﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>UltimateWindowsSecurity.com Forum / Ultimate Windows Security Forum / Security Log / 644 - User Account Locked Out  / Lots of 644 for user Administrator - unusual / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>UltimateWindowsSecurity.com Forum</description><link>http://forum.ultimatewindowssecurity.com/</link><webMaster>noreply@ultimatewindowssecurity.com</webMaster><lastBuildDate>Thu, 17 May 2012 09:10:03 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: Lots of 644 for user Administrator - unusual</title><link>http://forum.ultimatewindowssecurity.com/Topic98-91-1.aspx</link><description>Hello and thanks again for responding, I sent a response to you directly by e-mail on Fri 6/12/09 1:39 PM, the e-mail contains a little more information than i'd like to post here but if we manage to figure this out i'd like to clean it up a little and post it so other people can find a solution to this.&lt;br&gt;Thanks again for all your help and i'm looking forward to the webinar on Wednesday!</description><pubDate>Mon, 22 Jun 2009 08:27:35 GMT</pubDate><dc:creator>DarqAngels</dc:creator></item><item><title>RE: Lots of 644 for user Administrator - unusual</title><link>http://forum.ultimatewindowssecurity.com/Topic98-91-1.aspx</link><description>waiting on reply to private message</description><pubDate>Wed, 10 Jun 2009 12:03:19 GMT</pubDate><dc:creator>RandyFranklinSmith</dc:creator></item><item><title>Lots of 644 for user Administrator - unusual</title><link>http://forum.ultimatewindowssecurity.com/Topic98-91-1.aspx</link><description>Hello, &lt;br&gt;We have been experiencing an issue for sometime and it always comes back to this. We are using RSA enVision to track our logs and when I run a report against event ID 644 to see if we have failures for the day we always see a few hundred (in the morning) for administrator, by end of day its in the thousands.&lt;br&gt;&lt;br&gt;However here is what the errors look like.&lt;br&gt;&lt;br&gt;User Administrator&lt;br&gt;Device address: 172.x.x.x&lt;br&gt;Workstation: generally seems to be the same workstations lets call it MON0100&lt;br&gt;logon type = 0&lt;br&gt;Reason= blank&lt;br&gt;calling_address = blank&lt;br&gt;calling_username = DOM0100$ (DOM0100 is our primary domain controller)&lt;br&gt;&lt;br&gt;so the strange thing i am seeing is that we get these messages several hundred to thousand times a day and the calling username changes to various domain controllers throughout the day. When the error is reported from a workstation on a diffrent forest it will be calling address from that domain controller.&lt;br&gt;Does anyone have any idea why this is happening?&lt;br&gt;Thank you soooooo much in advance for any help at all!&lt;br&gt;-Dan&lt;br&gt;</description><pubDate>Fri, 05 Jun 2009 09:42:45 GMT</pubDate><dc:creator>DarqAngels</dc:creator></item></channel></rss>
