P
paddy8205
One of the laptops on the network is producing Event 676 errors in the
security log. Lots of them:
Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 676
Date: 3/31/2004
Time: 12:51:04 PM
User: NT AUTHORITY\SYSTEM
Computer: EKSTERN
Description:
Authentication Ticket Request Failed:
User Name: gamroot
Supplied Realm Name: domain.COM
Service Name: krbtgt/domain.COM
Ticket Options: 0x40810010
Failure Code: 0x6
Client Address: 131.27.3.18
I know the security event is caused by a bad user name, but sometimes
hundreds of these show up from this laptop's client address within a
short period of time and I don't recognize the user names. (gamroot,
bcmack, etc.) I can verify which computer it comes from because of
the DHCP leases. I've checked for viruses and spyware and came up
with nothing. At first I thought they might be letting someone else
use their computer while at home and VPN'd in but I got the same
events yesterday when they were in the office logged into the network.
Does anyone have any idea what else I can look for or use to track
down what is happening?
Thanks.
security log. Lots of them:
Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 676
Date: 3/31/2004
Time: 12:51:04 PM
User: NT AUTHORITY\SYSTEM
Computer: EKSTERN
Description:
Authentication Ticket Request Failed:
User Name: gamroot
Supplied Realm Name: domain.COM
Service Name: krbtgt/domain.COM
Ticket Options: 0x40810010
Failure Code: 0x6
Client Address: 131.27.3.18
I know the security event is caused by a bad user name, but sometimes
hundreds of these show up from this laptop's client address within a
short period of time and I don't recognize the user names. (gamroot,
bcmack, etc.) I can verify which computer it comes from because of
the DHCP leases. I've checked for viruses and spyware and came up
with nothing. At first I thought they might be letting someone else
use their computer while at home and VPN'd in but I got the same
events yesterday when they were in the office logged into the network.
Does anyone have any idea what else I can look for or use to track
down what is happening?
Thanks.