Windows-Server-2003
事件查看器視窗 2003 中有很多登錄/註銷事件
我似乎在安全事件查看器中獲得了很多這些條目。大約每小時8-12點。我想知道a)我應該擔心嗎?或b)實際發生了什麼,有人可以幫忙嗎?
Type: Success Audit Source: Security Category: Logon/Logoff User: Network Service or IUSR_WIN2003 Logon attempt using explicit credentials: Logged on user: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon GUID: - User whose credentials were used: Target User Name: IUSR_WIN2003 Target Domain: WILDEBB1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 13224 Source Network Address: - Source Port: -
同樣在錄製完這個之後,iis停止接受連接,我不得不重新啟動伺服器。與此不同的是,登錄過程使用了 ADVAPI…
Event Type: Success Audit Event Source: Security Event Category: Logon/Logoff Event ID: 540 Date: 05/06/2012 Time: 13:59:10 User: WILDEAA1\IUSR_WIN2003 Computer: WILDEAA1 Description: Successful Network Logon: User Name: IUSR_WIN2003 Domain: WILDEAA1 Logon ID: (0x0,0x5FDB22D) Logon Type: 8 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: WILDEAA1 Logon GUID: - Caller User Name: NETWORK SERVICE Caller Domain: NT AUTHORITY Caller Logon ID: (0x0,0x3E4) Caller Process ID: 13224 Transited Services: - Source Network Address: - Source Port: -
IUSR 帳戶是安裝 IIS 時創建的匿名使用者帳戶。您是否在該伺服器上執行任何網站?每當 IIS 嘗試為匿名使用者登錄帳戶時,您都會看到一個登錄事件。