Permabanned
- Joined
- 28 Dec 2009
- Posts
- 13,052
- Location
- london
It looks like one of our clients that has a managed firewall with the ISP is under a brute force attack against the sql server. The application log has 1000s of login attempts for the SA login and origin ip address is in some cases Chinese.
This is some of the ips:
117.21.174.104
121.17.166.150
31.63.224.70
31.211.136.247
114.112.63.227
I have called the ISP and asked them to investigate because the sql server should not even be public facing.
There does not appear to be any active connections to external ips from any of the servers. Any ideas how best to investigate this? With it being a managed firewall, i don't have access to, I can't look on the firewall for connections etc.
This is some of the ips:
117.21.174.104
121.17.166.150
31.63.224.70
31.211.136.247
114.112.63.227
I have called the ISP and asked them to investigate because the sql server should not even be public facing.
There does not appear to be any active connections to external ips from any of the servers. Any ideas how best to investigate this? With it being a managed firewall, i don't have access to, I can't look on the firewall for connections etc.