xboxscene.org forums

Author Topic: Security Log Errors On Our Sbs 2003 R2 Server.  (Read 44 times)

47_M450N_47

  • Archived User
  • Hero Member
  • *
  • Posts: 618
Security Log Errors On Our Sbs 2003 R2 Server.
« on: August 07, 2007, 07:49:00 AM »

Does anybody know what could be causing these?  They will appear in our Security Log from time to time (Windows SBS 2003 R2).  It isn't any of our users on the network.  Each time the user name will be something new and completely random, there's an example below.

Logon Failure:
    Reason:      Unknown user name or bad password
    User Name:   bullshit
    Domain:      
    Logon Type:   3
    Logon Process:   Advapi  
    Authentication Package:   MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
    Workstation Name:   ****
    Caller User Name:   ****
    Caller Domain:   ****
    Caller Logon ID:   (0x0,0x3E7)
    Caller Process ID:   2076
    Transited Services:   -
    Source Network Address:   -
    Source Port:   -

Anybody know what could be causing these?  If somebody is trying to get in, is there a way to tell what port or service they are trying to access it through?  I'd like to turn it off.
Logged

47_M450N_47

  • Archived User
  • Hero Member
  • *
  • Posts: 618
Security Log Errors On Our Sbs 2003 R2 Server.
« Reply #1 on: August 08, 2007, 12:38:00 PM »

Ok...so does anybody know of another forum (free) that I could ask this question at?
Logged

Alex548

  • Recovered User
  • Hero Member
  • *
  • Posts: 1717
Security Log Errors On Our Sbs 2003 R2 Server.
« Reply #2 on: August 09, 2007, 05:03:00 PM »

Computing.net

By the way, check your server for viruses/trojans.

Edit:
You might also wanna download and run the Microsoft Baseline Security Analyzer tool (MBSA) to check for existing vulnerabilities.

This post has been edited by Alex548: Aug 10 2007, 12:19 AM
Logged

47_M450N_47

  • Archived User
  • Hero Member
  • *
  • Posts: 618
Security Log Errors On Our Sbs 2003 R2 Server.
« Reply #3 on: August 10, 2007, 10:06:00 AM »

Yeah I've scanned it With SAV 10.1.5.5000 and it turns up clean.  I've also scanned it for rootkits with IceSword and Rootkit Revealer.  I downloaded and ran that Microsoft utility a few weeks ago and it didn't turn up anything either.  Thanks for the link, I'll see what they know.
Logged