Hacked

W

William C.

One of my win2k server all local user accounts always "Account Locked Out".
After i removed the NAT, it didn't happened anymore. Is It been hacked? What
should i do to resolve this problem?

It was installed with Windows 2000 server sp4.
 
D

Dusko Savatovic

One possible reason could be that some service is trying to log on. Never
run service under the Administrator account. Create another account and if
necessarry make it a member of Administrators group.
The other possibility is that someone is trying to break into your system.
Some recommendations:
1. Rename built-in Administrator account
2. Create decoy account named Administrator, but put it in Guests group. Set
very limited privileges for Guests group.
2. Turn on auditing of Logon and Logoff events. Examine security log
3. Set less restrictive Account lockout policies, something like 5 bad
attempts, unlock after 15 minutes. This way, you will not need to unlock
accounts manually.

Dusko Savatovic
 
S

Steven Umbach

Did you have file and print sharing installed on the external/internet network
adapter?? If so disable it and you need to use a properly configured firewall.
You can go to http://scan.sygatetech.com/ to do a basic vulnerability scan on
your current configuration. Of course you need to check your computers for
viruses/worms/trojans and make repairs or preferably format/reinstalls if you
find infected computers after isolating them from the network. --- Steve

https://www.microsoft.com/security/protect/
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top