Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

cracker using KSecDD

Posted on 2000-05-18
9
Medium Priority
?
1,243 Views
Last Modified: 2013-12-28
We have 2 NT4 servers with public IP addresses and no firewall.
Someone is trying to crack accounts on these servers. We can see lots of failure messages in the security event logs. They are always from a different domain, different username, different password but with the same logon type = 3 (Network) and logon process = KSecDD (Security Device Driver). What does it mean ? How could we stop these cracking attempts ?

We plan to install a firewall but we would like to find a solution before it.
TIA for any information.
0
Comment
Question by:lde
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 2
  • +1
9 Comments
 
LVL 6

Accepted Solution

by:
setiawan earned 450 total points
ID: 2820654
Hi Ide,

becareful, not to share some folder on your server with full access if your server published to internet.

Before you setting your firewall
I suggest you install the latest service pack for your NT Server from MS site.

hope this helps.

  danny
0
 
LVL 86

Expert Comment

by:jkr
ID: 2820940
0
 

Expert Comment

by:vbadier
ID: 2824324
Hi

What about your server? Domain controler or stand-alone?

Regarding your errors, they might be domain controler, because , as i know, logon type 2 and Logon process = User32 are for local security authentification, but the process KsecDD and the Logon type 3 are used for domain authentification.

So, actually, in my opinion, the cracker is stoped by the normal logon athentification.

Sorry not able to help you more for the moment.

Regard's
0
Connect further...control easier

With the ATEN CE624, you can now enjoy a high-quality visual experience powered by HDBaseT technology and the convenience of a single Cat6 cable to transmit uncompressed video with zero latency and multi-streaming for dual-view applications where remote access is required.

 

Expert Comment

by:vbadier
ID: 2824331
Sorry, What you could do is enable network monitoring and store trame. Then when reviewing the trame, you could know more about who is attempting to go in (like his IP adress). Then you can lock this particular ip adress.

Hope this help.
0
 

Expert Comment

by:vbadier
ID: 2824370
Sorry, What you could do is enable network monitoring and store trame. Then when reviewing the trame, you could know more about who is attempting to go in (like his IP adress). Then you can lock this particular ip adress.

Hope this help.
0
 

Author Comment

by:lde
ID: 2843213
Thank you all.
It looks like we had forgotten shared folders on the servers. The cracker used a software to try logins on these shared folders.
Now, we have unshared and it's over.
0
 

Author Comment

by:lde
ID: 2843220
Comment accepted as answer
0
 

Author Comment

by:lde
ID: 2843221
Thanks to setiawan.
We had forgotten shared folders.
0
 
LVL 6

Expert Comment

by:setiawan
ID: 2843258
You're welcome
0

Featured Post

The Ideal Solution for Multi-Display Applications

Check out ATEN’s VS1912 12-Port DP Video Wall Media Player at InfoComm 2017. Kerri describes how easy it is to design creative video walls in asymmetric layouts and schedule detailed playlists ahead of time with its advanced scheduling feature.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article helps those who get the 0xc004d307 error when trying to rearm (reset the license) Office 2013 in a Virtual Desktop Infrastructure (VDI) and/or those trying to prep the master image for Microsoft Key Management (KMS) activation. (i.e.- C…
This article shows how to use a free utility called 'Parkdale' to easily test the performance and benchmark any Hard Drive(s) installed in your computer. We also look at RAM Disks and their speed comparisons.
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

715 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question