Business
Jobs
  • About Us
  • Solutions
    • Job Postings
      Post your job and receive qualified candidates in 48h.
    • Candidate Assessments
      500+ technical and psychological tests, plus anti-fraud.
    • Headhunting
      Tailor-made executive search from start to finish.
    • Payroll + EOR
      Payroll dispersal and EOR across 15+ LATAM countries.
  • Pricing
  • Jobs

0

766
Views
AWS RDS (SQL Server) suspicious brute force login attempts

I have created a public RDS (SQL Server) instance. For my project requirement it has to be public. When I checked the log it shows several thousands of entries of failed login attempt from some IPs like the following, (i've tried creating several instances in different zones but still same issues). Any kind of help will be very much appreciated. Thanks.

Error Log:

2020-02-03 09:45:28.98 Logon       Login failed for user 'sa'. Reason: Could not find a login matching the name provided. [CLIENT: 61.12.74.190]
2020-02-03 09:45:29.31 Logon       Error: 18456, Severity: 14, State: 5.
2020-02-03 09:45:29.31 Logon       Login failed for user 'sa'. Reason: Could not find a login matching the name provided. [CLIENT: 61.12.74.190]
2020-02-03 09:45:29.42 Logon       Error: 18456, Severity: 14, State: 5.
2020-02-03 09:45:29.42 Logon       Login failed for user 'mssqla'. Reason: Could not find a login matching the name provided. [CLIENT: 112.53.236.114]
2020-02-03 09:45:29.48 Logon       Error: 18456, Severity: 14, State: 5.
2020-02-03 09:45:29.48 Logon       Login failed for user 'sa'. Reason: Could not find a login matching the name provided. [CLIENT: 61.12.74.190]
2020-02-03 09:45:29.73 Logon       Error: 18456, Severity: 14, State: 5.
2020-02-03 09:45:29.73 Logon       Login failed for user 'sa'. Reason: Could not find a login matching the name provided. [CLIENT: 61.12.74.190]
2020-02-03 09:45:30.08 Logon       Error: 18456, Severity: 14, State: 5.
2020-02-03 09:45:30.08 Logon       Login failed for user 'sa'. Reason: Could not find a login matching the name provided. [CLIENT: 61.12.74.190]

As a temporary fix i have black listed all the ip from VPC -> Network ACLs, for a couple of IPs this solution is OK but for hundreds of IPs this solution is quite painful so I'm expecting a much more efficient way to resolve this issue.

NOTE:

I checked the AWS forum and found a very old and similar issue but NO answer there https://forums.aws.amazon.com/thread.jspa?messageID=196538&#196538

Also, found a similar question on stackoverflow Is this a brute force attempt? (AWS SQL Server) which is also does NOT have any specified solution.

over 4 years ago · Santiago Trujillo
1 answers
Answer question

0

change the default sql server port 1433 by other...

PD: exactly the same problem was happening to me, I looked for aws information and its solution became very complicated, so I thought that if it is a brute force attack it would be the default sql user, sa, and the default port 1433, then change the default port and the connection of my application and solved the problem ... complex problem, simple solution.

over 4 years ago · Santiago Trujillo Report
Answer question
Find remote jobs

Discover the new way to find a job!

Top jobs
Top job categories
Business
Post vacancy Pricing Sales
Legal
Terms and conditions Privacy policy
© 2026 PeakU Inc. All Rights Reserved.
Andres GPT
Show me some job opportunities
There's an error!