Event Viewer-Source:Security-ID540/538

Event Viewer-Source:Security-ID540/538

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Event Viewer-Source:Security-ID540/538 P. Cully 10-18-2007
Posted by =?Utf-8?B?UC4gQ3VsbHk=?= on October 18, 2007, 9:21 am
If you were  Registered and logged in, you could reply and use other advanced thread options
A review of my security logs reports a number of users logging in to the
network successfully from a valid network machine at 5:46 in the morning. We
are a school with no remote access and the building is locked. Once the
machine was identified I checked the logs on that machine and ran spybot but
everything showed up clean.
Question: Could a student have not logged off when they finished working on
a machine and the repeated events have something to do with Kerberos checking
and reissuing tickets?
Observation: I ran a virus scan on one of the servers overnight and was
logged in as a user with the machine locked. When I checked the logs on that
machine this a.m. that same user was shown with ID540/538s during early
morning hours.
Machines that are not shut down appear in the logs have 540/538s happening
at the same time.
I've run Hijack this on the server and have collected a log file.
Thanks,
P



Similar ThreadsPosted
centralized event logging? centralized syslog... dumping event log? splunk? February 17, 2007, 2:55 am
Event log December 12, 2005, 7:32 am
Event ID 22. February 9, 2006, 3:49 pm
Event ID 626 October 3, 2006, 4:51 pm
Event ID: 537 October 30, 2006, 6:00 am
Event ID 537 March 28, 2007, 8:29 pm
Event ID: 675 September 12, 2007, 10:38 am
Event ID 560 August 4, 2008, 1:52 pm
event id 577 August 4, 2008, 1:58 pm
Event ID 675 August 25, 2008, 10:19 pm

The site map in XML format XML site map

Contact Us | Privacy Policy