Jump to content

'SA' attack on Windows Server


Tanmaya
 Share

Recommended Posts

Hi All,

New to windowsforum.org, It has helped me a lot in all types of queries, Now I have faced new problem under MSSQL Server 2005, I have Windows 2003 Standard Server with MSSQL 2005 Server, I have observed that, frequently Server gets SA login failure attempts, I have used IPSEC policy for blocking these IPs :angry: , but I have to do it manually every time. So my question is, Is there automated script or option available to block these IPs only for the SA attack and not for any other ports.

Regards,

Tanmaya. :rolleyes:

Link to comment
Share on other sites

Thanks for prompt reply.

I have installed MSSQL 2005 with latest patch and also under Firewall I have allowed 1433 port to access DBs remotely. But the scenario is, as 1433 port is open for remote connection, Hacker tries to connect through this port and increases network load on the Server, I keep blocking these IPs periodically, but its very annoying task for everyday.

So I am looking for the solution which will help me to either block these IPs only for 1433 or for 3 to 4 failure attempts, some custom script/program block the next login attempt from that IP for some specific period of time.

Waiting for valuable suggestion. :flowers:

Link to comment
Share on other sites

  • 4 weeks later...

Hi,

After long fight with this 'SA' attack, I have reached to some conclusion, which helped me to protect the Server from this attack,

1) Implemented IPSec policy, its OK, that I have to enter IP addresses manually to block them.

2) I have disabled Remote access for the MSSQL Databases, so whenever I have to administrate database, I need to login to RDP of the Server.

3) Removed TCP/IP & Named pipe connection for the databases, allowed only localhost connection.

Still its annoying to make it secured, but Ok. Achieved some bit of security for it. :flowers:

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy