Re: Internet password attacks

From: Rob R. Ainscough (robains_at_pacbell.net)
Date: 08/25/05


Date: Thu, 25 Aug 2005 12:22:11 -0700

So you can confirm SQL 2005 does address this issue? Do you have details on
how?

I have port 1433 and 1434 open also going thru a Virtual IP, so far no
attacks.

"Russell Stevens" <rustyprogrammer@online.nospam> wrote in message
news:um$43caqFHA.3524@tk2msftngp13.phx.gbl...
> Microsoft refuses to fix this glaring problem in SQL 2000. You can use a
> port monitor to get the IP numbers then block them with a firewall or use
> IPsec to block the IP numbers. It is a never ending job as new drones will
> be attacking every day.
>
> Microsoft's reply is that you shouldn't be doing this. Of course, they
> will be glad to sell you a copy of SQL Server 2005 that does fix this
> (non) problem.
>
> With a strong password, the attackers will never be successful, but they
> can eat up a lot of bandwidth trying.
>
> Russ Stevens
>
>



Relevant Pages

  • Is there any reason to use port 1433?
    ... I am new to SQL security. ... Some days ago I happened to open my event log and found lots of attacks have ... I changed the SQL server port from 1433 to ...
    (microsoft.public.sqlserver.security)
  • Re: SQL DBA Client
    ... What is required depends on how you expose your SQL... ... measures you should consider are changing the port number ... you're using and using a User account with minimal ... Enterprise Manager accordingly (configuring the Client ...
    (microsoft.public.windows.server.sbs)
  • Re: Merge replication in SQL Server
    ... However, port 443 is for https, did you want your SQL ... Configuring an instance of SQL Server to use a static port ... you can script out replication jobs by right clicking on a publication ...
    (microsoft.public.sqlserver.replication)
  • RE: MS SQL, find list of tables
    ... connected to the Access ODBC driver. ... MS SQL, find list of tables ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping carts, forms, ...
    (Pen-Test)
  • Re: SQL Server Password Cracker/Guesser
    ... >> Can anyone tell me what they are using to crack/guess SQL Server ... >> Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping carts, forms, ... Cross site scripting and other web attacks before hackers ...
    (Pen-Test)