Re: sa loginname being hacked

From: helmut woess (hw_at_iis.at)
Date: 10/16/05

  • Next message: Pipo: "Re: sa loginname being hacked"
    Date: Sun, 16 Oct 2005 19:36:34 +0200
    
    

    Am Sun, 16 Oct 2005 18:41:40 +0200 schrieb Pipo:

    > Yes, we did. We know one of their IPs and blocked it...
    > But they are using now another IP (IPnumber 9 and 3 different domains
    > also!!...:-<)
    > It takes a lot of work every time blocking another IP of theirs....
    > So the easy thing for us is to just simply(??) change the sa loginname into
    > something else.
    > But I guess that's not possible??
    > We cant change our Domain name or SQL server name also...!!
    > Why cant I change the sa loginname???
    >
    > thanks for the help Joseph
    >
    > "Joseph Bittman MVP MCSD" <RyanBittman@msn.com> schreef in bericht
    > news:ukgdT5m0FHA.2884@TK2MSFTNGP09.phx.gbl...
    >> October 16, 2005
    >>
    >> Don't you have a router in place between the SQL Server and the outside
    >> world? Can't you trace where the packets are coming from and block that
    >> IP/Domain name?
    >>
    >> --
    >> Joseph Bittman
    >> Microsoft Certified Solution Developer
    >> Microsoft Most Valuable Professional -- DPM
    >>
    >> Web Site: http://71.39.42.23/
    >> Static IP
    >> "Pipo" <Pipo@home.com> wrote in message
    >> news:OAK3n%23l0FHA.560@TK2MSFTNGP12.phx.gbl...
    >>> Hi,
    >>>
    >>> Is there a way to change the sa as loginname?
    >>> At work we are getting haked by 'brut-force', every second we are beinbg
    >>> attacked with sa and a password.
    >>> It's a matter of time when the password will be hacked, so changing the
    >>> password isnt a solution.
    >>> If we also can change the sa loginname we will be better of.
    >>> Or is there something else we can do to prevent the hackers to get our sa
    >>> password?
    >>>
    >>> Many thanks
    >>>
    >>
    >>
    Is your traffic between clients and Server encrypted? If not they can find
    login and passwort in clear text in the traffic.
    I can highly recommend to use a simple VPN-Server and allow connections
    from outside only over VPN!

    bye, helmut


  • Next message: Pipo: "Re: sa loginname being hacked"

    Relevant Pages

    • Re: sa loginname being hacked
      ... We cant change our Domain name or SQL server name also...!! ... Why cant I change the sa loginname??? ... > Microsoft Certified Solution Developer ...
      (microsoft.public.sqlserver.security)
    • Re: sa loginname being hacked
      ... SQL Server they said EXACTLY the opposite of what you just said. ... > should have a web server or some other server in place to receive the ... >> We cant change our Domain name or SQL server name also...!! ... >> Why cant I change the sa loginname??? ...
      (microsoft.public.sqlserver.security)
    • Re: sa loginname being hacked
      ... SQL Server MVP ... > Thanks for the answer Helmut, but we cant do the VPN solution you suggest. ... > So changing the sa loginname will be a good place to start, ...
      (microsoft.public.sqlserver.security)
    • Re: sa loginname being hacked
      ... when SQL Server is configured for only Windows authentication. ... >>> So changing the sa loginname will be a good place to start, I cant ...
      (microsoft.public.sqlserver.security)
    • Re: SQL Profiler - Empty NTUserName
      ... The LoginName in my application is a SQL Server username. ... It gets displayed properly in the Trace. ... NTUserName is missing. ...
      (microsoft.public.sqlserver.tools)