Need a way to track IP address of computers used for invalid logon attempts to SEPM (12 RU2)
Created: 07 Mar 2013 | 13 comments
In the past week I have received 3 emails from our SEPM that stated the following:
|
Time |
Site |
Server |
Severity |
Event Type |
Description |
|
03/07/2013 07:57:27 |
Site ABC |
ABC.domain.com |
Error |
An unexpected exception has occurred |
The administrator's user name or password is incorrect. Type a valid user name or password. |
These are occurring at times when I am not at work and there is no one (legitimate) that could be connected or trying to connect during these times. I need a way to determine the IP address of the computer that making these logon attempts.
Operating Systems:
Discussion Filed Under:
Comments 13 Comments • Jump to latest comment
Description: The administrator's user name or password is incorrect. Type a valid user name or password.
Your looking at the Administrative log right?
I don't believe there is any more info given in this log. You may want to disable that account and create a new one or change the password.
You can try this:
Go to Admin tab >> Administrators tab
Select the user name that is trying to log in and all info will be given here, Last logon IP and time. Does this help?
If you have AD sync setup for this account, you can check your DC logs
SEP Knowledge Base
Endpoint SWAT
I don’t see it listing the account name. When I implemented Symantec Endpoint Protection years ago, I changed the username of the built-in administrator. This doesn’t address my problem.
I need a way to figure out where these attempted logon attempts are coming from. If SEPM 12 used IIS instead of Apache then I could easily figure this out with the IIS log files.
Just strictly relying on the SEPM for this, I don't see a way. Would be nice to include the IP of the remote machine but I can't find anything.
SEP Knowledge Base
Endpoint SWAT
Then can Apache be configured to log this information like IIS can?
Couldn't say as I don't know much about it. Good reference here:
https://httpd.apache.org/docs/2.2/logs.html
But Symantec would likely have this answer.
SEP Knowledge Base
Endpoint SWAT
If you are the only resource for SEPM then deny access to all.
Granting or blocking access to remote Symantec Endpoint Protection Manager consoles
Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq
Rafeeq, that sounds like a good idea. However the link doesn't work and give the followign error:
Gateway Timeout
The proxy server did not receive a timely response from the upstream server.
Reference #1.7c9f33b8.1362790066.11302e59
See if this one worksL
http://www.symantec.com/business/support/index?pag...
SEP Knowledge Base
Endpoint SWAT
try this ,
http://www.symantec.com/business/support/index?pag...
the above link still works for me....:)
Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq
Hi Scott,
Don't forget the firewall component of the SEP client on that server, as well. It should be possible to create and apply a firewall policy that logs the details of connections to that server from remote addresses. Examine that log for unexpected source IP's.
It would not be a bad idea to take a close look at security on that server- are there any services running that really do not ned to be? Terminal Services, for example, if no one routinely uses RDP to access that machine. Make sure it is patched, does not have any unexpected ports open, and that admin accounts with access to that machine are given a new, strong password. Run a full system scan, as well.
Hope this helps!
Mick
With thanks and best regards,
Mick
Brian81 and Rafeeq, thanks those links worked. I have gone ahead \and restricted which IP address can logon, which helps me feel a little about security, but would still like to know the IP addresses.
I tested from a computer with an IP address not configured to access (via HOWTO81140). I could install the Java SEP manger via http://<server>:9090/symantec.html, which I was surprised wasn’t blocked. I did receive an error when trying to log on from that computer (something regarding that IP address wasn’t allowed). I got an email notification like before, which doesn’t include the IP address of the computer (see attachment). As far as I am concerned this functionality should be built in to SEPM and you shouldn’t be forced to create fancy firewall component of the SEP client on each SEPM.
Mick2009, your suggestion would also capture the IP address of ligament traffic between the SEP clients and our SEPM and would be a nightmare to look through. I have these SEPMs locked done pretty tightly through Windows, including via AD, Group Policy, run full virus scans nightly, non-default usernames, very strong passwords (> 15 characters), and other measures. I simply want SEPM to log and include the IP address of clients with invalid logon attempts. Other products I deal with have included this functionality for years and I am shocked me that Symantec hasn’t included this yet.
Cheers for the update, Scott!
Symantec AntiVirus 10.x had the capability to record the IP from which an admin logged in, but the ease of spoofing IP addresses robbed that feature of value. The fireall policy is the way I would do it, but that's just my 2 cents.
With thanks and best regards,
Mick
With thanks and best regards,
Mick
Would you like to reply?
Login or Register to post your comment.