Server 2003 failed logon/logoff audit records

Server 2003 failed logon/logoff audit records

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Server 2003 failed logon/logoff audit records danielhopkins@gmail.com 12-02-2005
Posted by danielhopkins@gmail.com on December 2, 2005, 4:29 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I am running Server 2003 Standard edition as a public webserver.
Recently the server has been experiencing numerous login attempts
resulting in the following audit log:

Event Type:        Failure Audit
Event Source:        Security
Event Category:        Logon/Logoff
Event ID:        537
Date:                12/2/2005
Time:                7:54:35 AM
User:                NT AUTHORITY\SYSTEM
Computer:        LONGS
Description:
Logon Failure:
        Reason:                An error occurred during logon
        User Name:        IUSR_WINSERVER2003
        Domain:                *****
        Logon Type:        3
        Logon Process:        ?Q
        Authentication Package:        NTLM
        Workstation Name:        *****
        Status code:        0xC000006D
        Substatus code:        0x0
        Caller User Name:        -
        Caller Domain:        -
        Caller Logon ID:        -
        Caller Process ID:        -
        Transited Services:        -
        Source Network Address:        **.***.***.***
        Source Port:        0

The question I have is, how is this logon event occurring? The source
network address has the ip of the server itself, which would seem to
mean that whoever (or whatever) is trying to login is doing so from the
actual machine?

What does the ?Q mean as a logon proccess?

Any answers or links would be much appreciated.

Thanks much,
Dan Hopkins


Posted by Arek Iskra [MVP] on December 2, 2005, 10:44 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
>I am running Server 2003 Standard edition as a public webserver.
> Recently the server has been experiencing numerous login attempts
> resulting in the following audit log:
>
> Event Type: Failure Audit
> Event Source: Security
> Event Category: Logon/Logoff
> Event ID: 537
> Date: 12/2/2005
> Time: 7:54:35 AM
> User: NT AUTHORITY\SYSTEM
> Computer: LONGS
> Description:
> Logon Failure:
> Reason: An error occurred during logon
> User Name: IUSR_WINSERVER2003
> Domain: *****
> Logon Type: 3
> Logon Process: ?Q
> Authentication Package: NTLM
> Workstation Name: *****
> Status code: 0xC000006D
> Substatus code: 0x0
> Caller User Name: -
> Caller Domain: -
> Caller Logon ID: -
> Caller Process ID: -
> Transited Services: -
> Source Network Address: **.***.***.***
> Source Port: 0
>
> The question I have is, how is this logon event occurring? The source
> network address has the ip of the server itself, which would seem to
> mean that whoever (or whatever) is trying to login is doing so from the
> actual machine?
>
> What does the ?Q mean as a logon proccess?
>
> Any answers or links would be much appreciated.
>
> Thanks much,
> Dan Hopkins
>


Is this server running IIS? The logon account is the IUSR_<server name>.
Someone (or something - an application or process for example) seems to be
failing to authenticate.

--
Arek Iskra
MVP for Windows Server - Software Distribution



Similar ThreadsPosted
Any audit option to monitor who/when DNS records get deleted? February 12, 2007, 12:25 pm
Audit Privilege Use - Windows 2003 Security Guide April 3, 2008, 5:04 am
How to audit WHO has shutdown a server? March 9, 2006, 9:14 am
Can not use UNC path in Windows server 2003 server 64 bit OS September 30, 2005, 4:19 pm
Netbios records (602 lifetime) June 8, 2006, 11:11 am
Re: There is a serious problem within Server 2003 SP1. July 17, 2005, 12:25 am
RE: WIndows Server 2003 July 29, 2005, 12:16 am
using ICF on 2003 server in domain? September 14, 2005, 2:50 am
Windows 2003 server SP1 September 16, 2005, 12:06 am
Unauthorized use of Server 2003 February 4, 2006, 8:21 am

The site map in XML format XML site map

Contact Us | Privacy Policy