MobileTechie
Well-Known Member
- Reaction score
- 32
- Location
- UK
Client's SBS 2008 system. I went to RDP in and the usual admin account was locked out. I used the backup admin account to get on and checked the security logs and there were tons of failed logins. Unlocking the account worked but was relocked almost instantly afterwards.
I changed the account username and now there are failed server logins every few seconds using the old account name. So clearly something or someone is hammering that login. However there is minimal info in each error report - no IP or anything so I'm assuming it's coming from the server itself?
I've pasted a sample error report below. I've run a script to see if any services are using this account as a logon but apparently not. Any idea how to track this down?
Cheers
An account failed to log on.
Subject:
Security ID: NULL SID
Account Name: -
Account Domain: -
Logon ID: 0x0
Logon Type: 3
Account For Which Logon Failed:
Security ID: NULL SID
Account Name: adminaccountname
Account Domain:
Failure Information:
Failure Reason: Unknown user name or bad password.
Status: 0xc000006d
Sub Status: 0xc0000064
Process Information:
Caller Process ID: 0x0
Caller Process Name: -
Network Information:
Workstation Name:
Source Network Address: -
Source Port: -
Detailed Authentication Information:
Logon Process: NtLmSsp
Authentication Package: NTLM
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
I changed the account username and now there are failed server logins every few seconds using the old account name. So clearly something or someone is hammering that login. However there is minimal info in each error report - no IP or anything so I'm assuming it's coming from the server itself?
I've pasted a sample error report below. I've run a script to see if any services are using this account as a logon but apparently not. Any idea how to track this down?
Cheers
An account failed to log on.
Subject:
Security ID: NULL SID
Account Name: -
Account Domain: -
Logon ID: 0x0
Logon Type: 3
Account For Which Logon Failed:
Security ID: NULL SID
Account Name: adminaccountname
Account Domain:
Failure Information:
Failure Reason: Unknown user name or bad password.
Status: 0xc000006d
Sub Status: 0xc0000064
Process Information:
Caller Process ID: 0x0
Caller Process Name: -
Network Information:
Workstation Name:
Source Network Address: -
Source Port: -
Detailed Authentication Information:
Logon Process: NtLmSsp
Authentication Package: NTLM
Transited Services: -
Package Name (NTLM only): -
Key Length: 0