Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

RE: IUSR issue after patch

Subject: RE: IUSR issue after patch
Date: Thu, 17 Mar 2005 22:27:37 -0500
Adam,

Did you check that registry key? And make sure it was set to "0' or "1" ?

To test to see if it is related to security setting, I mention this because
the error says "user not allowed to log on to this computer":

Make the IUSR account member of the Administrators group, reboot and tell us
what happens.  If it works, of course remove it from the administrators
group.

Go to your Security Policy | User Rights Assignment, and make sure IUSR has
the following rights:
Access this computer from the network
Allow log on locally
Log on as a batch job

Regards,

Dave Kleiman

-----Original Message-----
From: hartmann [mailto:hartmann@thestar.com.my]
Sent: Thursday, March 17, 2005 22:03
To: 'dave kleiman'; 'Security Basics Mailing List'
Subject: RE: IUSR issue after patch

Thanks Kleiman.

Emptied all de logs, but...still aint working.


Adam

-----Original Message-----
From: dave kleiman [mailto:dave@isecureu.com]
Sent: Friday, March 18, 2005 12:57 AM
To: 'hartmann'; 'Security Basics Mailing List'
Subject: RE: IUSR issue after patch

Adam,

If you can log in as an Admin you probably will find:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\crasho
nauditfail set to 2. And your security log might be full.

Empty it and set that to 1. Reboot

Regards,

Dave Kleiman
www.SecurityBreachResponse.com www.ComputerForensicInvestigations.com





-----Original Message-----
From: hartmann [mailto:hartmann@thestar.com.my]
Sent: Wednesday, March 16, 2005 23:43
To: 'Security Basics Mailing List'
Subject: IUSR issue after patch

- The server was unable to logon the Windows NT account
'IUSR_machinename'
due to the following error: Logon failure: user not allowed
to log on
to this computer. The data is the error code. -

Any ideas guys?
All sites hosted by this web server are now inaccessble
after a full
system patch.

Please help, and thanks a million in advance.

Regards,
Adam



/******************************************************************\
This message and any attachment(s) are confidential and may be
privileged or otherwise protected from disclosure. If you
are not the
intended recipient, please telephone or e-mail the sender
and delete
this message and any attachment from your system. If you
are not the
intended recipient you must not copy this message or attachment or
disclose the content to any other person.

Any opinion, view and/or other information in this message
and/or any
attachment(s) hereto which do not relate to the official
business of
Star Publications (Malaysia) Bhd shall not be deemed given nor
endorsed by Star Publications
(Malaysia) Bhd. Our company is not responsible for any
activity that
might be considered to be an illegal and/or improper use of email.

E-mail transmissions cannot be guaranteed to be secured or
error-free
as information could be intercepted, corrupted, lost, destroyed,
delayed, incomplete or contain viruses. The sender
therefore does not
accept liability for any errors or omissions in the
contents of this
message or for any virus damage which may arise as a result of this
e-mail transmission.
/******************************************************************\





______________________________________________________________________
This email has been scanned by the MessageLabs Email Security System.
For more information please visit
http://www.messagelabs.com/email
______________________________________________________________________



/******************************************************************\
This message and any attachment(s) are confidential and may
be privileged or otherwise protected from disclosure. If you
are not the intended recipient, please telephone or e-mail
the sender and delete this message and any attachment from
your system. If you are not the intended recipient you must
not copy this message or attachment or disclose the content
to any other person.

Any opinion, view and/or other information in this message
and/or any attachment(s) hereto which do not relate to the
official business of Star Publications (Malaysia) Bhd shall
not be deemed given nor endorsed by Star Publications
(Malaysia) Bhd. Our company is not responsible for any
activity that might be considered to be an illegal and/or
improper use of email.

E-mail transmissions cannot be guaranteed to be secured or
error-free as information could be intercepted, corrupted,
lost, destroyed, delayed, incomplete or contain viruses. The
sender therefore does not accept liability for any errors or
omissions in the contents of this message or for any virus
damage which may arise as a result of this e-mail transmission.
/******************************************************************\




<Prev in Thread] Current Thread [Next in Thread>