SIP Attack?
Posted: Sun Feb 27, 2011 10:19 pm
This situation is happening quite often and I really have no idea how dangerous it can be. Anyone knows what is it, how to detect it and how to fight against it?
data:image/s3,"s3://crabby-images/36e00/36e004acc8aee82915c2e0689300db77d7239a4a" alt="Image"
data:image/s3,"s3://crabby-images/36e00/36e004acc8aee82915c2e0689300db77d7239a4a" alt="Image"
I see a LOT of SIP scanning activity now days on public IP ranges.
One trick we do is pickup any IPs trying to connect to things they shouldnt (like core routers) on port 5060 or 5061 and add them to a banned list for a minimun of 12 hours.
If you do this on your internet gateway its a good way to stop some of this "rubbish traffic"
We even leave an IP or two in our customer ranges as "Honeypot IPs" to do the same thing.
This can of course be applied for people scanning for SSH etc as well..
Just a side note, as for dangerous it can be very dangerous! we have thousands of dollars lost when hackers compromised our voip system and abused it...
Cheers
I have spent couple of days, having studied a subject and other branches of a forum, haven't found the ready solution, have as a result made itself thus.Can you please post the rules used?
/ip firewall filter
add action=drop chain=input comment="Drop brute forcers" in-interface=ether1-gateway src-address-list=bf_blacklist
add action=drop chain=forward comment="Drop brute forcers - fw" in-interface=ether1-gateway src-address-list=bf_blacklist
add action=add-dst-to-address-list address-list=bf_blacklist address-list-timeout=15m chain=forward comment="BF detect 6 - sip - fw - add to block" content="SIP/2.0 401 Unauthorized" \
dst-address-list=bf_sip_stage5 in-interface=bridge-local log-prefix="BLOCK SIP FW BF" protocol=udp src-address=192.168.1.234 src-port=5060-5069
add action=add-dst-to-address-list address-list=bf_sip_stage5 address-list-timeout=1m chain=forward comment="BF detect 5 - sip - fw" content="SIP/2.0 401 Unauthorized" \
dst-address-list=bf_sip_stage4 in-interface=bridge-local protocol=udp src-address=192.168.1.234 src-port=5060-5069
add action=add-dst-to-address-list address-list=bf_sip_stage4 address-list-timeout=1m chain=forward comment="BF detect 4 - sip - fw" content="SIP/2.0 401 Unauthorized" \
dst-address-list=bf_sip_stage3 in-interface=bridge-local protocol=udp src-address=192.168.1.234 src-port=5060-5069
add action=add-dst-to-address-list address-list=bf_sip_stage3 address-list-timeout=1m chain=forward comment="BF detect 3 - sip - fw" content="SIP/2.0 401 Unauthorized" \
dst-address-list=bf_sip_stage2 in-interface=bridge-local protocol=udp src-address=192.168.1.234 src-port=5060-5069
add action=add-dst-to-address-list address-list=bf_sip_stage2 address-list-timeout=1m chain=forward comment="BF detect 2 - sip - fw" content="SIP/2.0 401 Unauthorized" \
dst-address-list=bf_sip_stage1 in-interface=bridge-local protocol=udp src-address=192.168.1.234 src-port=5060-5069
add action=add-dst-to-address-list address-list=bf_sip_stage1 address-list-timeout=1m chain=forward comment="BF detect 1 - sip - fw" content="SIP/2.0 401 Unauthorized" \
dst-address-list=!sip-auth in-interface=bridge-local protocol=udp src-address=192.168.1.234 src-port=5060-5069
add action=add-dst-to-address-list address-list=bf_blacklist address-list-timeout=15m chain=forward comment="BF detect 6 - sip - fw2 - add to block" content="SIP/2.0 404 Not Found" \
dst-address-list=bf_sip_stage5 in-interface=bridge-local log-prefix="BLOCK SIP FW BF" protocol=udp src-address=192.168.1.234 src-port=5060-5069
add action=add-dst-to-address-list address-list=bf_sip_stage5 address-list-timeout=1m chain=forward comment="BF detect 5 - sip - fw2" content="SIP/2.0 404 Not Found" dst-address-list=\
bf_sip_stage4 in-interface=bridge-local protocol=udp src-address=192.168.1.234 src-port=5060-5069
add action=add-dst-to-address-list address-list=bf_sip_stage4 address-list-timeout=1m chain=forward comment="BF detect 4 - sip - fw2" content="SIP/2.0 404 Not Found" dst-address-list=\
bf_sip_stage3 in-interface=bridge-local protocol=udp src-address=192.168.1.234 src-port=5060-5069
add action=add-dst-to-address-list address-list=bf_sip_stage3 address-list-timeout=1m chain=forward comment="BF detect 3 - sip - fw2" content="SIP/2.0 404 Not Found" dst-address-list=\
bf_sip_stage2 in-interface=bridge-local protocol=udp src-address=192.168.1.234 src-port=5060-5069
add action=add-dst-to-address-list address-list=bf_sip_stage2 address-list-timeout=1m chain=forward comment="BF detect 2 - sip - fw2" content="SIP/2.0 404 Not Found" dst-address-list=\
bf_sip_stage1 in-interface=bridge-local protocol=udp src-address=192.168.1.234 src-port=5060-5069
add action=add-dst-to-address-list address-list=bf_sip_stage1 address-list-timeout=1m chain=forward comment="BF detect 1 - sip - fw2" content="SIP/2.0 404 Not Found" dst-address-list=\
!sip-auth in-interface=bridge-local protocol=udp src-address=192.168.1.234 src-port=5060-5069