Re: sa loginname being hacked

From: Pipo (Pipo_at_home.com)
Date: 10/16/05


Date: Sun, 16 Oct 2005 21:00:23 +0200

Thanks for the answer Helmut, but we cant do the VPN solution you suggest.
Yes, it is encrypted, they dont have the password yet!!!
But if we dont do anything about it they will get it.
For now we change the password every 5 minutes but we need more securit y.
So changing the sa loginname will be a good place to start, I cant figure
out why I cant change that loginname!!! (like in Oracle!!)
Or give the sa user no more rights and create my own 'sa'...:-s

But I guess that the security of SQL server isnt that good or I am
wrong?????

"helmut woess" <hw@iis.at> schreef in bericht
news:1jmjhgla30xw6.g3j5avfsyn1b.dlg@40tude.net...
> Am Sun, 16 Oct 2005 18:41:40 +0200 schrieb Pipo:
>
>> Yes, we did. We know one of their IPs and blocked it...
>> But they are using now another IP (IPnumber 9 and 3 different domains
>> also!!...:-<)
>> It takes a lot of work every time blocking another IP of theirs....
>> So the easy thing for us is to just simply(??) change the sa loginname
>> into
>> something else.
>> But I guess that's not possible??
>> We cant change our Domain name or SQL server name also...!!
>> Why cant I change the sa loginname???
>>
>> thanks for the help Joseph
>>
>> "Joseph Bittman MVP MCSD" <RyanBittman@msn.com> schreef in bericht
>> news:ukgdT5m0FHA.2884@TK2MSFTNGP09.phx.gbl...
>>> October 16, 2005
>>>
>>> Don't you have a router in place between the SQL Server and the outside
>>> world? Can't you trace where the packets are coming from and block that
>>> IP/Domain name?
>>>
>>> --
>>> Joseph Bittman
>>> Microsoft Certified Solution Developer
>>> Microsoft Most Valuable Professional -- DPM
>>>
>>> Web Site: http://71.39.42.23/
>>> Static IP
>>> "Pipo" <Pipo@home.com> wrote in message
>>> news:OAK3n%23l0FHA.560@TK2MSFTNGP12.phx.gbl...
>>>> Hi,
>>>>
>>>> Is there a way to change the sa as loginname?
>>>> At work we are getting haked by 'brut-force', every second we are
>>>> beinbg
>>>> attacked with sa and a password.
>>>> It's a matter of time when the password will be hacked, so changing the
>>>> password isnt a solution.
>>>> If we also can change the sa loginname we will be better of.
>>>> Or is there something else we can do to prevent the hackers to get our
>>>> sa
>>>> password?
>>>>
>>>> Many thanks
>>>>
>>>
>>>
> Is your traffic between clients and Server encrypted? If not they can find
> login and passwort in clear text in the traffic.
> I can highly recommend to use a simple VPN-Server and allow connections
> from outside only over VPN!
>
> bye, helmut



Relevant Pages

  • Re: sa loginname being hacked
    ... SQL Server MVP ... > Thanks for the answer Helmut, but we cant do the VPN solution you suggest. ... > So changing the sa loginname will be a good place to start, ...
    (microsoft.public.sqlserver.security)
  • Re: Condi Rice pulls a Nixon
    ... I simplified to ab\void getting the debate further bogged down, ... really saying "im scared" and you and he are scared to tolerate my ... you why it doesnt apply.Just dont ask about your moms sexlife unless ... Sure cant, as long as you guys are too scared to try me.Pussies. ...
    (rec.martial-arts)
  • Re: Isotope decay chains
    ... >> if you dont know the inner momentum of a single nucleid ... > And the HUP has not yet been falsified. ... (and there i sa whole world that you cant know from that principle- so ... Superfertz (as i undesstood you suport the Superfertz as well ...
    (sci.physics)
  • Re: monitor not vga compatible help
    ... > keyboard,I cant spell very well and it is taking me a long time to write ... > I dont think that what I wrote was so hard to understand but it was ... >>> compatible i dont have disc know that xp has this driver but i read ... >>> understand it it is a tft monitor proview i have been to the sight ...
    (microsoft.public.windowsxp.general)
  • Re: Seeds of Hatred---Reaping the Harvest
    ... I dont mean a big reduction in the price of beer, ... I cant believe in you. ... About god, ... Why do frost patterns form on a windowpane? ...
    (soc.retirement)