Solved

MS WinXP and Server 2003 machines with same administrator/password combination: "bad username or password" ???

Posted on 2009-04-15
7
329 Views
Last Modified: 2012-06-27
Hi,

I have a Windows XP PRO SP3 machine which is only member of a workgroup.
Furthermore I have a MS Windows 2003 SP2 machine with its own Active Directory.

On both machines the administrator username and password are the same.

OK, now I log in as an administrator on my WinXP machine:
Now, if I do a "net use * \\server\C$" from the commandline on the WinXP machine, I get an error that my username or password is invalid:

C:\Documents and Settings\Administrator>net use * \\SERVER\C$
The password or user name is invalid for \\SERVER\C$.

Enter the user name for 'SERVER':

Strange enough, when I now type in: administrator and my password, the share will be connected.

It's strange that the server is asking for my credentials, because the passwords of the administrator account are for both PC's identical!

I also have a third Win XP machine, also WinXP PRO SP3, with the same config as the machine stated above (not part of a domain, just its own workgroup).
This machine has also the same password for the Administrator account, when I execute the command to connect the share I don't have to fill out my credentials:

C:\Documents and Settings\Administrator>net use * \\SERVER\C$
Drive Y: is now connected to \\SERVER\C$.

The command completed successfully.

Now for  the verry weird part, I've setup a virtual machine, installing Server 2003 SP2 on it, and edited the administrator user to again, have the same password as all of the aforementioned machines.
If I execute the command to connect the C$-share to my previous "problematic" win XP machine, it works without it asking my credentials!

So why is it, that this one server will NOT accept the password from the administrator user from this particular Windows XP machine???

The reason I am asking this is because I wanted to use Remote Debugging for ASP.NET pages with this client machine and server.
I have Visual Studio 2008 installed on the XP machine, and remote debugger 2008 on the server.
But the problem was that the Administrator user could not log on to the debugger service, while from another PC or another user it WAS possilbe!
So I started narrowing this problem down, and now it seems that only the administrator account from this Win XP machine is rejected.
I get the following failure audit on the server when I try to connect as "Administrator":

Event Type:      Failure Audit
Event Source:      Security
Event Category:      Account Logon
Event ID:      680
Date:            15-4-2009
Time:            13:34:34
User:            NT AUTHORITY\SYSTEM
Computer:      SERVER
Description:
Logon attempt by:      MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
 Logon account:      Administrator
 Source Workstation:      WINXPMACHINE
 Error Code:      0xC000006A

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

As you will see, the error code: 0xC000006A means that the password is invalid.

I've been researching this problem for quite a while now, and cannot seem to fix it.
One other thing: if I create another user on this problematic winxp machine and the same user on the server with again the same password, then it will work, the server accepts the credentials right away. Only NOT from the administrator??









0
Comment
Question by:dplus
  • 4
  • 2
7 Comments
 
LVL 3

Expert Comment

by:ealcaniz
ID: 24147210
Error code: 0xC000006A (Error code 0xC000006A) - According to Microsoft Windows XP attempts a limited logon for each account that is displayed on the Welcome screen to determine whether to prompt the user for a password. An attempted logon is logged for each account displayed. To resolve this problem, obtain the latest service pack for Windows XP. To prevent these events from being logged, disable the Welcome screen and use the classic logon screen or turn off auditing of logon events.
0
 
LVL 3

Expert Comment

by:ealcaniz
ID: 24147253
Another check this key in registry
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\NoLMHash there 3 values. Put 1 or 0.
More details in

How to prevent Windows from storing a LAN manager hash of your password in Active
Directory and local SAM databases
<http://support.microsoft.com/kb/299656/en-us>
0
 

Author Comment

by:dplus
ID: 24147320
All systems are fully patched and up-to-date with the latest service packs.
The policy: "Network security: Do not store LAN Manager hash value on next password change" is disabled and HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\NoLMHash has the value 0 (zero).
0
Free Gift Card with Acronis Backup Purchase!

Backup any data in any location: local and remote systems, physical and virtual servers, private and public clouds, Macs and PCs, tablets and mobile devices, & more! For limited time only, buy any Acronis backup products and get a FREE Amazon/Best Buy gift card worth up to $200!

 

Author Comment

by:dplus
ID: 24147466
By the way: the password for the administrator account is on all pc's more than 15 characters long and meets the complexity requirements. Wanted to say that because of the NTLM comments posted above by ealcaniz.
0
 
LVL 6

Expert Comment

by:danf0x
ID: 24147753
Hello I thought I would chime in on this.
  Remember that on a workgroup it tries to authenticate machinename/username not domain/username.  If the machine is not on the domain but the server does have a domain user the user and pass are the same but the group it tries to authenticate to is different.
0
 

Author Comment

by:dplus
ID: 24148036
Please understand it's only the ADMINISTRATOR account of 1 XP-machine which is giving problems.

If I create other users on this machine, or if I use another Administrator account on a different XP machine that is also NOT part of a domain, all goes well....

0
 

Accepted Solution

by:
dplus earned 0 total points
ID: 24599267
I did a reinstall of my Windows 2003 server, and all is functioning OK now.
Still don't know how this could happen...
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
If you need to start windows update installation remotely or as a scheduled task you will find this very helpful.
The viewer will learn how to successfully create a multiboot device using the SARDU utility on Windows 7. Start the SARDU utility: Change the image directory to wherever you store your ISOs, this will prevent you from having 2 copies of an ISO wit…
The Task Scheduler is a powerful tool that is built into Windows. It allows you to schedule tasks (actions) on a recurring basis, such as hourly, daily, weekly, monthly, at log on, at startup, on idle, etc. This video Micro Tutorial is a brief intro…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now