Solved

Security Audit Event 5152.  Is this a concern?

Posted on 2013-01-01
6
707 Views
Last Modified: 2013-01-09
I'm getting the attached event.  Do I need to be concerned?
audit.jpg
0
Comment
Question by:J.R. Sitman
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 21

Expert Comment

by:Radhakrishnan R
ID: 38734562
Hi,

This looks like the windows firewall hasn't set correctly for the inbound traffic. Also, it could be edge traversal settings. Have a look at this MS article and try to set edge traversal and see it stops the event.
 http://technet.microsoft.com/en-us/library/ee649264(v=ws.10).aspx
0
 

Author Comment

by:J.R. Sitman
ID: 38734633
The Windows firewall on that server is off.  If it's not a concern, then I can just ignore it, correct?
0
 
LVL 21

Accepted Solution

by:
Radhakrishnan R earned 200 total points
ID: 38734645
Hi,

Thanks for your reply. Bur unfortunately this event required attention as it's indicates that there is a inbound packet blocked by windows filtering. It could be a attempt of hacking.

Also, the windows firewall service in question should be on in windows 2008 environment. You can also refer this tech article and install the required hotfix (the error events are same)
http://support.microsoft.com/kb/2654852

Hope this helps
0
Optimize your web performance

What's in the eBook?
- Full list of reasons for poor performance
- Ultimate measures to speed things up
- Primary web monitoring types
- KPIs you should be monitoring in order to increase your ROI

 
LVL 18

Assisted Solution

by:Sarang Tinguria
Sarang Tinguria earned 100 total points
ID: 38734688
I tried to get WHOIS listing of 239.255.255.250 but could not find any details and the port 138 is used by NetBIOS  protocol used for File and Print Sharing under all current versions of Windows.

As this public IP is not from valid source it may be attempt of attack so would recommend you to check impact by blocking this IP on your external firewall and run full AV scan in safe mode
0
 

Author Comment

by:J.R. Sitman
ID: 38734725
I applied the patch.  I'll monitor it and post later.

Thanks
0
 

Author Closing Comment

by:J.R. Sitman
ID: 38760142
Thanks.  I applied the patch and blocked the ip address.
0

Featured Post

The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Did you know that more than 4 billion data records have been recorded as lost or stolen since 2013? It was a staggering number brought to our attention during last week’s ManageEngine webinar, where attendees received a comprehensive look at the ma…
Resolving an irritating Remote Desktop connection that stops your saved credentials from being used.
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…

615 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question