»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 01-16-2004, 02:43 PM   #1 (permalink)
Registered User
 
blubomber's Avatar
 
Join Date: Oct 2001
Location: Reno, NV
Posts: 776
blubomber is on a distinguished road
Send a message via Yahoo to blubomber
Outdoors Intrusion Attempt?!?!?!?!

I am using Microsoft ISA server 2000 at my work for our firewall and Proxy server.

I have an Audit enabled on the server for logon events that failed or are successfull. I was checking the event logs today under the security tab and found many failed attemps. Starting around 12:20PM and continuing with 2 Failure Audits every second to 12:27PM. So i am rulling out a user on my network. Plus, it is showing that it is the Administrator trying to login. When i look at the event details, the domain shows as D1MCSW31 and the workstation is the same. D1MCSW31 is not our domain.

My firewall did not pickup anything unusual so i am not sure if it was an attack from the outside or not. Can anyone help me out here. I still have to go through my logs to see if anything is there.

Thank you for any advice and guidance.

blubomber is offline   Reply With Quote
Old 01-22-2004, 02:51 PM   #2 (permalink)
Registered User
 
ArcticFox's Avatar
 
Join Date: Jan 2003
Location: Wilsonville, OR
Posts: 2,220
ArcticFox is on a distinguished road
Send a message via AIM to ArcticFox Send a message via MSN to ArcticFox Send a message via Yahoo to ArcticFox Send a message via Skype™ to ArcticFox
What ports were the attacks using?

And why are you using an ISA server when PCI is out?

Last edited by ArcticFox; 01-22-2004 at 02:53 PM.
ArcticFox is offline   Reply With Quote
Old 01-23-2004, 08:50 AM   #3 (permalink)
Registered User
 
blubomber's Avatar
 
Join Date: Oct 2001
Location: Reno, NV
Posts: 776
blubomber is on a distinguished road
Send a message via Yahoo to blubomber
ArcticFox,

This has to do with the other post i have on Port 445. After doing some packet sniffing, i found that the workstation name and others were trying to connect via port 445.

What is PCI??
blubomber is offline   Reply With Quote
Old 01-23-2004, 11:26 AM   #4 (permalink)
Registered User
 
ArcticFox's Avatar
 
Join Date: Jan 2003
Location: Wilsonville, OR
Posts: 2,220
ArcticFox is on a distinguished road
Send a message via AIM to ArcticFox Send a message via MSN to ArcticFox Send a message via Yahoo to ArcticFox Send a message via Skype™ to ArcticFox
Quote:
Originally posted by blubomber
What is PCI??
It's a joke. ISA was the slot that came before PCI invaded motherboards. It offered some like 2MB or whatever per second, and we are way past that right now.
ArcticFox is offline   Reply With Quote
Old 01-23-2004, 11:37 AM   #5 (permalink)
Registered User
 
blubomber's Avatar
 
Join Date: Oct 2001
Location: Reno, NV
Posts: 776
blubomber is on a distinguished road
Send a message via Yahoo to blubomber


Sorry, i totaly missed that. Good one.
blubomber is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 07:25 AM.