFPosted on 2004-01-05 at 05:30:45ID: 10042828

Hi skbohler,

Take a look at this question: http:Q_20830678.html

Greetings,

LucF

 

by: skbohlerPosted on 2004-01-05 at 05:33:41ID: 10042858

That was an original post of mine. Unfortunately, I didn't get the correct answers.

~Steve

 

by: LucFPosted on 2004-01-05 at 05:36:21ID: 10042882

Hmm, sorry about that.... :-(

Is this a known workstation for you: IPDAEW0061MIA If not, check your firewall settings.

 

by: skbohlerPosted on 2004-01-05 at 05:45:23ID: 10042981

Yes, that workstation is our server.

 

by: LucFPosted on 2004-01-05 at 05:51:17ID: 10043039

Check if you have anything scheduled at this time:
7:40:00 PM
Maybe backup/database cleaning... whatever... And look what username and passwords are set for these.

 

by: skbohlerPosted on 2004-01-05 at 05:57:17ID: 10043120

Good idea. I checked, but there is nothing.

There were about 600 of these attempts last night using all sorts of different usernames: oracle8, root, anyone, informix, ftproot, pwrchute, web, webmaster.

Looks like some person/software is trying out every typical username to try and gain entry.

 

by: LucFPosted on 2004-01-05 at 06:02:32ID: 10043176

 

by: Joseph_MoorePosted on 2004-01-05 at 08:00:52ID: 10044420

Well, Event ID 681 is detailed in this Technet article:
http://support.microsoft.com/?kbid=273499

And the specific decimal code error you have, 3221225572, correlates to this description:  "User logon with misspelled or bad user account"

So, someone is trying to do a brute force attack against your server, IPDAEW0061MIA. Is this a web server running IIS, or FTP, or SMTP, or any IIS-related service? Is this server on the Internet, with a public IP address or a NATted IP, so that anyone from the Internet can hit it? I have not looked at your previous question yet, so I'm sorry if I am repeating previous questions posted to it.

 

by: skbohlerPosted on 2004-01-05 at 08:04:47ID: 10044454

Yes, it's a web server on the Internet (behind a firewall at the hosting provider).

It's got a public IP address.

 

by: Joseph_MoorePosted on 2004-01-05 at 08:44:23ID: 10044785

Ok, so it is a web server. Is IIS running the web server function, or are you running Apache? Also, is it doing anything else, like FTP or e-mail (SMTP or POP3)? If so to that, is IIS or MS Exchange running that? And, is it doing anything else? Any other public-accessible functions?
Also, can you access the server to check, if IIS is running the web server, the W3SVC web server access logs?
Lastly, do you know if the hosting provider blocked all Windows ports (TCP 135, 139, 445, UDP 137-138) with their firewall?

 

by: skbohlerPosted on 2004-01-05 at 09:03:12ID: 10044965

IIS is the web publishing software.

Yes, we can access the W3SVC logs.

These are the rules that they said they configured the firewall with:

Trust to Untrust: Allow ANY
Untrust to Trust: Allow FTP
Untrust to Trust: Allow SMTP
Untrust to Trust: Allow DNS
Untrust to Trust: Allow HTTP
Untrust to Trust: Allow HTTPS
Untrust to Trust: Allow POP3
Untrust to Trust: Allow TS

They've also opened certain ports used, like 8888 and 8090

 

by: ampcatsPosted on 2004-01-05 at 09:09:38ID: 10045050

is there any need for authenticated users to be able to log on externally?
I assume you have run iislockdown tool

http://www.microsoft.com/windows2000/downloads/recommended/iislockdown/default.asp

and made sure you are up to date on sec patches (at least sp3 with patches
MS03-026
MS03-018 and
MS03-051 (esp if you run frontpage extensions)

in IIS settings, enable logging - next time you get an attack, match up http requests to times...

 

by: skbohlerPosted on 2004-01-05 at 09:13:09ID: 10045086

We need for a few users to access via Terminal Services and FTP.

I ran IISlockdown once, and it screwed some things up. I had to uninstall it.

All the security patches are up-to-date, according to windowsupdate.microsoft.com (or could I still be missing some?)

Where do I enable logging in IIS?

Thanks!

 

by: ampcatsPosted on 2004-01-05 at 09:17:48ID: 10045134

oop - took a while to post that - got one answer before posted Q

very related q is just below here

http://www.experts-exchange.com/Security/Win_Security/Q_20839897.html

i won't copy it - but see what is listening as well

 

by: Joseph_MoorePosted on 2004-01-05 at 09:32:06ID: 10045258

Ok, this is what it looks like to me. No NetBIOS ports are open from the Internet to your server, so that rules out that out. It probably is just someone using a tool like X-Scan, which can launch multiple-protocol attacks against a single target. These tools will take a username list and a dictionary file, and run through the total combinations against FTP, SMTP, Web, POP3, trying to find a username/password combo that is valid on the target.
That is probably what is happening here. I run Win2K servers as web servers, and I have seen this in my logs also.
There are things you can do to minimize the amount of risk. Now, things like strong, difficult to crack passwords, are a must. That's a given.
A web site suggestion I have for you involves Web Folders. Is your website installed in the C:\Inetpub\wwwroot folder? If so, I suggest you move it to another folder. WWWROOT folder has Web Folders functionality enabled by default; Web Folders lets an authenticated user use IE to drag-n-drop files to/from the web server (if they have read/write rights) just like using Windows Explorer. Now personally, I HATE Web Folders, and I never enable it. It is an attack vector. Someone can try to guess usernames/passwords using Web Folders. So I always say to not use the WWWROOT folder for this very reason. You can move your website to a different folder on the server, and make sure that Web Folders does not get enabled on this new folder.
You also might want to make sure that the IUSR_"MACHINENAME" account only has Read access on the website folder structure (no matter where you save it on the server), not Full Control or Write. Also, make sure the Everyone group does NOT have rights to the web site folder structure.
Something that I have found that is interesting that can be dangerous to an IIS-powered website is the Write checkbox when you look at the web site Properties in the Internet Services Manager snap-in. Don't allow the Write checkbox that is on the Home Directory tab of the website. It is possible, with Write enabled, and some NTFS permissions mis-set, to let external users delete your website by doing an HTTP DELETE command! Not the problem you are experiencing, but just one of the things I worry about with IIS and webservers!
Now, as for trying to find out what is happening, I would check the W3SVC logs (and SMTP and FTP) on the server, under the C:\Winnt\system32\logfiles directory. Check them, and try to co-orespond any interesting entries you see with the SEcurity log Failure Audits you have. The Security log, as you have seen, does NOT record the IP address of attackers. I know, annoying; that is how it works!
But, the W3SVC logs (as well as the other IIS processes, if they are attacked), DO record the IP address. It might be possible to find a few website hits that happened just before the attacks started. You might see all kinds of strange stuff in the W3SVC logs while the attacks were going on.
You see, IIS is treated just like normal Windows authentication in regards to the logging of failed logon events. It is logically the same as when you log into a Windows computer and type in the wrong password. Similar functions are called. I've spoken with Microsoft tech support on this before, and I was astonished to learn that IIS connections are just like drive mappings. The same logic applies. Users who have access to the files are granted access; if you don't have access, you are denied.
So, check the W3SVC logs, and match them up with the Security logs, to try and get an IP.
A couple of things to keep in mind. The IIS logs are all GMT time, so you will need to add/subtract the appropriate number of hours to match up the events with the SEcurity log events.
Also, the attacker could have had  his dictionary attack tool route through a public proxy server (if he was smart!). So, the IP you might find in the logs may not be the actual attacker IP. Just keep that in mind. But, any IP you can get is a place to start.
So, that is what I think is happening. Someone using a dictionary attack tool, scanning your server on possibly multiple ports against multiple services, looking for a weak username/password combo. Happens every day.
And BTW, I really don't like having Terminal Services enabled over the Internet like yours does. That is risky. Because say the attacker were to find a valid username/password combo in his scans. He could then connect via TS using that username/password and be IN YOUR SERVER! I always tell people to NOT have TS be available over the Internet. Just too dangerous. Plus, there is at least 1 tool that is specifically designed to do the dictionary attack against a TS session itself. The other services your server has I can understand, with web, ftp, e-mail. Sure. But TS is something I suggest you really consider if you want to risk having it open.
hope this slightly rambling stuff helps!

 

by: skbohlerPosted on 2004-01-05 at 09:42:54ID: 10045350

I'll try that out. Thanks!

If I shouldn't use TS, how can I administer my server without it?

 

by: Joseph_MoorePosted on 2004-01-05 at 09:58:54ID: 10045488

Oh, I saw your question on IIS logging (I am at work, so I can't check this thread that often). It is enabled by default on all IIS processes. Go to C:\WINNT\System32\LogFiles and there will be at least 1 subfolder for each IIS process, W3SVC1, MSFTPSVC1, SMTPSVC1. Those are the default folder names. Web is in W3SVC, FTP in MSFTPSVC and SMTP in SMTPSVC. There will be a .LOG file per day. They are just text files. You can open them in Excel; there are column headers at the top of each one.
Personally, I would start with the WEb logs. That is the most common attack vector. Check it out for anything strange, that relates to the times in the Security log file. Then go to FTP next. SMTP last. You will probably see something strange.
When you get the IP address(es) of attackers, do   a WHOIS to see who ownes them. You can take actions from there. Also, keep the IIS logs for any future legal action, as well as an export of your Security logs, in the event that you decide to do any legal action. Since no one is getting into your server (since all you have are failure events), then why bother. But you could at least take the attacker IPs and have the Hosting PRovider block those IPs at their firewall from getting to your server. Legal action is something else, and really only done if an attacker gets in and destroys your server.

 

by: skbohlerPosted on 2004-01-05 at 10:00:47ID: 10045498

OK, I've already had logging on all the while.

 

by: Joseph_MoorePosted on 2004-01-05 at 10:04:35ID: 10045529

As for how else you can remotely admin your server since TS is not a safe way, the usual answer is via VPN.
You see, I view TS open on the Internet like this as just as dangerous as having TCP ports 139 and 445 open! Yes, the famous Windows File Sharing ports. I think that TS is just as dangerous. You can bang against these ports with no initial authentication required, and try to guess a valid username/password, and if you get one, you are in and you can do anything you want! Just too risky!
So, this is why a VPN solution is good. The VPN ports/protocols are open at the firewall, and once you authenticate at the VPN, the rest of your traffic is routed through the VPN encrypted tunnel. So, you would connect via VPN, then launch your TS client. TS is NOT enabled through the firewall. Your TS session goes through the VPN tunnel, to the hosting provider, which then the VPN box there routes it to the TS port on the server internally, not to the Internet side. Much more secure. You could see if your hosting provider has a VPN setup in place for you to use to admin your box.

 

by: ampcatsPosted on 2004-01-05 at 10:18:47ID: 10045669

really, if your network is open, then all you can do is watch and secure against it...

watch...if attempts are to crack the IIS...

w3svc logs are the same - control panel, administrative tools, internet services manager, right click on root web, properties, edit master properties, enable logging, choose hourly if you are a fairly busy server (mine are secure client access (support pages and http served CRM pack for roadwarriors) and hack attempts only - 1 days log averages about 80K ) extended file format, extended properties, tick

time               duh - useful to tie with audit logs
c-ip                don't want them to be anonymous
s-sitename     what they were using to try it on with
s-port            where were they knocking?
cs-uri-query   what were they wanting?


to protect against anything...

the other things is that you can do is
narrow down terminal services access to only the accounts that need it no - access for unauthorised
disable logon permissions to relaxed office hours except for boss / roadwarriors - then overnight attempts by 9-5ers will just be ignored

passwords - passwords - passwords

make sure you have good passwords that have numbers / symbols / case mix in them - high security accounts, add a ALT-xxx between 130 and 250 on numeric keypad - most attempt programs don't even touch those symbols!
LOCKOUT more than 4 failed attempts for say 1 hour


A.

 

by: skbohlerPosted on 2004-01-05 at 10:23:03ID: 10045717

How do you specify which accounts have TS access?

 

by: ampcatsPosted on 2004-01-05 at 10:42:47ID: 10045866

joseph - lot of typing in little time - nice to see an expert that don't cut and paste standard lists to every post, and does read stuff! - it's what drove me away in '01

skbholer
if you still have the linksys BEFSR41 (from your post history)

http://www.linksys.com/Download/firmware.asp?fwid=3   has latest firmware which supports multi-L2TP-pass-through, previous ones didn't.

http://www.microsoft.com/windows2000/server/evaluation/news/bulletins/l2tpclient.asp  has a 98 / me / nt4 L2TP client but i have not used it.

 

by: ampcatsPosted on 2004-01-05 at 10:55:17ID: 10045949

oops that is version 1 and 2 firmware -

http://www.linksys.com/Download/firmware.asp?fwid=183   is ver 3

also, to prevent users from having TS access, uncheck the 'log on locally' permission to the terminal server in question...

http://www.microsoft.com/technet/prodtechnol/win2kts/maintain/optimize/secw2kts.asp it is a good read on TS - among it, is

Avoid installing Terminal Services on a domain controller for application sharing. Users or groups that access the Terminal Server must have the Log on Locally permission. If Terminal Services is installed on a domain controller, users would have the Log on Locally permission for all domain controllers within the domain. Terminal Services should only be installed on domain controllers in Remote Administration mode only. In addition, the Log on Locally permission should be granted only to administrators.

(of course that means you need to buy another copy of 2ksvr!) - but limiting it to those that need it is better than globally

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...