Previous Next

Thread: failed login attempts, logon process: IIS

Last post 08-12-2008 8:43 AM by jeff@zina.com. 1 replies.

Average Rating Rate It (5)

RSS

Page 1 of 1 (2 items)

Sort Posts:

  • 08-07-2008, 8:03 PM

    • jrnick
    • Not Ranked
    • Joined on 07-22-2008, 8:37 PM
    • Posts 4
    • jrnick

    failed login attempts, logon process: IIS

    I'm running IIS6 Windows2003, and as you'll see very quickly.. I'm pretty new to this stuff.
    Lately I've been getting bombarded with login attempts.... sometimes several in the same second, and it can last for hours.  The event viewer shows the following information for the failed login:

     Logon Failure:
         Reason:        Unknown user name or bad password
         User Name:    Admin
         Domain:        A**********
         Logon Type:    8
         Logon Process:    IIS    
         Authentication Package:    MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
         Workstation Name:    B**********    (my server's name)
         Caller User Name:    B********$
         Caller Domain:    A*********            (my domain)
         Caller Logon ID:    (0x0,0x3E7)
         Caller Process ID:    1812
         Transited Services:    -
         Source Network Address:    -
         Source Port:    -

     I don't know much about the authentication process... but what is the significance of 'Logon Process: IIS' ?   It seems to me that they're just trying to login into the server itself... like somebody would remotely log in to a server.  Does this mean they're logging in to IIS itself?   I'm confused....   Also, any advice on dealing with these attacks, or finding out useful information (like finding the ip address that its coming from)  would be greatly appreciated.

     

  • 08-12-2008, 8:43 AM In reply to

    Re: failed login attempts, logon process: IIS

    jrnick:
    Does this mean they're logging in to IIS itself? 

    No, it means they're attempting to and failing.

    jrnick:
    any advice on dealing with these attacks

    Firewall.  Only port 80 open.  No remote access to the system allowed.  A firewall with stateful inspection that has settings to block repeated attempts would be better.

    Jeff

    Look for Wrox's new book Professional IIS 7 in your local bookstore, or order now at Amazon.com
Page 1 of 1 (2 items)
Page view counter