PC Review


Reply
Thread Tools Rate Thread

Block clients from accessing domain controllers

 
 
Rob McShinsky
Guest
Posts: n/a
 
      13th Apr 2004
I am looking for a quick and dirty way to block identified clients both
inside and outside the domain from making logon attempts to the domain
controller. We have had some internal problems with variant of the Gaobot
virus which try feverishly to use its list of username and passwords against
the domain controller. We have seen upwards of 200000 failed logon attempts
in 15 minutes. This is causing a type of denial of service situation where
the domain controllers at out main site are getting loaded so much that
logon requests are being sent to DC's at different AD sites across slower
links. Any thoughts would be helpful.

Rob McShinsky


 
Reply With Quote
 
 
 
 
paisher
Guest
Posts: n/a
 
      13th Apr 2004

>-----Original Message-----
>I am looking for a quick and dirty way to block

identified clients both
>inside and outside the domain from making logon attempts

to the domain
>controller. We have had some internal problems with

variant of the Gaobot
>virus which try feverishly to use its list of username

and passwords against
>the domain controller. We have seen upwards of 200000

failed logon attempts
>in 15 minutes. This is causing a type of denial of

service situation where
>the domain controllers at out main site are getting

loaded so much that
>logon requests are being sent to DC's at different AD

sites across slower
>links. Any thoughts would be helpful.
>
>Rob McShinsky
>
>
>.
>Close port 88? Disable or stop the authentication

service.
 
Reply With Quote
 
Rob McShinsky
Guest
Posts: n/a
 
      13th Apr 2004
A little too dirty. That would shutdown the other 5000 people who do not
have the virus on their machine.


"paisher" <(E-Mail Removed)> wrote in message
news:1761801c42169$45817050$(E-Mail Removed)...
>
>>-----Original Message-----
>>I am looking for a quick and dirty way to block

> identified clients both
>>inside and outside the domain from making logon attempts

> to the domain
>>controller. We have had some internal problems with

> variant of the Gaobot
>>virus which try feverishly to use its list of username

> and passwords against
>>the domain controller. We have seen upwards of 200000

> failed logon attempts
>>in 15 minutes. This is causing a type of denial of

> service situation where
>>the domain controllers at out main site are getting

> loaded so much that
>>logon requests are being sent to DC's at different AD

> sites across slower
>>links. Any thoughts would be helpful.
>>
>>Rob McShinsky
>>
>>
>>.
>>Close port 88? Disable or stop the authentication

> service.



 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Block clients from accessing domain controllers Rob McShinsky Microsoft Windows 2000 5 13th Apr 2004 08:39 PM
Block clients from accessing domain controllers Rob McShinsky Microsoft Windows 2000 Active Directory 2 13th Apr 2004 03:24 PM
Clients registering as Domain Controllers in DNS =?Utf-8?B?SmF5bXo=?= Microsoft Windows 2000 Networking 0 6th Oct 2003 08:46 PM
Accessing Domain controllers through Firewall Nasser Hosseini Microsoft Windows 2000 Security 1 21st Jul 2003 03:31 PM
Accessing Domain controllers through Firewall Nasser Hosseini Microsoft Windows 2000 Networking 1 21st Jul 2003 03:31 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 07:09 AM.