Brekeke Forum Index » Brekeke SIP Server Forum

Post new topic   Reply to topic
SIP Registration Hack Attempt - How to guard against?*RSLVD*
Author Message
KentC
Brekeke Guru


Joined: 09 Dec 2011
Posts: 108
Location: rw-rw-rw-

PostPosted: Fri Sep 28, 2012 6:58 am    Post subject: SIP Registration Hack Attempt - How to guard against?*RSLVD* Reply with quote

1. Brekeke Product Name and version:
Brekeke Sip Server 2.x
2. Java version:
Jre 1.6
3. OS type and the version:
Centos 5.6
4. UA (phone), gateway or other hardware/software involved:
N/A
5. Select your network pattern from http://www.brekeke-sip.com/bbs/network/networkpatterns.html :
Enterprise
6. Your problem:

Brekeke Community,

Crazy situation.. So we had a hack attempt this morning...The
HeartBeat kept failing on a production server we have traffic on due to a SIP registration hack attempt originating from China. It has been blocked.

My question is do to the ever-growing attempts/attacks like this, how could we better protect ourselves moving forward against hackers like this? I saw the heartbeat go down 3 times till this was found and issue fixed early this morning.

Please advise. Thank you.



Kent C.


Last edited by KentC on Tue Oct 02, 2012 3:08 pm; edited 1 time in total
Back to top
View user's profile
hope
Brekeke Master Guru


Joined: 15 Jan 2008
Posts: 862

PostPosted: Fri Sep 28, 2012 9:16 am    Post subject: Reply with quote

http://wiki.brekeke.com/wiki/Avoid-attacks
Back to top
View user's profile
tuie2
Brekeke Talented


Joined: 23 Jan 2009
Posts: 57

PostPosted: Fri Sep 28, 2012 9:50 am    Post subject: Reply with quote

Also you can set trusted IP addresses in the router.
If you are using unix-like OS (e.g. Linux), tune the iptables to define trusted IP addresses.

https://isc.sans.edu/port.html?port=5060
There are many attacks to the port-5060 everyday.
Back to top
View user's profile
KentC
Brekeke Guru


Joined: 09 Dec 2011
Posts: 108
Location: rw-rw-rw-

PostPosted: Tue Oct 02, 2012 3:07 pm    Post subject: Reply with quote

Thank you for all the advice! I will save for the future since I didn't have a gameplan when this happened.
Back to top
View user's profile
Display posts from previous:   
Post new topic   Reply to topic    Brekeke Forum Index » Brekeke SIP Server Forum All times are GMT - 7 Hours
Page 1 of 1