"CDCSERVER"


my domain controller logs show server named cdcserver trying login every account in our ad , locking every account out. not have server named cscserver , constant. have 1200 accounts , getting locked out several times day. ideas?

hi,

cdcserver not ring bell me (exept sql cdc feature). might misconfigured system, malware infected host, rogue machine (intruder) or vm running on machine of 1 of employees.

my first advice attempt trace physical computer, disconnect network , investigate malicious software or misconfigurations.

if cannot trace physical computer, consider trace on network level. found, might disable switch port on and/or block it's traffic through means of firewall.

also, might worth investigating dc logs succesfull logons machine (which might indicated leaked credentials) , have users change passwords. put auditing on account creations (intruders commonly create account once obtained account has enough privileges so).


mcp/mcsa/mcts/mcitp



Windows Server  >  Security



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client