- Joined
- Nov 30, 2007
- Messages
- 4
- Reaction score
- 0
recently i discovered alot of anonamous log ons, guest log ons despite Guest account being off, here is a short list of items from my Security Log
Edit: Im running Windows XP home SP2 all windows Updates are done,
Event Type: Success Audit
Event Source: Security
Event Category: Privilege Use
Event ID: 576
Date: 12/1/2007
Time: 2:29:41 AM
User: NT AUTHORITY\NETWORK SERVICE
Computer: GEARJAMMER
Description:
Special privileges assigned to new logon:
User Name: NETWORK SERVICE
Domain: NT AUTHORITY
Logon ID: (0x0,0x3E4)
Privileges: SeAuditPrivilege
SeAssignPrimaryTokenPrivilege
SeChangeNotifyPrivilege
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 528
Date: 12/1/2007
Time: 2:29:41 AM
User: NT AUTHORITY\NETWORK SERVICE
Computer: GEARJAMMER
Description:
Successful Logon:
User Name: NETWORK SERVICE
Domain: NT AUTHORITY
Logon ID: (0x0,0x3E4)
Logon Type: 5
Logon Process: Advapi
Authentication Package: Negotiate
Workstation Name:
Logon GUID: {00000000-0000-0000-0000-000000000000}
Event Type: Success Audit
Event Source: Security
Event Category: Privilege Use
Event ID: 576
Date: 12/1/2007
Time: 2:28:54 AM
User: NT AUTHORITY\NETWORK SERVICE
Computer: GEARJAMMER
Description:
Special privileges assigned to new logon:
User Name: NETWORK SERVICE
Domain: NT AUTHORITY
Logon ID: (0x0,0x3E4)
Privileges: SeAuditPrivilege
SeAssignPrimaryTokenPrivilege
SeChangeNotifyPrivilege
Ive Been Trying to Rack my brain on how to stop this guy from getting in but having no luck
help me plz
Edit: Im running Windows XP home SP2 all windows Updates are done,
Event Type: Success Audit
Event Source: Security
Event Category: Privilege Use
Event ID: 576
Date: 12/1/2007
Time: 2:29:41 AM
User: NT AUTHORITY\NETWORK SERVICE
Computer: GEARJAMMER
Description:
Special privileges assigned to new logon:
User Name: NETWORK SERVICE
Domain: NT AUTHORITY
Logon ID: (0x0,0x3E4)
Privileges: SeAuditPrivilege
SeAssignPrimaryTokenPrivilege
SeChangeNotifyPrivilege
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 528
Date: 12/1/2007
Time: 2:29:41 AM
User: NT AUTHORITY\NETWORK SERVICE
Computer: GEARJAMMER
Description:
Successful Logon:
User Name: NETWORK SERVICE
Domain: NT AUTHORITY
Logon ID: (0x0,0x3E4)
Logon Type: 5
Logon Process: Advapi
Authentication Package: Negotiate
Workstation Name:
Logon GUID: {00000000-0000-0000-0000-000000000000}
Event Type: Success Audit
Event Source: Security
Event Category: Privilege Use
Event ID: 576
Date: 12/1/2007
Time: 2:28:54 AM
User: NT AUTHORITY\NETWORK SERVICE
Computer: GEARJAMMER
Description:
Special privileges assigned to new logon:
User Name: NETWORK SERVICE
Domain: NT AUTHORITY
Logon ID: (0x0,0x3E4)
Privileges: SeAuditPrivilege
SeAssignPrimaryTokenPrivilege
SeChangeNotifyPrivilege
Ive Been Trying to Rack my brain on how to stop this guy from getting in but having no luck
help me plz
Last edited: