home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Join TechIMO for Free!
Register Blogs FAQ Members List Calendar Search Today's Posts Mark Forums Read
Reply Get bargains at  »  Dealighted.com
 
Thread Tools
Currently Active Users: 1892
Discussions: 188,470, Posts: 2,244,182, Members: 232,725
Old May 26th, 2004, 02:44 PM   Digg it!   #1 (permalink)
Ultimate Member
 
eweruk's Avatar
 
Join Date: Oct 2001
Location: White Rock, Canada
Posts: 2,238
Send a message via ICQ to eweruk Send a message via AIM to eweruk
Help! Server being attacked!

One of my servers is constantly being attacked though so far, I can't see that they are getting in. They are trying all the default user names that M$ would have, I have none of those.

Looks like they are using a program, cause the rapid fire login attempts are insane. Here is where is gets interesting, one person has managed to get the correct user names and keeps locking the accounts since I have fairly tough rules on incorrect user name/pwd.

Question is: How did they get the list of user names????

eweruk is offline   Reply With Quote
Old May 26th, 2004, 02:48 PM     #2 (permalink)
Ultimate Member
 
Join Date: Oct 2001
Posts: 21,063
They're trying a brute force attempt... chances are they dont' have a list of user names just giong through a dictionary.

If you have a firewall block off the IP that is diogn the attack.

vass0922 is online now   Reply With Quote
Old May 26th, 2004, 03:07 PM     #3 (permalink)
addicted
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 6,103
Depending on your environment... one way a user list could might have been obtained: http://www.securityspace.com/smysecu...src=1&id=10150

DVNT1 is offline   Reply With Quote
Old May 26th, 2004, 03:10 PM     #4 (permalink)
Ultimate Member
 
MTAtech's Avatar
 
Join Date: Oct 2001
Location: Long Island, NY, USA
Posts: 4,646
Send a message via AIM to MTAtech Send a message via Yahoo to MTAtech
You may want to configure a timeout on userIDs that, let's say, locks out the account for 20 minutes if there are three failed logins. This will considerably slow down a brute force attempt.
__________________
"Those who can make you believe absurdities can make you commit atrocities" - Voltaire
MTAtech is offline   Reply With Quote
Old May 26th, 2004, 03:15 PM     #5 (permalink)
Ultimate Member
 
MTAtech's Avatar
 
Join Date: Oct 2001
Location: Long Island, NY, USA
Posts: 4,646
Send a message via AIM to MTAtech Send a message via Yahoo to MTAtech
Also, enable 'Interactive login: Do not display last users name.' (Administrative Tools, Security Settings ->Local policies-> Security options). This will prevent one from getting the user id already in the dialog box.
MTAtech is offline   Reply With Quote
Old May 26th, 2004, 03:17 PM     #6 (permalink)
Ultimate Member
 
eweruk's Avatar
 
Join Date: Oct 2001
Location: White Rock, Canada
Posts: 2,238
Send a message via ICQ to eweruk Send a message via AIM to eweruk
Actually, they are using something to get the specific user names cause we have very unique names, nothing in the dictionary.....
eweruk is offline   Reply With Quote
Old May 26th, 2004, 03:20 PM     #7 (permalink)
Ultimate Member
 
eweruk's Avatar
 
Join Date: Oct 2001
Location: White Rock, Canada
Posts: 2,238
Send a message via ICQ to eweruk Send a message via AIM to eweruk
Yes, I have the lock out after 5 invalid pwd and locked for 30 minutes....

Once one is locked they move to the next user name until that is locked....
eweruk is offline   Reply With Quote
Old May 26th, 2004, 03:22 PM     #8 (permalink)
addicted
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 6,103
Is this happening over the Internet?

Is this via MS Share, Terminal Server, IIS, or ?
DVNT1 is offline   Reply With Quote
Old May 26th, 2004, 03:28 PM     #9 (permalink)
Ultimate Member
 
eweruk's Avatar
 
Join Date: Oct 2001
Location: White Rock, Canada
Posts: 2,238
Send a message via ICQ to eweruk Send a message via AIM to eweruk
I believe terminal server at this point....
eweruk is offline   Reply With Quote
Old May 26th, 2004, 03:33 PM     #10 (permalink)
Ultimate Member
 
MTAtech's Avatar
 
Join Date: Oct 2001
Location: Long Island, NY, USA
Posts: 4,646
Send a message via AIM to MTAtech Send a message via Yahoo to MTAtech
can you determine if it is inside you company's network or from the outside?
MTAtech is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Pastor Defends Anti-Islam Sign Theophylact IMO Community 63 September 18th, 2003 07:00 PM
the mess in Iraq seems to be snowballing pickel IMO Community 54 July 8th, 2003 12:32 PM
Illigal links Otaru Applications and Operating Systems 71 September 6th, 2002 07:41 PM
What Did You Do Yesterday? Brainchild IMO Community 22 July 6th, 2002 03:08 AM
nimda and ntldr cornhusker Technical Support 11 April 5th, 2002 01:46 AM

Most Active Discussions
Is It Just Me? (3000)
"mastermind" of London at.. (65)
Intel Pentium 4 531 (7)
AMD Phenom II X4 940 Black Edition (11)
nVidia GTX 295 now available (21)
Replacing integrated video card (5)
Folderchat Weekday thread (458)
building a gaming computer, input p.. (14)
I think I just killed my computer w.. (26)
Recent Discussions
WD Hard drive reading the wrong.. (1)
P4MAM2-V Mobo Support For Dual .. (1)
can't add picture to this forum (1)
NTVDM CPU has encountered an il.. (8)
canon eos20d problem (1)
I cant sign into msn messenger,.. (8)
nVidia GTX 295 now available (21)
Folderchat Weekday thread (458)
Could I run this set-up (15)
Blackberry Storm, Gears of War .. (2)
Core 2 Quad Q9550 system (3)
COWBOOM Ripoff! Used Laptop w/$.. (4)


All times are GMT -4. The time now is 07:29 AM.
TechIMO Copyright 2008 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28