please dont rip this site

Windows Logon Failure Investigation

The following Event ID's indicate that a logon failed:

You should watch for events 529, 539 and 644. Event ID 529 entries can have various "Logon Types": +

Event ID 529 will also have a process ID that can be used to find the program that passed on the logon attempt. Use the Task Manager (ctrl+alt+delete then select Task Manager, or if logged in remotely, Start / Windows Security) to lookup the name of the process, from the "Processes" tab, select View / Select Columns and check "PID (Process Identifier)" then click ok.

With Event ID 529, Logon Type 3, and a PID that turns out to be inetinfo.exe, the error was probably caused by an attempt to log in to the server via the remote web workspace, Outlook web access, etc... The web access log may have more information including the IP address of the attacker.

With Event ID 529, Logon Type 3, and a PID that turns out to be advapi it was(apparently) an attempt to log in via SMTP and relay email^. The SMTP service can be set to log detailed events, which will include the IP address of the attacker. +

file: /Techref/os/win/logonfailure.htm, 3KB, , updated: 2008/2/25 10:11, local time: 2024/7/17 13:27, owner: JMN-EFP-786,

 ©2024 These pages are served without commercial sponsorship. (No popup ads, etc...).Bandwidth abuse increases hosting cost forcing sponsorship or shutdown. This server aggressively defends against automated copying for any reason including offline viewing, duplication, etc... Please respect this requirement and DO NOT RIP THIS SITE. Questions?
Please DO link to this page! Digg it! / MAKE!

<A HREF=""> Windows Logon Failure Investigation</A>

After you find an appropriate page, you are invited to your to this massmind site! (posts will be visible only to you before review) Just type a nice message (short messages are blocked as spam) in the box and press the Post button. (HTML welcomed, but not the <A tag: Instead, use the link box to link to another page. A tutorial is available Members can login to post directly, become page editors, and be credited for their posts.

Link? Put it here: 
if you want a response, please enter your email address: 
Attn spammers: All posts are reviewed before being made visible to anyone other than the poster.
Did you find what you needed?


Welcome to!


Welcome to!