Event 529

The event shows up like the following:
Event ID: 529
Source: Security
Type: Failure Audit
Category:  Logon/Logoff
User: NT AUTHORITY\SYSTE

Description:
Logon Failure:
  Reason:  Unknown user name or bad password
  User Name:  randyb
  Domain:  Snoopy
  Logon Type:  2
  Logon Process:  IIS
  Authentication Package:  MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
  Workstation Name:  Snoopy1

Snoopy1 is the server name.  We don't have a user name as randyb in our domain.  I can track down the ip address of randyb.  Here's the problem:
Our IT department believes that a "spidering technology" such as AskJeeves is indexing our servers.  I think that it is a hacker using a password cracker against us.  Can an indexing situation cause a 529 event id error?  If not, how is randyb trying to get into our servers so that I can stop him?  This is a NT 4 box.  Randyb is a remote user that isn't a domain user of ours.
ninja11Asked:
Who is Participating?
 
luvshakCommented:
Hi,

Try the below links:

http://support.microsoft.com/search/preview.aspx?scid=kb;en-us;Q172402 (This one talks about Event 529)

http://support.microsoft.com/default.aspx?scid=kb;en-us;Q182918 (This is a continue of above link)

This hopefully will answer your question.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.