Web Hosting Talk







View Full Version : been getting this error lately


frontserve
09-04-2002, 09:40 PM
We have seen a tremendous increase for this error on the Event Viewer for one of our Windows 2000 server.

Below is the exact error; is this a hacker trying to log in?? If yes, how do we find it??


Event Type: Warning
Event Source: W3SVC
Event Category: None
Event ID: 100
Date: 8/22/2002
Time: 3:34:24 PM
User: N/A
Computer: SERVERXXXX (we changed this)
Description:
The server was unable to logon the Windows NT account 'michael.h.lam' due to the following error: Logon failure: unknown user name or bad password. The data is the error code.
For additional information specific to this message please visit the Microsoft Online Support site located at: http://www.microsoft.com/contentredirect.asp.
Data:
0000: 2e 05 00 00 ....


What should we do or look for to find the person doing this?? We would like to find the person and block them out of our servers.

Any help is appreciated; thanks.

MikeM
09-04-2002, 10:45 PM
http://online.securityfocus.com/archive/82/274514/2002-05-28/2002-06-03/0

http://support.microsoft.com/support/kb/articles/Q236/0/07.ASP

Sounds like some one is trying an exploit... check your logs for connections at the same time the event is giving the error.

http://www.kb.cert.org/vuls/id/201704

To fix, you can try:
http://www.cert.org/security-improvement/practices/p059.html

TheRealDeal
11-23-2002, 04:28 AM
We had that problem before, just deploy the lockdown tool by microsoft.