• News
  • Security
  • Products
  • About Seqrite
Blogs on Information Technology, Network & Cybersecurity | Seqrite Blog
  • News
  • Security
  • Products
  • About Seqrite
Home  /  Security  /  Brute force attack on Microsoft SQL
Brute force attack on Microsoft SQL
04 May 2017

Brute force attack on Microsoft SQL

Written by Ankita Ashesh
Ankita Ashesh
Security

In recent events, we have been observing that hackers have started targeting Microsoft SQL(MSSQL) servers using its open TCP port. The database is configured with weak password, despite administrators agreeing to the importance of it. The reasons could be ease of use to the operator, lack of security awareness or simply underestimating risk factors.

By default, Microsoft SQL runs on TCP ports 1433/1434 with ‘SA’ as an administrator user.

Microsoft SQL Brute Force Attack Flow:

  1. The attacker uses port scanning techniques to identify the open ports on target system
  2. Once the attacker found port 1433/1434 in open state, it starts brute forcing the SA login which is a default administrator account
  3. The attacker usually holds a dictionary with the most common passwords used by database administrators, thus making the attack faster and successful in most cases
  4. Once the attacker has access to the ‘SA’ user, he gets the complete access of the database. Attacker may further exploit the system if Microsoft SQL server has vulnerabilities allowing the attacker to gain complete access of the operating system

Indicator of Infection:

  1. Microsoft SQL ‘SA’ user password changed unknowingly
  2. Multiple failed attempts to access ‘SA’ user

How much damage this attack can cause:

  1. Hacker can get the administrative access of database which is an integral part of any organization further which may result in loss of data and/or data getting stolen

How you can safeguard your system from this attack:

  1. Set complex password for database user like ‘SA’ user
  2. Disable the default user ‘SA’ and create another user with same privileges
  3. Change default TCP port i.e. 1433 to random port so that attacker cannot guess it easily
  4. Disable the Microsoft SQL(MSSQL) service if not used.

Ensuring above actions are in place is the primary prevention to stay away from these type of attacks. We also recommend customizing ‘Quick Heal Firewall’ which allows users to set the firewall rules to suit individual needs. If properly configured, Quick Heal Firewall can protect against these intrusion attacks by bottlenecking the network traffic to safeguard your network infrastructure. We have discussed similar ‘Firewall configuration’ in our previous blog about RDP brute force attacks.

Also, use Quick Heal Vulnerability Scanner to identify vulnerabilities and further patch/fix them to avoid getting exploited by such miscreants.

ACKNOWLEDGMENT

Subject Matter Expert
• Shantanu Vichare
– Threat Research and Response Team

 Previous PostLatest AV-TEST report rates Seqrite EPS as ‘Top ProductR...
Next Post  Banking malware, Dridex bounces back through PDF
Ankita Ashesh

About Ankita Ashesh

...

Articles by Ankita Ashesh »

Related Posts

  • data privacy

    The What, How, and Why of Data Privacy

    January 24, 2025
  • How the Recent Health Insurance Data Breach Could Affect You – and What You Can Do About It

    October 14, 2024
  • Defending against APT attacks with endpoint security

    How To Defend Against Advanced Persistent Threats (APTs): A Comprehensive Approach

    September 27, 2024
Featured Authors
  • Seqrite
    Seqrite

    Follow us for the latest updates and insights related to security for...

    Read more..
  • Sanjay Katkar
    Sanjay Katkar

    Sanjay Katkar is the Joint Managing Director of Quick Heal Technologies...

    Read more..
  • Mahua Chakrabarthy
    Mahua Chakrabarthy

    A tea connoisseur who firmly believes that life is too short for dull content....

    Read more..
Topics
apt (19) Cyber-attack (35) cyber-attacks (58) cyberattack (16) cyberattacks (13) Cybersecurity (322) cyber security (31) Cyber threat (33) cyber threats (48) Data (11) data breach (55) data breaches (28) data loss (28) data loss prevention (34) data privacy (11) data protection (24) data security (15) DLP (49) Encryption (16) endpoint security (107) Enterprise security (17) Exploit (14) firewall (11) GDPR (12) hackers (11) malware (76) malware attack (23) malware attacks (12) MDM (25) Microsoft (15) Network security (22) Patch Management (12) phishing (27) Ransomware (67) ransomware attack (30) ransomware attacks (30) ransomware protection (13) security (11) Seqrite (33) Seqrite Encryption (27) Seqrite EPS (33) Seqrite Services (16) UTM (34) Vulnerability (16) windows (11)
Loading
Resources
  • White Papers
  • Datasheets
  • Threat Reports
  • Manuals
  • Case Studies
About Us
  • About Seqrite
  • Leadership
  • Awards & Certifications
  • Newsroom
Archives
  • By Date
  • By Category
Loading

© 2025 Quick Heal Technologies Ltd. Cookie Policies Privacy Policies