[Dshield] Event ID 2025 (denial of service attack attempt) multipletime in the event log of the affected server
Esler, Joel - Contractor
joel.esler at rcert-s.army.mil
Tue Oct 12 16:50:56 GMT 2004
Do you have a tcpdump or a Snort output of the traffic?
Joel Esler, GCIA
From: list-bounces at lists.dshield.org
[mailto:list-bounces at lists.dshield.org] On Behalf Of Velis, Alain
Sent: Tuesday, October 12, 2004 11:58 AM
To: 'list at lists.dshield.org'
Subject: [Dshield] Event ID 2025 (denial of service attack attempt)
multipletime in the event log of the affected server
We have been seeing something very strange in the past 2 days.
We have been experiencing heavy latency on our Microsoft file & print
The only thing that sticks out is the event logs: Event ID 2025 (denial
of service attack attempt) multiple time in the event log of the
We have been seeing it on NT4 and W2K3
Any helps will be appreciated!
DShield and the Internet Storm Center are sponsored by the SANS
Institute. To learn more about current SANS training, see
send all posts to list at lists.dshield.org
To change your subscription options (or unsubscribe), see:
More information about the list