Event 529 and 681

R

Rick

I have been getting a large amount of events 529 and 681 every three days or
so.
I get about 280 of these event in about a 5 minute span. Then nothing or 3
days or so and then again.

The server is ISA with N2H2 on it. The ISA is in Cache mode only it is only
used for web filtering and is behind the firewall. It also have Exchange
2000 SP3 on this server. It had been going fine for about a year and then
this started. The system functions fine I was just wondering about this.

Any ideas would be most appreciated!!!

Thanks in advance,

Rick

Here are the events in case you need that.

Alert in Event log: Security
Type: Audit Failure Date: 3/9/2005
Time: 04:45 PM Source: Security
Category: (2): Logon/Logoff Event ID: 529
User: S-1-5-18
Description:
Logon Failure:

Reason: Unknown user name or bad password

User Name: 33333333

Domain: Logon Type: 3

Logon Process: Advapi

Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0

Workstation Name:(server name removed)


Alert in Event log: Security
Type: Audit Failure Date: 3/9/2005
Time: 04:45 PM Source: Security
Category: (9): Account Logon Event ID: 681
User: S-1-5-18
Description:
The logon to account: 33333333

by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0

from workstation: (server name removed)

failed. The error code was: 3221225572
 
A

Austin M. Horst

----------------
Event ID 529
----------------

http://www.eventid.net/display.asp?eventid=529&eventno=1&source=Security&phase=1

http://support.microsoft.com/default.aspx?scid=kb;en-us;159792
http://support.microsoft.com/default.aspx?scid=kb;en-us;159969
http://support.microsoft.com/default.aspx?scid=kb;en-us;171148
http://support.microsoft.com/default.aspx?scid=kb;en-us;172402
http://support.microsoft.com/default.aspx?scid=kb;en-us;174073
http://support.microsoft.com/default.aspx?scid=kb;en-us;174074
http://support.microsoft.com/default.aspx?scid=kb;en-us;238372
http://support.microsoft.com/default.aspx?scid=kb;en-us;239869
http://support.microsoft.com/default.aspx?scid=kb;en-us;272594
http://support.microsoft.com/default.aspx?scid=kb;en-us;287639
http://support.microsoft.com/default.aspx?scid=kb;en-us;290706
http://support.microsoft.com/default.aspx?scid=kb;en-us;299352
http://support.microsoft.com/default.aspx?scid=kb;en-us;305822
http://support.microsoft.com/default.aspx?scid=kb;en-us;312827
http://support.microsoft.com/default.aspx?scid=kb;en-us;326985
http://support.microsoft.com/default.aspx?scid=kb;en-us;328720
http://support.microsoft.com/default.aspx?scid=kb;en-us;811082
http://support.microsoft.com/default.aspx?scid=kb;en-us;824209
http://support.microsoft.com/default.aspx?scid=kb;en-us;890477

----------------
Event ID 681
----------------

http://www.eventid.net/display.asp?eventid=681&eventno=3&source=Security&phase=1

http://support.microsoft.com/default.aspx?scid=kb;en-us;174074
http://support.microsoft.com/default.aspx?scid=kb;en-us;272594
http://support.microsoft.com/default.aspx?scid=kb;en-us;273499
http://support.microsoft.com/default.aspx?scid=kb;en-us;287626
http://support.microsoft.com/default.aspx?scid=kb;en-us;297989
http://support.microsoft.com/default.aspx?scid=kb;en-us;321448
http://support.microsoft.com/default.aspx?scid=kb;en-us;326985
http://support.microsoft.com/default.aspx?scid=kb;en-us;824209
http://support.microsoft.com/default.aspx?scid=kb;en-us;837142


Austin M. Horst
 
R

Roger Abell

Where are these shown as coming from ?
Are these for "dumb" account names that often do not exist?
or are they using the list of actual accounts ?
 
R

Roger Abell

The events name the machine from which the login attempts
originate. There are tools out there that will hammer on a
system for as long as they are programmed to do, trying to
find username / password combinations that work.
All you have to do is have some exposed authentication
door, like a restricted access website, file shares, etc..
If the machine named is an internal machine, then go to it
and look for infection/malware.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top