Access Denied: Detecting PPTP Attacks on Remote Access Servers
Learn how to determine if an attacker is trying to access your RAS server by guessing usernames and passwords.
August 17, 2003
How can I detect attacks on my remote access server through PPTP? I want to know when someone is trying to guess usernames and passwords, and I haven't found any events in the Security log that clearly identify this situation.
Check your System log for event ID 20189 (The user Administrator connected from x.x.x.x. but failed an authentication attempt due to the following reason: There was an authentication failure because of an unknown user name or a bad password). As Figure 1 shows, event ID 20189 comes from RAS and provides the username specified by the possible attacker as well as the attacker's IP address, which might help you track attackers and report them to their ISP.
About the Author
You May Also Like