[Dshield] Event ID 2025 (denial of service attack attempt) multipletime in the event log of the affected server

Esler, Joel - Contractor joel.esler at rcert-s.army.mil
Tue Oct 12 16:50:56 GMT 2004


Do you have a tcpdump or a Snort output of the traffic?

Joel Esler, GCIA


-----Original Message-----
From: list-bounces at lists.dshield.org
[mailto:list-bounces at lists.dshield.org] On Behalf Of Velis, Alain
Sent: Tuesday, October 12, 2004 11:58 AM
To: 'list at lists.dshield.org'
Subject: [Dshield] Event ID 2025 (denial of service attack attempt)
multipletime in the event log of the affected server


Hello everyone,

 

We have been seeing something very strange in the past 2 days. 

We have been experiencing heavy latency on our Microsoft file & print
Servers.

 

The only thing that sticks out is the event logs: Event ID 2025 (denial
of service attack attempt) multiple time in the event log of the
affected server

 

We have been seeing it on NT4 and W2K3

 

 

Any helps will be appreciated!

 

Alain 

 

 

 

_______________________________________________
DShield and the Internet Storm Center are sponsored by the SANS
Institute. To learn more about current SANS training, see
http://www.sans.org .

_______________________________________________
send all posts to list at lists.dshield.org
To change your subscription options (or unsubscribe), see:
http://www.dshield.org/mailman/listinfo/list



More information about the list mailing list