Accounts being created with administrative group rights

Hello,
The server is a Windows 2003 R2 Enterprise fully patched used for Shared Hosting purposes.  It runs Hsphere control panel.  I am trying to identify how the following hack is happening. 
1) There are users being created with Administrative group rights.   Below is the EventViewer log for the user creation:
User Account Created:
     New Account Name:    username
     New Domain:    PCNAME
     New Account ID:    PCNAME\username
     Caller User Name:    PCNAME$
     Caller Domain:    DOMAINNAME
     Caller Logon ID:    (0x0,0x3E7)
     Privileges        -
 Attributes:
     Sam Account Name:    username
     Display Name:    <value not set>
     User Principal Name:    -
     Home Directory:    <value not set>
     Home Drive:    <value not set>
     Script Path:    <value not set>
     Profile Path:    <value not set>
     User Workstations:    <value not set>
     Password Last Set:    <never>
     Account Expires:    <never>
     Primary Group ID:    513
     AllowedToDelegateTo:    -
     Old UAC Value:    0x2DAB2B0
     New UAC Value:    0x2DAB2B0
     User Account Control:    -
     User Parameters:    <value not set>
     Sid History:    -
     Logon Hours:    <value changed, but not displayed>
There exists entries as well where the primary group ID is changed to the Administrative group, but I am omitting such.
2) I tried to identify what Caller Logon ID:    (0x0,0x3E7) means.  I found out from here:
 http://blog.joeware.net/2013/01/14/2667/ that I can use LogonSessions.exe to identify it.
Output from LogonSessions.exe is pasted below (snippet):
[0] Logon session 00000000:000003e7:
    User name:    DOMAINNAME\PCNAME$
    Auth package: NTLM
    Logon type:   (none)
    Session:      0
    Sid:          S-1-5-18
    Logon time:   9/11/2014 12:41:53 PM
    Logon server:
    DNS Domain:   
    UPN:          
        4: System
      316: smss.exe
      364: csrss.exe
      392: winlogon.exe
      440: services.exe
      452: lsass.exe
      628: svchost.exe
      756: LMAgent.exe
      840: svchost.exe
     1000: spoolsv.exe
     1252: avagent.exe
     1268: camWMIAgent.exe
     1324: cissesrv.exe
     1380: cpqrcmc.exe
     1404: vcagent.exe
     1440: svchost.exe
     1480: HsQuotas.exe
     1740: inetinfo.exe
     1780: EmailAgent.exe
     1856: snmp.exe
     1884: sysdown.exe
     1920: smhstart.exe
     2192: svchost.exe
     2388: cmd.exe
     2396: hpsmhd.exe
     2444: cqmgserv.exe
     2464: cqmgstor.exe
     2484: HSphere.exe
     2596: wmiprvse.exe
     2676: cmd.exe
     2684: rotatelogs.exe
     2692: cmd.exe
     2700: rotatelogs.exe
     2732: searchindexer.exe
     2812: hpsmhd.exe
     2824: cqmghost.exe
     2852: svchost.exe
     3044: cmd.exe
     3052: rotatelogs.exe
     3080: cmd.exe
     3088: rotatelogs.exe
     5452: svchost.exe
     5596: GravitixService.exe
     7392: csrss.exe
     7232: winlogon.exe
     6888: csrss.exe
     9832: winlogon.exe
    10388: wawrapper.exe
    10352: cpqnimgt.exe
     9496: msiexec.exe
     6068: w3wp.exe
     4748: webalizer.exe
3) I also learned from http://support.microsoft.com/kb/243330/en-us that   Sid:          S-1-5-18 means:
SID: S-1-5-18
Name: Local System
Description: A service account that is used by the operating system
That is all great info, but I am not sure I can put together what I have learned to attempt and get closer towards identifying how in the world users are being created and then being assigned administrative group rights.
I am a Linux person mostly, but I am comfortable following a properly explained thread regarding windows 2003 R2 Enterprise issues.
The server is fully patched and it is running Lumension security product.  What's more, Norman Malware tracker, tdskiller.exe (Kaspersky) and McAfee rootkitremover.exe have been run without any apparent Malware/Virus infection
Hope someone with advanced admin skills can advise.
Thank you

Hi,
You mentioned that, “I am trying to identify how the following hack is happening”, would you please tell us that why did you think the event represent a hacking behavior?
In a Shared Server Hosting environment, the underlying hosting control panel tool (Hsphere in this case) should be creating only virtual FTP users with a specific group.  So no users with Administrative group should be ever created.  If this happens,
it constitutes a breach of server security=positive hacking attempt.
>how in the world users are being created and then being assigned administrative group rights.
In addition, would you please be more specific about this question? Did you find the event message on a domain joined machine?
I want to be able to understand in full how/what process is allowing users to be created with Admin rights.  In other words, I want to know what IP was used to issue the command, if ASP.net was used (abused in this case), or anything else related to
it so that we can patch this particular hole.
Best Regards,
Amy

Similar Messages

  • Accounts Being Created With My Email

    I've just recieved about three emails saying that I have created three separate Skype accounts. I have not created these accounts, and it seems to be the work of spammers. Can they be deleted and prevent any forms of my email address from being able to create accounts?
    I have recieved emails that say that michaelsquitieri1, michaelsquitieri12, and michaelsquitieri121 were all created from one email address.

    you can contact customer service ([email protected]) tp report this incident and to request to unlink your email address from those unauthorized accounts.
    CONTACT SKYPE CUSTOMER SERVICE   |  HOW TO RECORD SKYPE VIDEO CALLS  | HOW TO HANDLE SUPICIOUS CALLS AND MESSAGES   |  WINDOWS PROBLEMS TROUBLESHOOTING   |  SKYPE DOWNLOAD LINKS  
    MORE TIPS, TRICKS AND UPDATES AT
    skypefordummies.blogspot.com

  • How I can see what accounts I created with my family pack in my old mobileme account?

    Any ideas how I can see what accounts I created with my family pack in my old mobileme account?
    i updated it when we need to migrate and all emails are active and being used.
    i need to update an email address. we use this for my personal company and need to keep the email in
    the same format so it matches the others in the company. i dont see it anywhere in my account now.
    i am using a .mac format. thanks.

    In order to see which devices are authorized on your account:
    Open iTunes
    Click Store
    Click Account
    Click View Account
    Enter your password
    Look in the second section iTunes in the Cloud
    To the far right you'll see Manage Devices
    Once it's clicked you will see all of the devices currently authorized in iTunes/on your account
    I was going to say, "Hope this helps," but based on the above, I'm pretty sure it did!
    Thanks guys...

  • To change charging account upon creating new emp group

    Dear experts,
    Our company want to create new emp group.I have problem to understand concept of employee grouping
    account determination.
    1. How do I know the new emp group that i created  goes to what emp grouping.
    2. If I want to change to new grouping, what should I do
    3. How to check whether the emp grouping that I created goes to the coorect emp grouping
    I'm quite worry if i'm make mistake during creating new em group.
    Thanks in advance

    if your Question is related to posting
    Than try to configure the Symbolic accounts as per the ESG for more info read the documentation and use of the feature PPMOD
    or else if you are looking at for the Groupings of EG and ESG
    SM30 , V_503_ALL
    After cofigureing  you will be haveing Testing or UAT right so not a problem with any Errors or issues

  • When i login with microsoft account cannot access with administrative share c$

    i have a problem when i login to windows with microsoft account cannot access any network computer with administrative sharing c$,d$ with windows 8.1 
    but when i login with local account can access
    and some people tell  me create key in regedit t fix it 
    after enter user name and password show this error 
    and i apply your instruction  and not fix until now
    note:
     my Machine windows 8.1 if another machine in network windows 7 can access a hidden share if machine in network windows 8.1 show this message in image 2 
    but if i login with local user can i access all machine hidden share network windows 7 and 8.1

    yes this computer i want to access  name poland2-work and have two users 
    first :administrator
    second : poland 2

  • XMP files not being created with DNGs...

    I'm used to using Bridge with ACR to process Nikon NEFs. But a recent camera update has me experimenting with converting the D3's NEFs to DNG files and editing them with CS2 and Bridge 1.04 which works better on my system. I've also experimented with CS3 and Bridge 2.1.1.9 with the same DNG files.
    In both cases XMP files are not being created when working with DNG files. I have enabled "Save image settings in : Sidecar ".xmp" files" turned ON. But they do not seem to be generated and I assume the ACR adjustments are being embedded in the DNG file. Meanwhile doing edits on NEF files continues to create .xmp files as expected.
    I find .xmp files to be very useful and I'm wondering why they're missing with DNG files? Are they hiding somewhere other than in the same folder that the images reside in?
    Thanks.
    Russell

    > The information contained in the XMP file is stored in the DNG file so there is no need for a separate file.
    Aww, yuck!! That's a real drag...
    When editing lots of files (yesterday's shoot produced 8GB) I back everything up to off-line storage and then, after doing all my edits and crops in ACR, I only have to copy over the small XMP files which takes no time at all.
    So if I re-edit the DNG with ACR I have to re-copy ALL the files again to the off-line storage.
    I used to sometimes even save 2 versions of the xmp files when I needed 2 different crops of the same images, such as doing a wide screen 'cinema' crop for a corporate client's Intranet presentation of their event, as well as more standard crops to be used for their newsletters.
    Guess I won't be using DNG any more..
    Thanks for the help Kees :-)
    Russell

  • No accounts being created - 10.5.4 install

    I recently tried an erase and reinstall of 10.5 server on a mac pro that I have acting as a stand alone server. The first time I installed I had no issues, just borked the config of DNS and I finally got some time to redo the install completely.
    Well the install process went ahead with no issues, I choose the advance setup, filled in all the required network and admin information (but skipped the registration parts), and the server rebooted leaving me at the login prompt. Everything looks good.
    I had trouble logging in - mainly I couldn't at all. I thought I was going crazy and miss-spelled the admin name (long and short) when creating the account. I rebooted from the install disc and went to the change password utility to check the name of the account and to reset the password. As it turns out the account was not available in the utility (it wasn't in the dropdown list, only root was there) so I fired up terminal to discover that no accounts were created by the setup process. The rest of the OS appears to be there and fine, but nothing in /Users.
    I tried running dscl from the terminal app on the install disc, but it's not there!
    *Any suggestions? Has anyone experience this before?* I tried searching for a couple hours and couldn't find an similar situations. I am currently running the install again and will choose standard instead of the advanced setup option (the VERY first install that I borked the settings on was done as standard and it worked fine...)
    Thanks!

    As expected Standard worked fine. Not sure what's up with the advance setup not actually setting anything up though.

  • Report EM12C for targets not associated with (Administration) Group

    Is there a report/view in EM12C for showing which targets are not associated with a Administration Group or a standard group?

    For administration groups, check the Unassigned Targets report, accessible from the Associations tab.
    For more details, look for the section "Identifying Targets Not Part of Any Administration Group" in the Administration Groups chapter of the EM 12c Administrator's Guide:
    http://docs.oracle.com/cd/E24628_01/doc.121/e24473/administration_group.htm#EMADM10011

  • Auto Save folder not being created with new project

    Just recently I've noticed that when I start a new project there is no auto save folder being created.  I have all preferences the same (auto save every 10 min with a max of 50 and save next to project files).  I have no idea why this started or what I can do to fix it. 

    So it seems to be working now.  I went back through other projects that have been open for some time and the most recent auto save file I could find for any of them was from Oct. 8th.  So auto save hasn't been working at all.  What I did was go into preferences and change the interval a little and the frequency from where I had had it since intial set up.  That seemed to have told it to turn it back on for some reason.  It's really weird.  I guess I'll just keep an eye on it, but people may want to check there folders just in case the same issue is happening.  I didn't realize it until today and it's been happening for a couple of weeks apparently. 

  • Accounting Document Post with Ledger Group

    Hi,
    I am trying you post accounting document using 'BAPI_ACC_DOCUMENT_POST', But my requirement is to post the acc documents with 'Ledger Group', I couldn't find any parameter in the  above mentioned BAPI. If anyone come accross same requirement please share your knowledge and suggest me how to proceed with this.
    Before posting this thread I searched for the threads with same category, but i couldn't find sufficient information.
    Regards,
    Narayan

    Hi Navitha,
    I am doing migration as It's a one time activity, If I implement BADI  it will be triggered whenever accounting document posting happens, Is there any other way to pass Ledger group like other BAPI / FM etc ?
    Regards,
    Narayan
    Edited by: narayanasamy rajagopal on Sep 30, 2009 11:08 AM

  • TLB STO's created in ECC via cif are being created with Intercompany Markup

    STO's created using TLB in APO when cif'd over to ECC6 get created with an Intercompany Markup.  When created manually in ECC6 using ME21N the markup is not part of the pricing and is correct.  Has anyone had this same situation?

    Abhishek,
    ECC Route is is part of ECC Transportation and Delivery scheduling,
    ( http://help.sap.com/erp2005_ehp_02/helpdata/EN/dd/5607e7545a11d1a7020000e829fd11/frameset.htm )
    and is not directly linked to SCM means of transport in standard SCM.  The analogue to Route in SCM is found in shipment scheduling in SCM.  If you wish to link route to alternative Means of Transport, you will need to use an enhancement.
    If you elect to use the more standard 'shipment scheduling' functionality to schedule your STOs instead of an enhancement, you do not need to implement the entire TLB or TPVS, you can pretty much implement just the shipment scheduling functionality.
    http://help.sap.com/saphelp_scm700_ehp02/helpdata/EN/05/f8923945b12c4de10000000a114084/frameset.htm
    Best Regards,
    DB49

  • Duplicate text files being created with ~ appended

    Whenever I edit a text file with TextEditor and save it, a duplicate file is created with a ~ appended to the end of the name.
    Example:
    After editing and saving my_file.txt my_file~.txt is also created.
    The result is I get two files with exactly the same contents.
    my_file.txt
    my_file~.txt
    I would really like to stop it from doing this. It clutters up everything. It has done this since I first installed the OS. My file system format is Mac OS Extended (Journaled). Any suggestions?

    I looked through the preferences for TextEditor. I had "Delete the automatic backup file unchecked". I think checking this option will fix the problem.

  • Sales Order Outbound IDOC - Restricting Items being created with a Segment

    Hi,
    I have a requirement to restrict segments being created for Items (Child) in Sales Order Outbound IDOC based on conditions in the Items (Parent & Child). Can you please suggest me a suitable solution?
    Basic Type: ORDERS05, Message Type: ORDRSP. What is the IDOC Function Module to be used to create Outbound IDOC for Sales Order?
    Appreciate Your Help.
    Thanks,
    Kannan
    Edited by: Kannan SA on Jan 3, 2008 3:03 PM

    Hi,
    if the segments are mandatory then you can't trigger the idoc without those segments.
    Otherwise, you can read the segment and clear all the data in it, the segment will not be attached to the outbound idoc.
    Where to do it? Search the CALL CUSTOMER-FUNCTION '002' for the outbound idoc for example IDOC_OUTPUT_INVOICE for Invocing.
    Regards,
    Baburaj

  • Accounts being created for internet fraud.

    Dear Skype Users!
    The group of people using English and German languages for the creation of internet-sending-money fraud has been discovered working actively in Skype accounts. The signs of these people are constantly being renovated profiles of US Army generals and oficers, sometimes civil high-positioned representatives. They can be easily recognized with USA national flag as profile picture wallpaper, pictures in military uniforms of different army departments taken from oficial US authorities websites, slogans which use the name of God like "In God We Trust". However countries of origin for profiles are different or changing. The cheating procedure is going on as follows. They approach user's contact lists as pending request for the new users to be instructed how to move in Skype. When accepted they try to make out as much as possible about the treated person, distinguish age category and income level. Normally they choose young girls, housewives and elder women. After a couple of days they call without video, speak English with West Indian or American accent and choose the tactic according to target's age. Sometimes  they offer the girl to marry himself, sometimes to receive a parcel with inheritage or a treasure. The marks how to discover the cheating offer is the amount of money value written first in numbers and immediatelly after in written letters in brackets like this: 1 000 000 $ (one million US dollars).  Main point is the "client" should send out relatively small portion of money afterwards for flight to her future fiancee, for delivery of the parcel, bank deposit via special post and so on.
    So, the moment  such offer appears you should know what happens. I applied to Skype admin to help for elimination of these cheating schemes from the system. But without help of users who should block these people with "abuse" sign it will never be successful. 
    With respect and good wishes,
    Elena
    This post was transferred from its previous location to create its own new topic here; its subject and/or title has been edited to differentiate the post from other inquiries and to reflect the post's content.

    Dear Skype users,
    Here is typical application from a frauder/scammer collected from communication after he/she sends a pending request for contact:
    [20:23:38] *** Gen Scot Robinson would like to add you on Skype
    Enter a message to introduce yourself.
    Dear trusted friend,
    Season Greetings and Good Tidings to you and your Family. With due respect to you and your entire family over there, I hope it’s well with you and your family.
    My names are General David Anderson a United States Army General presently serves here in Syria as the current Commander, International Security Assistance Force (ISAF) and Commander, U.S. Forces Syria.
    I am in desperate need of your assistance, I have summed up courage to contact you as my Brother, Sister and a friend, I am seeking your assistance to move the sum of (USD$ 22.7 Million) Twenty Two Million Seven Hundred Thousand United States Dollars to you as far as you will assured me that my share will be safe in your care until I complete my service here in Syria. This is no stolen money and there is no danger involved.
    Some money in various currencies was discovered in barrel at a farm house in the current Syrian Civil War as a result of clashes between President Bashar al-Assad's government and rebel forces who want him out or step down [Link to BBC news article - 404 error - redacted by Moderator] and it was agreed by staff Sgt. Kenneth Buff, General David Miller, and I that some part of this money be shared among us before informing anyone about the discovery, this was quite illegal thing to do but I tell you what, no compensation will make it up for the risk we have taken our lives in this hell whole of which my colleague was killed by a road side bomb last week.
    The above figure was given me as my share to cancel this kind of money became a problem for me, so with the help of a British contact working here and his office enjoys some immunity I was able to move the money to a security company in the United States as a diplomatic consignment. They are waiting for me to provide the name of the end receiver who they will deliver the parcel to, as a soldier I can not present myself as the direct owner of this funds it against our code of conduct we are not allowed to do business and the US Government is planting a close watch on all military personnel that is why I need you to help me receive this funds.
    The moment I get a response from you. that you are willing to help me I will forward all the details of the security company in the United States to you, so that you can contact them for immediate release, I want you to tell me how much you will accept for helping me to receive this funds.
    One more passionate appeal please do not discuss this issue with anyone, and please if you don't like this mail please destroy this message as any leakage of this information will be too bad for us soldiers here in Syria, this is the other reasons I will mention later has prompted me to reach you for help, I honestly want this matter to be resolved immediately please get back asap, my only way to communicate is by email: [e-mail removed for privacy and security]
    I am willing to give you 30% out of the total funds. What is your own opinion?
    My private email: [e-mail removed for privacy and security]
    Yours in service,
    Gen Scott Robinson

  • Locally cached copy of roaming profiles are being created with username.domainname.00x suffix

    First off let me give some background as to where we've come from and how we got to where we are today.  In my organazation we initially setup a Win 2k3 domain with roaming profiles.  The roaming profiles worked without a problem for about 6 years.  We migrated to a Windows 2k8 domain (non-2008 native mode) about two years ago.  Profiles have been working fine.  We recently did a rollout of 80% of our client machines with newly leased machines.  Once we did this, the profile issues have been...interesting to say the least.  I've been seeing a couple machines having issues loading their profiles correctly.  The users will complain of not being able to use MS Outlook, or they don't have their proper desktop icons on their desktop.  These erros can present themselves when the user changes their domain acct. password (per our security policey) or it may happen just out of the blue.  The user may be working perfectly fine on Monday, and then log off and on Tuesday when they login to their computer, the user will have these problems.  When this is reported to me, I login the computer that is having the issue and I look at the C:\Documents and Settings folder and I'll see sometimes multiple bogus profiles.  The profiles have a naming convention of %username%.%domainname%.00X .  The .00X will increment up 1 with each bogus profile.  Each of these bogus profiles will have only the local settings folder in them.  In order to fix this problem, we typically delete all the local profiles and let the computer pull the server copy back down.  Can someone please shed some light on this for me.  Thanks. 

    I have the exact same issue. All my machines are SP3 as well. I have tried UPHClean and it makes no difference. It's completely random when the username.domain.000 accounts start appearing and accounts become corrupt causing the same issue with outlook or a different set of desktop icons. After almost 3 months of having to reset user profiles (we have 1700 AD accounts and 3 IT guys), here's what I've found to this point.
    WINLOGON.EXE is the culprit. UPHClean doesn't appear to work well with SP3 or this particular version of WINLOGON. WINLOGON.EXE is locking (handle) the profile directory itself.
    7F8: File  (RW-)   C:\Documents and Settings\(User Directory)
    You cannot even run a batch script or something to "restart" winlogon to unlock the folder because it's a system process. When the user logs back in, the pc sees there is already a user profile folder there so it creates a new one with the domain name, rinse and repeat and you get:
    Username
    Username.Domain
    Username.Domain.000
    Username.Domain.001
    These will go on forever unless you use DELPROF in your GPO as a Computer/Windows/Startup script to remove all "USER ONLY" profiles from the docs and settings folder. This works great other than now, users seem to randomly loose their favorites. This is about the most discussed roaming profile issue on the internet but not a single person nor group of persons has created a 100% working fix for it. It's been a massive headache for me and my guys and I know thousands of other IT guys have or are still struggling with it.
    PLEASE Microsoft, fix this winlogon issue so it will release the user profile directory when the user logs out. PLEASE.

Maybe you are looking for

  • Importing Photos without using Aperture or iPhoto

    Hi all, I am preparing to migrate from the cuddly world of iPhoto into the big bad world of Aperture. During the transition I was hoping to continue using both programs (especially given the excellent photobook and slideshow functions of iPhoto) and

  • What is PMS Data Migration Experience and Data Migration Scripts preparatio

    Hi All what is PMS Data Migration Experience and Data Migration Scripts preparation why we use these in HRMS(EBS)

  • Problème convertisseur

    Bonjour, J'utilise comme logiciel adobe la version acrobat 8.1 standard et un logiciel pour faire des assemblages de PDF appelé PAGESCOPE WORKWARE les 2 logiciels sont sur le même DVD revendu par KONICA MINOLTA. Le logiciel Workware utilise adobe pou

  • Why can't iphoto locate some of my photos anymore?

    I have been using Iphoto for years and have never had this problem before.  Photos that I had previously imported, edited and printed are no longer able to be viewed or printed, but all of their information is still there.  The message that I get whe

  • Why can't I download FaceTime in apps

    I bought a used 4s with someone's FaceTime logged in and tried to get face time from apps and cannot find it ?