Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


Return to article

Access Denied: Detecting PPTP Attacks on Remote Access Servers
 

How can I detect attacks on my remote access server through PPTP? I want to know when someone is trying to guess usernames and passwords, and I haven't found any events in the Security log that clearly identify this situation.

Check your System log for event ID 20189 (The user Administrator connected from x.x.x.x. but failed an authentication attempt due to the following reason: There was an authentication failure because of an unknown user name or a bad password). As Figure 1 shows, event ID 20189 comes from RAS and provides the username specified by the possible attacker as well as the attacker's IP address, which might help you track attackers and report them to their ISP.







Reader Comments

"As Figure 1 shows" - only there is no figure 1.

shadowfaxs3 -August 27, 2004
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement