If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. |
|
|
Thread Tools | Display Modes |
#1
|
|||
|
|||
NT AUTHORITY\ANONYMOUS LOGON type 3
I got the following message on Event Viewer and I know that type 3 is user from network logged. Is that critical? If yes, is there a way to block it?
Event Type: Success Audit Event Source: Security Event Category: Logon/Logoff Event ID: 540 Date: 6/17/2004 Time: 4:30:00 PM User: NT AUTHORITY\ANONYMOUS LOGON Computer: LAPHOME Description: Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x12E3D) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: {00000000-0000-0000-0000-000000000000} For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. |
Ads |
#2
|
|||
|
|||
NT AUTHORITY\ANONYMOUS LOGON type 3
You could turn on your firewall..
With Pro version there are some local security policy settings you can use to impact null session / anonymous login. -- Roger Abell Microsoft MVP (Windows Server System: Security) MCSE (W2k3,W2k,Nt4) MCDBA "GuigoCLT" wrote in message ... I got the following message on Event Viewer and I know that type 3 is user from network logged. Is that critical? If yes, is there a way to block it? Event Type: Success Audit Event Source: Security Event Category: Logon/Logoff Event ID: 540 Date: 6/17/2004 Time: 4:30:00 PM User: NT AUTHORITY\ANONYMOUS LOGON Computer: LAPHOME Description: Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x12E3D) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: {00000000-0000-0000-0000-000000000000} For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. |
Thread Tools | |
Display Modes | |
|
|