Can anyone tell me what this means in my CLI? [Jun 27 12:47:44] NOTICE[2177]: chan_sip.c:14418 handle_request_invite: Call from '' to extension '+901148422885410' rejected because extension not found. [Jun 27 12:48:04] WARNING[2177]: chan_sip.c:1964 retrans_pkt: Maximum retries exceeded on transmission 768cac067094ca767d045f9ac57d60d3 for seqno 1 (Critical Response) -- See doc/sip-retransmit.txt. N1XBM*CLI> So I do have to extensions setup one is my tablet (which is off) I also have my cell phone (which I have in airplane mode). Is someone trying to hack my server? Thank you
It is someone trying to get into the sip server of your asterisk server. Sent from my iPhone
On Jun 27, 2014, at 12:59 PM, Robert Newberry <N1XBM@amsat.org> wrote:
Can anyone tell me what this means in my CLI?
[Jun 27 12:47:44] NOTICE[2177]: chan_sip.c:14418 handle_request_invite: Call from '' to extension '+901148422885410' rejected because extension not found. [Jun 27 12:48:04] WARNING[2177]: chan_sip.c:1964 retrans_pkt: Maximum retries exceeded on transmission 768cac067094ca767d045f9ac57d60d3 for seqno 1 (Critical Response) -- See doc/sip-retransmit.txt. N1XBM*CLI>
So I do have to extensions setup one is my tablet (which is off) I also have my cell phone (which I have in airplane mode). Is someone trying to hack my server?
Thank you
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
OK should I be concerned? it seems like it must be some sort of robot or script because it keeps trying the same handful of numbers. Is there anything I can do to stop it? I'd prefer not to turn of SIP since I use it. Thank you for your reply. On Fri, Jun 27, 2014 at 1:01 PM, Corey Dean <n3fe@repeater.net> wrote:
It is someone trying to get into the sip server of your asterisk server.
Sent from my iPhone
On Jun 27, 2014, at 12:59 PM, Robert Newberry <N1XBM@amsat.org> wrote:
Can anyone tell me what this means in my CLI?
[Jun 27 12:47:44] NOTICE[2177]: chan_sip.c:14418 handle_request_invite: Call from '' to extension '+901148422885410' rejected because extension not found. [Jun 27 12:48:04] WARNING[2177]: chan_sip.c:1964 retrans_pkt: Maximum retries exceeded on transmission 768cac067094ca767d045f9ac57d60d3 for seqno 1 (Critical Response) -- See doc/sip-retransmit.txt. N1XBM*CLI>
So I do have to extensions setup one is my tablet (which is off) I also have my cell phone (which I have in airplane mode). Is someone trying to hack my server?
Thank you
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
If you don’t have an outbound PSTN path it should matter too much unless they start hitting you hard which could cause your internet connection and or server to bog down. See http://www.voip-info.org/wiki/view/Fail2Ban+(with+iptables)+And+Asterisk From: app_rpt-users-bounces@ohnosec.org [mailto:app_rpt-users-bounces@ohnosec.org] On Behalf Of Robert Newberry Sent: Friday, June 27, 2014 1:34 PM To: Corey Dean Cc: app_rpt-users@ohnosec.org Subject: Re: [App_rpt-users] CLI help OK should I be concerned? it seems like it must be some sort of robot or script because it keeps trying the same handful of numbers. Is there anything I can do to stop it? I'd prefer not to turn of SIP since I use it. Thank you for your reply. On Fri, Jun 27, 2014 at 1:01 PM, Corey Dean <n3fe@repeater.net <mailto:n3fe@repeater.net> > wrote: It is someone trying to get into the sip server of your asterisk server. Sent from my iPhone
On Jun 27, 2014, at 12:59 PM, Robert Newberry <N1XBM@amsat.org <mailto:N1XBM@amsat.org> > wrote:
Can anyone tell me what this means in my CLI?
[Jun 27 12:47:44] NOTICE[2177]: chan_sip.c:14418 handle_request_invite: Call from '' to extension '+901148422885410' rejected because extension not found. [Jun 27 12:48:04] WARNING[2177]: chan_sip.c:1964 retrans_pkt: Maximum retries exceeded on transmission 768cac067094ca767d045f9ac57d60d3 for seqno 1 (Critical Response) -- See doc/sip-retransmit.txt. N1XBM*CLI>
So I do have to extensions setup one is my tablet (which is off) I also have my cell phone (which I have in airplane mode). Is someone trying to hack my server?
Thank you
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
How about just changing your SIP passwords? -- Tim :wq On Jun 27, 2014, at 10:34 AM, Robert Newberry <N1XBM@amsat.org> wrote:
OK should I be concerned? it seems like it must be some sort of robot or script because it keeps trying the same handful of numbers. Is there anything I can do to stop it? I'd prefer not to turn of SIP since I use it.
Thank you for your reply.
On Fri, Jun 27, 2014 at 1:01 PM, Corey Dean <n3fe@repeater.net> wrote: It is someone trying to get into the sip server of your asterisk server.
Sent from my iPhone
On Jun 27, 2014, at 12:59 PM, Robert Newberry <N1XBM@amsat.org> wrote:
Can anyone tell me what this means in my CLI?
[Jun 27 12:47:44] NOTICE[2177]: chan_sip.c:14418 handle_request_invite: Call from '' to extension '+901148422885410' rejected because extension not found. [Jun 27 12:48:04] WARNING[2177]: chan_sip.c:1964 retrans_pkt: Maximum retries exceeded on transmission 768cac067094ca767d045f9ac57d60d3 for seqno 1 (Critical Response) -- See doc/sip-retransmit.txt. N1XBM*CLI>
So I do have to extensions setup one is my tablet (which is off) I also have my cell phone (which I have in airplane mode). Is someone trying to hack my server?
Thank you
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
So I've implemented the changes people suggested except for fail2ban. I'm still reading up on it. I also didn't change passwords because that hasn't been compromised someone is fishing around looking for an outside line. Also someone mentioned checking a messages folder. Is it OK to clear out that file? It goes back to May. I'll keep you guys posted on how it goes. I'll be monitoring the server over the weekend.
'allowguest=no' is sip.conf ( http://www.voip-info.org/wiki/view/Asterisk+sip+allowguest) is definitely something you want to have set in this case. The malicious request most likely didn't circumvent the security of your system. The attacker only tried to probe port 5060 with a SIP INVITE to see if you were allowing unauthenticated calling to international numbers. In my opinion it's best to block all inbound traffic to port 5060 (UDP) with iptables, and add pass rules for intended hosts (unless that isn't possible because your sip clients bounce around on different networks with varying IPs). On Fri, Jun 27, 2014 at 3:04 PM, Robert Newberry <N1XBM@amsat.org> wrote:
So I've implemented the changes people suggested except for fail2ban. I'm still reading up on it.
I also didn't change passwords because that hasn't been compromised someone is fishing around looking for an outside line.
Also someone mentioned checking a messages folder. Is it OK to clear out that file? It goes back to May.
I'll keep you guys posted on how it goes. I'll be monitoring the server over the weekend.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
-- Andrew Sylthe KC9ONA
Someone is maliciously trying to dial international numbers through your system. On Friday, June 27, 2014, Robert Newberry <N1XBM@amsat.org> wrote:
Can anyone tell me what this means in my CLI?
[Jun 27 12:47:44] NOTICE[2177]: chan_sip.c:14418 handle_request_invite: Call from '' to extension '+901148422885410' rejected because extension not found. [Jun 27 12:48:04] WARNING[2177]: chan_sip.c:1964 retrans_pkt: Maximum retries exceeded on transmission 768cac067094ca767d045f9ac57d60d3 for seqno 1 (Critical Response) -- See doc/sip-retransmit.txt. N1XBM*CLI>
So I do have to extensions setup one is my tablet (which is off) I also have my cell phone (which I have in airplane mode). Is someone trying to hack my server?
Thank you
-- Andrew Sylthe KC9ONA
participants (5)
-
Andrew Sylthe -
Corey Dean -
Robert Newberry -
Scott Weis -
Tim Sawyer