Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Windows Small Business Server > Who's guessing passwords? - source of invalid logins to inetinfo, SBS2003

Reply
Thread Tools Display Modes

Who's guessing passwords? - source of invalid logins to inetinfo, SBS2003

 
 
Krzysztof Barski
Guest
Posts: n/a

 
      06-16-2010
Hello,
I am desperately trying to identify from where someone tries to login to our
sbs2003 server.
I'm getting several hundreds of event id 529 entries in security log,
spanning 30-40 minute interval, all share this info:
Username: (here someone guesses random names)
Login type: 3
Logon Process: Advapi
Workstation name: <my_server_name>
Username: <my_server_name$>
Source network address: <empty> It'd be nice if it wasn't
PID: <inetinfo_pid_always>

I thought since it always is about inetinfo, these invalid logons would be
listed in IIS log files, but they are not.
By the way, the first in a chain of these logon attempts also generates
eventid 1706 from MSExchangeTransport in application log.

I've read somewhere about debugging exchange for the purpose of identifying
failed logons but i don't want to do that, i'd like to see a log in any
format that would be containing source address or machine name

Please help me identify source of these attacks.
--
Regards
Krzysztof Barski

 
Reply With Quote
 
 
 
 
Paul Shapiro
Guest
Posts: n/a

 
      06-16-2010
"Krzysztof Barski" <> wrote in message
news:#...
> Hello,
> I am desperately trying to identify from where someone tries to login to
> our sbs2003 server.
> I'm getting several hundreds of event id 529 entries in security log,
> spanning 30-40 minute interval, all share this info:
> Username: (here someone guesses random names)
> Login type: 3
> Logon Process: Advapi
> Workstation name: <my_server_name>
> Username: <my_server_name$>
> Source network address: <empty> It'd be nice if it wasn't
> PID: <inetinfo_pid_always>
>
> I thought since it always is about inetinfo, these invalid logons would be
> listed in IIS log files, but they are not.
> By the way, the first in a chain of these logon attempts also generates
> eventid 1706 from MSExchangeTransport in application log.
>
> I've read somewhere about debugging exchange for the purpose of
> identifying failed logons but i don't want to do that, i'd like to see a
> log in any format that would be containing source address or machine name
>
> Please help me identify source of these attacks.
> --
> Regards
> Krzysztof Barski
>

I haven't seen these for a while, but I think it turned out to be attempts
to authenticate with the SMTP server. You can enable SMTP logging and you
may find further details there. I eventually decided there wasn't any point
to trying. The attack source rarely stays constant for long. In my case, I
had a flurry of such attacks for a week or two at a time, and then they
stopped. Occasionally they occur again, but never for long.

 
Reply With Quote
 
Krzysztof Barski
Guest
Posts: n/a

 
      06-16-2010


"Paul Shapiro" <> wrote in a message
news:...
> I haven't seen these for a while, but I think it turned out to be attempts
> to authenticate with the SMTP server. You can enable SMTP logging and you
> may find further details there. I eventually decided there wasn't any
> point to trying. The attack source rarely stays constant for long. In my
> case, I had a flurry of such attacks for a week or two at a time, and then
> they stopped. Occasionally they occur again, but never for long.


Thanks for the answer, Paul
I will be logging some more smtp stuff, then. I need to see it logged at
least once just to be sure that it really is thru smtp not an in-house job
by some unexpectedly "skillful" employee.

 
Reply With Quote
 
john doe
Guest
Posts: n/a

 
      06-17-2010
Get 'EventSentry Light' (free edition) and install it. We are using it and
it's great.

"Krzysztof Barski" <> wrote in message
news:%...
> Hello,
> I am desperately trying to identify from where someone tries to login to
> our sbs2003 server.
> I'm getting several hundreds of event id 529 entries in security log,
> spanning 30-40 minute interval, all share this info:
> Username: (here someone guesses random names)
> Login type: 3
> Logon Process: Advapi
> Workstation name: <my_server_name>
> Username: <my_server_name$>
> Source network address: <empty> It'd be nice if it wasn't
> PID: <inetinfo_pid_always>
>
> I thought since it always is about inetinfo, these invalid logons would be
> listed in IIS log files, but they are not.
> By the way, the first in a chain of these logon attempts also generates
> eventid 1706 from MSExchangeTransport in application log.
>
> I've read somewhere about debugging exchange for the purpose of
> identifying failed logons but i don't want to do that, i'd like to see a
> log in any format that would be containing source address or machine name
>
> Please help me identify source of these attacks.
> --
> Regards
> Krzysztof Barski
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
sbs 2008 migration cannot find source server Jim Budde Windows Small Business Server 6 02-08-2011 11:30 PM
Re: Script for news items Pegasus [MVP] Scripting 1 03-17-2010 06:29 PM
KDC Event ID 7 and Wins startup errors. GihanZ Windows Small Business Server 4 11-23-2009 01:43 AM
Security Failures after Password Change Zachary Server Security 14 10-30-2009 06:02 PM
HELP sfc /scannow William Beard Windows Vista Performance 17 05-11-2007 03:28 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59