Email received.
I recieved three emails on Friday 7th Nov, saying use this
security patch immediately, is this sent from Microsoft or
is this a hoax. I already use AVG 6 which is constantly
updated. Please reply asap. Tag: Look at these correction patch from the M$ Tag: 39257
hide network drive
I work with a program . This program uses some network
drive or share folders from network .
Iwant nobody can see these folders in " MY COMPUTER " ,
but my program work .
HOW CAN I DO THIS ? Tag: Look at these correction patch from the M$ Tag: 39255
File Encryption
If a file in an encrypted folder on a 2k server is
copied/moved over the internet to a local Windows XP
workstation encrypted folder--Is the file encrypted while
in transit over the internet? Tag: Look at these correction patch from the M$ Tag: 39253
.net passport username/password reader?
I have reason to suspect someone is trying to gain
my .net passport username and password. I have logged
into messenger, but there is another messenger icon that
is inactive. When I go to log in using it it looks fake
and does not have my stored usernames in the drop down
menu. Could this be something like HotmailHacker? How do
I get rid of it? Tag: Look at these correction patch from the M$ Tag: 39249
Changing default time for logout
I want to change the time that a user is able to stay on
the system inactively before the system goes idle and user
has to log back in.
Thanks,
Tim Tag: Look at these correction patch from the M$ Tag: 39243
whats the munging address?
I read here once that you can get a throw away address in
the event that a newsgroup, or other, asks you for one-
Is munging or throw away address the same thing???
WHere is this website(s) and how do they briefly work- OR
maybe there is a FAQ's on that site that would inform me
as well.thnks Tag: Look at these correction patch from the M$ Tag: 39241
RPC?
Hi im having problems with my computer, if I connect to
the internet it starts to shutdown after about 5 mins,
saying there is a failure with the RPC system. has
anyone got any idea what I can do to prevent it happening? Tag: Look at these correction patch from the M$ Tag: 39239
Win XP port 1900 & 5000 open
I have Win XP home with all the current updates applied.
Ports 1900 and 5000 (pnp) are supposed to be closed by an
old patch but mine are open? Tag: Look at these correction patch from the M$ Tag: 39238
OE stops my computer from receiving attachments
Is there anyone out there who can tell me how to get
around the problem of OE killing all incoming attachments
on my computer? Tag: Look at these correction patch from the M$ Tag: 39232
idgsearch.com
Help....I keep getting redirected to Idgsearch.com as my
home page.....any ideas anyone?? Tag: Look at these correction patch from the M$ Tag: 39231
Log-on password not working
I recently changed a password for logging on to my
administrator account. Later that day, my computer was
infected with the "Dafunks Keylogger.exe" and
the "HkLib.dll" Trojan Horse. I ran a virus scan to
clean up these two viruses. The following day when I
tried logging back on to my administrator account, my
password would not work. Is there anyway that I can get
back on to my administrator account? The only account
that I can log onto is a limited account. Tag: Look at these correction patch from the M$ Tag: 39230
** READ THIS BEFORE POSTING - answers to frequently asked questions 2003.11.08
Before you post a question to a Microsoft.public.*.security newsgroup, note
that your question may already be answered below:
Answers to Top Frequently Asked Questions:
http://securityadmin.info
My question is not mentioned below. How do I get an answer immediately,
with no waiting?
http://securityadmin.info/faq.htm#moreinfo
See also: http://www.google.com/groups?as_ugroup=microsoft.public.*
See also: http://www.google.com/advanced_group_search
See also: http://www.google.com
I want to post a problem or question to the newsgroup. What info do I need
to post in order to get a correct answer quickly?
http://securityadmin.info/faq.htm#netiquette
I just heard about a new Microsoft security patch update. Where can I get
the patch?
http://windowsupdate.microsoft.com OR
http://www.microsoft.com/technet/security/current.asp
I just installed a Microsoft security patch update, and now my computer is
having problems.
http://securityadmin.info/faq.htm#patchbroke
I received an email from Microsoft / Microsoft Support / Microsoft Internet
Security Center claiming to be a security patch [or comprehensive Internet
Explorer update]. Is this a virus?
http://securityadmin.info/faq.htm#microsoftemail
ALSO NOTE: www.grisoft.com is free antivirus, USE IT.
I received a virus email from a Microsoft email address. Who do I report
this to?
http://securityadmin.info/faq.htm#microsoftemail
I have the RPC Blaster worm "virus," what do I do?
http://www.microsoft.com/security/incident/blast.asp
ALSO NOTE: www.grisoft.com is free antivirus, USE IT.
My computer is giving RPC Remote Procedure Call messages.
There is a TFTP message or file on my computer.
My computer keeps locking up, and/or rebooting, or telling me that it will
reboot in 1 minute.
http://www.microsoft.com/security/incident/blast.asp
ALSO NOTE: www.grisoft.com is free antivirus, USE IT.
Where can I download the Blaster worm / RPC DCOM patch?
http://windowsupdate.microsoft.com OR
http://www.microsoft.com/technet/security/current.asp
I'm having a problem caused by the JDBGMGR.EXE Teddy Bear "virus" hoax, or I
want to replace this file.
http://securityadmin.info/faq.htm#jdbgmgr
I forgot my Windows logon password and can't log in. How do I reset it?
http://securityadmin.info/faq.htm#password
I have a problem or a question with a virus or with antivirus.
http://securityadmin.info/faq.htm#virus
NOTE: www.grisoft.com is free antivirus, USE IT.
Why is Outlook Express blocking my attachments as "unsafe"?
http://securityadmin.info/faq.htm#attachments
How do I stop getting pop-up messages? Or adware? Or spyware?
http://securityadmin.info/faq.htm#pop-ups
How do I block people from viewing adult or objectionable content on a
computer?
http://securityadmin.info/faq.htm#contentfilter
How do I block spam emails?
http://securityadmin.info/faq.htm#spam
There is a Content Advisor password blocking me from certain web sites.
http://securityadmin.info/faq.htm#contentadvisor
How do I delete an FTP folder that a hacker put on my computer and I cannot
delete?
http://securityadmin.info/faq.htm#ftpfolder
Have I been hacked? What do I do if I've been hacked?
http://securityadmin.info/faq.htm#hacked
How do I re-secure a computer that has been hacked?
http://securityadmin.info/faq.htm#re-secure
How do I test or improve the security on my computer to avoid being hacked?
http://securityadmin.info/faq.htm#harden
How do I investigate a suspicious IP address that may be trying to hack me?
http://securityadmin.info/faq.htm#trace
How do I report a hacker?
http://securityadmin.info/faq.htm#reporthacker
How do I use a port scanner or vulnerability scanner to test my security?
http://securityadmin.info/faq.htm#portscanner
How do I encrypt my files and/or hard drive?
http://securityadmin.info/faq.htm#encryption
How do I get a firewall? IDS?
http://securityadmin.info/faq.htm#firewall
I want to use the IPSec filtering or IP filtering feature of Windows to
block certain ports and have a problem or question.
http://securityadmin.info/faq.htm#ipsec
I have a problem or question with the XP ICF firewall.
http://securityadmin.info/faq.htm#icf
I have a problem or question with the IIS URLScan tool.
http://securityadmin.info/faq.htm#urlscan
How do I change the banner on my computer or server to hide what software
version I'm using?
http://securityadmin.info/faq.htm#banner
How do I enable Windows Auditing to tell who logged into Windows or who
accessed a file?
http://securityadmin.info/faq.htm#auditing
How do I inspect and disable programs that start up when Windows starts?
http://securityadmin.info/faq.htm#startup
How do I use RUNAS or let someone use RUNAS to run commands as administrator
without having to type the password?
http://securityadmin.info/faq.htm#runas
How do I let non-administrator users run Defrag or change their IP address?
http://securityadmin.info/faq.htm#runas
My question is not mentioned above. How do I get an answer immediately,
with no waiting?
http://securityadmin.info/faq.htm#moreinfo
See also: http://www.google.com/groups?as_ugroup=microsoft.public.*
See also: http://www.google.com/advanced_group_search
See also: http://www.google.com
I want to post a problem or question to the newsgroup. What info do I need
to post in order to get a correct answer quickly?
http://securityadmin.info/faq.htm#netiquette
Note that this is NOT a full list of all the questions answered in the FAQ.
Chances are, your question has probably already been answered. The complete
FAQ is at:
http://securityadmin.info/faq.htm#contents
I hope this is helpful. Feedback, suggestions and criticism regarding the
FAQ are welcome and may be emailed to me.
kind regards,
Karl Levinson, CISSP, MCSE, MVP
email: levinson_k@despammed.com Tag: Look at these correction patch from the M$ Tag: 39226
using other newsgroups & safety
Hi-I needed help with a non- microsoft program (corel-
word perfect 10) and a reader from this newsgroup
suggested for me to go to their Newsgroup site to answer
a question- I did; and when I clicked on the appropriate
NG, it opened up my outlook express and all the postings
were listed their. When I wanted to read them and clicked
on one os them, It told me that I had to sign up with a
news account(or something like that) in order to view the
postings. Of course, my ISP account name would then be
the one to use because of the POP3 thing. I dont want to
use my email address because of the danger in it. But
that is the only way to veiw these postings.
Here, at these MS newsgroups, one could click on anything
and read and not have to give the email address. Only if
you want to post something does it ask you for one. BUT
as we know, we could be anonymous@anonymous.com.
So my questions are these: # 1)How can I get around
using the email address I have with the ISP to do this.
#2) How safe is this news group (or others)if there is no
way around this.Can anyone answer this. Thnx
. Tag: Look at these correction patch from the M$ Tag: 39223
Help With Spyware Please
My Home Page is MSN.com and I like it but starting about a week ago, when I
launch IE I get a warning from Spybot that "Avenue A, Inc" (a spyware
program) is trying to load. If I change my Home Page to Yahoo.com, I do not
get the warning (which indicates to me that Avenue A, Inc is somehow keyed
to load when I launch IE with the Home Page set to MSN.com). If I launch IE
with Yahoo as my home page, then go to MSN.com, I do not get the Spybot
warning that Avenue A, Inc. is trying to load. Can anyone tell me if I can
reset IE so I can keep MSN.com as my home page without Avenue A, Inc trying
to load? (I've tried clearing all Cookies, IE Temp Files & History and
rebooting but that doesn't work). I don't know if it makes a difference but
I DO NOT have a static IP address. It changes each time I restart the
computer and connect to the Internet. Thanks for the help, Mac
I have a P-4, running Win XP Home on a PacBell DSL connection running
through a D-Link router ( Firewall for the Router is ON) , Win XP Firewall
is ON, and Spybot is ON.. Tag: Look at these correction patch from the M$ Tag: 39221
Security
patch after patch after patch after patch after patch...
I'm sick and tired of patching servers, users machines,
etc. etc.
where does it all end? why couldn't the software be
designed properly in the first place?
We have purchased our very LAST windows server product.
Goodbye, Microsoft, hello Linux :) Tag: Look at these correction patch from the M$ Tag: 39217
4 got pas/question
can anyone help me by telling me how to get new password
( but i dont know security question) Tag: Look at these correction patch from the M$ Tag: 39211
Security updates
I have downloaded all updates according to the Microsoft
Update Services. Each day I receive several notifications
telling me that there are more updates. Are these notices
correct? They look authentic, but I remebr being told that
there are bogus messages that say Microsoft and have
virusues in them. What should I do? Tag: Look at these correction patch from the M$ Tag: 39209
converting secure access 97 DB to Access 2k
Regardless of my access rights (I have admins) I get a
permissions error when tring to open the DB in question. I
created a replica of the original DB and was able to
convert it, but many forms and reports did not come over.
Does anyone know if there is a better way to approach this
conversion? Tag: Look at these correction patch from the M$ Tag: 39206
Critical updates
Why do I keep getting the same Critical update notice
every day after I've allready updated it that day
(KB819696) Tag: Look at these correction patch from the M$ Tag: 39204
Jet 4.0
I was scanning for updates for windows xp and the only
thing that i found was update for jet 4.0. Would someone
please tell me what that is?? Thanks Tag: Look at these correction patch from the M$ Tag: 39200
RPC Help
Can you help me out? I have a problem with my computer.
While i'm using my computer, sometimes a Warning message
comes up saying "Shuting down windows". Below it
says "RPC stopped functioning". It gives 30 seconds for
me to save my current data and then it shuts down and
restarts.
I would really appreciate it if you'd help me.
Justin Tag: Look at these correction patch from the M$ Tag: 39196
windows xp registration key
I have lost my registration # for windows xp. I
registered it with microsoft is there someplace they can
look it up for me. Tag: Look at these correction patch from the M$ Tag: 39194
** READ THIS BEFORE POSTING - answers to frequently asked questions 2003.11.07
Before you post a question to a Microsoft.public.*.security newsgroup, note
that your question may already be answered below:
Answers to Top Frequently Asked Questions:
http://securityadmin.info
My question is not mentioned below. How do I get an answer immediately,
with no waiting?
http://securityadmin.info/faq.htm#moreinfo
See also: http://www.google.com/groups?as_ugroup=microsoft.public.*
See also: http://www.google.com/advanced_group_search
See also: http://www.google.com
I want to post a problem or question to the newsgroup. What info do I need
to post in order to get a correct answer quickly?
http://securityadmin.info/faq.htm#netiquette
I just heard about a new Microsoft security patch update. Where can I get
the patch?
http://windowsupdate.microsoft.com OR
http://www.microsoft.com/technet/security/current.asp
I just installed a Microsoft security patch update, and now my computer is
having problems.
http://securityadmin.info/faq.htm#patchbroke
I received an email from Microsoft / Microsoft Support / Microsoft Internet
Security Center claiming to be a security patch [or comprehensive Internet
Explorer update]. Is this a virus?
http://securityadmin.info/faq.htm#microsoftemail
ALSO NOTE: www.grisoft.com is free antivirus, USE IT.
I received a virus email from a Microsoft email address. Who do I report
this to?
http://securityadmin.info/faq.htm#microsoftemail
I have the RPC Blaster worm "virus," what do I do?
http://www.microsoft.com/security/incident/blast.asp
ALSO NOTE: www.grisoft.com is free antivirus, USE IT.
My computer is giving RPC Remote Procedure Call messages.
There is a TFTP message or file on my computer.
My computer keeps locking up, and/or rebooting, or telling me that it will
reboot in 1 minute.
http://www.microsoft.com/security/incident/blast.asp
ALSO NOTE: www.grisoft.com is free antivirus, USE IT.
Where can I download the Blaster worm / RPC DCOM patch?
http://windowsupdate.microsoft.com OR
http://www.microsoft.com/technet/security/current.asp
I'm having a problem caused by the JDBGMGR.EXE Teddy Bear "virus" hoax, or I
want to replace this file.
http://securityadmin.info/faq.htm#jdbgmgr
I forgot my Windows logon password and can't log in. How do I reset it?
http://securityadmin.info/faq.htm#password
I have a problem or a question with a virus or with antivirus.
http://securityadmin.info/faq.htm#virus
NOTE: www.grisoft.com is free antivirus, USE IT.
Why is Outlook Express blocking my attachments as "unsafe"?
http://securityadmin.info/faq.htm#attachments
How do I stop getting pop-up messages? Or adware? Or spyware?
http://securityadmin.info/faq.htm#pop-ups
How do I block people from viewing adult or objectionable content on a
computer?
http://securityadmin.info/faq.htm#contentfilter
How do I block spam emails?
http://securityadmin.info/faq.htm#spam
There is a Content Advisor password blocking me from certain web sites.
http://securityadmin.info/faq.htm#contentadvisor
How do I delete an FTP folder that a hacker put on my computer and I cannot
delete?
http://securityadmin.info/faq.htm#ftpfolder
Have I been hacked? What do I do if I've been hacked?
http://securityadmin.info/faq.htm#hacked
How do I re-secure a computer that has been hacked?
http://securityadmin.info/faq.htm#re-secure
How do I test or improve the security on my computer to avoid being hacked?
http://securityadmin.info/faq.htm#harden
How do I investigate a suspicious IP address that may be trying to hack me?
http://securityadmin.info/faq.htm#trace
How do I report a hacker?
http://securityadmin.info/faq.htm#reporthacker
How do I use a port scanner or vulnerability scanner to test my security?
http://securityadmin.info/faq.htm#portscanner
How do I encrypt my files and/or hard drive?
http://securityadmin.info/faq.htm#encryption
How do I get a firewall? IDS?
http://securityadmin.info/faq.htm#firewall
I want to use the IPSec filtering or IP filtering feature of Windows to
block certain ports and have a problem or question.
http://securityadmin.info/faq.htm#ipsec
I have a problem or question with the XP ICF firewall.
http://securityadmin.info/faq.htm#icf
I have a problem or question with the IIS URLScan tool.
http://securityadmin.info/faq.htm#urlscan
How do I change the banner on my computer or server to hide what software
version I'm using?
http://securityadmin.info/faq.htm#banner
How do I enable Windows Auditing to tell who logged into Windows or who
accessed a file?
http://securityadmin.info/faq.htm#auditing
How do I inspect and disable programs that start up when Windows starts?
http://securityadmin.info/faq.htm#startup
How do I use RUNAS or let someone use RUNAS to run commands as administrator
without having to type the password?
http://securityadmin.info/faq.htm#runas
How do I let non-administrator users run Defrag or change their IP address?
http://securityadmin.info/faq.htm#runas
My question is not mentioned above. How do I get an answer immediately,
with no waiting?
http://securityadmin.info/faq.htm#moreinfo
See also: http://www.google.com/groups?as_ugroup=microsoft.public.*
See also: http://www.google.com/advanced_group_search
See also: http://www.google.com
I want to post a problem or question to the newsgroup. What info do I need
to post in order to get a correct answer quickly?
http://securityadmin.info/faq.htm#netiquette
Note that this is NOT a full list of all the questions answered in the FAQ.
Chances are, your question has probably already been answered. The complete
FAQ is at:
http://securityadmin.info/faq.htm#contents
I hope this is helpful. Feedback, suggestions and criticism regarding the
FAQ are welcome and may be emailed to me.
kind regards,
Karl Levinson, CISSP, MCSE, MVP
email: levinson_k@despammed.com Tag: Look at these correction patch from the M$ Tag: 39185
Help
Does anyone know how to delay a batch file from running.
I have researched this on he web & found the following;
sleep 6000
sleep 6000;
sleep (6000);
None of these pause my batch file for 60secs as it should.
I know about the pause command, unfortunately I need this
to run automatically at a certain time.
Regards
James
Ps I know this not a dos newsgroup but I thought that one
of you guru's would know Tag: Look at these correction patch from the M$ Tag: 39183
Policy editor in Windows 2003
HI,
I'd like to know if policy editor is still used for
Windows NT 4.0 clients in a Windows 2003 domain. If so
does anyone have any tips regarding migrating the policy
editor configurations from a Windows NT 4.0 domain to a
Windows 2003 domain.
Thanks
Peter Tag: Look at these correction patch from the M$ Tag: 39182
Howto: Smart card logon to a workstation belong to a different trusted domain/forest!
Dear all,
we are a business college which computers are not only used by our students
but also by students from other colleges (it's like, all colleges work
independently but a few courses are here and a few are there...)
But now to the problem: Smart card logon on a computer which belongs to an
other trusted domain but what hasn't issued the smart card certificate.
Let's take the following scenario:
(MS Windows 2003 Server Standard - forests and domains are running under
native mode)
(MS Windows XP workstations)
College A
is in forest A
and has the domain A
College B
is in forest B
and has the domain B
(there is a two-way forest trust, so the normal user logon (with username
and password) works fine.)
Let's continue:
now the students from College A are coming to College B and want to login
with their smart cards. But their smart card certs have been issued by
domain A and now I always get the error message "The system cannot log you
on. Your credentials could not be verified".
Ok, after a while of debugging I have realized that the certificate of the
root ca (from domain A) is missing on the workstations (from domain B).
I did the following test(s):
1.) I imported the root ca certificate to the Trusted Root CA Store of the
local computer (in domain B).
2.) I imported the sub ca certificate to the Intermediate CA Store of the
local computer (in domain B).
Then I still got the same error message.
3.) I logged in with any user account (username+password) from domain A and
that worked fine.
4.) After that I could also use the smart card to log in.
BUT: yesterday we continued getting the same error message although we have
done the steps before.
If we repeat these steps it works fine again.
Am I doing something wrong? Is something missing?
For any hint or better solution I am very thankful.
Best regards,
Hans
PS: All tests were made in a test lab but it represents the real
environment. Tag: Look at these correction patch from the M$ Tag: 39180
Internet Explorer Script Error -- major problem
My computer system must have been infected by a new virus
b/c my symmantec anti-virus software does not detect a
problem. This is what is happening to my system ...
Internet Explorer Script Error
Line 60
Char 3
Error: testwin is undefined
Code 0
URL // ad.searchsquire.com/testgeo.php
I am then bombarded with this error over and over again
until my system crashes .. I cannot seem to stop it even
with CLT ALT DLT and ending the task.
Anyone with any information, please contact me
Thanks Tag: Look at these correction patch from the M$ Tag: 39177
VPN Problems
We have 2 sites both running independantly
Each site has a netgear DG814 DSL router
The main site has a 3com office connect Firewall
The remote site has a 3com Cable/DSL Firewall
ISP has issued one static IP for each site
Both Routers are configured with NAT down to a private ip range
192.168.10 and 192.168.11
The Firewalls are then configured to NAT down from these ranges to
192.168.2 and 192.168.1
I have port forwarded 1723 on the main site end down to the windows
2000 server and i can now create VPN connections from the remote site-
Problems come about when i create two connections, the first and
second then both fail.
The other problem i have is i have port forwarded 3389 down to the
local server, if i dial into an ISP from my laptop then i can connect
using the mremote desktop client to the public IP of the main site
Terminal services , but i can't connect to this public IP from the 2nd
site.
i tried connecting two sites together as a VPN but the main office
connect firewall requires an upgrade.
I'm not sure if the problem is related to only having one source IP
and then this being NATd down.
i know it's not a straight forward problem (maybe it is ) but i would
appreciate some help and guidance from any one out there
Regards
Paul Tomlinson Tag: Look at these correction patch from the M$ Tag: 39170
content advisor and show pictures
I`m sure this is simple thing to rectify but can anyone
help me ,,, every site i visit i have to rt click boxes to
view pictures also everytime i go on line have to disable
content advisor. I have show pictures box ticked in
advanced settings Tag: Look at these correction patch from the M$ Tag: 39167
VPN & mapped drives to remote server
Here is an interesting one. W2K SP4, when either WinXP
or 2000 remote laptops connect to the server via VPN,
PPTP & DHCP and are authenticated they connot connect
thier mapped drives nor recreate them. However they can
connect to Outlook & ping the remoter server? If we log
the laptop in-house to the network then they will be able
to map the drives as well as remotly from then on. IS
there a setting somewher that I am missing so that we
don't have to bring all the laptops in-house to fix?
Thanks
Steve Tag: Look at these correction patch from the M$ Tag: 39166
Posting of e-mail addresses
Do not use your e-mail address on this site. I made that
mistake a couple of weeks ago, and my in box is filled
with virus attachments. I now use mail washer and preview
all e-mails. These newsgroups are mined for addresses to
spread the viruses. Tag: Look at these correction patch from the M$ Tag: 39157
FTC Obtains Order Barring Pop-up Spam Scam
"This is nothing more than a high-tech version of a classic scam," said
Howard Beales, Director of the FTC's Bureau of Consumer Protection. "The
defendants created the problem that they proposed to solve - for a fee.
Their pop-up spam wasted computer users' time and caused them needless
frustration."
http://www.ftc.gov/opa/2003/11/dsquared.htm Tag: Look at these correction patch from the M$ Tag: 39154
KDC certificate
I can't log on with my smartcard to the domain.
The event error message on the DC displays that the KDC
certificate is missing. On the workstation the error
message 'error 0x8000bb' is displayed.
How can i renew or install a new certificate for the KDC? Tag: Look at these correction patch from the M$ Tag: 39150
Bogus Microsoft messages
Ever since I installed a new HP Printer in October, 2003,
I have been receiving messages, with a Microsoft logo,
telling me about a "November 2003 Cumulative Patch" and
directing me to open the attachment below to receive it.
When I scan the attachment with my anti-virus software, it
tells me a virus exists. I don't open the attachment.
I get floods of this alleged Microsoft message, sometimes
a dozen or more a day. How can I get them to stop.
Robert Tag: Look at these correction patch from the M$ Tag: 39149
Simple CA guide
Hi,
I'm at a small company (35 people) but we need some Certificates for IPSec
VPNs and SSL connections. I found some guides from MS, but they all seam to
be build for Enterprise level customers. I need a simple guide for a simple
infrastructure... Not with top level security but with a reasonable level of
protection...
Is there anything like that?
Thanks,
Thomas Tag: Look at these correction patch from the M$ Tag: 39146
Successive anonymous logons
At times I may have 30 or 40 successful Anonymous Logons or Logoffs within
virtually the same timeframe. The only thing that changes is the LogonID.
This occurs on a Win2K IIS 5.1 server. Web log files show activity at that
time from one authenticated user. What can be causing this and is it
suspicious activity?
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 538
Date: 11/6/2003
Time: 8:50:16 AM
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: SERVER
Description:
User Logoff:
User Name: ANONYMOUS LOGON
Domain: NT AUTHORITY
Logon ID: (0x0,0x12F88DE5)
Logon Type: 3 Tag: Look at these correction patch from the M$ Tag: 39144