I've got one NT 4 Workstation here that is showing a strange "attack" pattern
against one (maybe others, still investigating) of my stand alone NT Servers.
Every 2 hours, starting 2 hours after the workstation is turned on, it attempts
to login to the server 4 times, 5 seconds between each login, and fails as the
workstation user account does not have access rights on the server. I have
tried shutting down all applications and still the workstation does the same
thing. Has anyone else ever heard of or seen this before? Any idea what I
should be looking for? I can't see anything out of place in the list of
processes on the workstation, and there is no reason for it to be doing this.
The only non-OS applications running are NAI VirusScan NT 4.0.3a and
Novell Workstation Manager. I can't see anything in the configurations of
either of these that would explain this sort of behaviour. A netstat -n on the
machine shows ports 1025, 1026, 1027, and 1028 connected to each other,
and connections to port 139 on other NT Servers to which the user has
access rights.
Dan
---
D.C. Crichton email: [EMAIL PROTECTED]
Senior Systems Analyst tel: +44 (0)121 706 6000
Computer Manuals Ltd. fax: +44 (0)121 606 0477
Computer book info on the web:
http://computer-manuals.co.uk/
Want to earn money? Join our affiliate scheme!
http://computer-manuals.co.uk/affiliate/
-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]