PC Review


Reply
Thread Tools Rate Thread

Vista x32 - Strange SSL System Events

 
 
Bathrone
Guest
Posts: n/a
 
      15th Aug 2007
Hi folks. Im getting recurring strange Vista events reported in the system
log. Its occuring on each boot. I am unsure how to diagnose this further and
I would appreciate any help with it. The events are:

SSL Certificate Settings deleted for Port : 192.168.1.2:6331 .
SSL Certificate Settings created by an admin process for Port :
192.168.1.2:6331 .
SSL Certificate Settings deleted for Port : 255.255.255.255:6331 .
SSL Certificate Settings created by an admin process for Port :
255.255.255.255:6331 .
SSL Certificate Settings deleted for Port : 255.255.255.255:6331 .
SSL Certificate Settings created by an admin process for Port :
255.255.255.255:6331 .

I dont know what settings are changing and what admin process is doing it.
Could this be some sort of man in the middle ssl hack attempt?

 
Reply With Quote
 
 
 
 
S. Pidgorny
Guest
Posts: n/a
 
      15th Aug 2007
What's the event id/source?

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *

"Bathrone" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> Hi folks. Im getting recurring strange Vista events reported in the system
> log. Its occuring on each boot. I am unsure how to diagnose this further
> and I would appreciate any help with it. The events are:
>
> SSL Certificate Settings deleted for Port : 192.168.1.2:6331 .
> SSL Certificate Settings created by an admin process for Port :
> 192.168.1.2:6331 .
> SSL Certificate Settings deleted for Port : 255.255.255.255:6331 .
> SSL Certificate Settings created by an admin process for Port :
> 255.255.255.255:6331 .
> SSL Certificate Settings deleted for Port : 255.255.255.255:6331 .
> SSL Certificate Settings created by an admin process for Port :
> 255.255.255.255:6331 .
>
> I dont know what settings are changing and what admin process is doing it.
> Could this be some sort of man in the middle ssl hack attempt?



 
Reply With Quote
 
Bathrone
Guest
Posts: n/a
 
      15th Aug 2007
Thanks Svyatoslav for helping me. All six of the events that occur together
each time on boot have source: HttpEvent

The events that are "SSL Certificate Settings deleted for Port : nnnnnn" all
have the ID: 15300 and the events that are "SSL Certificate Settings created
by an admin process for Port : nnnnnnnnn" all have the ID: 15301

 
Reply With Quote
 
Bathrone
Guest
Posts: n/a
 
      15th Aug 2007
Having rebooted again I got the six usual events, but also two new error
level events:

"An error occured while using SSL configuration for socket address
192.168.1.2:6331. The error status code is contained within the returned
data." Source: HttpEvent ID: 15021

and

"An error occured while using SSL configuration for socket address
255.255.255.255:6331. The error status code is contained within the
returned data." Source: HttpEvent ID: 15021

 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Strange behavior from Vista System sherwin dubren Windows Vista General Discussion 12 21st Sep 2009 09:35 PM
Strange Login events Andreas Moroder Microsoft Windows 2000 Security 2 30th Aug 2006 07:58 AM
Strange events =?Utf-8?B?bmljZWRheQ==?= Windows XP Help 7 5th Aug 2006 01:39 AM
Very strange events Aart Microsoft Windows 2000 Advanced Server 1 20th Aug 2003 07:21 AM
Strange Behavior w/Events Jason Turim Microsoft ASP .NET 0 19th Jul 2003 10:03 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 11:12 AM.