Computing.Net > Forums > Windows Server 2003 > Internal Prob or External Attack?

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Internal Prob or External Attack?

Reply to Message Icon

Name: bwelaj
Date: September 14, 2006 at 10:25:55 Pacific
OS: Server 2003
CPU/Ram: Dual 2.4 GHz/3.7 G Ram
Product: Microsoft
Comment:

Some time this morning I began getting a TON of security and logon events on our Exchange server. (Server 2003 SP1 with Exchange 2003).

The events are as follows:

In the System event log every second I get an Event 100 warning "The server was unable to logon the Windows NT account 'name'..."

For the last 10 hours these have been generated with the name changing every so often from dave, to martin, to john, to karl, etc.

At the same time I am getting tons of Failure Audits in the Security event log. I get events 529 and 680. The 529 states it was an unknown user name or password trying to access this Exchange server through IIS. The 680 errors give a similar error with the source being Microsoft_Authentication_Package.

I have checked eventid.net and the one solution I have tried is that I verified in our IIS metabase that NtAuthenticationProviders was set to Negotiate/NTML.

These errors were not there yesterday but are chronic now. We have no user id's in
Active Directory that match the ones that are attempting to log in. Is this indicative of an external brute force attack on our system? If so how can I go about finding out where its coming from and how to stop it? If its not an external attack I am at a loss of where to go next to try and resolve this issue.

Thanks in advance.



Sponsored Link
Ads by Google

Response Number 1
Name: Dirty_Sanchez
Date: September 14, 2006 at 12:05:11 Pacific
Reply:

At the very least I would verify AV definitions on all outlook clients and servers and run a scan. could be a mass mailer but, sounds like may be a brute force attack. have you ran a netstat from Exchange yet?


0

Response Number 2
Name: bwelaj
Date: September 14, 2006 at 13:08:10 Pacific
Reply:

Its a brute force attack. Installed Ethereal and discovered it was coming from China. We're squashing it now. Thanks.


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More


Read-only file problem wi... Security Question



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows Server 2003 Forum Home


Sponsored links

Ads by Google


Results for: Internal Prob or External Attack?

DNS Issue - Internal/external IP www.computing.net/answers/windows-2003/dns-issue-internalexternal-ip/4040.html

External workstations can't view www.computing.net/answers/windows-2003/external-workstations-cant-view/6549.html

Configure Internal Web Site www.computing.net/answers/windows-2003/configure-internal-web-site/6530.html