[Freeswitch-users] Fake ANI attack or issue.

Ken Rice krice at freeswitch.org
Tue Dec 10 03:54:58 MSK 2013


This is probably a sipvicious or similar scan looking for open sip servers
to terminate illicit traffic... There are numerous posts in the list
archives on this subject (and the list archives are heavily indexed by
google). Check out fail2ban and related wiki articles also...

Another way to limit this traffic is if you know all the netblocks only
allow sip traffic from those in IP Tables... Or filter those via the various
FS mechanisms...

K


On 12/9/13 6:39 PM, "stephen at picardogroup.com" <stephen at picardogroup.com>
wrote:

> Have an existing FS app using 800 inbound with SIP carrier. No IP address is
> sent.
> 
> Below is example of good call with proper ANI and DNIS sent from our carrier.
> (Modified to protect info.)
> 
> 12:27:43 lsvc:Inbound call from ANI xxxxxxxxxx to DNIS 800xxxxxxx
> 12:27:44 (121094) lsvc:SERVER_TYPE is: 0
> 12:27:44 (121093) lsvc:Staff 2 logged in
> 12:27:47 (121094) lsvc:Caller is entering his phone number
> 12:27:48 (121093) lsvc:disconnected reason was NONE
> 12:27:48 (121093) lsvc:lsvc_in: completed call successfully
> 12:27:52 (121094) lsvc:The caller typed in a home phone number of xxxxxxxxxx
> 
> Below is example of hits we are taking that are not being sent from our
> carrier (I assume direct hits to router)
> 
> 10:00:12 lsvc:Inbound call from ANI 100 to DNIS 001448703928456
> 10:00:13 (121218) lsvc:SERVER_TYPE is: 0
> 10:00:45 (121218) lsvc:disconnected reason was NONE
> 10:00:45 (121218) lsvc:Caller is entering his phone number
> 
> My question is there a way for me to prevent the fake ANI's from connecting?
> 
> 
> 
> 
> 
> _________________________________________________________________________
> Professional FreeSWITCH Consulting Services:
> consulting at freeswitch.org
> http://www.freeswitchsolutions.com
> 
> 
> 
> 
> Official FreeSWITCH Sites
> http://www.freeswitch.org
> http://wiki.freeswitch.org
> http://www.cluecon.com
> 
> FreeSWITCH-users mailing list
> FreeSWITCH-users at lists.freeswitch.org
> http://lists.freeswitch.org/mailman/listinfo/freeswitch-users
> UNSUBSCRIBE:http://lists.freeswitch.org/mailman/options/freeswitch-users
> http://www.freeswitch.org

-- 
Ken
http://www.FreeSWITCH.org
http://www.ClueCon.com
http://www.OSTAG.org
G+ ClueCon :    http://fs0.us/cluecon-gplus
FB ClueCon :    http://fs0.us/cluecon-fb
G+ FreeSwitch : http://fs0.us/freeswitch-gplus
FB FreeSWITCH : http://fs0.us/freeswitch-fb
Twitter : @FreeSWITCH_WIRE
irc.freenode.net #freeswitch

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.freeswitch.org/pipermail/freeswitch-users/attachments/20131209/581f07fd/attachment.html 


Join us at ClueCon 2013 Aug 6-8, 2013
More information about the FreeSWITCH-users mailing list