1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

XP admin pwd changed. is there a log?

Discussion in 'Windows XP' started by wacky, 2006/10/04.

  1. 2006/10/04
    wacky

    wacky Inactive Thread Starter

    Joined:
    2006/10/04
    Messages:
    3
    Likes Received:
    0
    Hello all,
    I'm a network admin at a small private school (for 1 class period per day). Apparently some rougue student has found a way to change the local admin pwd. I've since disabled booting from CD, USB, and floppy. I've now installed a Bios password as well.
    Normally students log-in on our domain, but some savvy student figured a way around this. I logged in with a seperate account and changed the local admin password again.

    I wonder, is there a log that would detail when a specific admin password has changed? If it doesn't necessarily mention a pwd. change, then possibly some other event that might help me narrow down the field?
    If Windows has such a feature it would greatly help me in tracking down this student. What type of things should I be looking for in the event log?


    Thanks,
    Zach
     
  2. 2006/10/05
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    Configure Audit Policies from Administrative Tools > Local Security Settings.
     
    Arie,
    #2

  3. to hide this advert.

  4. 2006/10/05
    wacky

    wacky Inactive Thread Starter

    Joined:
    2006/10/04
    Messages:
    3
    Likes Received:
    0
    Thank You.
    That will definitley help in the future. Are there specific processes I might check that are already noted in the system eventlog or the application event log that might help me do some forensic work?

    Zach
     
  5. 2006/10/05
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    You mention Domain. Does the domain comp keep a log of who logged on when? That would narrow down the possible culprits.
     
  6. 2006/10/05
    wacky

    wacky Inactive Thread Starter

    Joined:
    2006/10/04
    Messages:
    3
    Likes Received:
    0
    I already have a list of possible suspects. I'm trying to nail it down to one of two class periods.
    Yes, the domain logs user access. I don't think the PWD was changed due to a login attempt, but rather a boot disk of some sort. That's why Bios pwd has been set and the machine will now only boot from the HDD.
    I don't believe the student actually logged into the domain, This was done to the local admin account. Does the domain keep logs of who logs in even on local computers?


     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.