[asterisk-users] Find a way to block brute force attacks.

Zeeshan Zakaria zishanov at gmail.com
Tue Jun 29 12:38:20 CDT 2010


If I didn't have fail2ban, I would have way over 20k of these entries in my
asterisk log.

Zeeshan A Zakaria

--
www.ilovetovoip.com

On 2010-06-29 1:36 PM, "Rodrigo Lang" <rodrigoferreiralang at gmail.com> wrote:

Good afternoon.

Thanks to everyone for answers. What I find strange is the asterisk does not
have any native tool for him to SIP server security. Here's an example of
the syslog messages from asterisk:

[Jun 15 03:05:46] NOTICE [25284] chan_sip.c: Registration from '"213"
<sip:213 at my_extern_ip>' failed for '116 .124.128.82 '- Wrong password
[Jun 15 03:05:46] NOTICE [25284] chan_sip.c: Registration from '"213"
<sip:213 at my_extern_ip>' failed for '116 .124.128.82 '- Wrong password
[Jun 15 03:05:46] NOTICE [25284] chan_sip.c: Registration from '"213"
<sip:213 at my_extern_ip>' failed for '116 .124.128.82 '- Wrong password
[Jun 15 03:05:46] NOTICE [25284] chan_sip.c: Registration from '"213"
<sip:213 at my_extern_ip>' failed for '116 .124.128.82 '- Wrong password
[Jun 15 03:05:46] NOTICE [25284] chan_sip.c: Registration from '"213"
<sip:213 at my_extern_ip>' failed for '116 .124.128.82 '- Wrong password
[Jun 15 03:05:46] NOTICE [25284] chan_sip.c: Registration from '"213"
<sip:213 at my_extern_ip>' failed for '116 .124.128.82 '- Wrong password
[Jun 15 03:05:46] NOTICE [25284] chan_sip.c: Registration from '"213"
<sip:213 at my_extern_ip>' failed for '116 .124.128.82 '- Wrong password
[Jun 15 03:05:46] NOTICE [25284] chan_sip.c: Registration from '"213"
<sip:213 at my_extern_ip>' failed for '116 .124.128.82 '- Wrong password



More information about the asterisk-users mailing list