0

What to do? Block that IP in firewall? What is this?

Igor Golodnitsky
  • 287
  • 1
  • 2
  • 13

1 Answers1

3

Probably a bot/virus/zombie/what-ever trying to brute-force guess a login for a SQL server, and perhaps not handshaking or disconnecting after a failed attempt properly.

If you have no need for external connections to any SQL servers on yuor network then block port 1433 from everywhere. In fact, best practise is to block everything and only allow the specific things that you do need incoming.

If you do need external connections to a SQL server, then I suggest you try some form of VPN or other secure tunnelling arrangement instead of having the port open to the unforgiving outside world, even if IP filtered.

David Spillett
  • 22,754
  • 45
  • 67