In de security logboeken op de server (Windows 2000 Server SP4) verschijnen de laatste tijd de volgende 2 meldingen, 2 keer achter elkaar:
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 538
Date: 3-7-2003
Time: 15:17:08
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: SERVER01
Description:
User Logoff:
User Name: ANONYMOUS LOGON
Domain: NT AUTHORITY
Logon ID: (0x0,0xA3BDE1)
Logon Type: 3
Event Type: Success Audit
Event Source: Security
Event Category: Privilege Use
Event ID: 576
Date: 3-7-2003
Time: 15:17:08
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: SERVER01
Description:
Special privileges assigned to new logon:
User Name:
Domain:
Logon ID: (0x0,0xA3BDE1)
Assigned: SeChangeNotifyPrivilege
Wordt ons netwerk nu gehackt door iemand of heeft het te maken met Terminal services/remote desktop of iets anders?
Bvd
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 538
Date: 3-7-2003
Time: 15:17:08
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: SERVER01
Description:
User Logoff:
User Name: ANONYMOUS LOGON
Domain: NT AUTHORITY
Logon ID: (0x0,0xA3BDE1)
Logon Type: 3
Event Type: Success Audit
Event Source: Security
Event Category: Privilege Use
Event ID: 576
Date: 3-7-2003
Time: 15:17:08
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: SERVER01
Description:
Special privileges assigned to new logon:
User Name:
Domain:
Logon ID: (0x0,0xA3BDE1)
Assigned: SeChangeNotifyPrivilege
Wordt ons netwerk nu gehackt door iemand of heeft het te maken met Terminal services/remote desktop of iets anders?
Bvd