Dear Eric Fitzgerald and others who responded to audit
questions,
On many threads you have explained about event IDs 681,
529 and error code 3221225572, e.g.:
"681 is a failure event (account logon failure) in
the "Account Logon"
category of audits- it's generated when a security package
authenticates
your credentials. This occurs on the machine
authoritative for the account
being used- the local machine in the case of local
accounts ..."
This is all good, but I noticed that you MS guys never
answer main question asked by hundreds of people: is it a
security problem? Is it a hacking? Shall we worry? What
shall be done, if anything?
My problem is similar to others: on my W2k Pro workstation
I receive dozens logon failure audits per day about logon
attempts onto my machine's "default" account (does not
exist on my machine) from several workstations on our LAN,
and even from outsiders, with the event IDs 681, 529 and
error code 3221225572. It happens even over night, when
nobody is present and I am logged off. Two machines do it
much more often than others (both are Win ME). I checked
one - it is not infected. Could you please explain in
plain, user-friendly terms - what these logons mean in
terms of security? Norma or hacking attacks? Shell we do
something about it? How to stop it?
Please answer to my e-mail in addition to posting in
threads - I may miss it there.
Thank you in advance,
EAK


