Solved

cracker using KSecDD

Posted on 2000-05-18
9
1,196 Views
Last Modified: 2013-12-28
We have 2 NT4 servers with public IP addresses and no firewall.
Someone is trying to crack accounts on these servers. We can see lots of failure messages in the security event logs. They are always from a different domain, different username, different password but with the same logon type = 3 (Network) and logon process = KSecDD (Security Device Driver). What does it mean ? How could we stop these cracking attempts ?

We plan to install a firewall but we would like to find a solution before it.
TIA for any information.
0
Comment
Question by:lde
  • 3
  • 3
  • 2
  • +1
9 Comments
 
LVL 6

Accepted Solution

by:
setiawan earned 150 total points
Comment Utility
Hi Ide,

becareful, not to share some folder on your server with full access if your server published to internet.

Before you setting your firewall
I suggest you install the latest service pack for your NT Server from MS site.

hope this helps.

  danny
0
 
LVL 86

Expert Comment

by:jkr
Comment Utility
0
 

Expert Comment

by:vbadier
Comment Utility
Hi

What about your server? Domain controler or stand-alone?

Regarding your errors, they might be domain controler, because , as i know, logon type 2 and Logon process = User32 are for local security authentification, but the process KsecDD and the Logon type 3 are used for domain authentification.

So, actually, in my opinion, the cracker is stoped by the normal logon athentification.

Sorry not able to help you more for the moment.

Regard's
0
 

Expert Comment

by:vbadier
Comment Utility
Sorry, What you could do is enable network monitoring and store trame. Then when reviewing the trame, you could know more about who is attempting to go in (like his IP adress). Then you can lock this particular ip adress.

Hope this help.
0
Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

 

Expert Comment

by:vbadier
Comment Utility
Sorry, What you could do is enable network monitoring and store trame. Then when reviewing the trame, you could know more about who is attempting to go in (like his IP adress). Then you can lock this particular ip adress.

Hope this help.
0
 

Author Comment

by:lde
Comment Utility
Thank you all.
It looks like we had forgotten shared folders on the servers. The cracker used a software to try logins on these shared folders.
Now, we have unshared and it's over.
0
 

Author Comment

by:lde
Comment Utility
Comment accepted as answer
0
 

Author Comment

by:lde
Comment Utility
Thanks to setiawan.
We had forgotten shared folders.
0
 
LVL 6

Expert Comment

by:setiawan
Comment Utility
You're welcome
0

Featured Post

Why do Marketing keep bothering you?

Is your marketing department constantly asking for new email signature updates? Are they requesting a different design for every department? Do they need yet another banner added? Don’t let it get you down! There is an easy way to manage all of these requests...

Join & Write a Comment

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
If you get continual lockouts after changing your Active Directory password, there are several possible reasons.  Two of the most common are using other devices to access your email and stored passwords in the credential manager of windows.
The viewer will learn how to successfully create a multiboot device using the SARDU utility on Windows 7. Start the SARDU utility: Change the image directory to wherever you store your ISOs, this will prevent you from having 2 copies of an ISO wit…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now