Help - Search - Members - Calendar
Full Version: Login attempts by another server
The Planet Forums > Security > General Security > Windows Security
jpboyce
Just looking at my security logs and noticed a lot of entries like this:

CODE
Event Type:    Failure Audit

Event Source:    Security

Event Category:    Logon/Logoff

Event ID:    529

Date:  1/31/2006

Time:  7:47:21 PM

User:  NT AUTHORITYSYSTEM

Computer:    SERVER

Description:

Logon Failure:

 Reason:  Unknown user name or bad password

 User Name:    administrator

 Domain:  THE-234AB2D0704

 Logon Type:    3

 Logon Process:    NtLmSsp

 Authentication Package:    NTLM

 Workstation Name:    THE-234AB2D0704

 Caller User Name:    -

 Caller Domain:    -

 Caller Logon ID:    -

 Caller Process ID:    -

 Transited Services:    -

 Source Network Address:    67.19.188.186

 Source Port:    0


It's from the same IP each time. Is anyone else getting this?
ajz4221
If you have the IP, put it in your IPsec table. Maybe that will help cut the issue down some.
cprompt
It's quite normal, I'm afraid. Just keep the number of live accounts to a minimum and ensure you have strong passwords in place.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.