Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: How can I track this down? |
|---|---|
| Date: | Thu, 1 Jun 2006 14:38:01 -0500 |
Sounds like some kind of VOIP device ..
http://www.coffer.com/mac_find/?string=009096
./thanks ilaiy
I'm completely guessing here, but here's my thoughts:
It's probably a Cisco or other network mgmt device/software trying to authenticate with a Windows network because someone choose Windows domain/AD authentication for some optional feature (like proxy outbound authentication, user list, etc.).
The logon acct name is a MAC address, so search to find out who has that mac address. That will give you a clue.
-----Original Message----- From: Nick Duda [mailto:nduda@VistaPrint.com] Sent: Thursday, June 01, 2006 1:21 PM To: security-basics@securityfocus.com Subject: How can I track this down?
I'm getting a ton of these in my Security log on my DC. The logon account changes every so often, but its always a name that doesn't exist (as in we don't have a user account called 009096bb65cd) the from Workstation always says CISCO. I can't find anything in the logs that point me to an IP address. Running utils like nestat don't do much because there are already so many normal connections related to it being a DC. Any ideas?
The logon to account: 009096bb65cd by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 from workstation: CISCO failed. The error code was: 3221225572
Regards, Nick
--------------------- Confidentiality note The information in this email and any attachment may contain confidential and proprietary information of
VistaPrint and/or its affiliates and may be privileged or otherwise protected from disclosure. If you are
not the intended recipient, you are hereby notified that any review, reliance or distribution by others
or forwarding without express permission is strictly prohibited and may cause liability. In case you have
received this message due to an error in transmission, please notify the sender immediately and to delete
this email and any attachment from your system. ---------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Security Tips, Beauford, Jason |
|---|---|
| Next by Date: | RE: How can I track this down?, Portz, Jon |
| Previous by Thread: | RE: How can I track this down?, Roger A. Grimes |
| Next by Thread: | InfoSec Importance, Mohamad Mneimneh |
| Indexes: | [Date] [Thread] [Top] [All Lists] |