Thwarting SIP Attacks

mwiesbau

New Member
Joined
Mar 3, 2009
Messages
16
Reaction score
0
Hello, my call logs show lots of entries with source being SIP and destination 's'

each call was about 10 seconds
it seems that there were 3 consecutive calls at a time.

could someone explain??
this looks a little bit suspicious to me.

Thanks
 
When I have added a number to the blacklist and if that number calls again, the DIST will show "S".

What's the complete number on the source? phone number, try looking up on google or whocalled.us
 
I had exactly the same thing happen yesterday. Don't know what it is or where it came from.
 
These are anonymous sip calls that are attempting to either spam you or determine the specs of your phone system. They are generated directly from the internet as a SIP to SIP call.

The 's' context, I believe, is just a dead end (context "black-hole"), usually a busy signal or a hangup depending on how you have FreePBX defined to handle anonymous calls
 
Further enquiry points that they are coming from these IP addresses:
113.105.152.101,
113.105.152.102
113.105.152.104
119.147.116.152
119.147.116.144
113.105.153.44

Time to go read my nerdvittles security refresher on blocking anonymous sip calls.
 
I'm seeing much the same (between 30 and 50 entries) with IP addresses:

113.105.152.101
113.105.152.102
113.105.152.103
113.105.152.104

113.105.153.55

119.147.116.17
119.147.116.158

121.14.149.144
121.14.149.145

124.207.176.8

222.73.204.83

With caller id set to either "sip" or "asterisk".

I have anonymous calls set to "No", and the calls are going to context "s", but is there anything else I need to look at?
 
Thanks for the link, I just implemented the changes and tried an anon sip call. Worked like a charm. :biggrin5:

Only thing is, it doesn't appear the call attempts (I tried twice) were logged in the CDR.
 
That's why I like the DenyHosts program (http://denyhosts.sourceforge.net/). It reports all hacking attempts to a central database and the banned IP's are downloaded to all participating systems. I use it in addition to Fail2Ban.
 
If you are using a pfsense firewall in front of your LAN (as I do), denyhosts works there too.
 
Hi
Only thing is, it doesn't appear the call attempts (I tried twice) were logged in the CDR.

You won't see anything in the CDR, the call is rejected and hung up straight away and not answered, as it was previously.

Joe
 
inetnum: 113.96.0.0 - 113.111.255.255
netname: CHINANET-GD
descr: CHINANET Guangdong province network
descr: Data Communication Division
descr: China Telecom
country: CN

inetnum: 119.144.0.0 - 119.147.255.255
netname: CHINANET-GD
descr: CHINANET Guangdong province network
descr: Data Communication Division
descr: China Telecom
country: CN
 
Might be worth reviewing:

Welcome to IP Country: A New Layer of Asterisk Security


fail2ban.gif
 
Ward

It should not be difficult to construct a fail2ban rule that blocked IP addresses that tried to phone an invalid number.

Joe
 

Members online

Forum statistics

Threads
26,687
Messages
174,411
Members
20,257
Latest member
Dempan
Get 3CX - Absolutely Free!

Link up your team and customers Phone System Live Chat Video Conferencing

Hosted or Self-managed. Up to 10 users free forever. No credit card. Try risk free.

3CX
A 3CX Account with that email already exists. You will be redirected to the Customer Portal to sign in or reset your password if you've forgotten it.
Back
Top