Solved

disabled guest account still gets locked

Posted on 2014-01-24
5
1,295 Views
Last Modified: 2014-03-28
sbs 2003.  i have the default guest account disabled however, malicious bots try to authenticate with my smtp server using this guest account.  after the defined number of failed attempts i get 539 account lockout events for the guest account in the event log.  i don't understand why i get a lockout when the account is disabled.

i tried to duplicate this by loging onto my smtp server via telnet to port 25, ehlo, auth login command but the base64 that i use for "guest" (online decoder) results in a "guust" account login in the event log.  i'm not sure what i'm doing wrong here but what i'm trying to figure out is why do i get an account lockout on a disabled account?

any ideas
0
Comment
Question by:scraby
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
5 Comments
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 39806567
I am not sure how they are trying to authenticate to your Exchange Receive Connector using Guest Account but typically it is a best practice to rename both the guest account and also administrator account. Have you tried to rename the guest account? You can do this via GPO

Rename Guest and Administrator Account GPO

Will.
0
 
LVL 7

Author Comment

by:scraby
ID: 39806782
well, neither of these answers my question of how a disabled account is getting locked out?  i renamed the guest account anyway.
0
 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 250 total points
ID: 39806827
What do the logs say in regards to the lock out? Do they give you a source IP or anything in relation to that? Maybe it is a Guest Account on a different machine.

Anyways renaming the Guest account should be done as a best practice. Check and see if the account continues to get these error messages.

Will.
0
 
LVL 20

Accepted Solution

by:
compdigit44 earned 250 total points
ID: 39813668
Have you enabled verbose SMTP logging?
Have you checked your firewall logs?
Are you sure the source of the attack is external and not internal?
On your IIS SMTP virtual server, what are your relaying settings set to?
0

Featured Post

Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
A project that enables an administrator to perform actions within a user session context not just at the time of login but any time later on day(s) or week(s) later.
To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Servers >> Certificates…
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to: http://www.codetwo.com/excha…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question