Recommended Posts

Dear all,

Greetings and my sincere thanks for your kind advise in advance.

I have got a virtual web server which use to connect to a MSSQL2005 DB. This server contain a web base application running Tomcat and MSSQL 2005 as the default DB system.

These few weeks I realized that the connection speed to this server decease tremendously. I then checked in the App Event log of that server and found out that plenty of the "suspicious" connections attempt to the MSSQL2005 via "sa" account on this server (from different countries). And those IP addresses were not belong to anyone of what I know or assigned before.

Those IP vary from many countries that I don't recall I have assign the login account to. Would you please kindly advise the following:

1) How can I tell if the IP addresses that I grabbed from the App Event log if it is real IP addresses or "fake" IP addresses?

2) Is there any free tools that I can install on my server that monitor and report/alert me once there are suspicious network bandwidth or suspicious network attack?

3) How can I achieve to block those IP addresses that trying to access my server. By blocking IP addresses would not possible considering that if the "attacker" have a dynamic IP address everytime he/she connect to the internet. Blocking the DNS name to those countries would not feasible as well because many time, there are users (in same country) that I did assigned their access to this server.

I have a non real-time scanning feature FREE anti virus program, does it mean I have to purchase a better security suite (include firewall management and virus/spyware/malware/trojan detection feature)?

* by the way, how can I know if the connection from my server to the local ISP is having a connection bandwidth challenge? Is there any tools out there that I can use to check?

Regards,

Soh, Eng Beng

so you have a web page page that uses this mssql database as its backend right. And the database is housed on the same server the website is served from?

If this is the case why would you need to allow direct access to the database from anywhere other than that webserver? Opening up a sql server to the public net is going to generate lots of traffic to be sure.. Many worms and bots that all they do is look for sql servers open to the public.

So standard sql port is 1433, you will see this is on the top 10 list on sans

http://isc.sans.edu/port.html?port=1433

So yeah your going to see lots of traffic to it, just like you see brute to ssh server ;)

example in last 24 hours or so in my log for ssh

Jan 16 12:59:00 ubuntu sshguard[11163]: Blocking 201.134.42.58: 4 failures over 18 seconds.

Jan 16 15:52:59 ubuntu sshguard[11163]: Blocking 218.239.223.97: 4 failures over 6 seconds.

JJan 16 23:02:35 ubuntu sshguard[11163]: Blocking 85.198.188.145: 4 failures over 5 seconds.

Jan 17 07:09:56 ubuntu sshguard[24707]: Blocking 222.222.194.187: 4 failures over 9 seconds.

Jan 17 08:32:14 ubuntu sshguard[24707]: Blocking 122.200.76.162: 4 failures over 10 seconds.

Jan 17 09:57:51 ubuntu sshguard[24707]: Blocking 147.32.84.189: 4 failures over 4 seconds.

Jan 17 11:22:29 ubuntu sshguard[24707]: Blocking 147.32.84.189: 4 failures over 4 seconds.

Jan 17 17:15:08 ubuntu sshguard[24707]: Blocking 59.175.210.120: 4 failures over 8 seconds.

Jan 17 18:53:48 ubuntu sshguard[24707]: Blocking 116.255.254.197: 4 failures over 30 seconds.

Jan 17 22:21:45 ubuntu sshguard[24707]: Blocking 211.157.108.95: 4 failures over 7 seconds.

Jan 18 00:34:22 ubuntu sshguard[24707]: Blocking 61.19.248.45: 4 failures over 8 seconds.

Jan 18 08:17:50 ubuntu sshguard[5941]: Blocking 114.80.97.201: 4 failures over 10 seconds.

Jan 18 10:29:51 ubuntu sshguard[5941]: Blocking 80.237.155.55: 4 failures over 4 seconds.

Now I don't even allow password auth, only public key so they are never going to auth - but I still just block their ips 4 failures in specific amount of time. But your going to see this noise for sure on any common service port.. Even if you don't even run services on the ports your going to see probes for it.. The net is full of NOISE!!

Here is sample of destination ports my firewall is seeing on my home box

post-14624-0-86660500-1295388889.jpg

Where your problem is if your letting mssql even be talked to by anything other than your webserver -- Not sure exactly what your doing, but databases used for the backend of a website do not need to be open to the public net.. Only connections from itself (webserver) should be allowed.

BTW log only runs for like 24 hours and then is recycled. That graph is

This is a firewall log summary, of the last 2021 lines of the firewall log (Max 5000).

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • The most corrupt and vile CEO any company ever had ! The only company that makes an insane amount of money decade after decade but doesn't deliver on even barely passable quality to customers, screws over partners and treats employees like trash
    • PSA: Some other versions of Windows are losing support on October 14 too by Usama Jawad All of us here at Neowin likely know pretty well by now that Windows 10 is reaching end of support on October 14, 2025. You can extend support through paid and "free" means, but if you don't, you won't get any more security or feature updates following the aforementioned date. We also highlighted that the Long-Term Servicing Channel (LTSC) version Windows 10 22H2 is also reaching end of support on that date. Now, Microsoft has reminded customers that yet another variant of Windows is reaching end of life on October 14, 2025 too. On the Windows Release Health dashboard, Microsoft has published a reminder that the Enterprise, Education, and IoT SKUs of Windows 11, version 22H2 will hit end of support on October 14 as well. It is important to keep in mind that the Home and Pro variants of Windows 11, version 22H2 already reached end of life on October 8, 2024, and the extra year of lease on life will end for other SKUs within a few months too. Windows 11, version 22H2 for IoT, Enterprise, and Education was released on September 20, 2022, which means that they would have received just over three years of support by the time they "die", compared to the regular two years for Home and Pro. Customers on any of these versions should consider upgrading to version 23H2 or 24H2 as soon as possible, which have end of support dates of November 10, 2026 and October 12, 2027, respectively. Staying on a supported version of Windows is crucial as that allows you to receive regular security updates on your machine. If you're an IT admin, you should immediately begin planning a migration to a supported version of the operating system, and if you're an employee or someone using these versions of Windows in some other scenario, go to Settings > System > About and check out Windows Specifications > Version.
    • Secret Changelog: New Features: Settings > Start, home, and new tab page > New tab page > Copilot new tab page (Chat, search, and navigate with a modern new tab page inspired by Copilot) Settings > AI innovations (Explore Copilot Mode)
    • Microsoft is adding some very useful features to Word, Teams, Outlook, and more by Usama Jawad Image via Microsoft Microsoft 365 is the Redmond tech firm's premier solution for Office apps and cloud storage, among other things. Microsoft offers both consumer- and enterprise-oriented subscriptions for this solution, enabling customers to take full advantage of cloud-powered capabilities, in contrast to the LTSC versions of Office. Microsoft 365 apps and services regularly receive new updates and the good thing is that Microsoft tracks them in a very transparent way on its public roadmap. The Redmond company has updated its Microsoft 365 Roadmap with a lot of items in the past week or so, and there are several interesting features there that may excite its customers. For starters, Word is getting a very useful utility that will likely help people writing detailed documents using the software. Microsoft is integrating third-party citation providers in the Reference tab, so that users can quickly add citations. This is being made available to GCC, GCC High, and Department of Defense (DoD) customers on desktop and web this month. There are several improvements on the way for Copilot Notebooks too. Users can customize the format, style, and duration of Audio Overviews in the application through natural language prompts. These Audio Overviews can then be saved on OneDrive so that they can be shared with others too. All of these capabilities are landing on the web next month. Speaking of Copilot, Microsoft is moving the navigation pane for Copilot Chat from the right side of the app to the left. Apart from retaining the existing features, this repositioning allows Microsoft to add new capabilities such as an All Conversations tab, while also streamlining the overall navigation experience. This is being implemented for all customers using Outlook and Teams on the web from next month. In the latter software, Microsoft is also introducing regional settings that gives controls over the app's language and datetime formats. This is being made available for all Teams customers on Android, iOS, desktop, and the web from next month. Meanwhile, the desktop version of Teams is exclusively gaining the ability next month to search for meetings and participants in the search bar and take actions directly from there. Available actions include viewing recaps, accessing the dedicated meetings tab, and RSVP-ing. Microsoft added 39 items to the Microsoft 365 Roadmap, so you can understand that the selection of items described above is only scratching the tip of the iceberg. Check out other upcoming capabilities like Universal Print enhancements and more Copilot improvements on the dedicated webpage here.
  • Recent Achievements

    • Week One Done
      hhgygy earned a badge
      Week One Done
    • One Month Later
      hhgygy earned a badge
      One Month Later
    • One Year In
      NIKI77 earned a badge
      One Year In
    • Week One Done
      artistro08 earned a badge
      Week One Done
    • Dedicated
      Balaji Kumar earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      639
    2. 2
      ATLien_0
      238
    3. 3
      Xenon
      166
    4. 4
      neufuse
      145
    5. 5
      +FloatingFatMan
      122
  • Tell a friend

    Love Neowin? Tell a friend!