﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>UltimateWindowsSecurity.com Forum / Ultimate Windows Security Forum / Security Log / 529 - Logon Failure - Unknown user name or bad password  / Event ID 529 logged with little detail / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>UltimateWindowsSecurity.com Forum</description><link>http://forum.ultimatewindowssecurity.com/</link><webMaster>noreply@ultimatewindowssecurity.com</webMaster><lastBuildDate>Tue, 07 Feb 2012 12:21:25 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: Event ID 529 logged with little detail</title><link>http://forum.ultimatewindowssecurity.com/Topic343-23-1.aspx</link><description>Hi,&lt;/P&gt;&lt;P&gt;Check this post &lt;A href="http://forum.ultimatewindowssecurity.com/FindPost813.aspx"&gt;http://forum.ultimatewindowssecurity.com/FindPost813.aspx&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Javier</description><pubDate>Thu, 13 Oct 2011 18:02:11 GMT</pubDate><dc:creator>JavierC</dc:creator></item><item><title>RE: Event ID 529 logged with little detail</title><link>http://forum.ultimatewindowssecurity.com/Topic343-23-1.aspx</link><description>Hi&lt;br&gt;&lt;br&gt;I noticed similar events on my DC. This is an example of event ID 529 which is logged countless times:&lt;br&gt;&lt;br&gt;[b]Logon Failure:&lt;br&gt;	Reason:		Unknown user name or bad password&lt;br&gt;	User Name:	&lt;br&gt;	Domain:		xxxxx&lt;br&gt;	Logon Type:	3&lt;br&gt;	Logon Process:	NtLmSsp &lt;br&gt;	Authentication Package:	NTLM&lt;br&gt;	Workstation Name:	&lt;br&gt;	Caller User Name:	-&lt;br&gt;	Caller Domain:	-&lt;br&gt;	Caller Logon ID:	-&lt;br&gt;	Caller Process ID:	-&lt;br&gt;	Transited Services:	-&lt;br&gt;	Source Network Address:	-&lt;br&gt;	Source Port:	-[/b]&lt;br&gt;&lt;br&gt;I also noticed event ID 680 on the DC:&lt;br&gt;&lt;br&gt;[b]Logon attempt by:	MICROSOFT_AUTHENTICATION_PACKAGE_V1_0&lt;br&gt;Logon account:	&lt;br&gt;Source Workstation:	&lt;br&gt;Error Code:	0xC0000064[/b]&lt;br&gt;&lt;br&gt;According to Randy's encyclopedia, 0xC0000064 means "user name does not exist". As far as I know, NTLM is only used for Windows 2000 machines (which is not the case) or if a local user account is used.&lt;br&gt;&lt;br&gt;How can I find out where this is coming from if no source IP, source workstation or user name is logged?&lt;br&gt;&lt;br&gt;Thanks&lt;br&gt;Stefan</description><pubDate>Tue, 11 Oct 2011 11:49:25 GMT</pubDate><dc:creator>stefan</dc:creator></item><item><title>RE: Event ID 529 logged with little detail</title><link>http://forum.ultimatewindowssecurity.com/Topic343-23-1.aspx</link><description>it simply means someone is trying to logon over the network, probably to a shared folder, with either a bad username or bad password.</description><pubDate>Thu, 25 Mar 2010 08:42:53 GMT</pubDate><dc:creator>RandyFranklinSmith</dc:creator></item><item><title>Event ID 529 logged with little detail</title><link>http://forum.ultimatewindowssecurity.com/Topic343-23-1.aspx</link><description>I am getting 529 events logged on my Windows 2003 servers, but they only information they have is the reason of "Unknown user name or bad password" , that it is a type 3 (network) logon, Logon process is Kerberos and the authentication package is Kerberos. &lt;/P&gt;&lt;P&gt;Any ideas what could cause this or how I could get more details?</description><pubDate>Mon, 22 Mar 2010 05:49:50 GMT</pubDate><dc:creator>richard.hart@barclays.com</dc:creator></item></channel></rss>
