Re: Is there any way to prevent hacker trying to guess sa password?

From: helmut woess (hw_at_iis.at)
Date: 10/11/05


Date: Tue, 11 Oct 2005 20:30:36 +0200

Hi Rob,

I have the same situation, till now all my clients uses a fixed ip address
and my firewall is in stealth mode and talks only with privileged
addresses, so i had no attack till now on my SQL-Server, but in my next
project i have clients with dynamic addresses too.
So i am very interested in this article and hope for some tips.

In the moment i am trying to find out if VPN can help me.
Yes, the VPN Server can be attacked too. And there is no shelter against
DoS. But then this is handled (i hope very efficient) by the router and is
not stressing the SQL-Server or the valid connections.
The one and only really 100% save solution would be a leased circuit,
because: no connect to outside = no attack from outside ;-)
But this is to expensive for me.

bye,
Helmut



Relevant Pages

  • [NT] AOLs Instant Messaging Command Execution, HTML and JavaScript Injection Vulnerabilities
    ... Get your security news from a reliable source. ... AIM Pro is AOL's business-oriented version of AIM targeted for ... the vulnerable IM clients use an embedded Internet Explorer ... In particular this attack vector exposes workstations to: ...
    (Securiteam)
  • Re: ist das eine gute Idee?
    ... > Clients über das Internet auf den SQL-Server zugreifen. ... > ich dazu einen Server mit Win2000 und Outpost als Firewall drauf. ... Du hast einen SQL-Server, der bei dir steht und da sollen nur ... Beispielsweise ein VPN oder so etwas wie stunnel. ...
    (de.comp.security.firewall)
  • Re: "Heartbeats Implementierung"
    ... deinem fall ev. der sql-server) ein heartbeat per tcp/ip. ... das was du beschreibst mit dem sql-server und den mehreren threads sollte ja ... > Nun soll der Status saemtlicher Dienste abgefragt werden koennen, ... von allen Clients, auf denen der Dienst ...
    (microsoft.public.de.german.entwickler.dotnet.csharp)
  • RE: DDoS to microsoft sites
    ... sense that these are network aware. ... The primary difference between the two clients is that the first port scan I ... > - netbios (brute force attack on Administrator account) ... > connected to the Internet. ...
    (Incidents)
  • Re: Problem mit Netzwerksoftware
    ... verständlichen Umgebung und kannst Fehlfunktionen an den Clients ... SQL-Server eben, der von den Clients gefragt wird, ob er in der Tabelle XY ... Next by Date: ...
    (microsoft.public.de.german.windows.server.networking)