Tracking the Inside Intruder Using Net Log on Debug Logging in Microsoft
Total Page:16
File Type:pdf, Size:1020Kb
This document was prepared in conjunction with work accomplished under Contract No. DE-AC09-96SR18500 with the U. S. Department of Energy. DISCLAIMER This report was prepared as an account of work sponsored by an agency of the United States Government. Neither the United States Government nor any agency thereof, nor any of their employees, makes any warranty, express or implied, or assumes any legal liability or responsibility for the accuracy, completeness, or usefulness of any information, apparatus, product or process disclosed, or represents that its use would not infringe privately owned rights. Reference herein to any specific commercial product, process or service by trade name, trademark, manufacturer, or otherwise does not necessarily constitute or imply its endorsement, recommendation, or favoring by the United States Government or any agency thereof. The views and opinions of authors expressed herein do not necessarily state or reflect those of the United States Government or any agency thereof. This report has been reproduced directly from the best available copy. Available for sale to the public, in paper, from: U.S. Department of Commerce, National Technical Information Service, 5285 Port Royal Road, Springfield, VA 22161, phone: (800) 553-6847, fax: (703) 605-6900 email: [email protected] online ordering: http://www.ntis.gov/help/index.asp Available electronically at http://www.osti.gov/bridge Available for a processing fee to U.S. Department of Energy and its contractors, in paper, from: U.S. Department of Energy, Office of Scientific and Technical Information, P.O. Box 62, Oak Ridge, TN 37831-0062, phone: (865)576-8401, fax: (865)576-5728 email: [email protected] WSRC-TR-2004-00011 Tracking the Inside Intruder Using Net Logon Debug Logging in Microsoft® Windows® Server Operating Systems Christina S. Davis Principle Engineer Westinghouse Savannah River Company Savannah River Site Aiken, South Carolina 29808 [email protected] ABSTRACT This paper discusses how to use Net Logon In today’s well-connected environments of debug logging to identify and track malicious the internet, intranets, and extranets, protecting user activity both in real-time and for forensic the Microsoft Windows network can be a analysis. daunting task for the security engineer. Intrusion Detection Systems are a must-have for most companies, but few have either the financial KEYWORDS resources or the people resources to implement and maintain full-scale intrusion detection systems for their networks and hosts. Many will Netlogon, Inside Intruder, Tracking, Windows® at least invest in intrusion detection for their Server 2003, Windows® 2000, Logon internet presence, but others have not yet stepped up to the plate with regard to internal intrusion detection. Unfortunately, most attacks will come from within. 1. Introduction Microsoft® Windows® networks are often Microsoft Windows server operating systems the target of malicious computer hacker activity. are widely used across both large and small While some companies invest in third party enterprises. Unfortunately, there is no intrusion intrusion detection systems, others cannot afford detection built-in to the Windows server them or do not have the people resources to operating system. The security logs are valuable manage them. They must rely on the native tools but can be difficult to manage even in a small to and features of Microsoft® Windows® Server medium sized environment. So the question 2003 and Windows® 2000, such as the security arises, can one effectively detect and identify an logs, to look for questionable activity. inside intruder using the native tools that come with Microsoft Windows Server operating systems? One such method is to use Net Logon While the security logs are useful, they can be Service debug logging to identify and track unwieldy even in a small to medium sized malicious user activity. domain. It can be difficult to obtain real-time WSRC-TR-2004-00011 data from the security logs. The security value by typing nltest /dbflag:0x20000004 at a engineer needs additional methods of identifying command prompt. malicious user activity. One such method is the built-in debug logging feature of the Net Logon Service. This paper discusses how to use Net Complete information on how to enable Net Logon Service debug logging to track suspicious Logon debugging and all of its associated flag user activity in Windows® Server 2003 and options can be found on the Microsoft® web site Windows® 2000 networks. It also discusses [2]. methods for refining the data obtained from the Net Logon debug logs. NOTE: When the netlogon.log file grows to 19Mb, it is copied to the file, 2. What is the Net Logon Debugging %systemroot%\debug\netlogon.bak, and a new Feature? netlogon.log file is created. You may consider backing up the netlogon.bak file each day and retaining the backups for a period so that you In order to understand debug logging for the will have some history if you need to track Net Logon Service, we must define the Net activity over a period. 120 days is a good period Logon Service. According to Microsoft®, the to retain logs. Net Logon Service is defined as “a user-mode service that runs in the Windows® security subsystem. The Net Logon service passes the 2.2. Contents of the Netlogon.log File user's credentials through a secure channel to the domain database and returns the domain security Let us examine the netlogon.log file with the identifiers and user rights for the user. In 0x20000004 debug option set (Table 1). addition, the Net Logon service performs a variety of other functions related to the user 12/09 07:11:10 [LOGON] SamLogon: logon process, such as periodic password Transitive Network logon of updates for computer accounts and domain MYDOMAIN\CONNIEH from \\JACK-SPRATT (via controller discovery.” [1] SERV3) Entered 12/09 07:11:10 [LOGON] SamLogon: Transitive Network logon of MYDOMAIN\CONNIEH from \\JACK-SPRATT (via 2.1. Enabling Net Logon Debugging SERV3) Returns 0x0 12/09 07:11:10 [LOGON] SamLogon: Transitive Network logon of The Net Logon Service maintains an activity MYDOMAIN\CONNIEH from \\JACK-SPRATT (via SERV3) Entered log on the server in the directory, 12/09 07:11:10 [LOGON] SamLogon: %systemroot%\debug\netlogon.log. By default, Transitive Network logon of MYDOMAIN\ANNJ the log is empty. However, if one has a need to from \\ANN-JONES (via SERV7) Entered troubleshoot net logon activity, such as why user 12/09 07:11:10 [LOGON] SamLogon: Transitive Network logon of accounts keep locking out for no apparent MYDOMAIN\CONNIEH from \\JACK-SPRATT (via reason, a debug value may be set in the registry SERV3) Returns 0x0 of the domain controllers, to begin capturing net 12/09 07:11:10 [LOGON] SamLogon: logon authentication data. We will use the debug Transitive Network logon of MYDOMAIN\ANNJ from \\ANN-JONES (via SERV7) Returns 0x0 log to track the intruder. Table 1: 0x20000004 Debug Option Set In our case, we wish to identify and track We see the type of logon (e.g. network or only the actual user logon activity, and so we interactive), the domain/workgroup name of the will set the debug value to 0x20000004. This user, the user name, the machine from which the will weed out extraneous information such as user is logging on, and the machine to which the Site location and other session information that user is attempting to connect. The code 0x0 we will not need for user tracking. We set this means the logon was successful. 2 WSRC-TR-2004-00011 2.3. Parsing the Netlogon Log WIN2KPRO\Administrator from WIN2KPRO (via BOSS) Returns 0xC0000064 01/28 16:16:20 [LOGON] SamLogon: Transitive Network logon of When looking for hacker activity, we want to WIN2KPRO\Administrator from WIN2KPRO (via look first for potential scanning activity. We BOSS) Returns 0xC0000064 will see a great deal of failed logon attempts due Table 2: Failed Logon Data to an unknown user name (code 0xC0000064) or bad password (code 0xC000006A) and in some cases, a clear footprint of the utility used to The activity is suspicious because the perform the scan (such as Nessus® or ISS®). WIN2KPRO machine is attempting to By issuing a simple findstr command at the authenticate over the network with many command prompt or from within a batch file, different computers using a pass-through of the one can extract only the failed attempts, such as built-in Administrator account. Because the those cases where an unknown user name WIN2KPRO machine is attempting attempted to authenticate. authentication to so many machines in such a short period and the failures are unknown account names, this could suggest the use of a findstr /I "0xC0000064" scanning tool. In this instance, it could be c:\winnt\debug\netlogon.log >> someone looking for blank or easily guessed d:\save\failed.txt passwords as an easy means to hack into computers on the network. Also in this instance, the Administrator account does not exist on the When we examine the output of the findstr target machines. It has been renamed. A similar command, we see that the local user search on bad password attempt (code “Administrator” on a machine named 0xC000006A) would yield even more data for WIN2KPRO has attempted to authenticate or machines that have not renamed the access many different machines within a few Administrator account but where the scan seconds (Table 2). attempted to use a bad password. 01/28 16:16:11 [LOGON] SamLogon: Using the findstr command to parse data, we Transitive Network logon of can obtain a clear view of some scanning WIN2KPRO\Administrator from WIN2KPRO (via utilities, such as Nessus® (Table 3). The data MYLAPTOP) Returns 0xC0000064 01/28 16:16:11 [LOGON] SamLogon: are suspicious because we have one machine Transitive Network logon of targeted by many user names and passwords in a WIN2KPRO\Administrator from WIN2KPRO (via short period.