Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

How can you block win nt account lockouts from internet

Status
Not open for further replies.

dsr771

Programmer
Aug 5, 2003
4
0
0
US
Hi,

We recently had a webserver get the admin account locked out for 6 hours - what a mess - we've changed policy to shorter time now. If this happens to you, we received recommendations for ERD Commander which we may purchase, but our 6 hours expired before we purchased it.

But, how can we block the DOS attack that is coming from the internet that locks out every nt account on our server?

We have a firewall and block ports 135,137-139,445.
Are there any other ports that need to be blocked to prevent this kind of internet attack?

Any other changes?

How can we prevent them from seeing which nt accounts exist?

This is a public web server, so it's not possible to disconnect it from the internet.

The server is win nt4 sp6a, all patches applied.
But, we've seen the same problem on win2k servers.

Hope there's a way to block this.

Thanks

David
 
Search the web for info on hardening the webserver. The exploit being used may be in the webserver and not the OS.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top