Solved

cracker using KSecDD

Posted on 2000-05-18
9
1,239 Views
Last Modified: 2013-12-28
We have 2 NT4 servers with public IP addresses and no firewall.
Someone is trying to crack accounts on these servers. We can see lots of failure messages in the security event logs. They are always from a different domain, different username, different password but with the same logon type = 3 (Network) and logon process = KSecDD (Security Device Driver). What does it mean ? How could we stop these cracking attempts ?

We plan to install a firewall but we would like to find a solution before it.
TIA for any information.
0
Comment
Question by:lde
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 2
  • +1
9 Comments
 
LVL 6

Accepted Solution

by:
setiawan earned 150 total points
ID: 2820654
Hi Ide,

becareful, not to share some folder on your server with full access if your server published to internet.

Before you setting your firewall
I suggest you install the latest service pack for your NT Server from MS site.

hope this helps.

  danny
0
 
LVL 86

Expert Comment

by:jkr
ID: 2820940
0
 

Expert Comment

by:vbadier
ID: 2824324
Hi

What about your server? Domain controler or stand-alone?

Regarding your errors, they might be domain controler, because , as i know, logon type 2 and Logon process = User32 are for local security authentification, but the process KsecDD and the Logon type 3 are used for domain authentification.

So, actually, in my opinion, the cracker is stoped by the normal logon athentification.

Sorry not able to help you more for the moment.

Regard's
0
WordPress Tutorial 1: Installation & Setup

WordPress is a very popular option for running your web site and can be used to get your content online quickly for the world to see. This guide will walk you through installing the WordPress server software and the initial setup process.

 

Expert Comment

by:vbadier
ID: 2824331
Sorry, What you could do is enable network monitoring and store trame. Then when reviewing the trame, you could know more about who is attempting to go in (like his IP adress). Then you can lock this particular ip adress.

Hope this help.
0
 

Expert Comment

by:vbadier
ID: 2824370
Sorry, What you could do is enable network monitoring and store trame. Then when reviewing the trame, you could know more about who is attempting to go in (like his IP adress). Then you can lock this particular ip adress.

Hope this help.
0
 

Author Comment

by:lde
ID: 2843213
Thank you all.
It looks like we had forgotten shared folders on the servers. The cracker used a software to try logins on these shared folders.
Now, we have unshared and it's over.
0
 

Author Comment

by:lde
ID: 2843220
Comment accepted as answer
0
 

Author Comment

by:lde
ID: 2843221
Thanks to setiawan.
We had forgotten shared folders.
0
 
LVL 6

Expert Comment

by:setiawan
ID: 2843258
You're welcome
0

Featured Post

Optimize your web performance

What's in the eBook?
- Full list of reasons for poor performance
- Ultimate measures to speed things up
- Primary web monitoring types
- KPIs you should be monitoring in order to increase your ROI

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article summaries thoughts and ideas from two years of sustained use. It provides good reasoning to make the jump to Windows 10.
Windows 10 Creator Update has just been released and I have it working very well on my laptop. Read below for issues, fixes and ideas.
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question