|
板凳
楼主 |
发表于 2017-11-21 10:42:26
|
只看该作者
经过仔细对比查找,发现日志中有记录,只是没有账号信息,只有下面信息
2017-11-21T01:55:54.981Z,0000000000000ACC,2,x.x.x.x:143,y.y.y.y:3681,,0,31,30,authenticate,plain,"R=""2 NO AUTHENTICATE failed."";Msg=AuthFailedogonDenied"
有的是这样,带着账号信息
2017-11-21T02:06:03.673Z,0000000000000AEA,6,x.x.x.x:143,y.y.y.y:57188,,15,42,267,authenticate,NTLM,"R=""A4 NO AUTHENTICATE failed."";RpcL=-1;LdapL=-1;Msg=AuthFailedogonDenied"
2017-11-21T02:06:03.767Z,0000000000000AEA,7,x.x.x.x:143,y.y.y.y:57188,,0,39,21,login,zzz@www.com*****,"R=""A5 NO LOGIN failed."";RpcL=-1;LdapL=-1;Msg=LogonFailedoginDenied"
可能带账号信息的记录是正常的?不带账号信息的属于破解的?不是很明白。 |
|