{"id":248,"date":"2010-12-03T16:44:38","date_gmt":"2010-12-03T22:44:38","guid":{"rendered":"http:\/\/bozhidar.maramski.com\/?p=248"},"modified":"2010-12-03T16:51:28","modified_gmt":"2010-12-03T22:51:28","slug":"sip-brute-force-attack","status":"publish","type":"post","link":"https:\/\/bogi.maramski.com\/?p=248","title":{"rendered":"SIP brute force attack"},"content":{"rendered":"<p>\u00d0\u201d\u00d0\u00bd\u00d0\u00b5\u00d1\u0081 \u00d1\u2026\u00d0\u00b2\u00d0\u00b0\u00d0\u00bd\u00d0\u00b0\u00d1\u2026 \u00d0\u00ba\u00d0\u00b0\u00d0\u00ba \u00d0\u00bd\u00d0\u00b8 \u00d0\u00be\u00d0\u00bf\u00d0\u00b8\u00d1\u201a\u00d0\u00b2\u00d0\u00b0\u00d1\u201a SIP brute force attack.<br \/>\n\u00d0\u00a1\u00d0\u00bb\u00d1\u0192\u00d1\u2021\u00d0\u00b0\u00d0\u00b9\u00d0\u00bd\u00d0\u00be \u00d0\u00bf\u00d0\u00be\u00d0\u00b3\u00d0\u00bb\u00d0\u00b5\u00d0\u00b4\u00d0\u00bd\u00d0\u00b0\u00d1\u2026 \u00d0\u00b2 \u00d0\u00b0\u00d1\u0081\u00d1\u201a\u00d0\u00b5\u00d1\u20ac\u00d0\u00b8\u00d1\u0081\u00d0\u00ba\u00d0\u00b0 \u00d0\u00b8 \u00d0\u00b2\u00d0\u00b8\u00d0\u00b4\u00d1\u008f\u00d1\u2026 \u00d1\u2021\u00d0\u00b5 \u00d1\u0081\u00d0\u00b5 \u00d0\u00bf\u00d1\u20ac\u00d0\u00be\u00d0\u00b1\u00d0\u00b2\u00d0\u00b0\u00d1\u201a \u00d1\u0081 \u00d0\u00bf\u00d0\u00b0\u00d1\u20ac\u00d0\u00be\u00d0\u00bb\u00d0\u00b8 \u00d0\u00b4\u00d0\u00b0 \u00d1\u0081\u00d0\u00b5 \u00d0\u00bb\u00d0\u00be\u00d0\u00b3\u00d0\u00bd\u00d0\u00b0\u00d1\u201a \u00d0\u00bd\u00d0\u00b0 \u00d0\u00b5\u00d0\u00ba\u00d1\u0081\u00d1\u201a\u00d0\u00b5\u00d0\u00bd\u00d1\u02c6\u00d1\u0160\u00d0\u00bd\u00d0\u00b8\u00d1\u201a\u00d0\u00b5 116 \u00d0\u00b8 \u00d0\u00b4\u00d1\u20ac. \u00d0\u2019\u00d1\u0081\u00d1\u0160\u00d1\u2030\u00d0\u00bd\u00d0\u00be\u00d1\u0081\u00d1\u201a \u00d0\u00bd\u00d0\u00b5 \u00d0\u00b1\u00d0\u00b5\u00d1\u02c6\u00d0\u00b5 \u00d1\u0081\u00d0\u00bb\u00d1\u0192\u00d1\u2021\u00d0\u00b0\u00d0\u00b9\u00d0\u00bd\u00d0\u00be \u00d0\u00b7\u00d0\u00b0\u00d1\u2030\u00d0\u00be\u00d1\u201a\u00d0\u00be \u00d1\u201a\u00d1\u0160\u00d1\u20ac\u00d1\u0081\u00d0\u00b5\u00d1\u2026 \u00d0\u00bf\u00d1\u20ac\u00d0\u00b8\u00d1\u2021\u00d0\u00b8\u00d0\u00bd\u00d0\u00b0 \u00d0\u00b7\u00d0\u00b0 \u00d1\u0081\u00d0\u00bb\u00d0\u00b0\u00d0\u00b1\u00d0\u00b8\u00d1\u008f \u00d1\u0160\u00d0\u00bf\u00d0\u00bb\u00d0\u00be\u00d1\u0192\u00d0\u00b4 \u00d1\u201a\u00d0\u00b5\u00d0\u00b7\u00d0\u00b8 \u00d0\u00b4\u00d0\u00bd\u00d0\u00b8. \u00d0\u00a3\u00d1\u201a\u00d1\u20ac\u00d0\u00b5 \u00d1\u0081\u00d0\u00bb\u00d0\u00b5\u00d0\u00b4 \u00d0\u00be\u00d0\u00b1\u00d1\u008f\u00d0\u00b4 Comcast \u00d1\u2030\u00d0\u00b5 \u00d0\u00bf\u00d1\u20ac\u00d0\u00b0\u00d1\u201a\u00d1\u008f\u00d1\u201a \u00d1\u201a\u00d0\u00b5\u00d1\u2026\u00d0\u00bd\u00d0\u00b8\u00d0\u00ba \u00d0\u00bd\u00d0\u00b0 \u00d0\u00bc\u00d1\u008f\u00d1\u0081\u00d1\u201a\u00d0\u00be \u00d0\u00b7\u00d0\u00b0\u00d1\u2030\u00d0\u00be\u00d1\u201a\u00d0\u00be \u00d1\u0160\u00d0\u00bf\u00d0\u00bb\u00d0\u00be\u00d1\u0192\u00d0\u00b4\u00d0\u00b0 \u00d0\u00b5\u00d0\u00b4\u00d0\u00b2\u00d0\u00b0 \u00d0\u00b4\u00d0\u00be\u00d1\u0081\u00d1\u201a\u00d0\u00b8\u00d0\u00b3\u00d0\u00b0 300\u00d0\u00ba\u00d0\u00b1\u00d0\u00bf\u00d1\u0081.<\/p>\n<p>\u00d0\u00a1\u00d0\u00bf\u00d0\u00be\u00d0\u00bc\u00d0\u00bd\u00d0\u00b8\u00d1\u2026 \u00d1\u0081\u00d0\u00b8 \u00d1\u2021\u00d0\u00b5 \u00d0\u00b8\u00d0\u00bc\u00d0\u00b0\u00d1\u2026 \u00d0\u00b8\u00d0\u00bd\u00d1\u0081\u00d1\u201a\u00d0\u00b0\u00d0\u00bb\u00d0\u00b8\u00d1\u20ac\u00d0\u00b0\u00d0\u00bd fail2ban \u00d0\u00bd\u00d0\u00be \u00d1\u0081\u00d0\u00b5 \u00d0\u00be\u00d0\u00ba\u00d0\u00b0\u00d0\u00b7\u00d0\u00b0 \u00d1\u2021\u00d0\u00b5 \u00d0\u00bd\u00d0\u00b5 \u00d1\u20ac\u00d0\u00b0\u00d0\u00b1\u00d0\u00be\u00d1\u201a\u00d0\u00b8 \u00d1\u0081 \u00d0\u00b0\u00d1\u0081\u00d1\u201a\u00d0\u00b5\u00d1\u20ac\u00d0\u00b8\u00d1\u0081\u00d0\u00ba.<br \/>\n\u00d0\u0178\u00d0\u00be\u00d1\u0081\u00d0\u00bb\u00d0\u00b5 \u00d0\u00bf\u00d0\u00be <a href=\"http:\/\/www.voip-info.org\/wiki\/view\/Fail2Ban+%28with+iptables%29+And+Asterisk\">\u00d1\u0081\u00d0\u00bb\u00d0\u00b5\u00d0\u00b4\u00d0\u00bd\u00d0\u00be\u00d1\u201a\u00d0\u00be<\/a> \u00d1\u2026\u00d0\u00be\u00d1\u0192\u00d1\u201a\u00d0\u00be \u00d0\u00ba\u00d0\u00be\u00d0\u00bd\u00d1\u201e\u00d0\u00b8\u00d0\u00b3\u00d1\u0192\u00d1\u20ac\u00d0\u00b8\u00d1\u20ac\u00d0\u00b0\u00d1\u2026 fail2ban \u00d0\u00b7\u00d0\u00b0 \u00d1\u20ac\u00d0\u00b0\u00d0\u00b1\u00d0\u00be\u00d1\u201a\u00d0\u00b0 \u00d1\u0081 \u00d0\u00b0\u00d1\u0081\u00d1\u201a\u00d0\u00b5\u00d1\u20ac\u00d0\u00b8\u00d1\u0081\u00d0\u00ba\u00d0\u00b0.<\/p>\n<p>\u00d0\u00a1\u00d0\u00bb\u00d0\u00b5\u00d0\u00b4 \u00d0\u00ba\u00d0\u00b0\u00d1\u201a\u00d0\u00be \u00d0\u00b3\u00d0\u00be \u00d0\u00ba\u00d0\u00be\u00d0\u00bd\u00d1\u201e\u00d0\u00b8\u00d0\u00b3\u00d1\u0192\u00d1\u20ac\u00d0\u00b8\u00d1\u20ac\u00d0\u00b0\u00d1\u2026 \u00d0\u00b8 \u00d1\u20ac\u00d0\u00b5\u00d1\u0081\u00d1\u201a\u00d0\u00b0\u00d1\u20ac\u00d1\u201a\u00d0\u00b8\u00d1\u20ac\u00d0\u00b0\u00d1\u2026 \u00d0\u00b2\u00d0\u00b5\u00d0\u00b4\u00d0\u00bd\u00d0\u00b0\u00d0\u00b3\u00d0\u00b0 \u00d1\u0081\u00d0\u00b8 \u00d0\u00bd\u00d0\u00b0\u00d0\u00bc\u00d0\u00b5\u00d1\u20ac\u00d0\u00b8 \u00d0\u00b2\u00d1\u0160\u00d0\u00bf\u00d1\u20ac\u00d0\u00be\u00d1\u0081\u00d0\u00bd\u00d0\u00be\u00d1\u201a\u00d0\u00be \u00d0\u00b0\u00d0\u00b8-\u00d0\u00bf\u00d0\u00b8 \ud83d\ude42<\/p>\n<p>[root@triton filter.d]# [root@triton filter.d]# iptables -L -v<br \/>\n pkts bytes target     prot opt in     out     source               destination<br \/>\n   24  1528 fail2ban-ssh  tcp  &#8212;  any    any     anywhere             anywhere            multiport dports ssh<br \/>\n 4002  867K fail2ban-ASTERISK  all  &#8212;  any    any     anywhere             anywhere<br \/>\n84913   31M DROP       all  &#8212;  any    any     server88-208-211-73.live-servers.net  anywhere<\/p>\n<p>\u00d0\u009d\u00d0\u00b0\u00d0\u00b7\u00d0\u00b4\u00d1\u20ac\u00d0\u00b0\u00d0\u00b2\u00d0\u00b5 \ud83d\ude42<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u00d0\u201d\u00d0\u00bd\u00d0\u00b5\u00d1\u0081 \u00d1\u2026\u00d0\u00b2\u00d0\u00b0\u00d0\u00bd\u00d0\u00b0\u00d1\u2026 \u00d0\u00ba\u00d0\u00b0\u00d0\u00ba \u00d0\u00bd\u00d0\u00b8 \u00d0\u00be\u00d0\u00bf\u00d0\u00b8\u00d1\u201a\u00d0\u00b2\u00d0\u00b0\u00d1\u201a SIP brute force attack. \u00d0\u00a1\u00d0\u00bb\u00d1\u0192\u00d1\u2021\u00d0\u00b0\u00d0\u00b9\u00d0\u00bd\u00d0\u00be \u00d0\u00bf\u00d0\u00be\u00d0\u00b3\u00d0\u00bb\u00d0\u00b5\u00d0\u00b4\u00d0\u00bd\u00d0\u00b0\u00d1\u2026 \u00d0\u00b2 \u00d0\u00b0\u00d1\u0081\u00d1\u201a\u00d0\u00b5\u00d1\u20ac\u00d0\u00b8\u00d1\u0081\u00d0\u00ba\u00d0\u00b0 \u00d0\u00b8 \u00d0\u00b2\u00d0\u00b8\u00d0\u00b4\u00d1\u008f\u00d1\u2026 \u00d1\u2021\u00d0\u00b5 \u00d1\u0081\u00d0\u00b5 \u00d0\u00bf\u00d1\u20ac\u00d0\u00be\u00d0\u00b1\u00d0\u00b2\u00d0\u00b0\u00d1\u201a \u00d1\u0081 \u00d0\u00bf\u00d0\u00b0\u00d1\u20ac\u00d0\u00be\u00d0\u00bb\u00d0\u00b8 \u00d0\u00b4\u00d0\u00b0 \u00d1\u0081\u00d0\u00b5 \u00d0\u00bb\u00d0\u00be\u00d0\u00b3\u00d0\u00bd\u00d0\u00b0\u00d1\u201a \u00d0\u00bd\u00d0\u00b0 \u00d0\u00b5\u00d0\u00ba\u00d1\u0081\u00d1\u201a\u00d0\u00b5\u00d0\u00bd\u00d1\u02c6\u00d1\u0160\u00d0\u00bd\u00d0\u00b8\u00d1\u201a\u00d0\u00b5 116 \u00d0\u00b8 \u00d0\u00b4\u00d1\u20ac. \u00d0\u2019\u00d1\u0081\u00d1\u0160\u00d1\u2030\u00d0\u00bd\u00d0\u00be\u00d1\u0081\u00d1\u201a \u00d0\u00bd\u00d0\u00b5 \u00d0\u00b1\u00d0\u00b5\u00d1\u02c6\u00d0\u00b5 \u00d1\u0081\u00d0\u00bb\u00d1\u0192\u00d1\u2021\u00d0\u00b0\u00d0\u00b9\u00d0\u00bd\u00d0\u00be \u00d0\u00b7\u00d0\u00b0\u00d1\u2030\u00d0\u00be\u00d1\u201a\u00d0\u00be \u00d1\u201a\u00d1\u0160\u00d1\u20ac\u00d1\u0081\u00d0\u00b5\u00d1\u2026 \u00d0\u00bf\u00d1\u20ac\u00d0\u00b8\u00d1\u2021\u00d0\u00b8\u00d0\u00bd\u00d0\u00b0 \u00d0\u00b7\u00d0\u00b0 \u00d1\u0081\u00d0\u00bb\u00d0\u00b0\u00d0\u00b1\u00d0\u00b8\u00d1\u008f \u00d1\u0160\u00d0\u00bf\u00d0\u00bb\u00d0\u00be\u00d1\u0192\u00d0\u00b4 \u00d1\u201a\u00d0\u00b5\u00d0\u00b7\u00d0\u00b8 \u00d0\u00b4\u00d0\u00bd\u00d0\u00b8. \u00d0\u00a3\u00d1\u201a\u00d1\u20ac\u00d0\u00b5 \u00d1\u0081\u00d0\u00bb\u00d0\u00b5\u00d0\u00b4 \u00d0\u00be\u00d0\u00b1\u00d1\u008f\u00d0\u00b4 Comcast \u00d1\u2030\u00d0\u00b5 \u00d0\u00bf\u00d1\u20ac\u00d0\u00b0\u00d1\u201a\u00d1\u008f\u00d1\u201a \u00d1\u201a\u00d0\u00b5\u00d1\u2026\u00d0\u00bd\u00d0\u00b8\u00d0\u00ba \u00d0\u00bd\u00d0\u00b0 \u00d0\u00bc\u00d1\u008f\u00d1\u0081\u00d1\u201a\u00d0\u00be \u00d0\u00b7\u00d0\u00b0\u00d1\u2030\u00d0\u00be\u00d1\u201a\u00d0\u00be \u00d1\u0160\u00d0\u00bf\u00d0\u00bb\u00d0\u00be\u00d1\u0192\u00d0\u00b4\u00d0\u00b0 \u00d0\u00b5\u00d0\u00b4\u00d0\u00b2\u00d0\u00b0 \u00d0\u00b4\u00d0\u00be\u00d1\u0081\u00d1\u201a\u00d0\u00b8\u00d0\u00b3\u00d0\u00b0 300\u00d0\u00ba\u00d0\u00b1\u00d0\u00bf\u00d1\u0081. \u00d0\u00a1\u00d0\u00bf\u00d0\u00be\u00d0\u00bc\u00d0\u00bd\u00d0\u00b8\u00d1\u2026 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[15],"tags":[],"class_list":["post-248","post","type-post","status-publish","format-standard","hentry","category-voip"],"_links":{"self":[{"href":"https:\/\/bogi.maramski.com\/index.php?rest_route=\/wp\/v2\/posts\/248"}],"collection":[{"href":"https:\/\/bogi.maramski.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bogi.maramski.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bogi.maramski.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bogi.maramski.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=248"}],"version-history":[{"count":5,"href":"https:\/\/bogi.maramski.com\/index.php?rest_route=\/wp\/v2\/posts\/248\/revisions"}],"predecessor-version":[{"id":262,"href":"https:\/\/bogi.maramski.com\/index.php?rest_route=\/wp\/v2\/posts\/248\/revisions\/262"}],"wp:attachment":[{"href":"https:\/\/bogi.maramski.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=248"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bogi.maramski.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=248"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bogi.maramski.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=248"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}