Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Pen-Test
[Top] [All Lists]

Re: XP RDP event log 682 ?

Subject: Re: XP RDP event log 682 ?
Date: 14 Dec 2004 19:28:14 -0000
In-Reply-To: <BAY24-DAV3EF0369DD0B58FF913A23DAAA0@phx.gbl>

Bill,

I have a few event log 682's (user has reconnected to a disconnected TS
session) on an XP machine at work that shows:
Session Name:    Console
Client Name:    Unknown
Client Address:    Unknown

All other event log 682's show Session Name:    RDP-Tcp# and they also
display the Client Name and Address.

Does this mean that these Unknown ones connected via Console were
connections made by someone who hacked the password and used a stealthed OS
?

Perhaps not (what's a "stealthed OS"???)

A quick search on EventID.net reveals:
http://www.eventid.net/display.asp?eventid=682&eventno=1802&source=Security&phase=1

On TechNet:
http://www.microsoft.com/technet/security/guidance/secmod144.mspx

Scroll down to "Logon Events".

See also: "...Event ID 682 indicates when a connection to a previously 
disconnected session has occurred."

Hope that helps,

H. Carvey
"Windows Forensics and Incident Recovery"
http://www.windows-ir.com

<Prev in Thread] Current Thread [Next in Thread>