?
Solved

Catch Rogue User: Send SMS to Mobile Phone when Logon Detected

Posted on 2003-11-22
4
Medium Priority
?
212 Views
Last Modified: 2013-12-04
Question:
I would like to know how to have an SMS sent to my mobile phone when a certain user attempts to logon to a PC in our Win2k domain.

Background/Why/Problem:
I have changed the local and domain Administrator accounts to have only user privledges. I use a different user name to administer. I wish to catch the person who is trying to logon as "Administrator" (domain admin not local).  Even though they are wasting their time I feel the person must be spoken to. I have examined the logs but am always a few minutes behind... I need instant notification to my mobile as our users move between PC's quite frequently.

Our Setup:
3 x Windows 2000 Server Active Directory Domain Filesevers. Over 190 Windows 2000 Professional Clients joined to the domain. Users can logon using their own individual user account on any PC (roaming profiles).

Here is an example of the SMS I would like sent to my mobile phone:

22/11/2003 - 10:12am
PC NAME: "IPS-E4-LAB-26"
USER NAME: "Administrator"
MESSAGE: Failed Logon Attempt


Finally, I am willing to use a third party solution as long as you can recommend it and not just post a link.
0
Comment
Question by:Matite
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 4

Accepted Solution

by:
ferg-o earned 2000 total points
ID: 9809172

If you enable SNMP on the server and have it pump auditing events to OpenNMS ( http://www.opennms.org ) you can use an SMS modem to send you through the messages. I know of a company using this solution for all their network management stuff. They use a Siemens SMS modem.

Another way to do it, which may be tidier would be to use an IDS system like ISS or Manhunt which can send failed login messages via SNMP to OpenNMS.

If you have money you could use HP OpenView which has an SMS alerting add on option.
0
 
LVL 4

Expert Comment

by:ferg-o
ID: 9809173

If you enable SNMP on the server and have it pump auditing events to OpenNMS ( http://www.opennms.org ) you can use an SMS modem to send you through the messages. I know of a company using this solution for all their network management stuff. They use a Siemens SMS modem.

Another way to do it, which may be tidier would be to use an IDS system like ISS or Manhunt which can send failed login messages via SNMP to OpenNMS.

If you have money you could use HP OpenView which has an SMS alerting add on option.
0

Featured Post

The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In today's information driven age, entrepreneurs have so many great tools and options at their disposal to help turn good ideas into a thriving business. With cloud-based online services, such as Amazon's Web Services (AWS) or Microsoft's Azure, bus…
In a recent article here at Experts Exchange (http://www.experts-exchange.com/articles/18880/PaperPort-14-in-Windows-10-A-First-Look.html), I discussed my nine-month sandbox testing of the Windows 10 Technical Preview, specifically with respect to r…
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…
In this brief tutorial Pawel from AdRem Software explains how you can quickly find out which services are running on your network, or what are the IP addresses of servers responsible for each service. Software used is freeware NetCrunch Tools (https…
Suggested Courses
Course of the Month9 days, 20 hours left to enroll

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question