Possible security problem

Possible security problem

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Possible security problem TwistedPair 11-02-2007
Posted by TwistedPair on November 2, 2007, 10:33 am
If you were  Registered and logged in, you could reply and use other advanced thread options
All,
I have a curious problem where stuff is changing in our AD domain, but
there's no record of those changes in the event log. For instance, just
recently, a couple of users needed to be added back into a group that they
were previously members of.

1. None of the administrators are admitting to the change.

2. Nothing shows up in the security event logs with regard to the removal of
those accounts although I see the events for the user being added back in.

3. The reason for it not appearing in the event log could not possibly be
due to recency problems, meaning, the event had to have occurred before the
log events for it were overwritten (it happened just a couple of days ago).

4. DCdiag, netdiag, and the AD-related event logs are showing no problems.

5. Additionally other suspicious event have happened, like password
expiration settings changing and no record of that occurring in the event
log . . . Things like that.

I'm not liking the conclusions this is leaving me with as you can imagine.
If we've been compromised, I need concrete evidence. If any of you happen
to have any ideas on possible other things to check, I'd be greatly
interested.

Thanks!



Posted by S. Pidgorny on November 3, 2007, 6:18 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
What I'd do:

1. Make sure your auditing works: add/delete users from the group and
identify the audit trail;
2. Set up alerting on the audit events (using eventtriggers.exe, for
example);
3. Action on the alerts - identify who's making changes, and why;
4. Use smart cards only for administrative logon so that there will be no
issue with passwords


--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *



> All,
> I have a curious problem where stuff is changing in our AD domain, but
> there's no record of those changes in the event log. For instance, just
> recently, a couple of users needed to be added back into a group that they
> were previously members of.
>
> 1. None of the administrators are admitting to the change.
>
> 2. Nothing shows up in the security event logs with regard to the removal
> of
> those accounts although I see the events for the user being added back in.
>
> 3. The reason for it not appearing in the event log could not possibly be
> due to recency problems, meaning, the event had to have occurred before
> the
> log events for it were overwritten (it happened just a couple of days
> ago).
>
> 4. DCdiag, netdiag, and the AD-related event logs are showing no problems.
>
> 5. Additionally other suspicious event have happened, like password
> expiration settings changing and no record of that occurring in the event
> log . . . Things like that.
>
> I'm not liking the conclusions this is leaving me with as you can imagine.
> If we've been compromised, I need concrete evidence. If any of you happen
> to have any ideas on possible other things to check, I'd be greatly
> interested.
>
> Thanks!
>
>



Posted by TwistedPair on November 4, 2007, 1:31 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Good info, thank you!

> What I'd do:
>
> 1. Make sure your auditing works: add/delete users from the group and
> identify the audit trail;
> 2. Set up alerting on the audit events (using eventtriggers.exe, for
> example);
> 3. Action on the alerts - identify who's making changes, and why;
> 4. Use smart cards only for administrative logon so that there will be no
> issue with passwords
>
>
> --
> Svyatoslav Pidgorny, MS MVP - Security, MCSE
> -= F1 is the key =-
>
> * http://sl.mvps.org * http://msmvps.com/blogs/sp *
>
>
>
>> All,
>> I have a curious problem where stuff is changing in our AD domain, but
>> there's no record of those changes in the event log. For instance, just
>> recently, a couple of users needed to be added back into a group that
>> they
>> were previously members of.
>>
>> 1. None of the administrators are admitting to the change.
>>
>> 2. Nothing shows up in the security event logs with regard to the removal
>> of
>> those accounts although I see the events for the user being added back
>> in.
>>
>> 3. The reason for it not appearing in the event log could not possibly be
>> due to recency problems, meaning, the event had to have occurred before
>> the
>> log events for it were overwritten (it happened just a couple of days
>> ago).
>>
>> 4. DCdiag, netdiag, and the AD-related event logs are showing no
>> problems.
>>
>> 5. Additionally other suspicious event have happened, like password
>> expiration settings changing and no record of that occurring in the event
>> log . . . Things like that.
>>
>> I'm not liking the conclusions this is leaving me with as you can
>> imagine.
>> If we've been compromised, I need concrete evidence. If any of you
>> happen
>> to have any ideas on possible other things to check, I'd be greatly
>> interested.
>>
>> Thanks!
>>
>>
>
>



Similar ThreadsPosted
Security Problem>>> Need Help!!! December 21, 2005, 9:42 pm
Cox security problem May 1, 2006, 12:53 pm
RE: Security Problem... April 16, 2007, 7:46 pm
Security Problem!!! November 22, 2007, 10:02 pm
Security Event Log problem October 18, 2005, 11:20 pm
Problem with security rights February 14, 2006, 6:08 pm
security problem on pipe December 31, 2006, 7:47 am
Web Certificate Enrollment security problem March 15, 2006, 2:57 am
Folder Security/ Permissions problem on W2K3 March 1, 2006, 11:25 pm
Is Outlook auto responder security problem? January 31, 2007, 2:18 pm

The site map in XML format XML site map

Contact Us | Privacy Policy