[asterisk-users] asterisk security....again

2011-02-28 Thread Rizwan Hisham
Hi all, The problem I have been experiencing since last month is that some of my customers are getting calls with Asterisk Unknown caller id. Most of them in the middle of the night. And my asterisk server has no record of these calls. The customers were getting irritated as you can imagine. I

Re: [asterisk-users] asterisk security....again

2011-02-28 Thread Steven Howes
On 28 Feb 2011, at 10:33, Rizwan Hisham wrote: The problem I have been experiencing since last month is that some of my customers are getting calls with Asterisk Unknown caller id. Most of them in the middle of the night. And my asterisk server has no record of these calls. The customers

Re: [asterisk-users] asterisk security....again

2011-02-28 Thread A J Stiles
On Monday 28 Feb 2011, Steven Howes wrote: 'asterisk security' is a misleading subject line. Guessing someone just scanned some IP addresses and made calls. You need what's called a 'firewall'. Well, assuming you're on Linux then you've already *got* a firewall. Just add some iptables rules

Re: [asterisk-users] asterisk security....again

2011-02-28 Thread Ricardo Carvalho
Probably, you are receiving INVITE attacks from some tool like sipvicious. You should rearange your network to cover some inportant security issues. The IP address of you server can be revealed in some unincrypted SIP signaling of some call through the Internet to/from your server's client, or

Re: [asterisk-users] asterisk security....again

2011-02-28 Thread Rizwan Hisham
thanks for the replies. I dont want to rule-out the possibility of network sniffing. I am sure its not an inside job. The server is off-site and is hosted by a very well reputed hosting company. So if someone is sniffing, what should I do? Probably, you are receiving INVITE attacks from some

Re: [asterisk-users] asterisk security....again

2011-02-28 Thread Terry Brummell
...@lists.digium.com [mailto:asterisk-users-boun...@lists.digium.com] On Behalf Of Ricardo Carvalho Sent: Monday, February 28, 2011 6:31 AM To: Asterisk Users Mailing List - Non-Commercial Discussion Subject: Re: [asterisk-users] asterisk securityagain Probably, you are receiving INVITE

Re: [asterisk-users] asterisk security....again

2011-02-28 Thread Rizwan Hisham
] asterisk securityagain Probably, you are receiving INVITE attacks from some tool like sipvicious. You should rearange your network to cover some inportant security issues. The IP address of you server can be revealed in some unincrypted SIP signaling of some call through the Internet

Re: [asterisk-users] asterisk security....again

2011-02-28 Thread Rizwan Hisham
-users] asterisk securityagain Probably, you are receiving INVITE attacks from some tool like sipvicious. You should rearange your network to cover some inportant security issues. The IP address of you server can be revealed in some unincrypted SIP signaling of some call through

Re: [asterisk-users] asterisk security....again

2011-02-28 Thread Kevin P. Fleming
On 02/28/2011 07:27 AM, Rizwan Hisham wrote: Any suggestions on encrypting the sip and rtp. I have done some googling on it. looks like it is not supported by most end point devices or service providers. But still your thoughts will be appreciated on this subject. You cannot protect a remote

Re: [asterisk-users] asterisk security....again

2011-02-28 Thread Rizwan Hisham
Thanks Mr. Kevin. Can anyone please also tell me which firewall is best suited for asterisk/sip attack prevention. Is there any firewall built specially to address sip security problems? On Mon, Feb 28, 2011 at 6:38 PM, Kevin P. Fleming kpflem...@digium.comwrote: On 02/28/2011 07:27 AM, Rizwan

Re: [asterisk-users] asterisk security....again

2011-02-28 Thread Jamie A. Stapleton
] asterisk securityagain Thanks Mr. Kevin. Can anyone please also tell me which firewall is best suited for asterisk/sip attack prevention. Is there any firewall built specially to address sip security problems? On Mon, Feb 28, 2011 at 6:38 PM, Kevin P. Fleming kpflem...@digium.commailto:kpflem

Re: [asterisk-users] asterisk security....again

2011-02-28 Thread satish patel
...@computer-business.com To: asterisk-users@lists.digium.com Date: Mon, 28 Feb 2011 10:27:33 -0500 Subject: Re: [asterisk-users] asterisk securityagain http://sipera.com/ is one such product. From: asterisk-users-boun...@lists.digium.com [mailto:asterisk-users-boun...@lists.digium.com] On Behalf