I saw in my call detail records a block of about 50 call attempts made within 2 minutes minutes of each other to international numbers, and using a variety of prefixes. All calls showed the status "failed", so I presume they did not connect. The from field was "sip". Here is an example:
sip 9011441383417547 2/13/10 5:02 AM 0 seconds Failed My guess is that my server was being probed to see if it could be hijacked for free calls. Does that seem right? What exactly does it mean to have "sip" as the From? Is there a checklist for security measures to ensure that an installation is reasonably protected from such attempts? Thanks, Jeff _______________________________________________ sipx-users mailing list [email protected] List Archive: http://list.sipfoundry.org/archive/sipx-users Unsubscribe: http://list.sipfoundry.org/mailman/listinfo/sipx-users sipXecs IP PBX -- http://www.sipfoundry.org/
