Empresas
Empleos
  • Sobre nosotros
  • Soluciones
    • Publicación de vacantes
      Publica tu vacante y recibe candidatos calificados en 48h.
    • Evaluación de candidatos
      500+ pruebas técnicas y psicológicas, más anti-fraude.
    • Headhunting
      Búsqueda ejecutiva a la medida de principio a fin.
    • Nómina + EOR
      Dispersión de nómina y EOR en más de 15 países de LATAM.
  • Precios
  • Empleos

0

775
Vistas
AWS RDS (SQL Server) suspicious brute force login attempts

I have created a public RDS (SQL Server) instance. For my project requirement it has to be public. When I checked the log it shows several thousands of entries of failed login attempt from some IPs like the following, (i've tried creating several instances in different zones but still same issues). Any kind of help will be very much appreciated. Thanks.

Error Log:

2020-02-03 09:45:28.98 Logon       Login failed for user 'sa'. Reason: Could not find a login matching the name provided. [CLIENT: 61.12.74.190]
2020-02-03 09:45:29.31 Logon       Error: 18456, Severity: 14, State: 5.
2020-02-03 09:45:29.31 Logon       Login failed for user 'sa'. Reason: Could not find a login matching the name provided. [CLIENT: 61.12.74.190]
2020-02-03 09:45:29.42 Logon       Error: 18456, Severity: 14, State: 5.
2020-02-03 09:45:29.42 Logon       Login failed for user 'mssqla'. Reason: Could not find a login matching the name provided. [CLIENT: 112.53.236.114]
2020-02-03 09:45:29.48 Logon       Error: 18456, Severity: 14, State: 5.
2020-02-03 09:45:29.48 Logon       Login failed for user 'sa'. Reason: Could not find a login matching the name provided. [CLIENT: 61.12.74.190]
2020-02-03 09:45:29.73 Logon       Error: 18456, Severity: 14, State: 5.
2020-02-03 09:45:29.73 Logon       Login failed for user 'sa'. Reason: Could not find a login matching the name provided. [CLIENT: 61.12.74.190]
2020-02-03 09:45:30.08 Logon       Error: 18456, Severity: 14, State: 5.
2020-02-03 09:45:30.08 Logon       Login failed for user 'sa'. Reason: Could not find a login matching the name provided. [CLIENT: 61.12.74.190]

As a temporary fix i have black listed all the ip from VPC -> Network ACLs, for a couple of IPs this solution is OK but for hundreds of IPs this solution is quite painful so I'm expecting a much more efficient way to resolve this issue.

NOTE:

I checked the AWS forum and found a very old and similar issue but NO answer there https://forums.aws.amazon.com/thread.jspa?messageID=196538&#196538

Also, found a similar question on stackoverflow Is this a brute force attempt? (AWS SQL Server) which is also does NOT have any specified solution.

over 4 years ago · Santiago Trujillo
1 Respuestas
Responde la pregunta

0

change the default sql server port 1433 by other...

PD: exactly the same problem was happening to me, I looked for aws information and its solution became very complicated, so I thought that if it is a brute force attack it would be the default sql user, sa, and the default port 1433, then change the default port and the connection of my application and solved the problem ... complex problem, simple solution.

over 4 years ago · Santiago Trujillo Denunciar
Responde la pregunta
Encuentra empleos remotos

¡Descubre la nueva forma de encontrar empleo!

Top de empleos
Top categorías de empleo
Empresas
Publicar vacante Precios Comercial
Legal
Términos y condiciones Política de privacidad
© 2026 PeakU Inc. All Rights Reserved.
Andres GPT
Recomiéndame algunas ofertas
Necesito ayuda