我想弄清楚爲什麼失敗的遠程桌面連接(從Windows遠程桌面)顯示客戶端IP地址作爲連字符。這裏是事件日誌中我得到我的賬號輸入錯誤密碼(服務器是完全外我家的電腦):IP地址在事件日誌中顯示爲連接失敗的遠程桌面連字符
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
<EventID>4625</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>12544</Task>
<Opcode>0</Opcode>
<Keywords>0x8010000000000000</Keywords>
<TimeCreated SystemTime="2012-03-25T19:22:14.694177500Z" />
<EventRecordID>1658501</EventRecordID>
<Correlation />
<Execution ProcessID="544" ThreadID="12880" />
<Channel>Security</Channel>
<Computer>[Delete for Security Purposes]</Computer>
<Security />
</System>
<EventData>
<Data Name="SubjectUserSid">S-1-0-0</Data>
<Data Name="SubjectUserName">-</Data>
<Data Name="SubjectDomainName">-</Data>
<Data Name="SubjectLogonId">0x0</Data>
<Data Name="TargetUserSid">S-1-0-0</Data>
<Data Name="TargetUserName">[Delete for Security Purposes]</Data>
<Data Name="TargetDomainName">[Delete for Security Purposes]</Data>
<Data Name="Status">0xc000006d</Data>
<Data Name="FailureReason">%%2313</Data>
<Data Name="SubStatus">0xc000006a</Data>
<Data Name="LogonType">3</Data>
<Data Name="LogonProcessName">NtLmSsp </Data>
<Data Name="AuthenticationPackageName">NTLM</Data>
<Data Name="WorkstationName">MyComputer</Data>
<Data Name="TransmittedServices">-</Data>
<Data Name="LmPackageName">-</Data>
<Data Name="KeyLength">0</Data>
<Data Name="ProcessId">0x0</Data>
<Data Name="ProcessName">-</Data>
<Data Name="IpAddress">-</Data>
<Data Name="IpPort">-</Data>
</EventData>
</Event>
在網上發現什麼,我試圖阻止終端服務攻擊。任何見解表示讚賞,我已經幾個小時seraching後,在網上找到什麼......
[Event Logging IPAddress does not always resolve]的可能重複(http://stackoverflow.com/questions/1734635/event-logging-ipaddress-does-not-always-resolve) – jjxtra 2012-03-25 19:38:56