You are here: Re: Too many sa failed logins « MsSQL Server « IT news, forums, messages
Re: Too many sa failed logins

Posted by Simon Hayes on 08/05/05 02:04

"John Dalberg" <johnd@hotmail.com2> wrote in message
news:xz07aent6ftr.1g83xxhvdhwdi$.dlg@40tude.net...
>
> The event log is showing a ton of failed sa logins. The server is
> connected
> to the net. I am assuming this is a dictionary attack to get the sa
> password. I am trying to find out if this is an inside attempt or from the
> outside. While the profiler will tell me which program or script is
> sending
> it, how do I find out which ip address(s) from the net is doing this?
>
>
> --
> John Dalberg

I don't have a real answer to your question, but exposing a database server
directly to the internet is somewhat unusual - can you use a VPN or some
other OS-level mechanism to prevent direct connections? Profiler can capture
some information about a failed login, but since the hostname and
application name can be set by the client, you can't trust the information
anyway. The best option for monitoring attempted connections would be at the
OS or network level - if a client doesn't authenticate with MSSQL, then the
database server has no good way to get information about it.

Simon

 

Navigation:

[Reply to this message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация