Apparent Security violations recorded in Event Viewer

From: Pat Rogers (progers_at_kc.rr.com)
Date: 07/23/04


Date: Fri, 23 Jul 2004 11:11:03 -0700

I am receiving the following event in the event viewer. I
believe that it is from hackers trying to execute Sql
Statements against my Sql Server to gain access to my
website. I only have port 80 open via my firewall, so I'm
confused as to how they are getting in. Does anyone have
any suggestions?

Any help, ideas, suggestions would be greatly appreciated.

Pat Rogers

Event Type: Information
Event Source: ODBC Error (388221)
Event Category: None
Event ID: 0
Date: 7/21/2004
Time: 8:44:23 AM
User: N/A
Computer: P6-CR2-SVR
Description:
The description for Event ID ( 0 ) in Source ( ODBC Error
(388221) )
cannot be found. The local computer may not have the
necessary registry
information or message DLL files to display messages from
a remote
computer. The following information is part of the event:
Message Text:
=============
SQL Selected Record is invalid: - 00000.



Relevant Pages

  • strange errors in execute sql task
    ... while executing "execute sql" tasks. ... Incorrect syntax near "1" ... uninstalling & installing sql server didn't help. ...
    (microsoft.public.sqlserver.dts)
  • strange errors with dts and sql
    ... while executing "execute sql" tasks. ... Incorrect syntax near "1" ... uninstalling & installing sql server didn't help. ...
    (microsoft.public.sqlserver.server)
  • It doesnt work if it has begin ... end
    ... I have a variable in my SQL statement. ... Kris wrote: ... >> pass this into the Execute SQL Step as a ... >Allan Mitchell (Microsoft SQL Server MVP) ...
    (microsoft.public.sqlserver.dts)
  • Re: SQL Server - DB2 data transfer
    ... If you have IBM's ODBC drivers install on your SQL Server you can create a ... linked server to the AS/400 and use the OPENQUERY statement to execute sql ...
    (microsoft.public.sqlserver.server)
  • Re: Assistance with ASP Redirect Evertjan
    ... It is very dangerous to put a clientside string like ... Hackers can easily construct a string for http://mysite,com/db.asp?CD =... ... See: What is SQL Injection? ...
    (microsoft.public.inetserver.asp.general)