Interesting SIP Scanning

"telemetry stations that transfer periodic hydrologic data measurements in the northern territories of Canada" seems very germane to the subject matter discussed.
 
It doesn't seem particulary crafty, unless there is some clever exploit inside the packet. Sending the same query from multiple sources is extremely unlikely to get a different response.

My biggest question is if the pattern from the snippet holds for any length of time, why hasn't fail2ban fired? An individual IP sending a request every 30-ish seconds would be 20-ish attempts in a 10 minute window.
 

Members online

Forum statistics

Threads
26,687
Messages
174,410
Members
20,257
Latest member
Dempan
Get 3CX - Absolutely Free!

Link up your team and customers Phone System Live Chat Video Conferencing

Hosted or Self-managed. Up to 10 users free forever. No credit card. Try risk free.

3CX
A 3CX Account with that email already exists. You will be redirected to the Customer Portal to sign in or reset your password if you've forgotten it.
Back
Top