I have a Windows Server 2022 server with IPBAN installed to make hacking it more difficult but in the logs occasionally I see:

2023-02-20 03:59:23.5304|WARN|IPBan|Login succeeded, address: XX.XXX.XXX.XXX, user name: ANONYMOUS LOGON, source: RDP

I've been searching and found that this is most likely harmless is this correct?

Also how do I replicate and prevent these logins?

  • Did you even bother to check the logs on the target host?
    – Greg Askew
    Feb 20 at 6:15
  • This is from the target host... Feb 20 at 6:59
  • I'm referring to the security logs. That have information about authentication.
    – Greg Askew
    Feb 20 at 12:05


You must log in to answer this question.

Browse other questions tagged .