Re: Too many sa failed logins




"John Dalberg" <johnd@xxxxxxxxxxxx> wrote in message
news:xz07aent6ftr.1g83xxhvdhwdi$.dlg@xxxxxxxxxxxxx
>
> The event log is showing a ton of failed sa logins. The server is
> connected
> to the net. I am assuming this is a dictionary attack to get the sa
> password. I am trying to find out if this is an inside attempt or from the
> outside. While the profiler will tell me which program or script is
> sending
> it, how do I find out which ip address(s) from the net is doing this?
>
>
> --
> John Dalberg

I don't have a real answer to your question, but exposing a database server
directly to the internet is somewhat unusual - can you use a VPN or some
other OS-level mechanism to prevent direct connections? Profiler can capture
some information about a failed login, but since the hostname and
application name can be set by the client, you can't trust the information
anyway. The best option for monitoring attempted connections would be at the
OS or network level - if a client doesn't authenticate with MSSQL, then the
database server has no good way to get information about it.

Simon


.



Relevant Pages

  • Re: Network intermittently dropping the connection to shared files on server
    ... what we were using with our SBS2000 server with no problems. ... It's a small Server plus 4 Client W/S set up in one office. ... All users that have current connections to the shared files are ... We have a small network < 5 clients connected to a new Dell ...
    (microsoft.public.windows.server.sbs)
  • Re: TCP server stop receiving new connections
    ... reset the event mask of your listening socket each time you ... I have a strange problem in my class library used by all our client ... server applications. ... incomming connections, but keeps current connections. ...
    (microsoft.public.win32.programmer.networks)
  • Re: RTC remoting > Explained in 11 minutes
    ... transport components for connections between clients and servers. ... server response but also server request (to client) -> client response) ... handed off to the different attached plugin command handlers which have ...
    (borland.public.delphi.thirdpartytools.general)
  • Re: Network intermittently dropping the connection to shared files on server
    ... ISA Server detected routes through adapter Loopback that do not correlate ... It's a small Server plus 4 Client W/S set up in one office. ... All users that have current connections to the shared files are ... We have a small network < 5 clients connected to a new Dell ...
    (microsoft.public.windows.server.sbs)
  • Re: CSocket question
    ... client for some reason disconnects. ... server checks for idle time there can easily be 5-30 connections that are ... connections were actively sending data. ...
    (microsoft.public.win32.programmer.networks)