[Freeswitch-users] sip auth challenge HACKING ???

curriegrad2004 curriegrad2004 at gmail.com
Tue Mar 8 18:32:06 MSK 2011


Or just for fun, you can set up a honeypot with all extensions routing
to nowhere or to a very very nasty extension ;)

On Tue, Mar 8, 2011 at 3:00 AM, Dmitry Saratsky <simpot at simpot.com> wrote:
> I’m blocking it with: http://wiki.freeswitch.org/wiki/Fail2ban
>
>
>
>
>
>
>
> From: freeswitch-users-bounces at lists.freeswitch.org
> [mailto:freeswitch-users-bounces at lists.freeswitch.org] On Behalf Of Erkan
> Ünlü
> Sent: 08 Mar 2011 12:39
> To: freeswitch-users at lists.freeswitch.org
> Subject: [Freeswitch-users] sip auth challenge HACKING ???
>
>
>
> Hi FS Users,
>
>
>
> in last time i see in my console of FS this kind of error messages.
>
>
>
> [WARNING] sofia_reg.c:1246 SIP auth challenge (INVITE) on sofia profile
> 'internal' for [5828@?????????] from ip ???7?.1??.7??.???
>
>
>
> i check my config files ever again and again, but today the console is only
> given this kind of messages. Maybe 20 messages per second.
>
>
>
> i see the ip that given in the console “from ip xx.xx.xx.xx” i block this ip
> in my firewall and everything is fine.
>
> Now i understand that this a trying to hacking my server. The blocking of
> the ip is a solution but can not handle this in Freeswitch, because i see
> this problem sometimes on different FS servers also and in normally the FS
> server maybe must can handle this problem. For example with automatic black
> lists if an ip trys more than 20 times with wrong login. So the ip will be
> banned for 1 hour or so.
>
>
>
> i’m interesting in if other users have the same problems and ideas in how we
> can handle this.
>
>
>
> Kind regards
>
> Erkan
>
>
>
> _______________________________________________
> FreeSWITCH-users mailing list
> FreeSWITCH-users at lists.freeswitch.org
> http://lists.freeswitch.org/mailman/listinfo/freeswitch-users
> UNSUBSCRIBE:http://lists.freeswitch.org/mailman/options/freeswitch-users
> http://www.freeswitch.org
>
>



More information about the FreeSWITCH-users mailing list