A Windows XP help forum. PCbanter

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Go Back   Home » PCbanter forum » Microsoft Windows XP » Security and Administration with Windows XP
Site Map Home Register Authors List Search Today's Posts Mark Forums Read Web Partners

Multiple Logon Failure/Success Audits



 
 
Thread Tools Display Modes
  #1  
Old November 29th 05, 07:23 AM posted to microsoft.public.windowsxp.security_admin
external usenet poster
 
Posts: n/a
Default Multiple Logon Failure/Success Audits

Hi:

1. While trying to login remotely to my XP machine (say XP1), I noticed
multiple 'failure audits' from this machine (XP2). I did login incorrectly
once and that was a valid entry to be seen in the logs of XP1. However, there
were multiple such entries of which I am clueless about.
Any help is appreciated.
Ads
  #2  
Old November 29th 05, 07:40 AM posted to microsoft.public.windowsxp.security_admin
external usenet poster
 
Posts: n/a
Default Multiple Logon Failure/Success Audits

It is not unusual to see multiple logon failures recorded for a single
failed logon attempt and these failures would have the same approximate
timestamp. If you are seeing a lot of logon failures at different times and
days then someone may be trying to access your computer and your best
defense is to use a very strong user password or smart card for any account
that is allowed to access the computer remotely. If you can configure your
firewall to allow remote access attempts only from authorized IP addresses
that can increase security but may not be possible if the users that need
access do not have a static public IP address or roam from place to place.
L2tp can also increase security because it requires that both computer
[first] and user authenticate to the VPN connection ideally with
certificates. --- Steve


"WhoC@nItbN0W" wrote in message
...
Hi:

1. While trying to login remotely to my XP machine (say XP1), I noticed
multiple 'failure audits' from this machine (XP2). I did login
incorrectly
once and that was a valid entry to be seen in the logs of XP1. However,
there
were multiple such entries of which I am clueless about.
Any help is appreciated.



  #3  
Old November 29th 05, 07:59 AM posted to microsoft.public.windowsxp.security_admin
external usenet poster
 
Posts: n/a
Default Multiple Logon Failure/Success Audits

While the password, who can access remotely and the like policies are in
place, what bothers me is that for a single bad logon, tens of entries are
made in approximately a second or two.
While brute force is a possibility here, all the log entries point tothe
machine XP2, where I was sitting and trying to login remotely. Hence, this
possibility can be disregarded ( There were no tools running during this time
on XP2 - made sure of that).
And wow! I didn't know I could type my password so many times in a second!!

Jokes apart, any further ideas are appreciated.

Thanks

"Steven L Umbach" wrote:

It is not unusual to see multiple logon failures recorded for a single
failed logon attempt and these failures would have the same approximate
timestamp. If you are seeing a lot of logon failures at different times and
days then someone may be trying to access your computer and your best
defense is to use a very strong user password or smart card for any account
that is allowed to access the computer remotely. If you can configure your
firewall to allow remote access attempts only from authorized IP addresses
that can increase security but may not be possible if the users that need
access do not have a static public IP address or roam from place to place.
L2tp can also increase security because it requires that both computer
[first] and user authenticate to the VPN connection ideally with
certificates. --- Steve


"WhoC@nItbN0W" wrote in message
...
Hi:

1. While trying to login remotely to my XP machine (say XP1), I noticed
multiple 'failure audits' from this machine (XP2). I did login
incorrectly
once and that was a valid entry to be seen in the logs of XP1. However,
there
were multiple such entries of which I am clueless about.
Any help is appreciated.




  #4  
Old November 29th 05, 07:20 PM posted to microsoft.public.windowsxp.security_admin
external usenet poster
 
Posts: n/a
Default Multiple Logon Failure/Success Audits

That is known behavior in Windows and in part the number of entries depends
on the number of authentication methods that are allowed as shown in the
security option for lan manager authentication level in Local Security
Policy [assuming XP pro] where you may want to configure it to send ntlmv2
response only for all your computers if you do not have a need to use file
and print sharing ever with W9X computers. Also this is a reason Microsoft
suggests for those using account lockout to use an account lockout threshold
of no less than ten bad attempts. --- Steve

http://www.microsoft.com/resources/d...en-us/576.mspx
--- lan manager authentication level


"WhoC@nItbN0W" wrote in message
...
While the password, who can access remotely and the like policies are in
place, what bothers me is that for a single bad logon, tens of entries are
made in approximately a second or two.
While brute force is a possibility here, all the log entries point tothe
machine XP2, where I was sitting and trying to login remotely. Hence, this
possibility can be disregarded ( There were no tools running during this
time
on XP2 - made sure of that).
And wow! I didn't know I could type my password so many times in a
second!!

Jokes apart, any further ideas are appreciated.

Thanks

"Steven L Umbach" wrote:

It is not unusual to see multiple logon failures recorded for a single
failed logon attempt and these failures would have the same approximate
timestamp. If you are seeing a lot of logon failures at different times
and
days then someone may be trying to access your computer and your best
defense is to use a very strong user password or smart card for any
account
that is allowed to access the computer remotely. If you can configure
your
firewall to allow remote access attempts only from authorized IP
addresses
that can increase security but may not be possible if the users that need
access do not have a static public IP address or roam from place to
place.
L2tp can also increase security because it requires that both computer
[first] and user authenticate to the VPN connection ideally with
certificates. --- Steve


"WhoC@nItbN0W" wrote in message
...
Hi:

1. While trying to login remotely to my XP machine (say XP1), I
noticed
multiple 'failure audits' from this machine (XP2). I did login
incorrectly
once and that was a valid entry to be seen in the logs of XP1. However,
there
were multiple such entries of which I am clueless about.
Any help is appreciated.






 




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
SOLVED error 1385 "Logon failu the user has not been granted the requested logon type at this computer james hanley Windows XP Help and Support 5 October 26th 09 01:50 PM
logon to multiple SBS Domains Keith @ Link Up Windows XP Help and Support 0 November 14th 05 10:22 AM
Sound settings with multiple users Scott S. General XP issues or comments 4 November 8th 05 10:52 PM
Logon Error: "command length is incorrect" (NO ONE LOGON) Griobhtha Windows XP Help and Support 3 July 15th 05 07:22 PM
SOLVED error 1385 "Logon failu the user has not been granted the requested logon type at this computer james hanley Networking and the Internet with Windows XP 3 April 3rd 05 09:22 PM






All times are GMT +1. The time now is 03:52 PM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright ©2004-2024 PCbanter.
The comments are property of their posters.