Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other firewalls
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 21st, 2002, 11:28 PM
suzy software
 
Posts: n/a
Default Increase In Microsoft-SQL-Server Scans?

Has anyone else noticed an increase in Microsoft-SQL-Server scans while using Zone Alarm?

Over the past 3-4 days I've received a ton of inbound *Microsoft-SQL-Server scans.

What are they and why so many now?

I'm using Zone Alarm 2.6.88 and Visual Zone to read my logfiles.

Thanks for any info.
  #2  
Old May 21st, 2002, 11:38 PM
FanJ
 
Posts: n/a
Default Re: Increase In Microsoft-SQL-Server Scans?

Hi Suzy,

Welcome !

See also here, where was something posted about it:

http://www.security-pro.co.uk/yabb/YaBB.pl?board=osif;action=display;num=1022006809
  #3  
Old May 22nd, 2002, 01:18 AM
UNICRON's Avatar
UNICRON UNICRON is offline
Technical Expert
 
Join Date: Feb 2002
Location: Nanaimo BC Canada
Posts: 1,935
Default Re: Increase In Microsoft-SQL-Server Scans?

I just checked my router logs. Wow, what is normally an unrelenting sub7 port 27374 barrage is now a MS SQL Server barrage. 6 of one, Half doz of the other I guess. Seems like the amount of scans hasn't changed all that much. Makes me think the people who normally scan for sub7 have changed to SQL Server.

2 years ago it was an IIS vulnerability that gave away the sa password without argument. I had a lot of fun with that one.
__________________
Not every thing that can be counted counts, and not everything that counts can be counted.
  #4  
Old May 22nd, 2002, 08:07 AM
suzy software
 
Posts: n/a
Default Re: Increase In Microsoft-SQL-Server Scans?

Thanks for the link. *It helped.
  #5  
Old May 24th, 2002, 07:59 PM
RedHoney
 
Posts: n/a
Default Re: Increase In Microsoft-SQL-Server Scans?

Hi all!

I've been using NeoWatch as my firewall for several years now. *I have to say, I've tried them all but NW is by far the best investment of $40 I've made. *I have been SWAMPED with SQL server scans lately...as many as 10-12 in a few hours! Fortunately, NW allows me to simply ban the offending ip (after I use their 'report this event' option). * That seemed to slow down the barrage somewhat from power-scanners that show up frequently.

Does anyone know who started this awful trend and why? *
  #6  
Old May 26th, 2002, 06:32 PM
Raygun Raygun is offline
Infrequent Poster
 
Join Date: Apr 2002
Location: The Beach!
Posts: 31
Default Re: Increase In Microsoft-SQL-Server Scans?

I was wondering why they don't just block or ban the IP. Hell I run the new BlackIce PC Protection BIP for shot and I can easily block an IP. I hope you can do that in ZA?
__________________
-raygun-
  #7  
Old May 27th, 2002, 01:20 AM
UNICRON's Avatar
UNICRON UNICRON is offline
Technical Expert
 
Join Date: Feb 2002
Location: Nanaimo BC Canada
Posts: 1,935
Default Re: Increase In Microsoft-SQL-Server Scans?

It really makes no difference. If you don't use SQL server and I bet 99% of the people here do not, then the scans are harmless. Whether you ban the IP or not, you are still losing bandwidth to the scan irregardless.

If you DO use SQL server, and *have it exposed to *the internet intead of have it attached to your back end on a private network, then you probably could use some skills upgrades. If you use SQL Server and have it exposed to the net AND have NO PASSWORD (these things have to happen for this threat to be harmful) then you pretty much deserve to be plagued.

Quote:
this packet is an attempt to login to the MSSQL server, using the account name 'sa' and an empty password. This is the default authentication set-up for MSSQL installation.

Who could be that stupid?
__________________
Not every thing that can be counted counts, and not everything that counts can be counted.
 

Wilders Security Forums > Security Products > other firewalls « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:10 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums