I have a Windows Server 2008 R2 box running IIS 7.0 and SQL 2008 R2. I have a Juniper firewall protecting my server but we do have port 80 open to the Internet because we require it. My IIS logs are pretty mild. I have a few script attempts here and there, but my SQL logs are flooded (1000+/day) with 'sa' logon attempts.
How is my SQL server getting hit without my IIS Server logging it?
The IP in the message is the source of the attempt - is that the IP of the SQL server, or the web server (or are they both on the same box)?
I'd suggest running a trace for the "Audit Login" and "Audit
More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008.
Determine the location of the FSMO roles by lo…