Go Back   Wireless and Wifi Forums > News > Newsgroups > uk.telecom.voip
Register FAQ Forum Rules Members List Calendar Search Today's Posts Advertise Mark Forums Read

 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 11-09-2010, 07:17 AM
Gordon Henderson
Guest
 
Posts: n/a
Default Re: SIP attacks on SPA

In article <710id6t3q5hdome9d0rqcnimulqve5e13l@4ax.com>,
Mark <mark_news@ymail.com> wrote:
>Anyone else had an increasing number of SIP attacks on their ATA?
>
>Symptom was a series of reboots of my SPA3102 typically between 9pm
>and 11pm (I heard the PSTN relay clicking unexpectedly).
>
>Delving into the logs there were brute force SIP attacks followed by
>soft reboots on "out of memory" errors. It turns out this was
>happening several times per day.
>
>Fixed by restricting allowed IP to my service provider domain which is
>a severe clamp-down but no real problem for my usage.


Criminals the world over are constantly trying to steal resources from
VoIP systems. This is no surprise, and it would not surprise me if once
they have access to your ATA, they can then extract the SIP account
credentials and use it for their own uses.

What I do find surprising is that your ATA is accessable from the
public Internet - are you port-forwarding to it, or is it on a dedicated
IP address?

If you don't need to port-forward to it, then don't...

Gordon

Reply With Quote
  #2 (permalink)  
Old 11-09-2010, 08:49 AM
Brian A
Guest
 
Posts: n/a
Default Re: SIP attacks on SPA

On Tue, 09 Nov 2010 08:25:03 +0000, Mark wrote:

> On Tue, 9 Nov 2010 08:17:51 +0000 (UTC), Gordon Henderson
> <gordon+usenet@drogon.net> wrote:
>
>>In article <710id6t3q5hdome9d0rqcnimulqve5e13l@4ax.com>, Mark
>><mark_news@ymail.com> wrote:
>>>Anyone else had an increasing number of SIP attacks on their ATA?
>>>
>>>Symptom was a series of reboots of my SPA3102 typically between 9pm
>>>and 11pm (I heard the PSTN relay clicking unexpectedly).
>>>
>>>Delving into the logs there were brute force SIP attacks followed by
>>>soft reboots on "out of memory" errors. It turns out this was
>>>happening several times per day.
>>>
>>>Fixed by restricting allowed IP to my service provider domain which is
>>>a severe clamp-down but no real problem for my usage.

>>
>>Criminals the world over are constantly trying to steal resources from
>>VoIP systems. This is no surprise, and it would not surprise me if once
>>they have access to your ATA, they can then extract the SIP account
>>credentials and use it for their own uses.
>>
>>What I do find surprising is that your ATA is accessable from the public
>>Internet - are you port-forwarding to it, or is it on a dedicated IP
>>address?

>
> It's behind a home router with a private IP address :(
>
>
>>If you don't need to port-forward to it, then don't...

>
> I don't...

So, I'd be interested to know the mechanism of how this can be done when
these is no port forwarding.

Also, how do you restrict to just your ISP?
Is this in your router or somewhere in the SPA?

--
Remove 'no_spam_' from email address.
Running Linux Ubuntu 10.04 LTS (Long term Support). Very customisable,
secure,not sluggish, and streets ahead of that other mainstream operating
system. PAN newsreader has filters to get rid of spam.

Reply With Quote
  #3 (permalink)  
Old 11-09-2010, 08:31 PM
Graham.
Guest
 
Posts: n/a
Default Re: SIP attacks on SPA


> Looking more deeply, the ALG (appl layer gateway) was enabled on the
> router - the router configuration was set with the SIP ALG enabled by
> default.

is dead.)

Would that be a Netgear router?
My understanding is the Netgear implementation of SIP ALG is fundamentally flawed, and it's best left disabled.
Whether hackers can exploit the flaw as such, I have no idea.
--
Graham.

%Profound_observation%



Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
China not behind Google attacks says Cyber security expert n3td3v alt.computer.security 0 01-16-2010 04:21 AM
A Free Guide On Web Application Security - Best Ways to MinimizePrevalent Risk of Attacks Mike alt.computer.security 0 03-27-2009 10:43 AM
Attacks prompt third parties to fix flaw imhotep comp.security.misc 0 10-03-2006 05:02 AM
More zero-day attacks plague Microsoft users imhotep comp.security.misc 0 10-01-2006 04:34 AM


All times are GMT. The time now is 08:57 PM.



Powered by vBulletin® Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.6.0 PL2

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45