Solved

Microsof SBS 2003 Security Events

Posted on 2013-12-12
7
228 Views
Last Modified: 2014-04-15
We use GFI Server monitoring, and we are experiencing 5 security events that repeatedly alert us from the Security Event Log. The total amount of alerts can reach into their thousands within the week. The alert descriptions indicate that the security event is triggered from internal users, computers and IP addresses.

There are 2 sites linked via a VPN. The primary site uses 10.0.0.0, whilst the remote site uses 192.168.1.0.

The alerts in question relate to the following Event ID's:
529
673
673
675
680

For further clarity, please see attached document providing event logs as extracted from the SBS Server, with accompanying notes at the bottom of each event.

I would like to identify the cause and resolution of each event.

Thank you in advance.
Event-ID-s.docx
0
Comment
Question by:swan_solutions
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
7 Comments
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 39713793
What ports do you have open and forwarded to the server because a lot of them may be external hackers trying to break into your server using port 3389 for example.

Another problem with SBS is hackers trying port 25 to work out a username / password combo that works and my article can help sort that problem out for you:

http://alanhardisty.wordpress.com/2010/12/01/increase-in-hacker-attempts-on-windows-exchange-servers-one-way-to-slow-them-down/

Alan
0
 

Author Comment

by:swan_solutions
ID: 39713913
The following ports are open:

Destination - SBS Server
3389
(access from specific destinations only - not open to general public)
1723
443
143


Destination - Analysis Computer using IP 10.0.0.76
12340 to 12360
(now closed as there is no further requirement for these ports to be open)

On the point of SMTP we have redirected port 77 (public) to port 25 (private). SMTP is routed via an external party and has been restricted to specific IP ranges
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 39713933
No problems - if you don't use port 25 directly, then that will not be a problem.

Do you use IMAP?  Any reason to have that working as you shouldn't need it normally.

It seems to be that HPC009 is generating / appearing in a lot of the errors you are seeing.  Is there anything on that PC that shouldn't be there?

Have you run an AV / Malware scan on it?

Is the user having problems authenticating?

Others may be OWA problems as they are coming from the server itself (127.0.0.1).

What is your server internal IP address?

Alan
0
Why You Need a DevOps Toolchain

IT needs to deliver services with more agility and velocity. IT must roll out application features and innovations faster to keep up with customer demands, which is where a DevOps toolchain steps in. View the infographic to see why you need a DevOps toolchain.

 

Author Comment

by:swan_solutions
ID: 39717031
I have disabled the IMAP port as this is not longer in use.

I will investigate HPC009 and any user/AV/Malware related issus and report back on this.

When you say OWA problems, does anything specific spring to mind?

The server IP is 10.0.0.2

Thanks
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 39725494
When I refer to OWA - it may be people failing to login to OWA which could be a genuine user or a hacker / script kiddie trying to break in that way.

Alan
0
 

Accepted Solution

by:
swan_solutions earned 0 total points
ID: 39991953
No resolution found on this issue
0
 

Author Closing Comment

by:swan_solutions
ID: 40001098
Other suggestions did not resolve this issue
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
lock down downloads folder 8 91
2 fax modems - One phone line ( Temporarily ) possible ? How ? 7 84
Moving on from sbs 2008... 36 130
Windows 2008 SBS Patch 2 41
Because virtualization becomes more and more common, and, with Microsoft Hyper-V included in Windows Server at no additional costs, and, most server hardware nowadays is more than capable of running a physical Small Business Server (SBS) 2008 or 201…
I’m often asked about newer and larger USB drives connected to SBS2008 and 2011 failing Windows Server Backup vs the older USB drives not failing. As disk space continues to grow and drive technology change SBS2008 and some SBS2011 end up with the f…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question