ΠΡΠ΅ΠΊΠΈ, ΠΊΠΎΠΉΡΠΎ ΡΠ΅ Π΅ ΠΎΠΏΠΈΡΠ²Π°Π» Π΄Π° ΡΡΠ°ΡΡΠΈΡΠ° Π²ΠΈΡΡΡΠ°Π»Π½Π° ΠΌΠ°ΡΠΈΠ½Π° Π² ΠΎΠ±Π»Π°ΠΊΠ°, Π΅ Π΄ΠΎΠ±ΡΠ΅ Π½Π°ΡΡΠ½ΠΎ, ΡΠ΅ ΡΡΠ°Π½Π΄Π°ΡΡΠ΅Π½ RDP ΠΏΠΎΡΡ, Π°ΠΊΠΎ Π±ΡΠ΄Π΅ ΠΎΡΡΠ°Π²Π΅Π½ ΠΎΡΠ²ΠΎΡΠ΅Π½, ΠΏΠΎΡΡΠΈ Π²Π΅Π΄Π½Π°Π³Π° ΡΠ΅ Π±ΡΠ΄Π΅ Π°ΡΠ°ΠΊΡΠ²Π°Π½ ΠΎΡ Π²ΡΠ»Π½ΠΈ ΠΎΡ Π³ΡΡΠ±ΠΈ ΠΎΠΏΠΈΡΠΈ Π·Π° ΠΏΠ°ΡΠΎΠ»Π° ΠΎΡ ΡΠ°Π·Π»ΠΈΡΠ½ΠΈ IP Π°Π΄ΡΠ΅ΡΠΈ ΠΏΠΎ ΡΠ΅Π»ΠΈΡ ΡΠ²ΡΡ.
Π ΡΠ°Π·ΠΈ ΡΡΠ°ΡΠΈΡ ΡΠ΅ ΠΏΠΎΠΊΠ°ΠΆΠ° ΠΊΠ°ΠΊ Π΄Π°
Π Quest InTrust ΠΌΠΎΠΆΠ΅ΡΠ΅ Π΄Π° ΠΊΠΎΠ½ΡΠΈΠ³ΡΡΠΈΡΠ°ΡΠ΅ Π΄Π΅ΠΉΡΡΠ²ΠΈΡ Π·Π° ΠΎΡΠ³ΠΎΠ²ΠΎΡ, ΠΊΠΎΠ³Π°ΡΠΎ ΡΠ΅ Π·Π°Π΄Π΅ΠΉΡΡΠ²Π° ΠΏΡΠ°Π²ΠΈΠ»ΠΎ. ΠΡ Π°Π³Π΅Π½ΡΠ° Π·Π° ΡΡΠ±ΠΈΡΠ°Π½Π΅ Π½Π° ΡΠ΅Π³ΠΈΡΡΡΠ°ΡΠΈΠΎΠ½Π½ΠΈ ΡΠ°ΠΉΠ»ΠΎΠ²Π΅ InTrust ΠΏΠΎΠ»ΡΡΠ°Π²Π° ΡΡΠΎΠ±ΡΠ΅Π½ΠΈΠ΅ Π·Π° Π½Π΅ΡΡΠΏΠ΅ΡΠ΅Π½ ΠΎΠΏΠΈΡ Π·Π° ΠΎΡΠΎΡΠΈΠ·Π°ΡΠΈΡ Π½Π° ΡΠ°Π±ΠΎΡΠ½Π° ΡΡΠ°Π½ΡΠΈΡ ΠΈΠ»ΠΈ ΡΡΡΠ²ΡΡ. ΠΠ° Π΄Π° ΠΊΠΎΠ½ΡΠΈΠ³ΡΡΠΈΡΠ°ΡΠ΅ Π΄ΠΎΠ±Π°Π²ΡΠ½Π΅ΡΠΎ Π½Π° Π½ΠΎΠ²ΠΈ IP Π°Π΄ΡΠ΅ΡΠΈ ΠΊΡΠΌ Π·Π°ΡΠΈΡΠ½Π°ΡΠ° ΡΡΠ΅Π½Π°, ΡΡΡΠ±Π²Π° Π΄Π° ΠΊΠΎΠΏΠΈΡΠ°ΡΠ΅ ΡΡΡΠ΅ΡΡΠ²ΡΠ²Π°ΡΠΎ ΠΏΠ΅ΡΡΠΎΠ½Π°Π»ΠΈΠ·ΠΈΡΠ°Π½ΠΎ ΠΏΡΠ°Π²ΠΈΠ»ΠΎ Π·Π° ΠΎΡΠΊΡΠΈΠ²Π°Π½Π΅ Π½Π° ΠΌΠ½ΠΎΠΆΠ΅ΡΡΠ²ΠΎ Π½Π΅ΡΡΠΏΠ΅ΡΠ½ΠΈ Π°Π²ΡΠΎΡΠΈΠ·Π°ΡΠΈΠΈ ΠΈ Π΄Π° ΠΎΡΠ²ΠΎΡΠΈΡΠ΅ ΠΊΠΎΠΏΠΈΠ΅ ΠΎΡ Π½Π΅Π³ΠΎ Π·Π° ΡΠ΅Π΄Π°ΠΊΡΠΈΡΠ°Π½Π΅:
Π‘ΡΠ±ΠΈΡΠΈΡΡΠ° Π² ΡΠ΅Π³ΠΈΡΡΡΠ°ΡΠΈΠΎΠ½Π½ΠΈΡΠ΅ ΡΠ°ΠΉΠ»ΠΎΠ²Π΅ Π½Π° Windows ΠΈΠ·ΠΏΠΎΠ»Π·Π²Π°Ρ Π½Π΅ΡΠΎ, Π½Π°ΡΠ΅ΡΠ΅Π½ΠΎ InsertionString.
ΠΡΠΎ ΠΊΠ°ΠΊ ΠΈΠ·Π³Π»Π΅ΠΆΠ΄Π° ΡΠ΅ΠΊΡΡΡΡ Π½Π° ΡΡΠ±ΠΈΡΠΈΠ΅ 4625:
An account failed to log on.
Subject:
Security ID: S-1-5-21-1135140816-2109348461-2107143693-500
Account Name: ALebovsky
Account Domain: LOGISTICS
Logon ID: 0x2a88a
Logon Type: 2
Account For Which Logon Failed:
Security ID: S-1-0-0
Account Name: Paul
Account Domain: LOGISTICS
Failure Information:
Failure Reason: Account locked out.
Status: 0xc0000234
Sub Status: 0x0
Process Information:
Caller Process ID: 0x3f8
Caller Process Name: C:WindowsSystem32svchost.exe
Network Information:
Workstation Name: DCC1
Source Network Address: ::1
Source Port: 0
Detailed Authentication Information:
Logon Process: seclogo
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
This event is generated when a logon request fails. It is generated on the computer where access was attempted.
The Subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
The Logon Type field indicates the kind of logon that was requested. The most common types are 2 (interactive) and 3 (network).
The Process Information fields indicate which account and process on the system requested the logon.
The Network Information fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
The authentication information fields provide detailed information about this specific logon request.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
ΠΡΠ²Π΅Π½ ΡΠΎΠ²Π° ΡΠ΅ Π΄ΠΎΠ±Π°Π²ΠΈΠΌ ΡΡΠΎΠΉΠ½ΠΎΡΡΡΠ° Π½Π° ΠΌΡΠ΅ΠΆΠΎΠ²ΠΈΡ Π°Π΄ΡΠ΅Ρ Π½Π° ΠΈΠ·ΡΠΎΡΠ½ΠΈΠΊΠ° ΠΊΡΠΌ ΡΠ΅ΠΊΡΡΠ° Π½Π° ΡΡΠ±ΠΈΡΠΈΠ΅ΡΠΎ.
Π‘Π»Π΅Π΄ ΡΠΎΠ²Π° ΡΡΡΠ±Π²Π° Π΄Π° Π΄ΠΎΠ±Π°Π²ΠΈΡΠ΅ ΡΠΊΡΠΈΠΏΡ, ΠΊΠΎΠΉΡΠΎ ΡΠ΅ Π±Π»ΠΎΠΊΠΈΡΠ° IP Π°Π΄ΡΠ΅ΡΠ° Π² Π·Π°ΡΠΈΡΠ½Π°ΡΠ° ΡΡΠ΅Π½Π° Π½Π° Windows. ΠΠΎ-Π΄ΠΎΠ»Ρ Π΅ Π΄Π°Π΄Π΅Π½ ΠΏΡΠΈΠΌΠ΅Ρ, ΠΊΠΎΠΉΡΠΎ ΠΌΠΎΠΆΠ΅ Π΄Π° ΡΠ΅ ΠΈΠ·ΠΏΠΎΠ»Π·Π²Π° Π·Π° ΡΠΎΠ²Π°.
Π‘ΠΊΡΠΈΠΏΡ Π·Π° Π½Π°ΡΡΡΠΎΠΉΠΊΠ° Π½Π° Π·Π°ΡΠΈΡΠ½Π° ΡΡΠ΅Π½Π°
param(
[Parameter(Mandatory = $true)]
[ValidateNotNullOrEmpty()]
[string]
$SourceAddress
)
$SourceAddress = $SourceAddress.Trim()
$ErrorActionPreference = 'Stop'
$ruleName = 'Quest-InTrust-Block-Failed-Logons'
$ruleDisplayName = 'Quest InTrust: Blocks IP addresses from failed logons'
function Get-BlockedIps {
(Get-NetFirewallRule -Name $ruleName -ErrorAction SilentlyContinue | get-netfirewalladdressfilter).RemoteAddress
}
$blockedIps = Get-BlockedIps
$allIps = [array]$SourceAddress + [array]$blockedIps | Select-Object -Unique | Sort-Object
if (Get-NetFirewallRule -Name $ruleName -ErrorAction SilentlyContinue) {
Set-NetFirewallRule -Name $ruleName -RemoteAddress $allIps
} else {
New-NetFirewallRule -Name $ruleName -DisplayName $ruleDisplayName -Direction Inbound -Action Block -RemoteAddress $allIps
}
Π‘Π΅Π³Π° ΠΌΠΎΠΆΠ΅ΡΠ΅ Π΄Π° ΠΏΡΠΎΠΌΠ΅Π½ΠΈΡΠ΅ ΠΈΠΌΠ΅ΡΠΎ ΠΈ ΠΎΠΏΠΈΡΠ°Π½ΠΈΠ΅ΡΠΎ Π½Π° ΠΏΡΠ°Π²ΠΈΠ»ΠΎΡΠΎ, Π·Π° Π΄Π° ΠΈΠ·Π±Π΅Π³Π½Π΅ΡΠ΅ ΠΎΠ±ΡΡΠΊΠ²Π°Π½Π΅ ΠΏΠΎ-ΠΊΡΡΠ½ΠΎ.
Π‘Π΅Π³Π° ΡΡΡΠ±Π²Π° Π΄Π° Π΄ΠΎΠ±Π°Π²ΠΈΡΠ΅ ΡΠΎΠ·ΠΈ ΡΠΊΡΠΈΠΏΡ ΠΊΠ°ΡΠΎ ΠΎΡΠ³ΠΎΠ²ΠΎΡ Π½Π° ΠΏΡΠ°Π²ΠΈΠ»ΠΎΡΠΎ, Π΄Π° Π°ΠΊΡΠΈΠ²ΠΈΡΠ°ΡΠ΅ ΠΏΡΠ°Π²ΠΈΠ»ΠΎΡΠΎ ΠΈ Π΄Π° ΡΠ΅ ΡΠ²Π΅ΡΠΈΡΠ΅, ΡΠ΅ ΡΡΠΎΡΠ²Π΅ΡΠ½ΠΎΡΠΎ ΠΏΡΠ°Π²ΠΈΠ»ΠΎ Π΅ Π°ΠΊΡΠΈΠ²ΠΈΡΠ°Π½ΠΎ Π² ΠΏΠΎΠ»ΠΈΡΠΈΠΊΠ°ΡΠ° Π·Π° Π½Π°Π±Π»ΡΠ΄Π΅Π½ΠΈΠ΅ Π² ΡΠ΅Π°Π»Π½ΠΎ Π²ΡΠ΅ΠΌΠ΅. ΠΠ³Π΅Π½ΡΡΡ ΡΡΡΠ±Π²Π° Π΄Π° Π±ΡΠ΄Π΅ Π°ΠΊΡΠΈΠ²ΠΈΡΠ°Π½ Π΄Π° ΠΈΠ·ΠΏΡΠ»Π½ΡΠ²Π° ΡΠΊΡΠΈΠΏΡ Π·Π° ΠΎΡΠ³ΠΎΠ²ΠΎΡ ΠΈ ΡΡΡΠ±Π²Π° Π΄Π° ΠΈΠΌΠ° ΠΏΠΎΡΠΎΡΠ΅Π½ΠΈΡ ΠΏΡΠ°Π²ΠΈΠ»Π΅Π½ ΠΏΠ°ΡΠ°ΠΌΠ΅ΡΡΡ.
Π‘Π»Π΅Π΄ ΠΏΡΠΈΠΊΠ»ΡΡΠ²Π°Π½Π΅ Π½Π° Π½Π°ΡΡΡΠΎΠΉΠΊΠΈΡΠ΅ Π±ΡΠΎΡΡ Π½Π° Π½Π΅ΡΡΠΏΠ΅ΡΠ½ΠΈΡΠ΅ Π°Π²ΡΠΎΡΠΈΠ·Π°ΡΠΈΠΈ Π½Π°ΠΌΠ°Π»Ρ Ρ 80%. ΠΏΠ΅ΡΠ°Π»Π±Π°? ΠΠ°ΠΊΡΠ² ΡΡΡΠ°Ρ
ΠΎΡΠ΅Π½!
ΠΠΎΠ½ΡΠΊΠΎΠ³Π° ΠΎΡΠ½ΠΎΠ²ΠΎ ΡΠ΅ ΠΏΠΎΡΠ²ΡΠ²Π° ΠΌΠ°Π»ΠΊΠΎ ΡΠ²Π΅Π»ΠΈΡΠ΅Π½ΠΈΠ΅, Π½ΠΎ ΡΠΎΠ²Π° ΡΠ΅ Π΄ΡΠ»ΠΆΠΈ Π½Π° ΠΏΠΎΡΠ²Π°ΡΠ° Π½Π° Π½ΠΎΠ²ΠΈ ΠΈΠ·ΡΠΎΡΠ½ΠΈΡΠΈ Π½Π° Π°ΡΠ°ΠΊΠ°. Π‘Π»Π΅Π΄ ΡΠΎΠ²Π° Π²ΡΠΈΡΠΊΠΎ ΠΎΡΠ½ΠΎΠ²ΠΎ Π·Π°ΠΏΠΎΡΠ²Π° Π΄Π° Π·Π°ΠΏΠ°Π΄Π°.
Π ΡΠ΅ΡΠ΅Π½ΠΈΠ΅ Π½Π° Π΅Π΄Π½Π° ΡΠ΅Π΄ΠΌΠΈΡΠ° ΡΠ°Π±ΠΎΡΠ° ΠΊΡΠΌ ΠΏΡΠ°Π²ΠΈΠ»ΠΎΡΠΎ Π½Π° Π·Π°ΡΠΈΡΠ½Π°ΡΠ° ΡΡΠ΅Π½Π° Π±ΡΡ Π° Π΄ΠΎΠ±Π°Π²Π΅Π½ΠΈ 66 IP Π°Π΄ΡΠ΅ΡΠ°.
ΠΠΎ-Π΄ΠΎΠ»Ρ Π΅ Π΄Π°Π΄Π΅Π½Π° ΡΠ°Π±Π»ΠΈΡΠ° Ρ 10 ΡΠ΅ΡΡΠΎ ΡΡΠ΅ΡΠ°Π½ΠΈ ΠΏΠΎΡΡΠ΅Π±ΠΈΡΠ΅Π»ΡΠΊΠΈ ΠΈΠΌΠ΅Π½Π°, ΠΈΠ·ΠΏΠΎΠ»Π·Π²Π°Π½ΠΈ Π·Π° ΠΎΠΏΠΈΡΠΈ Π·Π° Π°Π²ΡΠΎΡΠΈΠ·Π°ΡΠΈΡ.
ΠΠΎΡΡΠ΅Π±ΠΈΡΠ΅Π»ΡΠΊΠΎ ΠΈΠΌΠ΅
ΠΡΠΎΠΉ
Π ΠΏΡΠΎΡΠ΅Π½ΡΠΈ
Π°Π΄ΠΌΠΈΠ½ΠΈΡΡΡΠ°ΡΠΎΡ
1220235
40.78
Π°Π΄ΠΌΠΈΠ½ΠΈΡΡΡΠ°ΡΠΎΡ
672109
22.46
ΠΏΠΎΡΡΠ΅Π±ΠΈΡΠ΅Π»
219870
7.35
contoso
126088
4.21
contoso.com
73048
2.44
Π°Π΄ΠΌΠΈΠ½ΠΈΡΡΡΠ°ΡΠΎΡ
55319
1.85
ΡΡΡΠ²ΡΡ
39403
1.32
sgazlabdc01.contoso.com
32177
1.08
administrateur
32377
1.08
sgazlabdc01
31259
1.04
ΠΠ°ΠΆΠ΅ΡΠ΅ Π½ΠΈ Π² ΠΊΠΎΠΌΠ΅Π½ΡΠ°ΡΠΈΡΠ΅ ΠΊΠ°ΠΊ ΡΠ΅Π°Π³ΠΈΡΠ°ΡΠ΅ Π½Π° Π·Π°ΠΏΠ»Π°Ρ ΠΈ Π·Π° ΠΈΠ½ΡΠΎΡΠΌΠ°ΡΠΈΠΎΠ½Π½Π°ΡΠ° ΡΠΈΠ³ΡΡΠ½ΠΎΡΡ. ΠΠ°ΠΊΠ²Π° ΡΠΈΡΡΠ΅ΠΌΠ° ΠΈΠ·ΠΏΠΎΠ»Π·Π²Π°ΡΠ΅ ΠΈ ΠΊΠΎΠ»ΠΊΠΎ Π΅ ΡΠ΄ΠΎΠ±Π½Π°?
ΠΠΊΠΎ ΡΠ΅ ΠΈΠ½ΡΠ΅ΡΠ΅ΡΡΠ²Π°ΡΠ΅ Π΄Π° Π²ΠΈΠ΄ΠΈΡΠ΅ InTrust Π² Π΄Π΅ΠΉΡΡΠ²ΠΈΠ΅,
ΠΡΠΎΡΠ΅ΡΠ΅ΡΠ΅ Π΄ΡΡΠ³ΠΈΡΠ΅ Π½ΠΈ ΡΡΠ°ΡΠΈΠΈ Π·Π° ΠΈΠ½ΡΠΎΡΠΌΠ°ΡΠΈΠΎΠ½Π½Π° ΡΠΈΠ³ΡΡΠ½ΠΎΡΡ:
ΠΠ·ΡΠΎΡΠ½ΠΈΠΊ: www.habr.com