Welcome to ServerForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Member Server Logons

 
   Windows Server (Home) -> Windows Server Security RSS
Next:  Microsoft Key Recovery Tool (Reskit)  
Author Message
"Sean

External


Since: Sep 12, 2003
Posts: 1



(Msg. 1) Posted: Fri Sep 12, 2003 10:04 am
Post subject: Member Server Logons
Archived from groups: microsoft>public>windows>server>security (more info?)

This is, presumably, explainable by a security guru with ease...

We have a terminal server that also handles a few print job requests for
users. A user who *never* uses the machine is shown as logging into it with
the following "Success Audit" events:

1. LOGON/LOGOFF > 540 > CHAMBERS > HOOD
2. LOGON/LOGOFF > 538 > CHAMBERS > HOOD
3. LOGON/LOGOFF > 540 > CHAMBERS > HOOD
4. LOGON/LOGOFF > 538 > CHAMBERS > HOOD
5. LOGON/LOGOFF > 540 > CHAMBERS > HOOD

We know that she *didn't* actually log onto HOOD for terminal server use.
But in her workstation security log at about the same time (7:40:38 AM) it
shows:

1. LOGON/LOGOFF > 528 > NETWORK SERVICE > CPU-E00021
2. LOGON/LOGOFF > 538 > HOOD$ > CPU-E00021

What could this be? I don't see any print items in her workstation system
event log. And nothing in her workstation application event log either. Is
there any way of knowing what service she was trying to use on the HOOD
server?

K

 >> Stay informed about: Member Server Logons 
Back to top
Login to vote
Dmitry Korolyov

External


Since: Sep 08, 2003
Posts: 22



(Msg. 2) Posted: Sat Sep 13, 2003 9:39 pm
Post subject: Re: Member Server Logons [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Do you have any shared folders on the HOOD server? Because from the logs you
provided, it looks like the user connects to a share (redirected my
documents, mapped network drive etc) located on that server when logging
interactively into workstation.

--
Dmitry Korolyov
d__k DeleteThis @nospamformorons.mail.ru
To e-mail me, remove "nospamformorons"
from the address.


"Sean (Kashi) McGilloway" <noreplies DeleteThis @wscd.com> wrote in message
news:bjsubb$mujmv$1@ID-202586.news.uni-berlin.de...
> This is, presumably, explainable by a security guru with ease...
>
> We have a terminal server that also handles a few print job requests for
> users. A user who *never* uses the machine is shown as logging into it
with
> the following "Success Audit" events:
>
> 1. LOGON/LOGOFF > 540 > CHAMBERS > HOOD
> 2. LOGON/LOGOFF > 538 > CHAMBERS > HOOD
> 3. LOGON/LOGOFF > 540 > CHAMBERS > HOOD
> 4. LOGON/LOGOFF > 538 > CHAMBERS > HOOD
> 5. LOGON/LOGOFF > 540 > CHAMBERS > HOOD
>
> We know that she *didn't* actually log onto HOOD for terminal server use.
> But in her workstation security log at about the same time (7:40:38 AM) it
> shows:
>
> 1. LOGON/LOGOFF > 528 > NETWORK SERVICE > CPU-E00021
> 2. LOGON/LOGOFF > 538 > HOOD$ > CPU-E00021
>
> What could this be? I don't see any print items in her workstation system
> event log. And nothing in her workstation application event log either. Is
> there any way of knowing what service she was trying to use on the HOOD
> server?
>
> K
>
>

 >> Stay informed about: Member Server Logons 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Apache on W2k Server - Does anyone know of ANY legitimate reason why two unkillable instances of Apache would be running on an internal non-web server? Apache has not been installed by anyone legitimately. The only software installed is Veritas Backup Exec and a home-grown..

Anti-Virus software for WIN2K Server? - I just discovered that I can't install Norton AV on my new WIN2K Server, which I use as the gateway to my DirecWay Satellite. Can some one suggest a good Anti-Virus software package that will install on the WIN2K Server?

IAS Server - Hey all, I am currently using IAS to authenticate our VPN connections from our PIX. I added another client (my backbone switch) to the IAS and another Access Policy. When I try and authenticate myself from the switch, it does not let me pass unless I..

IIS6 Web Server Certificate Wizard Not Running - When I click on Server Certificate under any site...new or old...the Web Server Certificate Wizard does not start. Nothing Happens at all. I have been trying to figure this out for way too long. I have no idea what the problem could be. This is a..
   Windows Server (Home) -> Windows Server Security All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]