Reply
 
Thread Tools Display Modes
  #1  
Old 12-11-09, 02:50 PM
jason559 jason559 is offline
Junior Member
 
Join Date: Aug 2009
Posts: 5
Missed calls from "sip" "asterisk" hacked?
This started November 26 with just one IP:
113.105.152.102. It is now added these two: 66.117.50.225, 204.57.122.6. Late last night they hit my extension 10 times.

I have absolutely no idea what to do about this. My PSTN only allows local calls, but I do use Vitelity for LD, so they could make long distance calls from my box if they got in.
Reply With Quote
  #2  
Old 12-11-09, 03:01 PM
wardmundy wardmundy is offline
Nerd Uno
 
Join Date: Oct 2007
Posts: 3,881
http://nerdvittles.com/index.php?p=580
Reply With Quote
  #3  
Old 12-11-09, 03:07 PM
jason559 jason559 is offline
Junior Member
 
Join Date: Aug 2009
Posts: 5
I am using PBX in a flash, so step one says I already have IP tables. And directed me to these forums for help
Reply With Quote
  #4  
Old 12-11-09, 03:49 PM
blakekrone blakekrone is offline
Member
 
Join Date: Aug 2008
Location: Chaska, MN
Posts: 56
We have seen those as well, but only on a couple of extensions and it isn't going through my Piaf serer, seems to be direct ip calls.
Reply With Quote
  #5  
Old 12-11-09, 05:28 PM
MyKroFt MyKroFt is offline
Guru
 
Join Date: Oct 2008
Posts: 508
use the ip filtering in the extension settings....
Reply With Quote
  #6  
Old 12-11-09, 06:13 PM
Lost Trunk Lost Trunk is offline
Guru
 
Join Date: Aug 2008
Posts: 157
One suggestion I haven't seen mentioned much, but that I think would help, is if you have someone trying to get in from one or more particular IP address(es), add a line (or lines) that specifically blocks them to /etc/asterisk/sip_custom.conf - e.g.:

deny 113.105.152.102/255.255.255.255
deny 66.117.50.225/255.255.255.255
deny 204.57.122.6/255.255.255.255

If this works as I understand, any address you enter in this way should at least be permanently blocked for SIP access. I don''t know if similar lines in iax_additional.conf would block entry using that protocol, but if you don't have any IAX extensions, it's less of a concern anyway.

This isn't a substitute for any of the suggestions in Ward's post, just a possible bit of added protection.
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 09:01 PM.


Design by Vjacheslav Trushkin, color scheme by ColorizeIt!.
Powered by vBulletin®
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright ©2007-2008, Ward Mundy & Associates