Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


aw

aw

286 posts

Ultimate Geek


#84766 7-Jun-2011 23:08
Send private message

I'm on the receiving end of a brute force SIP registration attack coming from 111.75.255.9, trying to log on to my Asterisk box with random extension numbers.

I've fixed my fail2ban but it's still coming in thick and fast despite now being blocked, and it's pushed my data usage up quite high, and is having a DoS effect. It's been going on all day.

Anyone else getting this? It's fierce.

edit: added details of the attack

Create new topic
maverick
3594 posts

Uber Geek

Trusted
WorldxChange

  #478820 8-Jun-2011 01:50
Send private message

This is actaully normal for a SIP attack, SIP Scans go on all the time so hence the reason to secure your box and to only respond to the SIP proxy you require , otherwise once they find you they will get trying.

These BOT's will have pre set scripts, once they get a SIP response from a insecure box they will go through through their pre programmed list and just keep trying unfortunatly    




Yes I am a employee of WxC (My Profile) ... but I do have my own opinions as well Wink

             

https://www.facebook.com/wxccommunications



sbiddle
30853 posts

Uber Geek

Retired Mod
Trusted
Biddle Corp
Lifetime subscriber

  #478824 8-Jun-2011 07:04
Send private message

It's pretty common these days. Once the attack stats there isn't anything you can do to stop it until they give up.

IMHO fail2ban along with a good iptables firewall setup is an even more essential part of an Asterisk setup than phones themselves. Unless you have a very good reason to do so port 5060 should never be exposed to the internet, and if it is it should be locked down to the IP(s) of your VoIP provider. If you need remote endpoints on the internet there are plenty of ways of managing these such as via VPN that will reduce the security risks.

aw

aw

286 posts

Ultimate Geek


  #478847 8-Jun-2011 09:13
Send private message

I use remote extensions, which is why I had this on. Just last week they all became iPhones so VPN has become an option, I'll investigate that.

fail2ban kicked in properly last night once I removed the typo in which log file it was scanning, but I'm still receiving 10-20 REGISTER packets per second, even now. It's ballooned my data usage (12GB where I would have otherwise used about 4), Phil can this offending IP (it's just been the one above) be blocked at the ISP level?



maverick
3594 posts

Uber Geek

Trusted
WorldxChange

  #478851 8-Jun-2011 09:23
Send private message

Will take a look




Yes I am a employee of WxC (My Profile) ... but I do have my own opinions as well Wink

             

https://www.facebook.com/wxccommunications

maverick
3594 posts

Uber Geek

Trusted
WorldxChange

  #478862 8-Jun-2011 09:42
Send private message

should be dead now




Yes I am a employee of WxC (My Profile) ... but I do have my own opinions as well Wink

             

https://www.facebook.com/wxccommunications

aw

aw

286 posts

Ultimate Geek


  #478877 8-Jun-2011 10:13
Send private message

Thanks, just remoted in, the attack (with its DoS effect) looks to be successfully blocked.

I see it was affecting multiple Xnet customers:

http://www.ipillion.com/ip/111.75.255.9

rphenix
985 posts

Ultimate Geek

Lifetime subscriber

  #478983 8-Jun-2011 15:14
Send private message

aw: I use remote extensions, which is why I had this on. Just last week they all became iPhones so VPN has become an option, I'll investigate that.


Use an IAX2 client if possible for software based remote extensions, that way you can keep SIP closed except between WXC and yourself.  If your using remote hard phones (or want to) look at something like Yealink SIP-T26P with openvpn support so can setup an openvpn server, have the phones connect to that, and from there to the private lan ip of the pbx.

If you must open SIP up to the outside world, then I would use something like a SIP Port knock (of sorts) rather clever ;)

 
 
 

Cloud spending continues to surge globally, but most organisations haven’t made the changes necessary to maximise the value and cost-efficiency benefits of their cloud investments. Download the whitepaper From Overspend to Advantage now.
richms
28168 posts

Uber Geek

Trusted
Lifetime subscriber

  #479962 11-Jun-2011 00:50
Send private message

Is there any way that a IP PBX could just do a port unreachable for any incoming SIP stuff that would fail instead of sending back a response?

If traffic wasnt so expensive it would be more fun to let them register and put the call recordings up on youtube to funny pictures like that crank phone guy, but I have a feeling that they would all be in some minority language that would make it not very fun.




Richard rich.ms

Regs
4066 posts

Uber Geek

Trusted
Snowflake

  #480467 12-Jun-2011 23:25
Send private message

richms: Is there any way that a IP PBX could just do a port unreachable for any incoming SIP stuff that would fail instead of sending back a response?

If traffic wasnt so expensive it would be more fun to let them register and put the call recordings up on youtube to funny pictures like that crank phone guy, but I have a feeling that they would all be in some minority language that would make it not very fun.



many firewalls just seem to be 'black holes' for packets.  i.e. they accept but discard the packets so the sender never gets an ACK.


as for the phone calls, most of the hacks are from cheap phone calling card companies, or sip trunkers, so you'd just get a bunch of random regular calls in whatever language/country the plans are being sold in.




Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.