Pwdlastset appears to be incorrect

We have four Win 2008 R2 Enterprise DCs.  Approximately 7500 user objects.
Last Wednesday a user called in that her password had expired. Her pwdlastset attribute in AD Users and Computers showed a time of 2:30am that morning.  This timeframe didn't make a lot of sense to us, so we ran a (DSRazor) report on that
attribute against all users.  312 user objects showed having that attribute changed within a 3 minute period of 2:30am that morning.  The user objects affected spread across multiple states in different OUs.  We did a quick spot-check and,
excluding one other user, people did not have any issues logging into their accounts with their current passwords.  So, even though that attribute showed that it had been reset at 2:30am that morning, it hadn't.
We ran the report the next day as well, and the users could still login with their original passwords, but the attribute was still showing 2:30am.
Any ideas on what can cause that attribute to be set to -1, without the users'/admin resetting the users' passwords?
Thanks!  April

Thank you all for responding.  The PFE Blog post was very informative.  We looked at the Security Logs of the four DCs and the log size setting is set to 128 Meg (overwrite), which appears to only hold about 2 hours of data.  I did see the
4723/4724 events in the logs, but we just don't have the history needed to see what made the change. 
We believe this was a one-time occurrence.  We cannot hunt down any program that would have an internal script to reset a subset of users' passwords at 2:30 AM on a Wednesday.
Could a DC time sync issue of some sort cause this, or a DC hiccup?  Any other ideas of how to search for the culprit?
If this does happen again, I'm thinking we won't be able to track it again, unless somehow we catch it in the 2-3 hours that the DC security logs maintain information.  Since 128 Meg holds ~2-3 hours of data for our system, we would need to
set it to ~1 Gig to catch 1 day's worth of auditing data.  Besides the security/auditing logs, are there other tools available to see who/what program reset a user's password?
My boss has asked the following question.  I believe the answer is yes, but this seemed like a good place to ask it anyway.  Is there any way a hacker could replicate the problem to programmatically change a bunch of accounts to log in with them
or otherwise gain access?
Thanks for your help.  April

Similar Messages

  • HT1414 I am unable to restore my IPhone from a previous back up as the password appears to be incorrect, how can I access a previously stored back up?

    I am unable to restore my IPhone from a previous back up as the password appears to be incorrect, how can I access a previously stored back up?

    Use the correct password. If you don't know it there is no way to bypass it.

  • Group name appears to be incorrect

    Running on WiSMs on 6.0.196 and IOS version 12.4(21a)JHA. We never have configured groups, we have always just left them at default-group. While I was tracking down another issue, I noticed the following logs. Some of the APs are showing in "default-group" but most of them are showing in "none".
    Is this a problem or a bug?
    AP Name             Slots  AP Model             Ethernet MAC       Location          Port  Country  Priority  GroupName
    south-0w011          2     AIR-LAP1242AG-A-K9   00:1f:ca:27:e8:32  default location  LAG   US       1         none
    east-020             2     AIR-LAP1242AG-A-K9   00:24:c4:a0:f0:64  default location  LAG   US       1         none
    west-278             2     AIR-LAP1242AG-A-K9   00:1f:ca:28:26:3a  default location  LAG   US       1         default-group
    west-206g            2     AIR-LAP1242AG-A-K9   00:22:90:1a:43:50  default location  LAG   US       1         none
    east-178e            2     AIR-LAP1242AG-A-K9   00:1d:70:97:e0:e6  default location  LAG   US       1         default-group
    west-1eddeskn        2     AIR-LAP1242AG-A-K9   00:1d:70:97:e4:02  default location  LAG   US       1         none
    west-1angio          2     AIR-LAP1242AG-A-K9   00:1d:70:97:e0:ec  default location  LAG   US       1         none
    south-mdf-temp       2     AIR-LAP1242AG-A-K9   00:24:c4:a0:f0:bc  default location  LAG   US       1         none
    west-1ermain         2     AIR-LAP1242AG-A-K9   00:1d:70:97:e8:94  default location  LAG   US       1         none
    south-0w016          2     AIR-LAP1242AG-A-K9   00:1d:70:97:e4:66  default location  LAG   US       1         default-group
    west-189f            2     AIR-LAP1242AG-A-K9   00:1d:70:98:08:48  default location  LAG   US       1         none
    east-270b            2     AIR-LAP1242AG-A-K9   00:22:90:1a:45:86  default location  LAG   US       1         default-group
    west-195a            2     AIR-LAP1242AG-A-K9   00:22:90:1a:45:90  default location  LAG   US       1         none
    east-120             2     AIR-LAP1242AG-A-K9   00:1f:ca:28:24:e2  default location  LAG   US       1         none
    west-296             2     AIR-LAP1242AG-A-K9   00:22:90:1a:44:7e  default location  LAG   US       1         default-group
    west-240             2     AIR-LAP1242AG-A-K9   00:1d:70:97:d7:86  default location  LAG   US       1         none
    west-150             2     AIR-LAP1242AG-A-K9   00:24:c4:a0:ef:e0  default location  LAG   US       1         none
    west-1endo5          2     AIR-LAP1242AG-A-K9   00:1d:70:97:e3:90  default location  LAG   US       1         none
    west-245b            2     AIR-LAP1242AG-A-K9   00:1d:70:98:07:6c  default location  LAG   US       1         none
    east-230             2     AIR-LAP1242AG-A-K9   00:1d:70:97:e0:f4  default location  LAG   US       1         default-group
    east-219             2     AIR-LAP1242AG-A-K9   00:1d:70:97:e4:9a  default location  LAG   US       1         default-group
    east-280             2     AIR-LAP1242AG-A-K9   00:24:c4:a0:df:6c  default location  LAG   US       1         none
    west-275             2     AIR-LAP1242AG-A-K9   00:1d:70:97:d2:ea  default location  LAG   US       1         none
    mop-0wc              2     AIR-LAP1242AG-A-K9   00:1d:70:97:e3:80  default location  LAG   US       1         none
    west-1endo1          2     AIR-LAP1242AG-A-K9   00:1d:70:97:e3:2a  default location  LAG   US       1         none
    west-1treat18        2     AIR-LAP1242AG-A-K9   00:1d:70:97:df:16  default location  LAG   US       1         none
    south-030            2     AIR-LAP1242AG-A-K9   00:1d:70:97:e4:26  default location  LAG   US       1         none
    west-051             2     AIR-LAP1242AG-A-K9   00:24:c4:a0:e3:68  default location  LAG   US       1         none

    Thank you all for responding.  The PFE Blog post was very informative.  We looked at the Security Logs of the four DCs and the log size setting is set to 128 Meg (overwrite), which appears to only hold about 2 hours of data.  I did see the
    4723/4724 events in the logs, but we just don't have the history needed to see what made the change. 
    We believe this was a one-time occurrence.  We cannot hunt down any program that would have an internal script to reset a subset of users' passwords at 2:30 AM on a Wednesday.
    Could a DC time sync issue of some sort cause this, or a DC hiccup?  Any other ideas of how to search for the culprit?
    If this does happen again, I'm thinking we won't be able to track it again, unless somehow we catch it in the 2-3 hours that the DC security logs maintain information.  Since 128 Meg holds ~2-3 hours of data for our system, we would need to
    set it to ~1 Gig to catch 1 day's worth of auditing data.  Besides the security/auditing logs, are there other tools available to see who/what program reset a user's password?
    My boss has asked the following question.  I believe the answer is yes, but this seemed like a good place to ask it anyway.  Is there any way a hacker could replicate the problem to programmatically change a bunch of accounts to log in with them
    or otherwise gain access?
    Thanks for your help.  April

  • Read receipts in Messages for Mac appear to be incorrect.

    My outgoing messages to a friend are getting marked Read instead of staying as Delivered.  I am certain that he does not have Read receipts on.
    After some testing, it seems that it is my reading the messages on my iPhone that is triggering the Read receipt.

    Hi,
    At present there is not a specific feedback point for Messages
    http://www.apple.com/feedback/
    I am only seeing "delivered" on IM in Messages (although sometimes the Phone has them)
    The "Delivered" never appears on both.
    Neither my son or myself have the "read" function ON in the settings on our phones.
    7:56 PM      Saturday; February 18, 2012
    Please, if posting Logs, do not post any Log info after the line "Binary Images for iChat"
      iMac 2.5Ghz 5i 2011 (Lion 10.7.3)
     G4/1GhzDual MDD (Leopard 10.5.8)
     MacBookPro 2Gb (Snow Leopard 10.6.8)
     Mac OS X (10.6.8),
    "Limit the Logs to the Bits above Binary Images."  No, Seriously

  • System Management Homepage Versions on Support Site appear to be incorrect

    The site states that 7.3.2 is the new version that addresses the Heartbleed Vulnerbility, but when you go to download that one it states the link doesn't exist.  When you download the 7.2.3 version it says it was released on April 14th 2014. 
    http://h18013.www1.hp.com/products/servers/management/agents/

    Thank you for your reply!  As it turns out, this wasn't related to a permissions issue at all -- it had to do with some corrupted content that was transferred via the migration tool.  The corrupt files were removed, the page was refreshed, and
    lo and behold it started working again.
    Another thing I tried but didn't work out for me was:
    http://www.savtechsol.com/Education/BeckysBlog/Lists/Posts/Post.aspx?ID=174 

  • Incorrect logical system name for datasources - entry not in TADIR

    Hi all,
    I currently can't replicate or edit any of my data sources because, after we applied some patches, the logical system name appears to be incorrect and a message is displayed saying the R3TR RSDS entry does not exist in table TADIR.
    For example:
    Object directory entry R3TR RSDS 0EMPLOYEE_0016_ATTR           R3DEV does not exist.
    That's correct, because all entries exist for my actual source system CD1CLNT175, not for SAP standard R3DEV.
    Does anybody have any idea how I can update my source system configuration/mapping? I've looked on the forum but couldn't
    find a clear cut answer.
    Thanks a lot!
    Markus

    Hi all,
    I think the solution lies in SAP note 1604726 "DataSources with package assignment cannot be activated"
    1. When you access the change transaction RSDS, the system issues error message TK 753 "Object directory entry R3TR ... does not exist" twice.
    2. When you try to activate the DataSource, the system issues error message TK 425 "Invalid call sequence for interfaces when recording changes".
    My message is TK753.. and before that I receive TK425, I guess we have to apply SP28... time for Mario and Luigi to apply some pizzas... ehmm patches...!
    I will let you know if that solved the problem, thanks for your help guys!
    Markus

  • I downloaded a application to my iphone5, however when i open the application i receive a message stating that my device clock apperars to be incorrect as a result you may experience problems using this application. How do i fix this issue?

    Im trying to watch a show but because of this message its not allowing me to do so. Again the error message im receiving is " Your device's clock appears to be incorrect as a result you ,ay experince problems using this application" how do i resolve this issue?

    If there are problems with updating or with the permissions then best is to download the full version and trash the currently installed version to do a clean install of the new version.
    Download a new copy of the Firefox application and save the disk image file to the desktop
    *Firefox 26.0: http://www.mozilla.org/en-US/firefox/all.html
    *Trash the current Firefox application (open the Applications folder in the Finder and drag the Firefox application to the Trash) to do a clean (re-)install
    *Install the new version that you have downloaded
    *https://support.mozilla.org/kb/Installing+Firefox+on+Mac
    Your personal data is stored elsewhere in the Firefox profile folder, so you won't lose your bookmarks and other personal data when you uninstall and (re)install Firefox.
    *http://kb.mozillazine.org/Profile_folder_-_Firefox

  • BUG: Info panel displays incorrect Hue values

    Recently, I've been doing a lot of work with color in Fireworks and came across the following bug, which appears to be a longstanding issue within the application. Rather than keeping it to myself, I figured I'd post it here in addition to submitting a bug report with Adobe. So here it is...
    Hue values displayed within the Info panel (in HSB mode) do not consistently match the values displayed in the Color Mixer panel—including basic colors such as pure Yellow, Cyan, and Magenta. The values are 1 degree off—most often below the Color Mixer value, but sometimes above (as with Magenta). This holds true whether using with the Eyedropper tool or the Color Picker swatches eyedropper, and whether sampling from the canvas or from swatches.
    For example, the following inconsistencies were observed when sampling the centermost horizontal strip within CS6's default Color Cubes swatches picker. Note that over 50% of these colors are affected by the issue.
    The Color Mixer seems to display the correct values, while the Info panel's values appear to be incorrect. Note that this issue affects the HSB mode only; the RGB and Hex values are consistent between both panels.
    This bug has been observed in Fireworks CS6, Fireworks CS5.1 and Fireworks 8 on Mac OS 10.6.8 (Snow Leopard).
    Here's the bug report submitted for this issue:
    Product name: Fireworks
    Product Version: 12.0.0.236
    Product Language: English
    Your operating system: Mac OS 10.6.8 (Intel-based)
    ******BUG******
    Concise problem statement: The Info panel displays incorrect Hue values for many colors—including pure Yellow, Cyan, and Magenta. The Hue values are usually 1 degree below the value displayed in the Color Mixer panel (e.g., 59 instead of 60 for Yellow) but sometimes 1 degree above (e.g., 301 instead of 300 for Magenta). This is true whether using the Eyedropper tool or the Color Picker swatches eyedropper, and whether sampling from the canvas or from swatches.
    Steps to reproduce bug:
    In an open Fireworks document, open the Info, Color Mixer, and Swatches panels. Within the Color Mixer and Info panels, set the color mode to HSB.
    Draw a Rectangle and set its fill to Yellow (#FFFF00) using the Color Picker.
    Observe the Hue values displayed in the Color Mixer and Info panels.
    Select the Eyedropper (I) tool, and sample the rectangle's fill color. Again, observe the Hue values displayed in both the Color Mixer and Info panels.
    Results: In both steps 3 and 4, the Hue value for pure Yellow (#ffff00) appears as 60 degrees in the Color Mixer panel but 59 degrees in the Info panel.
    Expected results: The Hue for pure Yellow (#ffff00) should appear as 60 degrees in both panels.
    Note that this issue affects the Info panel's HSB mode only; the RGB and Hex values are consistent between panels. Also note that this bug affects over 50% of the "pure" hues within CS6's Color Cubes swatches palette. For more info, see the following forum post:
    http://forums.adobe.com/thread/1083391
    This bug has been observed in Fireworks CS6, CS5.1 and FW8 on Mac OS 10.6.8 (Snow Leopard).

    I haven't done anything other than add my footage to the timeline. I have 2 layers (1 targa seq and 1 png seq). As I move my mouse from the Timeline to the Comp Panel, the color values flash for a split second and go away. If I press Opt+1 (2, 3, and 4) the Info Panel displays the color for that one pixel but the values go blank as soon as I move my mouse. This happens in the Comp Panel mostly. If I open a Footage or Layer Panel, sometimes the values show, sometimes not. Never had this issue in previous versions.

  • SAPDB in status STOPPED INCORRECTLY due to file system failure

    Hi community,
    we have a problem with our SAPDB server.
    The file system on which the whole database is installed disappeared form the list of filesystem mounted because of hardware problems,  the database instances crashed. Now the problem should be technically solved, the filesystem is mounted again and files should be not corrupted
    The first problem was to start the x server, If I tried to start it replied with the following error:
    en950_GetProgramExecPath failed:
    OS_ERROR  0: No system errortext for ERRNO 0
    RTE_ERROR 1: Open Registry:No such file or directoryIndepPrograms
    I resolved the problem looking at the file in directory /var/spool/sql/ini and changing the extensions of two files:
    SAP_DBTech.ini from Registry_dcom.ini.cnt01
    SAP_DBTech.ini from SAP_DBTech.ini.cnt01
    Now the x server starts correctly, but the state of the 2 SAPDB instances appears as STOPPED INCORRECTLY
    My questions:
    - Why the configuration files had that (wrong) extension ?
    - What is the correct procedure to try to start the instances in this case?
    Regards, Valerio

    > The file system on which the whole database is installed disappeared form the list of filesystem mounted because of hardware problems,  the database instances crashed. Now the problem should be technically solved, the filesystem is mounted again and files should be not corrupted
    SHOULD is the keyword of the last sentence!
    > The first problem was to start the x server, If I tried to start it replied with the following error:
    >
    >
    en950_GetProgramExecPath failed:
    > OS_ERROR  0: No system errortext for ERRNO 0
    > RTE_ERROR 1: Open Registry:No such file or directoryIndepPrograms
    >
    > I resolved the problem looking at the file in directory /var/spool/sql/ini and changing the extensions of two files:
    >
    > SAP_DBTech.ini from Registry_dcom.ini.cnt01
    > SAP_DBTech.ini from SAP_DBTech.ini.cnt01
    Hmm... one thing is for sure: the MaxDB software does not rename these files!
    > Now the x server starts correctly, but the state of the 2 SAPDB instances appears as STOPPED INCORRECTLY
    Did you had a look into the KNLDIAG files?
    > My questions:
    > - Why the configuration files had that (wrong) extension ?
    No idea? Storage/Filesystem issue?
    Bad user?
    > - What is the correct procedure to try to start the instances in this case?
    Depending on how much is broken here... reinstall the software from scratch and either re-register the instances or perform a restore and recovery of them.
    regards,
    Lars

  • Safari incorrectly caches window.setTimeout in setTimeout loop

    I submitted an Apple bug report for this issue, but I wanted to post it to a public forum in case others have experienced this issue. It appears that Safari incorrectly caches the value of window.setTimeout (and does not respect new values to which it is set) if it exceeds a certain number of executions in a setTimeout loop. It's probably best shown through an example.
    To reproduce, create an HTML page with the following content, and open it in Safari with the JavaScript console open:
    <!DOCTYPE html>
    <script>
    var MAX_RETRY = 99;
    var count = 0;
    function retry() {
      console.log('retry called');
      if (count++ < MAX_RETRY) {
        window.setTimeout(retry, 10);
      } else if (next) {
        next();
    var next = function() {
      next = null;
      window.setTimeout = function() {
        console.log('fake set timeout called');
      count = 0;
      console.log('second retry attempts');
      retry();
    console.log('first retry attempts');
    retry();
    </script>
    All browsers except Safari correctly output the following to the JS log:
    first retry attempts
    retry called (100 times)
    second retry attempts
    retry called
    fake set timeout called
    Safari does not respect the reassignment of window.setTimeout after it has executed in the setTimeout loop too many times. It instead outputs the following:
    first retry attempts
    retry called (100 times)
    second retry attempts
    retry called (100 times)
    If you decrease the value of MAX_RETRY enough, Safari will eventually respect the new value of window.setTimeout. On Safari 6.0.5, MAX_RETRY seemingly has to be <= 8. On earlier versions of Safari, it has to be even lower.

    Thanks for the info! Very useful to not become crazy while debugging it

  • 30gb video ipod showing incorrect storage capacity

    Hi,
    I have a 30gb ipod. When I connect the ipod & open itunes or ipod updater, the ipod appears with an incorrect storage capacity.
    The updater shows all other information correctly, except for Capacity, which shows at 65.0GB
    With nothing on the ipod, Itunes shows used: 4.49GB, free: 58.99GB. If I try to transfer any files I get a message saying that there is not enough free space to transfer the files.
    I have restored to factory settings, re-installing all software, changing usb ports etc but nothing seems to have helped...
    Any suggestions would be greatly appreciated!
    Thanks,
    Matt.
      Windows XP  

    How about this?
    http://docs.info.apple.com/article.html?artnum=93499

  • Caption labels do not appear on correct photo in print contact sheet

    I have created a 6 photo contact sheet and wish to have the caption field appear as a label below each photo in the grid.  The 1st photo went ok,  2nd photo accepted caption but appeared on the incorrect photo when moved from library to print view.  I have deleted the captions and reentered them and still incorrect.

    Try closing LR and then reopen. If the problem persists post a screenshot in the Print module with captions on all six pictures and explain what's wrong.

  • I keep getting "Login Failure Incorrect Sync Key". What do I do?

    I have have username and password with Firefox. I have installed sync on home computer and have obtained sync key. I have installed Home on my iPhone. When I open Home, it provides code. I enter code in to Add A Device page on home computer. It says device successfully added. When I press Done on home computer, message on iPhone appears "Login Failure Incorrect Sync Key". I live in Sweden. What do I need to do to make this work? Thanks, Tosh

    An upgrade of Firefox Home came through the itunes store and "lo and behold" it all works now albeit the interface is somewhat different to the desktop version. but at least all the bookmarks are there. Hope those who shared the same problem get it rectified.
    Regards to you all.

  • Incorrect dates in Moments

    I have recently synced quite a few photos, old and new, onto my iPad (iOS 7.1.2) using iTunes (11.3.0.54) on my Windows 7 machine and not all, but some photos are appearing in Moments under the wrong date.
    After checking (and changing if needed) the Date Taken, Date Created, Date Modified and Date Accessed for the photos and the folder each group of photos are in, some are still appearing under the incorrect date.

    photo_journ wrote:
    Oh that's brilliant. Thanks very much. Worked like a charm.
    Does that indicate any other underlying problem with the user account?
    no. just some minor corruption in the preference file with the date settings. we deleted it and it was recreated from scratch with default values.
    I just tried loading some CDs that were burnt on an older PowerBook Pro and the Macbook Pro wont read any of them -- all the same brand. Other brands it reads fine so I'm wondering if the dates might issue might indicate an underlying problem?
    this is quite unrelated to the date issue. it could be a bad CD brand - can easily happen with some cheap ones. or there could be something wrong with the burner on the powerbook. can you read those CDs on other computers?
    I left this open in case you have any more information you would like to add - even about the fix for the dates. Otherwise feel free to close it.
    as the thread starter you are the only person one who can close this thread.
    Thanks again. It was annoying.
    John

  • How do I correct an incorrect but embedded Apple ID in order to be able to access the App Store?

    I recently installed Yosemite 10.10.1 in my iMac,  Upon receiving notice of upgrades available I attempted to access via the App Store as required.  I was directed to enter my :Apple ID and password;  however, an ID was already entered and it was not mine.  Any attempt I made to highlight and correct the ID failed - it was unresponsive.  I attempted to use management of my account to verify the correct ID;  the file showed my correct ID but when I attempted again to log in to the App Store the same incorrect and immutable ID appeared. The incorrect ID is that of my wife for her OS 10.6.8 laptop.

    1. Triple-click anywhere in the line of text below on this page to select it:
    kMDItemAppStoreHasReceipt=1
    Copy the selected text to the Clipboard by pressing the key combination command-C.
    2. In the Finder, press command-F to open a search window, or select
              File ▹ Find
    from the menu bar. In the search window, select
              Search: This Mac
    from the row of tokens below the toolbar. Below that is a popup menu of search criteria, initially showing Kind. From that menu, select
              Other...
    A sheet will drop down. In that sheet, select
              Raw Query
    as the criterion, then click OK or press return.
    Now there will be a text box to the right of the menu of search criteria. That's where you enter the raw search query. Click in that box and paste the text you copied earlier by pressing command-V.
    3. The search window will now show all the App Store products that are installed. Compare those search results with the list of your purchases from the App Store. To see the complete list, you may need to unhide hidden purchases. If any apps were download from the App Store using other Apple ID accounts that you control, sign in to the store under each of those ID's and check the purchases.
    4. At least one of the apps in the Spotlight search results is not among your purchases in the App Store. Move each such item to the Trash, after quitting it if it's running. You may be prompted for your administrator password. Empty the Trash.
    5. Quit and relaunch the App Store. Test.
    If you find these instructions confusing, ask for an alternative method.

Maybe you are looking for