I've got one NT 4 Workstation here that is showing a strange "attack" pattern 
against one (maybe others, still investigating) of my stand alone NT Servers. 
Every 2 hours, starting 2 hours after the workstation is turned on, it attempts 
to login to the server 4 times, 5 seconds between each login, and fails as the 
workstation user account does not have access rights on the server. I have 
tried shutting down all applications and still the workstation does the same 
thing. Has anyone else ever heard of or seen this before? Any idea what I 
should be looking for? I can't see anything out of place in the list of 
processes on the workstation, and there is no reason for it to be doing this. 
The only non-OS applications running are NAI VirusScan NT 4.0.3a and 
Novell Workstation Manager. I can't see anything in the configurations of 
either of these that would explain this sort of behaviour. A netstat -n on the 
machine shows ports 1025, 1026, 1027, and 1028 connected to each other, 
and connections to port 139 on other NT Servers to which the user has 
access rights.

Dan

---
D.C. Crichton                 email: [EMAIL PROTECTED]
Senior Systems Analyst        tel:   +44 (0)121 706 6000
Computer Manuals Ltd.         fax:   +44 (0)121 606 0477

Computer book info on the web:
   http://computer-manuals.co.uk/
Want to earn money? Join our affiliate scheme!
   http://computer-manuals.co.uk/affiliate/
-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]

Reply via email to