Re: Internet password attacks

From: Russell Stevens (rustyprogrammer_at_online.nospam)
Date: 08/25/05


Date: Thu, 25 Aug 2005 15:00:09 -0400

Microsoft refuses to fix this glaring problem in SQL 2000. You can use a
port monitor to get the IP numbers then block them with a firewall or use
IPsec to block the IP numbers. It is a never ending job as new drones will
be attacking every day.

Microsoft's reply is that you shouldn't be doing this. Of course, they will
be glad to sell you a copy of SQL Server 2005 that does fix this (non)
problem.

With a strong password, the attackers will never be successful, but they can
eat up a lot of bandwidth trying.

Russ Stevens



Relevant Pages

  • Re: Stumped - Level 16 error terminates stored proc
    ... without this fix. ... (The fix claims to be for all levels of SQL Server 2000, ... Capture Error 1222 ... why is it terminating the stored procedure and not allowing me to handle the ...
    (microsoft.public.sqlserver.server)
  • Re: if statement comparing variable
    ... the sql ... designers code so that i could restrict which section to show. ... statement to select my desired section or created a new stored sql to do ... how often this page would actually be used, I just wanted a quick fix. ...
    (microsoft.public.inetserver.asp.general)
  • Re: MS03-031 issue
    ... I tried the workaround (set the passwords from another SQL) but am ... Back out the hot fix or apply another fix? ... >> A supported fix is now available from Microsoft, ... call Microsoft Product Support Services so that the ...
    (microsoft.public.sqlserver.security)
  • Re: Controlling System Messages
    ... Microsoft has a "move server" tool that will fix the URL in SQL ... "Approaching SharePoint Web site storage limit", ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Sql insert Question
    ... What you are seeing is a classic example of a vulnerability to a SQL ... Obviously you want to fix this here, ... If your database doesn't support parameterized stored procedures or you ... quote with two single quotes (not double quotes but literally two ...
    (microsoft.public.dotnet.framework.aspnet)