jnuts said:
Do you have any kind of VPN access at work?
What about dudes that hookup laptops to your wired network?
We have one VPN setup. A dedicate link between one specific server in our office and one at one of our clients offices.
That connection so far has never been used except during setup (I monitor it).
There are three laptops in our office - now four with my new laptop. I own two of the laptops, and another Mac guy has one, and then a new guy has a Windows machine.
While he is a major pain in my ass, he isn't the issue since he is very new and the problems have been there since before I have.
The domains that they are failing on are legit domains of companies in town. We are on a frame relay system - I don't know if they are also on a frame relay system and perhaps also go through our provider.
The security logs show it as if someone was in our domain and trying to log into a different domain - but they aren't hacking (or if they are, they are the most retarded hackers I've ever seen).
It looks exactly as if I brought in a machine and tried to log in to one domain with a machine setup as another.
Except these machines are not physically in our office. It is a small enough office that I can be sure of that.
Very bizzarre - and some of the machines are servers.
Our firewall blocks pretty much everything - for a bit we had an RDC port open that directed to our primary domain controller. I shut that off since I don't have a static IP.
In the logs for our firewall, it knows that it is supposed to only allow a fixed range of IPs to use it - but it will still sometimes show that one of our highest bandwidth users is some IP that is a different domain.
The whole thing is making me feel stupid and makes everyone else tell me that it is impossible... which is what I've been saying all along - but I also have the logs that say otherwise.