473,412 Members | 2,005 Online
Bytes | Software Development & Data Engineering Community
Post Job

Home Posts Topics Members FAQ

Join Bytes to post your question to a community of 473,412 software developers and data experts.

IPSEC from C# without AD ??

bb
I am trying to find out how to control an IPSEC policy - mainly add a new IP
to an existing policy - from C# code. My SQL Server installation is getting
pounded by brute force password attack for the sa user. To stop this I wrote
a Windows Service to detect when this is happening. Currently when it detects
that someone is attempting to do this, it will email me with the ip so I can
add it easily to my blocking IP IPSEC policy. What I would really like to do,
is when it detects and attemp it will add the IP to the IP Security Policy
automatically. Any ideas on this one? I have searched and searched and cannot
find anything on this.

Info:
Windows 2000 System
Nov 16 '05 #1
3 3931
why is your SQL Server's port available to ANYBODY on the Internet?

Wouldn't the easiest thing be simply to make the SQL Server inaccessable
from a non-local web site?

--- Nick

"bb" <bb@discussions.microsoft.com> wrote in message
news:82**********************************@microsof t.com...
I am trying to find out how to control an IPSEC policy - mainly add a new IP to an existing policy - from C# code. My SQL Server installation is getting pounded by brute force password attack for the sa user. To stop this I wrote a Windows Service to detect when this is happening. Currently when it detects that someone is attempting to do this, it will email me with the ip so I can add it easily to my blocking IP IPSEC policy. What I would really like to do, is when it detects and attemp it will add the IP to the IP Security Policy
automatically. Any ideas on this one? I have searched and searched and cannot find anything on this.

Info:
Windows 2000 System

Nov 16 '05 #2
bb
This isnt helpful. Does anyone else have an actual helpful response? Thank
you in advance.

BB

"Nick Malik" wrote:
why is your SQL Server's port available to ANYBODY on the Internet?

Wouldn't the easiest thing be simply to make the SQL Server inaccessable
from a non-local web site?

--- Nick

"bb" <bb@discussions.microsoft.com> wrote in message
news:82**********************************@microsof t.com...
I am trying to find out how to control an IPSEC policy - mainly add a new

IP
to an existing policy - from C# code. My SQL Server installation is

getting
pounded by brute force password attack for the sa user. To stop this I

wrote
a Windows Service to detect when this is happening. Currently when it

detects
that someone is attempting to do this, it will email me with the ip so I

can
add it easily to my blocking IP IPSEC policy. What I would really like to

do,
is when it detects and attemp it will add the IP to the IP Security Policy
automatically. Any ideas on this one? I have searched and searched and

cannot
find anything on this.

Info:
Windows 2000 System


Nov 16 '05 #3
I suppose you are right... it doesn't come across as terribly helpful.

I suggest that you place a web service between your client app (on the
internet) and your sql server. MS SQL Server is fairly susceptible to
attack and there are still viruses out there that can disable SQL Server if
the port is directly exposed.

As for modifying the IPSec policy directly, I am sorry for not being able to
help more. I haven't investigated the ins and outs of poor security
designs.

--- Nick

"bb" <bb@discussions.microsoft.com> wrote in message
news:D6**********************************@microsof t.com...
This isnt helpful. Does anyone else have an actual helpful response? Thank
you in advance.

BB

"Nick Malik" wrote:
why is your SQL Server's port available to ANYBODY on the Internet?

Wouldn't the easiest thing be simply to make the SQL Server inaccessable
from a non-local web site?

--- Nick

"bb" <bb@discussions.microsoft.com> wrote in message
news:82**********************************@microsof t.com...
I am trying to find out how to control an IPSEC policy - mainly add a new
IP
to an existing policy - from C# code. My SQL Server installation is

getting
pounded by brute force password attack for the sa user. To stop this I

wrote
a Windows Service to detect when this is happening. Currently when it

detects
that someone is attempting to do this, it will email me with the ip so
I can
add it easily to my blocking IP IPSEC policy. What I would really like
to do,
is when it detects and attemp it will add the IP to the IP Security

Policy automatically. Any ideas on this one? I have searched and searched and

cannot
find anything on this.

Info:
Windows 2000 System


Nov 16 '05 #4

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

3
by: Babar Qaisrani | last post by:
Hi I have a query regarding socket programming . im trying to create a dummy IPSec (ESP)header Packet . My Packet looks like <code> struct mypkt { struct iphdr ip; struct _myesp esp; struct...
14
by: D. Alvarado | last post by:
Hello, I am trying to open a window containing an image and I would like the image to be flush against the window -- i.e. have no padding or border. Can I make this happen with a single call to a...
9
by: WalterR | last post by:
This is my first time here, so there may be earlier relevant threads of which I am unaware. Though my experience with DB2 is not extensive, such as it is was under OS/390 or equ. My main...
2
by: Igor MALY | last post by:
Hi, Exist any alternative manage property (create policy, setting filter) of ipsec on Windows Server 2003 from .NET framework? My program using extern command netsh, but it's not elegant solution....
0
by: Cc | last post by:
how do i add ipfilter list to ipsec through vb.net ? currently i generate i file and use ipseccmd to import the file. is there direct way from vb.net? thks, charles
1
by: manu | last post by:
plz tell me if there are any api available on windows or not for IPsec .. also tell about the system calls on linux. thnx in advance...:)
1
by: TampaWebDevelopment | last post by:
I use IPSec to create a filter list of IP addresses that I ban from accessing one of my servers. Right now, I use the MMC to manage an existing IP Filter List; adding a new filter to the list each...
5
by: mmcd79 | last post by:
I built a VB.net application that makes use of a machine level DB connection string setting, and a user level starting location setting. The machine level setting and the default user based...
1
by: =?Utf-8?B?Ry4gQ2FzYWJpYW5jYQ==?= | last post by:
I an trying to set up a VPN to access my office. My router only supports IPSec and the client Vista provides is based on PPTP. Is there any way to set up an IPSec client in VIsta and XP or do I...
0
BarryA
by: BarryA | last post by:
What are the essential steps and strategies outlined in the Data Structures and Algorithms (DSA) roadmap for aspiring data scientists? How can individuals effectively utilize this roadmap to progress...
1
by: nemocccc | last post by:
hello, everyone, I want to develop a software for my android phone for daily needs, any suggestions?
1
by: Sonnysonu | last post by:
This is the data of csv file 1 2 3 1 2 3 1 2 3 1 2 3 2 3 2 3 3 the lengths should be different i have to store the data by column-wise with in the specific length. suppose the i have to...
0
marktang
by: marktang | last post by:
ONU (Optical Network Unit) is one of the key components for providing high-speed Internet services. Its primary function is to act as an endpoint device located at the user's premises. However,...
0
by: Hystou | last post by:
Most computers default to English, but sometimes we require a different language, especially when relocating. Forgot to request a specific language before your computer shipped? No problem! You can...
0
Oralloy
by: Oralloy | last post by:
Hello folks, I am unable to find appropriate documentation on the type promotion of bit-fields when using the generalised comparison operator "<=>". The problem is that using the GNU compilers,...
0
jinu1996
by: jinu1996 | last post by:
In today's digital age, having a compelling online presence is paramount for businesses aiming to thrive in a competitive landscape. At the heart of this digital strategy lies an intricately woven...
0
by: Hystou | last post by:
Overview: Windows 11 and 10 have less user interface control over operating system update behaviour than previous versions of Windows. In Windows 11 and 10, there is no way to turn off the Windows...
0
isladogs
by: isladogs | last post by:
The next Access Europe User Group meeting will be on Wednesday 1 May 2024 starting at 18:00 UK time (6PM UTC+1) and finishing by 19:30 (7.30PM). In this session, we are pleased to welcome a new...

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.