Answered Is it Hacking activity

  • Mittwoch, 21. November 2012 04:03
     
     

    Exchange and AD are installed in same server. Yesterday have found someone try to use difference name to login by POP3

    After that on AD event log have found some event log Event log 4624 , Security ID ANONYMOUS logon ,5140 File Share --Share Name \\*\IPC$ also 4624 logged on by another AD server.

    Is it mean the hacker have already break into our system ?

    Thanks,

    Ricky

Alle Antworten

  • Donnerstag, 22. November 2012 05:25
     
     Beantwortet


    Please check Bruce's suggestion in the thread below. Might be useful to you as well:

    Hundreds of audit events 4624, 4634, and 4672 every second on Server 2008 SP2 Domain Controller.

    http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/adea8148-f9dd-45a8-bccc-1d44aa90ec83/

    Niko