<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic OneAgent v1.277.165 on Win Srv 2019 v1809 generates thousands of logins to 445 SMB in Open Q&amp;A</title>
    <link>https://community.dynatrace.com/t5/Open-Q-A/OneAgent-v1-277-165-on-Win-Srv-2019-v1809-generates-thousands-of/m-p/230378#M29868</link>
    <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;On a Windows box A (&lt;SPAN&gt;Windows Server 2019 Version 1809 OS Build 17763.5122&lt;/SPAN&gt;), we upgraded OneAgent from&amp;nbsp;&lt;SPAN&gt;1.271.135.20230810-115019 to 1.277.165.20231024-150054 : we get thousands of network attempted logins from box A, with many local technical users, and many Active Directory recently connected users, to many Windows&amp;nbsp; targets machines on port 445 (SMB). Some times thousands per minute. Also toward Unix boxes. It is not constant. Happens some times for hour, sometime&amp;nbsp;for minutes. It triggers alerts here. And stopped us to deploy this version on the parc.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When we stop or rollback OneAgent : no problem any more.&lt;BR /&gt;We tried intermédiate version :&amp;nbsp;1.275.146.20231002-095820 : looks like no problem in that case.&lt;BR /&gt;We also tried latest OA version :&amp;nbsp;1.277.196 : same problem.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Looks like brute force attack. Maybe attempting vulnerabilities exploit ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any one exposed to that ? Any known solutions ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;--&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Tickets ref:&lt;BR /&gt;Dynatrace:&amp;nbsp;250650&lt;BR /&gt;Private internal: Jira&amp;nbsp;DEVOPS-15019&lt;/P&gt;</description>
    <pubDate>Thu, 30 Nov 2023 08:58:03 GMT</pubDate>
    <dc:creator>gilles_tabary</dc:creator>
    <dc:date>2023-11-30T08:58:03Z</dc:date>
    <item>
      <title>OneAgent v1.277.165 on Win Srv 2019 v1809 generates thousands of logins to 445 SMB</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/OneAgent-v1-277-165-on-Win-Srv-2019-v1809-generates-thousands-of/m-p/230378#M29868</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;On a Windows box A (&lt;SPAN&gt;Windows Server 2019 Version 1809 OS Build 17763.5122&lt;/SPAN&gt;), we upgraded OneAgent from&amp;nbsp;&lt;SPAN&gt;1.271.135.20230810-115019 to 1.277.165.20231024-150054 : we get thousands of network attempted logins from box A, with many local technical users, and many Active Directory recently connected users, to many Windows&amp;nbsp; targets machines on port 445 (SMB). Some times thousands per minute. Also toward Unix boxes. It is not constant. Happens some times for hour, sometime&amp;nbsp;for minutes. It triggers alerts here. And stopped us to deploy this version on the parc.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When we stop or rollback OneAgent : no problem any more.&lt;BR /&gt;We tried intermédiate version :&amp;nbsp;1.275.146.20231002-095820 : looks like no problem in that case.&lt;BR /&gt;We also tried latest OA version :&amp;nbsp;1.277.196 : same problem.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Looks like brute force attack. Maybe attempting vulnerabilities exploit ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any one exposed to that ? Any known solutions ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;--&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Tickets ref:&lt;BR /&gt;Dynatrace:&amp;nbsp;250650&lt;BR /&gt;Private internal: Jira&amp;nbsp;DEVOPS-15019&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 08:58:03 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/OneAgent-v1-277-165-on-Win-Srv-2019-v1809-generates-thousands-of/m-p/230378#M29868</guid>
      <dc:creator>gilles_tabary</dc:creator>
      <dc:date>2023-11-30T08:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: OneAgent v1.277.165 on Win Srv 2019 v1809 generates thousands of logins to 445 SMB</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/OneAgent-v1-277-165-on-Win-Srv-2019-v1809-generates-thousands-of/m-p/237232#M31095</link>
      <description>&lt;P&gt;Turns out&lt;/P&gt;&lt;P&gt;- it can be mitigated by excluding network disk monitoring&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="java"&gt;Operating system: 'Windows', name: ''\\*\*'
Operating system: 'Windows', name: '\\*'&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- support says "we found a bug"&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2024 12:08:57 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/OneAgent-v1-277-165-on-Win-Srv-2019-v1809-generates-thousands-of/m-p/237232#M31095</guid>
      <dc:creator>gilles_tabary</dc:creator>
      <dc:date>2024-02-15T12:08:57Z</dc:date>
    </item>
  </channel>
</rss>

