locked
Login failed for user 'sa'. RRS feed

  • Question

  • We keep getting this error, each day, sometimes for up to 8 hours

     

     

    Login failed for user 'sa'. [CLIENT: 60.12.36.69]

     

    Login failed for user 'sa'. [CLIENT: 222.186.13.48]

     

    Login failed for user 'sa'. [CLIENT: 222.187.105.220]

     

     

    On this server, we do not have any active databases nor do we have any reporting services deployed to it.  Why are we getting this error?  I have been told it is because someone from the outside is trying to dial in.  If my firewall is closed as well as the ISS FTP, how can this happen?  The login has been disabled and the permission to connect to the db engine is grant.

     

    Thanks

     

     

     

    Wednesday, October 8, 2008 6:39 PM

Answers

  • Turn off Inbound port 1433/1434 in the firewall, and that should block the default instance from access to the internet.  You have a serious security risk if you are getting external IP attempts to login with SA on your SQL Server.  SQL servers should not be plugged into the Internet directly.  They should be behind a hardware type firewall in a segmented DMZ and require IPSec tunneling for access over the web.

     

    Wednesday, October 8, 2008 7:40 PM

All replies

  • Turn off Inbound port 1433/1434 in the firewall, and that should block the default instance from access to the internet.  You have a serious security risk if you are getting external IP attempts to login with SA on your SQL Server.  SQL servers should not be plugged into the Internet directly.  They should be behind a hardware type firewall in a segmented DMZ and require IPSec tunneling for access over the web.

     

    Wednesday, October 8, 2008 7:40 PM
  • can you login in my laptop by teamviewer? please? and show me?

    thanks

    • Proposed as answer by sejaad Tuesday, November 4, 2014 7:56 AM
    Tuesday, November 4, 2014 7:54 AM