Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations derfloh on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Does this look like a SQL Slammer attempt?

Status
Not open for further replies.

ianbla

IS-IT--Management
Oct 31, 2001
156
GB
2003-02-12 08:11:17 Local7.Info 192.168.10.1 27915: %SEC-6-IPACCESSLOGP: list 171 denied udp 192.168.10.132(1133) -> 255.255.255.255(1434), 1 packet

192.168.10.1 is the internal interface on the Gateway router that I am logging. 192.168.10.132 is the client.

I have tyhe follwoing ACL entry on the internal interface on the gateway;

access-list 171 deny udp any any eq 1434 log (1 matches)

I have looked at the user machine and cannot understand why this happened, he has SQL (SP3) installed but fully patched up.
 
That port is also used in part of the Enterprise SQL Admin application, from what I understand. I'm not a DBA but have used SQL mgmt tools in the past.
 
He has the SQL service set to manual so it couldn't have started at bootup.

I'm confused!!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top