Proventia Network IPS, RealSecure Desktop, RealSecure Desktop Protector 3.6, RealSecure Server Sensor, RealSecure Network, BlackICE Server Protection, BlackICE PC Protection, BlackICE Agent for Server, Proventia Network IDS, Proventia Desktop, Proventia-G 1.1 and earlier, IBM Security Server Protection for Windows, Proventia Network MFS, Virtual Server Protection for Vmware, Proventia Server IPS for Linux technology:
This security event is categorized as an audit event. It is not necessarily indicative of an attack or threat to your network. This signature reports access attempts to the NT Security Accounts Manager (SAM) Database Management Services using named pipes.
Medium
Proventia Network IPS: XPU 1.42, RealSecure Desktop: enz, RealSecure Desktop Protector 3.6: enz, RealSecure Server Sensor: XPU 23.2, RealSecure Network: XPU 23.2, BlackICE Server Protection: 3.6.cpa, BlackICE PC Protection: 3.6cpa, BlackICE Agent for Server: 3.6eof, Proventia Network IDS: XPU 23.2, Proventia Desktop: 8.0.614.1, Proventia-G 1.1 and earlier: XPU 23.2, IBM Security Server Protection for Windows: 2.1.14.2400, IBM Security Server Protection for Windows: 1.0.914.0, Proventia Network MFS: XPU 1.39, Virtual Server Protection for Vmware: 1.0, Proventia Server IPS for Linux technology: 1.0
Microsoft Windows NT: 4.0
Unauthorized Access Attempt
An attempt to access the NT Security Accounts Manager (SAM) Database Management Services using the PIPE/samr service has been detected. The PIPE/samr service allows remote management of the SAM Database on a server or a workstation. If a remote attacker accesses the SAM Database, the attacker can obtain sensitive information that is stored on the system.
This event is for informational purposes only.
Microsoft Knowledge Base Article - 155601
INFO: Understanding SAM Active Contexts Under Windows NT, Windows 2000, or Windows XP
http://support.microsoft.com/default.aspx?scid=kb;en-us;155601
ISS X-Force
NT SAM Database access detected using PIPE/samr service
http://www.iss.net/security_center/static/15653.php