Suspicious External SIP calls
I got 4 "from SIP external" entries in my call log today. That is unusual because nobody should be attempting to reach us that way. Could someone take a look at the following log entries and tell me how alarmed I should be and what I should do about it (if anything). Could just be a mistaken call attempt but the IP address was different each time. It looks like all the attempts terminated in a system recording (Congestion or No Service) but I blocked all my SIP and DUNDI pinholes until I hear from the gurus here.
This box was originally installed from the PIAF 1.2 ISO but was update-*'d (most recently) on 03/19/09 which I think corresponds to a security alert Ward put out. It is behind a router with NAT.
Here is a relevant snippet from var/log/asterisk/full:
[2010-01-08 22:33:34] VERBOSE[17715] logger.c: == Spawn extension (from-sip-external, s, 3) exited non-zero on 'SIP/91.121.173.176-08b0cab8'
[2010-01-08 22:33:42] WARNING[3099] chan_sip.c: Maximum retries exceeded on transmission
[email protected] for seqno 102 (Criti
cal Response)
[2010-01-09 00:00:02] VERBOSE[18008] logger.c: == Parsing '/etc/asterisk/manager.conf': [2010-01-09 00:00:02] VERBOSE[18008] logger.c: Found
[2010-01-09 00:00:02] VERBOSE[18008] logger.c: == Parsing '/etc/asterisk/manager_additional.conf': [2010-01-09 00:00:02] VERBOSE[18008] logger.c: Found
[2010-01-09 00:00:02] VERBOSE[18008] logger.c: == Parsing '/etc/asterisk/manager_custom.conf': [2010-01-09 00:00:02] VERBOSE[18008] logger.c: Found
[2010-01-09 00:00:02] VERBOSE[18008] logger.c: == Manager 'admin' logged on from 127.0.0.1
[2010-01-09 00:00:02] VERBOSE[18008] logger.c: == Manager 'admin' logged off from 127.0.0.1
[2010-01-09 01:52:40] NOTICE[3099] chan_sip.c: Peer '6812' is now UNREACHABLE! Last qualify: 107
[2010-01-09 01:53:18] NOTICE[3099] chan_sip.c: Peer '6812' is now Reachable. (208ms / 2000ms)
[2010-01-09 02:50:31] VERBOSE[18636] logger.c: -- Executing [011441844208220@from-sip-external:1] NoOp("SIP/64.62.243.6-08b0cab8", "Received incoming SIP
connection from unknown peer to 011441844208220") in new stack
[2010-01-09 02:50:31] VERBOSE[18636] logger.c: -- Executing [011441844208220@from-sip-external:2] Set("SIP/64.62.243.6-08b0cab8", "DID=011441844208220")
in new stack
[2010-01-09 02:50:31] VERBOSE[18636] logger.c: -- Executing [011441844208220@from-sip-external:3] Goto("SIP/64.62.243.6-08b0cab8", "s|1") in new stack
[2010-01-09 02:50:31] VERBOSE[18636] logger.c: -- Goto (from-sip-external,s,1)
[2010-01-09 02:50:31] VERBOSE[18636] logger.c: -- Executing [s@from-sip-external:1] GotoIf("SIP/64.62.243.6-08b0cab8", "0?from-trunk|011441844208220|1")
in new stack
[2010-01-09 02:50:31] VERBOSE[18636] logger.c: -- Executing [s@from-sip-external:2] Set("SIP/64.62.243.6-08b0cab8", "TIMEOUT(absolute)=15") in new stack
[2010-01-09 02:50:31] VERBOSE[18636] logger.c: -- Channel will hangup at 2010-01-09 07:50:46 UTC.
[2010-01-09 02:50:31] VERBOSE[18636] logger.c: -- Executing [s@from-sip-external:3] Answer("SIP/64.62.243.6-08b0cab8", "") in new stack
[2010-01-09 02:50:31] VERBOSE[18636] logger.c: -- Executing [s@from-sip-external:4] Wait("SIP/64.62.243.6-08b0cab8", "2") in new stack
[2010-01-09 02:50:33] VERBOSE[18636] logger.c: -- Executing [s@from-sip-external:5] Playback("SIP/64.62.243.6-08b0cab8", "ss-noservice") in new stack
[2010-01-09 02:50:33] VERBOSE[18636] logger.c: -- <SIP/64.62.243.6-08b0cab8> Playing 'ss-noservice' (language 'en')
[2010-01-09 02:50:38] VERBOSE[18636] logger.c: -- Executing [s@from-sip-external:6] PlayTones("SIP/64.62.243.6-08b0cab8", "congestion") in new stack
[2010-01-09 02:50:38] VERBOSE[18636] logger.c: -- Executing [s@from-sip-external:7] Congestion("SIP/64.62.243.6-08b0cab8", "5") in new stack
[2010-01-09 02:50:43] VERBOSE[18636] logger.c: == Spawn extension (from-sip-external, s, 7) exited non-zero on 'SIP/64.62.243.6-08b0cab8'
[2010-01-09 02:50:43] VERBOSE[18636] logger.c: -- Executing [h@from-sip-external:1] NoOp("SIP/64.62.243.6-08b0cab8", "Hangup") in new stack
[2010-01-09 02:50:43] VERBOSE[18636] logger.c: -- Executing [h@from-sip-external:2] Set("SIP/64.62.243.6-08b0cab8", "DID=s") in new stack
[2010-01-09 02:50:43] VERBOSE[18636] logger.c: -- Executing [h@from-sip-external:3] Goto("SIP/64.62.243.6-08b0cab8", "s|1") in new stack
[2010-01-09 02:50:43] VERBOSE[18636] logger.c: -- Goto (from-sip-external,s,1)
[2010-01-09 02:50:43] VERBOSE[18636] logger.c: -- Executing [s@from-sip-external:1] GotoIf("SIP/64.62.243.6-08b0cab8", "0?from-trunk|s|1") in new stack
[2010-01-09 02:50:43] VERBOSE[18636] logger.c: -- Executing [s@from-sip-external:2] Set("SIP/64.62.243.6-08b0cab8", "TIMEOUT(absolute)=15") in new stack
[2010-01-09 02:50:43] VERBOSE[18636] logger.c: -- Channel will hangup at 2010-01-09 07:50:58 UTC.
[2010-01-09 02:50:43] VERBOSE[18636] logger.c: -- Executing [s@from-sip-external:3] Answer("SIP/64.62.243.6-08b0cab8", "") in new stack
[2010-01-09 02:50:43] VERBOSE[18636] logger.c: == Spawn extension (from-sip-external, s, 3) exited non-zero on 'SIP/64.62.243.6-08b0cab8'
[2010-01-09 02:50:51] WARNING[3099] chan_sip.c: Maximum retries exceeded on transmission
[email protected] for seqno 102 (Critica
l Response)
[2010-01-09 04:02:26] VERBOSE[3093] logger.c: -- Remote UNIX connection
There is more and I can provide if helpful.
Thanks,
Dallas