Windows OS
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
 
User Name:
Password:
Remember me
Go Back   ASP Free ForumsSystem AdministrationWindows OS

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread ASP Free Forums Sponsor:
  #1  
Old June 24th, 2005, 10:50 AM
RadioactiveFrog's Avatar
RadioactiveFrog RadioactiveFrog is offline
Senior Glowing Wizard
ASP Free God 7th Plane (8000 - 8499 posts)
 
Join Date: May 2005
Location: Sussex
Posts: 8,203 RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)  Folding Points: 156364 Folding Title: Super Ultimate Folder - Level 1Folding Points: 156364 Folding Title: Super Ultimate Folder - Level 1Folding Points: 156364 Folding Title: Super Ultimate Folder - Level 1Folding Points: 156364 Folding Title: Super Ultimate Folder - Level 1Folding Points: 156364 Folding Title: Super Ultimate Folder - Level 1Folding Points: 156364 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 3 Weeks 4 Days 39 m 12 sec
Reputation Power: 291
Send a message via MSN to RadioactiveFrog
Facebook
logging access to the shared files of winserver2k3

hey all,

i am learning to run winserv2k3 and i have some shared files on the network. It is a workgroup not a domian. When the user chooses to view all network computers and double clicks on the server icon they are prompted for a username and password. Is there a way of checking the details of the access that is attempted?

cheeres

RF

Reply With Quote
  #2  
Old June 25th, 2005, 03:58 PM
edwinbrains's Avatar
edwinbrains edwinbrains is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Mar 2004
Location: UK
Posts: 140 edwinbrains User rank is Private First Class (20 - 50 Reputation Level)edwinbrains User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 8 h 44 m 10 sec
Reputation Power: 5
If you enable auditing (Local Security Policy > Local Policies > Audit Policies) you should be able to see both success and failure logins. The page below gives details of the different things you can audit:

http://channels.lockergnome.com/it/..._auditing.phtml

Reply With Quote
  #3  
Old June 25th, 2005, 04:23 PM
RadioactiveFrog's Avatar
RadioactiveFrog RadioactiveFrog is offline
Senior Glowing Wizard
ASP Free God 7th Plane (8000 - 8499 posts)
 
Join Date: May 2005
Location: Sussex
Posts: 8,203 RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)  Folding Points: 156364 Folding Title: Super Ultimate Folder - Level 1Folding Points: 156364 Folding Title: Super Ultimate Folder - Level 1Folding Points: 156364 Folding Title: Super Ultimate Folder - Level 1Folding Points: 156364 Folding Title: Super Ultimate Folder - Level 1Folding Points: 156364 Folding Title: Super Ultimate Folder - Level 1Folding Points: 156364 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 3 Weeks 4 Days 39 m 12 sec
Reputation Power: 291
Send a message via MSN to RadioactiveFrog
Facebook
Quote:
Originally Posted by edwinbrains
If you enable auditing (Local Security Policy > Local Policies > Audit Policies) you should be able to see both success and failure logins. The page below gives details of the different things you can audit:

http://channels.lockergnome.com/it/..._auditing.phtml

stunning, thanks edwin, i will have a crack when i am next home.

Reply With Quote
  #4  
Old July 3rd, 2005, 04:00 PM
oneMSBi's Avatar
oneMSBi oneMSBi is offline
Caution:Loderator Moose !
ASP Free Newbie (0 - 499 posts)
 
Join Date: May 2005
Location: India
Posts: 235 oneMSBi User rank is Corporal (100 - 500 Reputation Level)oneMSBi User rank is Corporal (100 - 500 Reputation Level)oneMSBi User rank is Corporal (100 - 500 Reputation Level)oneMSBi User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 1 Day 22 h 49 m 43 sec
Reputation Power: 6
ummm... once you set the correct policies to enable the logging of user access you can use a script like this to check the logs for just entries related to user access. Mind you i have provided a general VBScript and its up to you to modify it to your needs

Code:
' This code displays events in an Event Log.
' ---------------------------------------------------------------

' ------ SCRIPT CONFIGURATION ------
strLog = "<LogName>"       ' e.g. 'Application' or 'Security' or 'System'
intNum = <intMax>          ' e.g. 50  (Max number of events to display)
strServer = "<ServerName>" ' e.g. put your server name here (use "." for local server)
' ------ END CONFIGURATION ---------

' These constants are taken from WbemFlagEnum
const wbemFlagReturnImmediately = 16
const wbemFlagForwardOnly = 32

' i use this first part to determine how many events are in the log

set objWMI = GetObject("winmgmts:\\" & strServer & "\root\cimv2")
set colLogs = objWMI.ExecQuery("Select * from Win32_NTEventlogFile " & _
              "Where Logfilename = '" & strLog & "'",, _
              wbemFlagReturnImmediately + wbemFlagForwardOnly)
if colLogs.Count > 1 then
   WScript.Echo "Fatal error.  Number of logs found: " & colLogs.Count
   WScript.Quit
end if
for each objLog in colLogs
   intLogMax = objLog.NumberofRecords
next

if intLogMax > intNum then
   intNum = intLogMax - intNum
else
   intNum = intLogMax
end if

' Now I get all of the events up to total of intNum

set colEvents = objWMI.ExecQuery("Select * from Win32_NTLogEvent " & _
                "Where Logfile = '" & strLog & "' and RecordNumber >= " & _
                intNum,,wbemFlagReturnImmediately + wbemFlagForwardOnly)
for each objEvent in colEvents
   Wscript.Echo "Date: " & objEvent.TimeWritten
   Wscript.Echo "Source: " & objEvent.SourceName
   Wscript.Echo "Category: " & objEvent.Category
   Wscript.Echo "Type: " & objEvent.Type
   Wscript.Echo "Event Code: " & objEvent.EventCode
   Wscript.Echo "User: " & objEvent.User
   Wscript.Echo "Computer: " & objEvent.ComputerName
   Wscript.Echo "Message: " & objEvent.Message
   WScript.Echo "------"
next


or you can make little custom scripts to do specific tasks like
Code:
' This code prints the last logon timestamp for a user.
' ---------------------------------------------------------------

' ------ SCRIPT CONFIGURATION ------
strUserDN = "<UserDN>"  ' e.g. cn=david,ou=soccer,dc=davidbeckham,dc=com
' ------ END CONFIGURATION ---------

set objUser = GetObject("LDAP://" & strUserDN)
set objLogon = objUser.Get("lastLogonTimestamp")
intLogonTime = objLogon.HighPart * (2^32) + objLogon.LowPart 
intLogonTime = intLogonTime / (60 * 10000000)
intLogonTime = intLogonTime / 1440
WScript.Echo "Approx last logon timestamp: " & intLogonTime + #1/1/1601#


cheers
Comments on this post
nofriends agrees!

Reply With Quote
  #5  
Old July 3rd, 2005, 04:41 PM
RadioactiveFrog's Avatar
RadioactiveFrog RadioactiveFrog is offline
Senior Glowing Wizard
ASP Free God 7th Plane (8000 - 8499 posts)
 
Join Date: May 2005
Location: Sussex
Posts: 8,203 RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)  Folding Points: 156364 Folding Title: Super Ultimate Folder - Level 1Folding Points: 156364 Folding Title: Super Ultimate Folder - Level 1Folding Points: 156364 Folding Title: Super Ultimate Folder - Level 1Folding Points: 156364 Folding Title: Super Ultimate Folder - Level 1Folding Points: 156364 Folding Title: Super Ultimate Folder - Level 1Folding Points: 156364 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 3 Weeks 4 Days 39 m 12 sec
Reputation Power: 291
Send a message via MSN to RadioactiveFrog
Facebook
cheers DB, that looks rather clever for me !!

Reply With Quote
  #6  
Old July 6th, 2005, 03:52 PM
oneMSBi's Avatar
oneMSBi oneMSBi is offline
Caution:Loderator Moose !
ASP Free Newbie (0 - 499 posts)
 
Join Date: May 2005
Location: India
Posts: 235 oneMSBi User rank is Corporal (100 - 500 Reputation Level)oneMSBi User rank is Corporal (100 - 500 Reputation Level)oneMSBi User rank is Corporal (100 - 500 Reputation Level)oneMSBi User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 1 Day 22 h 49 m 43 sec
Reputation Power: 6
oh ok.. but its atually quite simple.. anyways.. good luck

Reply With Quote
  #7  
Old July 7th, 2005, 03:33 AM
RadioactiveFrog's Avatar
RadioactiveFrog RadioactiveFrog is offline
Senior Glowing Wizard
ASP Free God 7th Plane (8000 - 8499 posts)
 
Join Date: May 2005
Location: Sussex
Posts: 8,203 RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)  Folding Points: 156364 Folding Title: Super Ultimate Folder - Level 1Folding Points: 156364 Folding Title: Super Ultimate Folder - Level 1Folding Points: 156364 Folding Title: Super Ultimate Folder - Level 1Folding Points: 156364 Folding Title: Super Ultimate Folder - Level 1Folding Points: 156364 Folding Title: Super Ultimate Folder - Level 1Folding Points: 156364 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 3 Weeks 4 Days 39 m 12 sec
Reputation Power: 291
Send a message via MSN to RadioactiveFrog
Facebook
Quote:
Originally Posted by David Beckham
oh ok.. but its atually quite simple.. anyways.. good luck


cheers,

the event logging that edwin suggested works well for me!! For now anyway. I might wanna do more with it later but one step at a time!!

Reply With Quote
Reply

Viewing: ASP Free ForumsSystem AdministrationWindows OS > logging access to the shared files of winserver2k3


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 2 hosted by Hostway