|
|||||||||||
|
Re: Weird Windows logon attempts
From: Bojan Zdrnja <bojan.zdrnja(at)lss.hr>
Date: Mon Feb 24 2003 - 04:07:55 EST
> We have just setup ntsyslog from sourceforge.net. Our security policy is to log
You should see same logs in your server's event log. > Has anyone seen this? They are 2k/XP boxes. Does Windows 2k/XP automagically try
Can you maybe confirm that problem is happening only when users work on Windows XP boxes ? > Feb 22 13:27:49 exchange.auckland.ac.nz/exchange.auckland.ac.nz
<You probably knew this>
Basically, you should check on both machines (server and client here) what's happening.
I had similar problem, but only with Windows XP machines.
Solution was to switch off the setting in the Explorer for Automatic discovery
of network folders and shares.
Other problem with this, besides it's filling your logs on servers, is that if you have some Pre-Win2K machines on the network, XP will transmit it's password to those machines as well. It will transmit LM hash which is weak. You can disable Windows XP generating LM hash by modifying following registry key: HKLM\SYSTEM\CurrentControlSet\Control\Lsa\NoLMHash it's value should be set to 1 (REG_DWORD). More info about this at: http://www.sans.org/top20/#W6 Best regards, Bojan Zdrnja
<Pre>Lose another weekend managing your IDS?
Take back your personal time.
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:59 EDT |
||||||||||
|
|||||||||||