Hey, I've got a very wierd issue here, to be honest it's scaring me.
I've got a W2k DC, our file and intranet server, upgraded from windows
NT4 ages ago...
All the user profiles are stored in C:\Winnt\Profiles, nothing out of
the ordenary here, but this is whats scaring me:
Directory of C:\WINNT\Profiles
21/08/2001 10:01a <DIR> .
21/08/2001 10:01a <DIR> ..
01/08/2001 04:04p <DIR> Administrator.000
07/07/2000 01:59p <DIR> ADMINI~1~000
13/08/2001 04:04p <DIR> All Users
16/08/2001 08:31a <DIR> DOU04
19/07/2001 11:44a <DIR> gracie
20/08/2001 12:15p <DIR> LOV02
21/08/2001 09:50a <DIR> Peter
19/04/2000 05:43p <DIR> Policy
21/08/2001 10:57a <DIR> ROW04
29/05/2001 01:14p <DIR> SMS#_MORPHEUS.STUDENT
22/05/2001 12:16p <DIR> SMS&_MORPHEUS
22/05/2001 12:17p <DIR> SMSCliToknAcct&
22/05/2001 12:08p <DIR> SMSLogonSvc
0 File(s) 0 bytes
Administrators, I can handle, SMS... I can handle... gracie... well,
he's our other admin.
This scares me though:
16/08/2001 08:31a <DIR> DOU04
20/08/2001 12:15p <DIR> LOV02
21/08/2001 10:57a <DIR> ROW04
These are domain users. We're a school, they are students. They are only
members of the domain users group.
We have terminal services running, but in remote admin mode, only
administrators can log on.
Below is a dump of eventvwr for the ROW04 user... the type 3 logons
don't worry me, they're network logons... probably for his home drive.
But whats the "Service Ticket Granted?" HELP!!!
Thanks.
Will Lotto
Systems Administrator
Bendigo Senior Secondary College
Eventvwr says:
21/08/2001,10:01:53 AM,Security,Success Audit,Logon/Logoff
,538,STUDENT\ROW04,MORPHEUS,"User Logoff:
User Name: ROW04
Domain: STUDENT
Logon ID: (0x0,0xE78BE5)
Logon Type: 3
"
21/08/2001,10:01:53 AM,Security,Success Audit,Logon/Logoff
,540,STUDENT\ROW04,MORPHEUS,"Successful Network Logon:
User Name: ROW04
Domain: STUDENT
Logon ID: (0x0,0xE78BE5)
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name: "
21/08/2001,10:01:53 AM,Security,Success Audit,Logon/Logoff
,538,STUDENT\ROW04,MORPHEUS,"User Logoff:
User Name: ROW04
Domain: STUDENT
Logon ID: (0x0,0xE78B94)
Logon Type: 3
"
21/08/2001,10:01:53 AM,Security,Success Audit,Logon/Logoff
,540,STUDENT\ROW04,MORPHEUS,"Successful Network Logon:
User Name: ROW04
Domain: STUDENT
Logon ID: (0x0,0xE78B94)
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name: "
21/08/2001,10:01:53 AM,Security,Success Audit,Account Logon ,673,NT
AUTHORITY\SYSTEM,MORPHEUS,Service Ticket Granted:
User Name: ROW04
User Domain: BSSC.EDU.AU
Service Name: MORPHEUS$
Service ID: STUDENT\MORPHEUS$
Ticket Options: 0x40810010
Ticket Encryption Type: 0x17
Client Address: 127.0.0.1
21/08/2001,10:01:53 AM,Security,Success Audit,Logon/Logoff
,538,STUDENT\ROW04,MORPHEUS,"User Logoff:
User Name: ROW04
Domain: STUDENT
Logon ID: (0x0,0xE78ABC)
Logon Type: 3
"
21/08/2001,10:01:53 AM,Security,Success Audit,Logon/Logoff
,540,STUDENT\ROW04,MORPHEUS,"Successful Network Logon:
User Name: ROW04
Domain: STUDENT
Logon ID: (0x0,0xE78ABC)
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name: "
21/08/2001,10:01:53 AM,Security,Success Audit,Logon/Logoff
,538,STUDENT\ROW04,MORPHEUS,"User Logoff:
User Name: ROW04
Domain: STUDENT
Logon ID: (0x0,0xE78A53)
Logon Type: 3
"
21/08/2001,10:01:53 AM,Security,Success Audit,Logon/Logoff
,540,STUDENT\ROW04,MORPHEUS,"Successful Network Logon:
User Name: ROW04
Domain: STUDENT
Logon ID: (0x0,0xE78A53)
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name: "
21/08/2001,10:01:53 AM,Security,Success Audit,Logon/Logoff
,538,STUDENT\ROW04,MORPHEUS,"User Logoff:
User Name: ROW04
Domain: STUDENT
Logon ID: (0x0,0xE789DE)
Logon Type: 3
"
21/08/2001,10:01:53 AM,Security,Success Audit,Logon/Logoff
,540,STUDENT\ROW04,MORPHEUS,"Successful Network Logon:
User Name: ROW04
Domain: STUDENT
Logon ID: (0x0,0xE789DE)
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name: "
!���0���z[l��pj���o�̬i٢�X���Z���