Advertisement

07.22.2008 at 06:30AM PDT, ID: 23585001
[x]
Attachment Details

It appears somone (or something) is trying to hack into our server.  Is our server safe?

Asked by afs166 in Security Utilities, Networking Security Vulnerabilities, SBS Small Business Server

Tags:

I have been receiving this error message (see the snippet below) since the beginning of July.  When I look at the Security event log I see a FAILURE AUDIT. When I examine the details I see that different user names and passwords are being tried to gain access to the server.  So far, the username and password names have not matched and I don't believe that anyone has gained unauthorized access to the server.  The attempts last usually about 30 minutes, but some have been longer and there are typically 2 attempts per minute.  There is typically one attempt per day at differing times.

When I go to the System log I see warnings saying that the server was unable to logon the the Windows NT account "xxxxx" due to an unknown username or password.  The name XXXXX changes all of the time unless they ar trying to gain access using the administrator or variations of administrator account.  I assume they are using the administrator acccount with different passwords.  

Is there something that I should be doing to deflect these attempts to gain access to our server?
Start Free Trial
1:
2:
3:
4:
5:
6:
7:
8:
9:
10:
11:
12:
13:
14:
15:
16:
17:
Source Event ID Last Occurrence Total Occurrences 
  Security 529 7/21/2008 4:34 AM 8,449 * 
Logon Failure: 
  Reason: Unknown user name or bad password 
  User Name: julian 
  Domain: XX (I've changed our real domain name)
  Logon Type: 8 
  Logon Process: IIS 
  Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 
  Workstation Name: SERVERNAME (I've changed our real server name)
  Caller User Name: SERVERNAME$ (I've changed our real server name)
  Caller Domain: XX  (this was our own domain name - I've changed our real domain name)
  Caller Logon ID: (0x0,0x3E7) 
  Caller Process ID: 712 
  Transited Services: - 
  Source Network Address: - 
  Source Port: -
 
Loading Advertisement...
 
[+][-]07.22.2008 at 06:48AM PDT, ID: 22059289

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.22.2008 at 07:01AM PDT, ID: 22059421

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.22.2008 at 07:14AM PDT, ID: 22059579

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.22.2008 at 07:20AM PDT, ID: 22059650

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.22.2008 at 08:53AM PDT, ID: 22060722

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Security Utilities, Networking Security Vulnerabilities, SBS Small Business Server
Tags: Logon Failure - Unknown user name or bad password
Sign Up Now!
Solution Provided By: ormerodrutter
Participating Experts: 1
Solution Grade: B
 
 
[+][-]07.22.2008 at 11:29AM PDT, ID: 22062175

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628