SQL tracing

From: Dave (isp-lists@beachcomp.com)
Date: 04/06/03

  • Next message: panth3r: "Re: Iptables Clues and Advices."
    From: "Dave" <isp-lists@beachcomp.com>
    To: <isp-lists@beachcomp.com>
    Date: Sat, 5 Apr 2003 17:40:04 -0500
    
    

    Hi all,

    Running SQL 7 on a 2000 system.
    It seems someone is anxious to login. I'm seeing numerous back to back
    failed logins for sa, admin and user into the SQL master database.

    Is there a way to trace any of this? Being that it's 7.0, running
    profiler cant get remote machine name or info.
    I know this would be very simply using a firewall log, but that assumes
    ones colo center knows what they're doing, and I'm finding out quickly
    that despite an impressive sales pitch, they don't.

    So, is there any software solution? Is there any logs I'm overlooking?
    How can I trace who it is?
    Do you know of any software that will simply keep detailed logs
    regarding access on a certain port?

    Thanks in advance for your help.

    Dave

    PS.. I understand you may have the urge to blast the email with why I'm
    running an open SQL server.... However, at this time, I have no choice
    but to do it until some contracts expire. Thanks for the concern though.
    :-)

    -------------------------------------------------------------------
    SurfControl E-mail Filter puts the brakes on spam,
    viruses and malicious code. Safeguard your business
    critical communications. Download a free 30-day trial:
    http://www.securityfocus.com/SurfControl-security-basics


  • Next message: panth3r: "Re: Iptables Clues and Advices."

    Relevant Pages

    • Re: testing vulnerable web application.
      ... You should be able to just open up your logs and look for things that are out of the ordinary. ... Keep your database and all but double check it to make sure there really aren't accounts and what not that should not be there. ... We assumed the attacker was using some sort of SQL injection to alter the DB records or possibly he can craft a SQL query in a way that will create an admin account to use to simply log in and alter the records and then delete his username...NO rogue admin accounts have ever been found. ... You have an option to go with a managed service or an enterprise software. ...
      (Pen-Test)
    • Re: Unable to start SQL SERVER service for a SQL EXPRESS instance.
      ... Event Viewer, as you directed), so that's what that said. ... As for the SQL Error Log, there don't appear to be ANY logs. ... Now, it won't install completely. ...
      (microsoft.public.sqlserver.clients)
    • Re: Getting Started - RAID, Multiple Instances, SQL 2000-2005 . . .
      ... SQL 2000 Std. ... Data and Logs on RAID 5 partition ... Planning to put OS on RAID 1 partition, logs on different RAID 1 partition, ...
      (microsoft.public.sqlserver.setup)
    • Re: Does NTBackup backup SQL Express?
      ... In which case I assume the logs do NOT get flushed so this is not an option ... as I know enough that the logs must be flushed during every full backup. ... and the SBS server I regularly use runs MySQL not SQL ... I've always scripted my SQL Server backups separatly. ...
      (microsoft.public.windows.server.sbs)
    • Re: Tracing Web service calls
      ... Message logs. ... I beleive IBM have created such a tool for their web service ... No SQL database blocking. ...
      (microsoft.public.dotnet.framework.aspnet)