﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>UltimateWindowsSecurity.com Forum / Ultimate Windows Security Forum / Security Log / 529 - Logon Failure - Unknown user name or bad password </title><generator>InstantForum.NET v4.1.4</generator><description>UltimateWindowsSecurity.com Forum</description><link>http://forum.ultimatewindowssecurity.com/</link><webMaster>noreply@ultimatewindowssecurity.com</webMaster><lastBuildDate>Tue, 07 Feb 2012 11:56:43 GMT</lastBuildDate><ttl>20</ttl><item><title>Secutiry incidents due to logon type 3</title><link>http://forum.ultimatewindowssecurity.com/Topic874-23-1.aspx</link><description>Hello folks, we have a security log management solution but we are receiving tons of alerts regarding event id 529 with logon type 3. After investigation we find out that in all the cases is because a computer is having problems to connect with AD or because support use the local Administrator to patch systems or perform other kind of maintenance, and since we have Active Directory every time a no valid user tries to access Internet it causes access denied because this user is not a valid domain user.&lt;br&gt;&lt;br&gt;So my question is there a possible scenario where logon type 3 might represent a real force attack against one of my servers?&lt;br&gt;&lt;br&gt;Regards&lt;br&gt;</description><pubDate>Wed, 14 Dec 2011 16:40:08 GMT</pubDate><dc:creator>cportuguez</dc:creator></item><item><title>Event ID 529 Only Comes with Logon Type and Logon Process the rest is blanck</title><link>http://forum.ultimatewindowssecurity.com/Topic833-23-1.aspx</link><description>Logon Failure:&lt;br&gt; 	Reason:		Unknown user name or bad password&lt;br&gt; 	User Name:	&lt;br&gt; 	Domain:		&lt;br&gt; 	Logon Type:	3&lt;br&gt; 	Logon Process:	Kerberos&lt;br&gt; 	Authentication Package:	Kerberos&lt;br&gt; 	Workstation Name:	-&lt;br&gt; 	Caller User Name:	-&lt;br&gt; 	Caller Domain:	-&lt;br&gt; 	Caller Logon ID:	-&lt;br&gt; 	Caller Process ID:	-&lt;br&gt; 	Transited Services:	-&lt;br&gt; 	Source Network Address:	-&lt;br&gt; 	Source Port:	-&lt;br&gt;&lt;br&gt;Can somebody help me to identify why almost all the information is missing on this event. This event is happening on a DC and these events are happening very often.&lt;br&gt;&lt;br&gt;How can I identify what user is causing the failed attempts, what IP is using, etc?????</description><pubDate>Tue, 08 Nov 2011 13:32:07 GMT</pubDate><dc:creator>cportuguez</dc:creator></item><item><title>Event ID 529 logged with little detail</title><link>http://forum.ultimatewindowssecurity.com/Topic343-23-1.aspx</link><description>I am getting 529 events logged on my Windows 2003 servers, but they only information they have is the reason of "Unknown user name or bad password" , that it is a type 3 (network) logon, Logon process is Kerberos and the authentication package is Kerberos. &lt;/P&gt;&lt;P&gt;Any ideas what could cause this or how I could get more details?</description><pubDate>Mon, 22 Mar 2010 05:49:50 GMT</pubDate><dc:creator>richard.hart@barclays.com</dc:creator></item><item><title>529 &amp; 680 logged every 8 hours on DC</title><link>http://forum.ultimatewindowssecurity.com/Topic727-23-1.aspx</link><description>I'm seeing a pair of event id 529 failure audits logged exactly every 8 hours  (to the second) on my primary DC (2003), but I cannot figure out what is causing it (i.e. what or who is trying to logon). &lt;/p&gt;&lt;p&gt;The 'user name' identified by the 529 event is a  domain admin (user) account. It is 'logon type:3' so it's trying to connect to a  network share or IIS. The 'logon process' is "advapi" (Windows advanced API?). &lt;br&gt;'workstation name' is the name of the PDC this event was logged on. 'caller  user name' is the "machine account" for the PDC (i.e. the same computer name with $ at  the end). I was thinking 'workstation name' was the machine that logged the  event (the target) and 'caller name' was the "source" machine, but 'source  network address' in this case is the IP of a (backup) DC (also 2003). So, I guess I'm not understanding  what these fields are referring to. &lt;br&gt;'caller process id' points to  lsass.exe--assuming this process id is referring to the PDC in this case. I've  observed no process with that id on on the machine identified by the source  network address (the backup DC). Is 'caller process id' the process id on the  target machine that the source user/machine is using? or the process id on the  source machine?  FYI: the 'caller process id' is always the same ("544").&lt;br&gt;Two "Failure Audit" Event ID 680 events occur at the exact same time as the 529 events, every time they are logged.  These events show the 'logon account' is the same as the 'user name' in the 529 events.  The 'source workstation' is the same as the 'workstation name in the 529 events. The error code is 0xC000006A.  I understand this means the user is successfully authenticated via NTLM instead of Kerberos, but I still can't figure out what is triggering these event log entries. &lt;/p&gt;&lt;p&gt;Can you tell me where else to look?&lt;/p&gt;&lt;p&gt;SAMPLE EVENT ID: 529&lt;/p&gt;&lt;p&gt;logon failure:&lt;br&gt;reason:unknown user name or bad password&lt;br&gt;user name:admin_sun&lt;br&gt;domain:suntech&lt;br&gt;logon type:3&lt;br&gt;logon process:advapi  &lt;br&gt;authentication package:negotiate&lt;br&gt;workstation name:sundata&lt;br&gt;caller user name:sundata$&lt;br&gt;caller domain:suntech&lt;br&gt;caller logon id:(0x0,0x3e7)&lt;br&gt;caller process id:544&lt;br&gt;transited services:-&lt;br&gt;source network address:10.129.10.27&lt;br&gt;source port:9405     [THE PORTS APPEAR TO BE RANDOM, ALTHOUGH EACH PAIR OF EVENTS USES PORTS 2 APPART: e.g. 9405 &amp;amp; 9407, 56748 &amp;amp; 56750, etc.]&lt;/p&gt;&lt;p&gt;SAMPLE EVENT ID: 680&lt;/p&gt;&lt;p&gt;Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0&lt;br&gt; Logon account: admin_vapor&lt;br&gt; Source Workstation: VAPORDATA&lt;br&gt; Error Code: 0xC000006A&lt;br&gt;</description><pubDate>Mon, 13 Jun 2011 18:30:35 GMT</pubDate><dc:creator>simplifi</dc:creator></item><item><title>Event ID 529 with username : User and SYSTEM</title><link>http://forum.ultimatewindowssecurity.com/Topic671-23-1.aspx</link><description>Hi,&lt;br&gt;&lt;br&gt;   I am getting many logs (From my 2003 DC) with Event ID 529 that have username : [b]User [/b]and Caller username : [b]SYSTEM[/b].  Anyone have any idea what generate that?&lt;br&gt;&lt;br&gt;Thanks.</description><pubDate>Tue, 10 May 2011 14:11:46 GMT</pubDate><dc:creator>phoenixsecure</dc:creator></item><item><title>Cannot corelate Caller Logon ID which is in Hex</title><link>http://forum.ultimatewindowssecurity.com/Topic620-23-1.aspx</link><description>I have multiple instances of a 529 type 3 happening in Win 2003 svr. I cannot leverage the little information that is availible in the event properties.&lt;/P&gt;&lt;P&gt;Caller Logon ID: (0x0,0x3E7)&lt;/P&gt;&lt;P&gt;Is there a ref somewhere that matches up this hex to process or user account?&lt;/P&gt;&lt;P&gt;Thanks for and advice you may have.&lt;/P&gt;&lt;P&gt;-C</description><pubDate>Mon, 21 Mar 2011 10:44:41 GMT</pubDate><dc:creator>cstaubin</dc:creator></item><item><title>Workstation Names in LOG</title><link>http://forum.ultimatewindowssecurity.com/Topic342-23-1.aspx</link><description>HI Ive been trying to work out what this means for a while now, not found anything online about it at all. All logonTypes i get are logon type3 no idea why i dont see any other type apart from 0. I am all so trying to work out why most the logonfailures are logged when attempting to access \\TMP Workstation. Im guessing TMP stands for Temp possibly network share?</description><pubDate>Thu, 18 Mar 2010 12:55:43 GMT</pubDate><dc:creator>Darryl</dc:creator></item><item><title>source network address</title><link>http://forum.ultimatewindowssecurity.com/Topic262-23-1.aspx</link><description>Is there any way to get XP Pro to log the source network address in event 529 - or in another event? I am logging event 529 but there is no source IP address shown.</description><pubDate>Tue, 10 Nov 2009 11:26:12 GMT</pubDate><dc:creator>southside_steve</dc:creator></item><item><title>Logon types question</title><link>http://forum.ultimatewindowssecurity.com/Topic183-23-1.aspx</link><description>Randy,&lt;br&gt;&lt;br&gt;Currently we are using GFI for event log management and when I run a report on 'Failed Logins' pulling from event ID 529, under 'logon type' 99.9% of them show as 'Network'. If I run a report looking for 'interactive' there are none. Any idea why the majority of failed logins under event ID 529 show up as 'Network' with very little listed as 'interactive'?&lt;br&gt;&lt;br&gt;Thanks</description><pubDate>Mon, 24 Aug 2009 14:51:19 GMT</pubDate><dc:creator>jwalzer</dc:creator></item><item><title>Event on DCs when unknown password is used</title><link>http://forum.ultimatewindowssecurity.com/Topic212-23-1.aspx</link><description>Randy, &lt;/P&gt;&lt;P&gt;I want to document the use of wrong password during the try-to-logon-process initiated on a Member Server (or Client Computer) when the user uses its domain account. I thought, that 529 will be logged on security event log on DC but it isn't so. Could you please tell me how I will be able to document the occurence of wrong password while a users is trying to log on at a member server or workstation with his domain account? &lt;/P&gt;&lt;P&gt;Thanks in advance. &lt;/P&gt;&lt;P&gt;Alex</description><pubDate>Wed, 16 Sep 2009 09:47:22 GMT</pubDate><dc:creator>alex.fischer</dc:creator></item><item><title>not logging 529 errors</title><link>http://forum.ultimatewindowssecurity.com/Topic100-23-1.aspx</link><description>Randy,&lt;/P&gt;&lt;P&gt;I have created a GPO in which I am logging both successful and failure for 'Audit account logon events' and 'Audit logon events'.  I am distributing this GPO to all DC's and member servers.  I deliberately tried to logon to a DC with an incorrect password for the domain Administrator account, but for some reason I am not logging any 529's on the DC or any other DC.  What am I doing wrong?</description><pubDate>Tue, 09 Jun 2009 09:47:35 GMT</pubDate><dc:creator>cmpyx</dc:creator></item></channel></rss>
