Hey All,
Where do I being. We have NT Server 4.0 SP 6 in a domain setup.
Lately, we have had folders/files mysteriously disappear on us. So, recently, I enabled Auditing of the deletion (both success and failures) of files from our network drives (which all point to a local drive on the NT Server).
Well, over the weekend, a folder was "mysteriously" deleted, so I looked at the security log. It shows that the folder was deleted by me! (Well, my user anyways). It happened at 11:30pm last night, and I wasn't even here.
I log off of my workstation every day (we have VNC, but I rotate passwords for myself and VNC every month to a randomly generated strong password).
I looked at 11:29, and it shows a logon success event for type 3 (net use, net view, file manager).
Can anyone help me figure out what to do to figure out who is doing this, or how I might be able to track it. I am thinking about just setting my account to disabled before I leave every day now....
Thanks in advance!
Tim Kao
Where do I being. We have NT Server 4.0 SP 6 in a domain setup.
Lately, we have had folders/files mysteriously disappear on us. So, recently, I enabled Auditing of the deletion (both success and failures) of files from our network drives (which all point to a local drive on the NT Server).
Well, over the weekend, a folder was "mysteriously" deleted, so I looked at the security log. It shows that the folder was deleted by me! (Well, my user anyways). It happened at 11:30pm last night, and I wasn't even here.
I log off of my workstation every day (we have VNC, but I rotate passwords for myself and VNC every month to a randomly generated strong password).
I looked at 11:29, and it shows a logon success event for type 3 (net use, net view, file manager).
Can anyone help me figure out what to do to figure out who is doing this, or how I might be able to track it. I am thinking about just setting my account to disabled before I leave every day now....
Thanks in advance!
Tim Kao