?
Solved

monitor users, security breach

Posted on 2008-10-31
10
Medium Priority
?
324 Views
Last Modified: 2013-12-04
Hello Experts,

I have 5 terminal servers that allow my plant workers to use thin clients to logon.
Each department has a workstation.
So say i have a windows department, with 8 employees that work in it.
the username is different for each department, with a generic password for all departments.
Recently i have had some reports of one department that is no 24 hours logon being used to probe our network.
I know the username and the password and to which termial server they are logging.
What i want to try and do, is catch them "in the act" so to speak.
I can turn on secuity logging on the domain and monitor for logon times, thats my first step.
Are there any other tips or tricks that will aid me in dealing with my offender?
0
Comment
Question by:wlacroix
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 2
  • +2
10 Comments
 
LVL 14

Expert Comment

by:dfxdeimos
ID: 22853908
Do you have a baseball bat?

Seriously though, what types of tips are you looking for? How to detect logins, monitor what they are doing, etc...
0
 
LVL 18

Expert Comment

by:sk_raja_raja
ID: 22854501
hahhhhahahhhahahahahhhahahhhaha...... probably you should some spy agent on those workstations as a background service, but still it will not be more effective
0
 
LVL 18

Expert Comment

by:sk_raja_raja
ID: 22854517
probably you can install the dameware client on these workstations and see from your machine what they are doing...even the VNC would help
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 18

Expert Comment

by:sk_raja_raja
ID: 22854529
The Classroom Spy Professional allows you to see live screens of remote computers. This way, you can always watch what users are doing on the remote computer. Additionally, you have the ability to take control of a remote computer by controlling the mouse and keyboard; this is especially useful when you need to assist the person who uses the remote computer. If you are an administrator, you can easily administer remote computers from your computer

http://www.sharewareconnection.com/titles/remote-screen.htm
0
 
LVL 9

Expert Comment

by:BDoellefeld
ID: 22855896
I've used employee activity monitor before, it's ok.

http://www.imonitorsoft.com/products.htm 
0
 
LVL 3

Author Comment

by:wlacroix
ID: 22857873
the workstations in my plant are dumb terminals, i use standard PCs with boot disks to hit my terminal servers, so nothing to install on the local, they dont even have hard drives.

So with all the users logged into termial services i need to monitor a session.

Can i view what they are doing without having to ask them permission, i think its a termial server setting but need to test.
0
 
LVL 14

Accepted Solution

by:
dfxdeimos earned 750 total points
ID: 22859224
0
 
LVL 3

Author Comment

by:wlacroix
ID: 22872075
dfx,

what i got out of that article is the ability to remote into a users session without permission. Thank you. I will award you partial points if anything else comes up.

In the mean time, where can one buy a bat :)
0
 
LVL 3

Author Comment

by:wlacroix
ID: 23028484
tonqxiaofeng,

this product looks to be designed for the desktop. We are running terminal services and I dont remember reading anything regarding terminal services.
0
 
LVL 4

Expert Comment

by:neopumpkin
ID: 25445611
late contribution, i know, but why didn't anyone mention that wlacroix could have used terminal services manager to view the session that his users are logged into.  

wlacroix, the setting you referred to is on the properties page of the users account in AD. on the terminal services tab, you can specify whether a user is required to click ok or not when viewing their session.
0

Featured Post

NFR key for Veeam Agent for Linux

Veeam is happy to provide a free NFR license for one year.  It allows for the non‑production use and valid for five workstations and two servers. Veeam Agent for Linux is a simple backup tool for your Linux installations, both on‑premises and in the public cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Background Information Recently I have fixed file server permission issues for one of my client. The client has 1800 users and one Windows Server 2008 R2 domain joined file server with 12 TB of data, 250+ shared folders and the folder structure i…
Article by: btan
The intent is not to repeat what many has know about Ransomware but more to join its dots of what is it, who are the victims, why it exists, when and how we respond on infection. Lastly, sum up in a glance to share such information with more to help…
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…
If you’ve ever visited a web page and noticed a cool font that you really liked the look of, but couldn’t figure out which font it was so that you could use it for your own work, then this video is for you! In this Micro Tutorial, you'll learn yo…
Suggested Courses
Course of the Month9 days, 4 hours left to enroll

764 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question