Groups | Blog | Home
all groups > iis security > december 2004 >

iis security : ISS service account keeps locking out


Drew
12/3/2004 7:51:01 AM
Hello Microsoft,

You always have the answers
Please take the time to read and respond to this.

Please help me with this; I'm a network administrator with an account
lockout problem. We have an ISS domain account which has administrative
permissions to all the machines on the network. The ISS scanner uses this
account to authenticate to the machine its scanning. For some reason, the
account continually keeps locking out during scanning. Randomly..!!
I have ruled out all the basics and have even created a separate second ISS
account with the same permissions; this one keeps locking out too. The
Netlogon.log on the DCs shows Transitive Network logons from the machines
it’s scanning. Some successful, some not.

I believe the following are the successful logons...

SamLogon: Transitive Network logon of Domain1\ISSaccount from ISS-Scanner
(via CONFmachine) Returns 0x0

Some of the unsuccessful ones appear as follows

SamLogon: Transitive Network logon of (null)\Domain1\ISSaccount from \\ (via
Confmachine) Returns 0xC0000064

What does the (null) mean?
Also after the from, where you should see ISS-Scanner, all there is are 2
\\??
When I look at these events on the local machine, the source workstation,
where it normally give you the IP or machine name of the remote machine
making the logon request, it also just has the 2 \\?

A few more unsuccessful entries

SamLogon: Transitive Network logon of (null)\ISSaccount from \\ (via
Confmachine)Returns 0xC000006A

Here the entry doesn't even list the domain name before the user account,
just the (null) and still lists the FROM machine as just \\. However it still
returns a 0xc06A error which means bad password.
By the looks of it, shouldn't it come back with unknown username?

Eventually the log fills up with 0x00000234 when the account finally locks out

Does anyone know?
What the (null) means?
Why the FROM is listed as only \\
Why the account is locking out

PLEASE. ANY HELP WOULD BE GREATLY APPRECIATED.

Drew
12/3/2004 8:29:02 AM
Yes sorry

[quoted text, click to view]
Drew
12/3/2004 8:43:05 AM
i used replace in WORD to change some of the domain and account info because
I didn't want to post the real domain info....must have mistype it...

[quoted text, click to view]
Drew
12/3/2004 8:49:13 AM
When the IIS scans a machines, it use a domain account to actually log into
the machine, giving it more access to the machine and allows us to search for
more vulnerabilities.
[quoted text, click to view]
Tom Kaminski [MVP]
12/3/2004 10:53:45 AM
[quoted text, click to view]

Do you mean IIS?

Tom Kaminski [MVP]
12/3/2004 11:35:51 AM
[quoted text, click to view]

I don't understand what you mean by:
"The ISS scanner uses this account to authenticate to the machine its
scanning."

Tom Kaminski [MVP]
12/3/2004 1:47:45 PM
[quoted text, click to view]

Sorry, I'm still confused. IIS is a web server so I'm not sure what you
mean by having it "scan" another machine. I've only ever used IIS to host
web sites.

AddThis Social Bookmark Button