Event Viewer - Security Log

Event Viewer - Security Log

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Event Viewer - Security Log CCI Helpdesk 09-05-2007
Posted by =?Utf-8?B?Q0NJIEhlbHBkZXNr?= on September 5, 2007, 6:54 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Folks,

We are seeing this entry in the Security log of our event viewer on one of
our servers.

It is usually followed by a failed attempt to login with a standard user
account.
The account usually gets "locked out"

This is what we see prior to the "lock out"

Logon Failure:
        Reason:                Unknown user name or bad password
        User Name:        isdiua
        Domain:                CCI-USA
        Logon Type:        3
        Logon Process:        NtLmSsp
        Authentication Package:        NTLM

Has anyone see this before? Is someone piggybacking on someone's login the
network from a remote computer?

Please advise.

CCI Helpdesk.


Posted by Roger Abell [MVP] on September 5, 2007, 11:52 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
There is no way to tell you what is happening from the
info provided, except that a valid account is being tried
with an invalid password (based on what you said) and
that it is using NTLM instead of Kerberos to attempt a
network login (such as share access). Other events
recorded should be showing you the machine name of
the origin of the attempts.
This might be something as simple as that account
having recently undergone a password change but
the account is used interactively and has shares that
are defined to be persistent (and are now using the
wrong password).

Roger

> Folks,
>
> We are seeing this entry in the Security log of our event viewer on one of
> our servers.
>
> It is usually followed by a failed attempt to login with a standard user
> account.
> The account usually gets "locked out"
>
> This is what we see prior to the "lock out"
>
> Logon Failure:
> Reason: Unknown user name or bad password
> User Name: isdiua
> Domain: CCI-USA
> Logon Type: 3
> Logon Process: NtLmSsp
> Authentication Package: NTLM
>
> Has anyone see this before? Is someone piggybacking on someone's login the
> network from a remote computer?
>
> Please advise.
>
> CCI Helpdesk.
>



Posted by =?Utf-8?B?Q0NJIEhlbHBkZXNr?= on September 6, 2007, 11:20 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Roger,

Thanks - this is a Citrix Server - we do not have an account "isdiua" in our
domain by that name.

Unless it is some acronym for a Microsoft service?

It is like we are "hit" with that login as an initial login attempt for a
non-account then attempting to user our Helpdesk account to login. After that
the next entry shows the Helpdesk account has been locked out. It looks like
we are being probed with some password attack agent - is there a way to
detect that?

We are trying to figure out how the "vermin" are attempting to use the
single logon NTLM authentication to gain access.

Thanks
CCI Helpdesk


"CCI Helpdesk" wrote:

> Folks,
>
> We are seeing this entry in the Security log of our event viewer on one of
> our servers.
>
> It is usually followed by a failed attempt to login with a standard user
> account.
> The account usually gets "locked out"
>
> This is what we see prior to the "lock out"
>
> Logon Failure:
>         Reason:                Unknown user name or bad password
>         User Name:        isdiua
>         Domain:                CCI-USA
>         Logon Type:        3
>         Logon Process:        NtLmSsp
>         Authentication Package:        NTLM
>
> Has anyone see this before? Is someone piggybacking on someone's login the
> network from a remote computer?
>
> Please advise.
>
> CCI Helpdesk.
>

Posted by on September 6, 2007, 12:23 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
That is strange. Is Vnc installed on this Citrix server, by chance?

J Wolfgang Goerlich

On Sep 6, 11:20 am, CCI Helpdesk
> Roger,
>
> Thanks - this is a Citrix Server - we do not have an account "isdiua" in our
> domain by that name.
>
> Unless it is some acronym for a Microsoft service?
>
> It is like we are "hit" with that login as an initial login attempt for a
> non-account then attempting to user our Helpdesk account to login. After that
> the next entry shows the Helpdesk account has been locked out. It looks like
> we are being probed with some password attack agent - is there a way to
> detect that?
>
> We are trying to figure out how the "vermin" are attempting to use the
> single logon NTLM authentication to gain access.
>
> Thanks
> CCI Helpdesk
>
>
>
> "CCI Helpdesk" wrote:
> > Folks,
>
> > We are seeing this entry in the Security log of our event viewer on one of
> > our servers.
>
> > It is usually followed by a failed attempt to login with a standard user
> > account.
> > The account usually gets "locked out"
>
> > This is what we see prior to the "lock out"
>
> > Logon Failure:
> > Reason: Unknown user name or bad password
> > User Name: isdiua
> > Domain: CCI-USA
> > Logon Type: 3
> > Logon Process: NtLmSsp
> > Authentication Package: NTLM
>
> > Has anyone see this before? Is someone piggybacking on someone's login the
> > network from a remote computer?
>
> > Please advise.
>
> > CCI Helpdesk.- Hide quoted text -
>
> - Show quoted text -



Posted by =?Utf-8?B?Q0NJIEhlbHBkZXNr?= on September 6, 2007, 1:02 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
JWG,

Yes, we have UltraVNC installed.

CCI


"jwgoerlich@gmail.com" wrote:

> That is strange. Is Vnc installed on this Citrix server, by chance?
>
> J Wolfgang Goerlich
>
> On Sep 6, 11:20 am, CCI Helpdesk
> > Roger,
> >
> > Thanks - this is a Citrix Server - we do not have an account "isdiua" in our
> > domain by that name.
> >
> > Unless it is some acronym for a Microsoft service?
> >
> > It is like we are "hit" with that login as an initial login attempt for a
> > non-account then attempting to user our Helpdesk account to login. After that
> > the next entry shows the Helpdesk account has been locked out. It looks like
> > we are being probed with some password attack agent - is there a way to
> > detect that?
> >
> > We are trying to figure out how the "vermin" are attempting to use the
> > single logon NTLM authentication to gain access.
> >
> > Thanks
> > CCI Helpdesk
> >
> >
> >
> > "CCI Helpdesk" wrote:
> > > Folks,
> >
> > > We are seeing this entry in the Security log of our event viewer on one of
> > > our servers.
> >
> > > It is usually followed by a failed attempt to login with a standard user
> > > account.
> > > The account usually gets "locked out"
> >
> > > This is what we see prior to the "lock out"
> >
> > > Logon Failure:
> > > Reason: Unknown user name or bad password
> > > User Name: isdiua
> > > Domain: CCI-USA
> > > Logon Type: 3
> > > Logon Process: NtLmSsp
> > > Authentication Package: NTLM
> >
> > > Has anyone see this before? Is someone piggybacking on someone's login the
> > > network from a remote computer?
> >
> > > Please advise.
> >
> > > CCI Helpdesk.- Hide quoted text -
> >
> > - Show quoted text -
>
>
>

Similar ThreadsPosted
Event Viewer : Security January 12, 2006, 11:52 am
Event Viewer-Source:Security-ID540/538 October 18, 2007, 9:21 am
Event Viewer Security shows Guest logon? May 11, 2006, 8:54 pm
Event viewer July 29, 2007, 10:54 am
Locking down Event Viewer October 20, 2005, 10:28 am
Event viewer - access denied July 12, 2005, 3:58 pm
Internet Explorer in event viewer September 19, 2008, 5:30 am
remote access logons in Event Viewer July 28, 2005, 12:06 pm
can't access remote registry + event viewer September 7, 2005, 9:41 pm
VPN error 718 timeout while server event viewer grants user access August 28, 2008, 11:54 pm

The site map in XML format XML site map

Contact Us | Privacy Policy