小编eft*_*trm的帖子

Windows 安全日志中的意外匿名登录

我有一些项目的 VPS 服务器帐户,当日志中出现以下内容时(在试图猜测帐户详细信息的机器人洪流中......),我刚刚解决了一个问题。我对此感到相当惊讶;来宾帐户在 Windows 的用户控制面板中明显被禁用。

有什么想法可能会在这里发生吗?

An account was successfully logged on.

Subject:
    Security ID:        NULL SID
    Account Name:        -
    Account Domain:        -
    Logon ID:        0x0

Logon Type:            3

New Logon:
    Security ID:        ANONYMOUS LOGON
    Account Name:        ANONYMOUS LOGON
    Account Domain:        NT AUTHORITY
    Logon ID:        0xed801aa
    Logon GUID:        {00000000-0000-0000-0000-000000000000}

Process Information:
    Process ID:        0x0
    Process Name:        -

Network Information:
    Workstation Name:    WIN7USE-NAN0EX2
    Source Network Address:    114.38.156.233
    Source Port:        55598

Detailed Authentication Information:
    Logon Process:        NtLmSsp
    Authentication Package:    NTLM
    Transited Services: …
Run Code Online (Sandbox Code Playgroud)

security windows windows-server-2008-r2

6
推荐指数
1
解决办法
5万
查看次数

标签 统计

security ×1

windows ×1

windows-server-2008-r2 ×1