Drop Table

Support Forum for database administrators and web based access to important newsgroups related to databases
Register on Database Support Forum Edit your profileCalendarFind other Database Support forum membersFrequently Asked QuestionsSearch this forum -> 
For Database admins: Free Database-related Magazines Now Free shipping to Texas


Post New Thread










Thread
Author

how can I log 'hackers' failed attempts to login w/ip
Hello, I have a db server that has to be open to the internet.. and I
get 'hackers' trying to login to sa/power all day.

The thing is, the connection is 'force encryption' , so I cannot sniff
the traffic.. and since these 'hackers' are using their own tools, I
cannot tell their client software to send me their IP. (I know i
canget their hostname via C2 audits)


So basically, how do I monitor for these things and how to auto block
IPs.


any ideas?


thanks
Leee


Report this thread to moderator Post Follow-up to this message
Old Post
trend
07-31-05 08:23 AM


Re: how can I log 'hackers' failed attempts to login w/ip
Hi

As well as changing the hostname they also probably falsifying their IP
address. If you really have to leave the database open to the internet, then
you may want to block unknow IP addresses at the firewall. You should also
make sure that you are not using the default ports.

Depending on what you are doing, you may want to consider using a web
service or some other interim application as the means to communicate with
your database, you can then keep a tighter control over who/what connects.

John

"trend" <trend42@hotmail-dot-com.no-spam.invalid> wrote in message
news:Ru- dncm8YPCz93HfRVn_vA@
giganews.com...
> Hello, I have a db server that has to be open to the internet.. and I
> get 'hackers' trying to login to sa/power all day.
>
> The thing is, the connection is 'force encryption' , so I cannot sniff
> the traffic.. and since these 'hackers' are using their own tools, I
> cannot tell their client software to send me their IP. (I know i
> canget their hostname via C2 audits)
>
>
> So basically, how do I monitor for these things and how to auto block
> IPs.
>
>
> any ideas?
>
>
> thanks
> Leee
>



Report this thread to moderator Post Follow-up to this message
Old Post
John Bell
07-31-05 08:23 AM


Sponsored Links





Last Thread Next Thread
Post New Thread

MS SQL Server archive

Show a Printable Version Email This Page to Someone! Receive updates to this thread
Microsoft SQL Server
Access database support
PostgreSQL Replication
SQL Server ODBC
FoxPro Support
PostgreSQL pgAdmin
SQL Server Clustering
MySQL ODBC
Web Applications with dBASE
SQL Server CE
MySQL++
Sybase Database Support
MS SQL Full Text Search
PostgreSQL Administration
SQL Anywhere support
DB2 UDB Database
Paradox Database Support
Filemaker Database
Berkley DB
SQL 2000/2000i database
ASE Database
Forum Jump:
All times are GMT. The time now is 11:05 AM.

 
Mobile devices forum | Database support forum archive




Copyrights DropTable.com Database Support Forum 2004 - 2006