1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

See users logged into Windows 2000 server

Discussion in 'Windows XP' started by Magueta, Feb 8, 2005.

Thread Status:
Not open for further replies.
  1. Magueta

    Magueta Thread Starter

    Joined:
    Jan 16, 2005
    Messages:
    20
    I'm wondering if there's some way to tell if there is someone else logged onto a Windows 2000 server. In Unix there's the who command that tells you absolutely everyone who's logged onto the server. Is there something similar in Windows? Netstat is not an option because I use filesharing so there are way too many connections to get any idea if there's someone logged on that shouldn't be. I've gotten these weird authentication errors in my security event log and after some research it was clear that they could mean lots of things but some of the results mentioned that they got the same messages when they tried to logon to the Windows server using SSH and that they would get the errors but would logon anyway.
    I'm not running SSH but the information has prompted me to make sure my system hasn't been compromised even though it is unlikely.
    For those of you who are curious here are the events:
    What do you think? If possible can this post also be linked to from the security forum? It may help.
    Thanks

    Joe

    ================================================================
    EVENT # : 889
    EVENT LOG : Security
    EVENT TYPE : Audit Failure
    SOURCE : Security
    CATEGORY : Account Logon
    EVENT ID : 681
    USERNAME : NT AUTHORITY\SYSTEM
    COMPUTER : <MyWorkstationName>
    TIME : 2/7/2005 8:00:00 PM
    MESSAGE : The logon to account: Administrator
    by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
    from workstation: <MyWorkstationName>
    failed. The error code was: 3221225578

    ================================================================
    EVENT # : 890
    EVENT LOG : Security
    EVENT TYPE : Audit Failure
    SOURCE : Security
    CATEGORY : Logon/Logoff
    EVENT ID : 529
    USERNAME : NT AUTHORITY\SYSTEM
    COMPUTER : <MyWorkstationName>
    TIME : 2/7/2005 8:00:00 PM
    MESSAGE : Logon Failure:
    Reason: Unknown user name or bad password
    User Name: Administrator
    Domain: <MyWorkstationName>
    Logon Type: 4
    Logon Process: Advapi
    Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
    Workstation Name: <MyWorkstationName>
    ================================================================
     
  2. Squashman

    Squashman Trusted Advisor

    Joined:
    Apr 4, 2003
    Messages:
    19,786
  3. Magueta

    Magueta Thread Starter

    Joined:
    Jan 16, 2005
    Messages:
    20
    Thanks LwdSquashman, the information is helpful.

    Joe
     
As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/328034

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice