You can subscribe to this list here.
2008 |
Jan
|
Feb
|
Mar
(41) |
Apr
(35) |
May
(18) |
Jun
(5) |
Jul
(4) |
Aug
(37) |
Sep
(9) |
Oct
(20) |
Nov
(50) |
Dec
(217) |
---|---|---|---|---|---|---|---|---|---|---|---|---|
2009 |
Jan
(212) |
Feb
(76) |
Mar
(113) |
Apr
(88) |
May
(130) |
Jun
(54) |
Jul
(208) |
Aug
(223) |
Sep
(112) |
Oct
(63) |
Nov
(131) |
Dec
(103) |
2010 |
Jan
(247) |
Feb
(130) |
Mar
(43) |
Apr
(92) |
May
(40) |
Jun
(43) |
Jul
(43) |
Aug
(80) |
Sep
(44) |
Oct
(74) |
Nov
(21) |
Dec
(46) |
2011 |
Jan
(36) |
Feb
(11) |
Mar
(21) |
Apr
(33) |
May
(4) |
Jun
(12) |
Jul
(5) |
Aug
(20) |
Sep
|
Oct
(64) |
Nov
(26) |
Dec
(71) |
2012 |
Jan
(13) |
Feb
(24) |
Mar
(11) |
Apr
(2) |
May
(10) |
Jun
(5) |
Jul
(13) |
Aug
(7) |
Sep
(26) |
Oct
(22) |
Nov
(17) |
Dec
(16) |
2013 |
Jan
(6) |
Feb
(6) |
Mar
(6) |
Apr
(8) |
May
(20) |
Jun
|
Jul
(1) |
Aug
(4) |
Sep
(18) |
Oct
(3) |
Nov
(14) |
Dec
(33) |
2014 |
Jan
(26) |
Feb
(6) |
Mar
(69) |
Apr
(10) |
May
|
Jun
(8) |
Jul
(18) |
Aug
(22) |
Sep
(19) |
Oct
(17) |
Nov
|
Dec
(4) |
2015 |
Jan
(14) |
Feb
(18) |
Mar
|
Apr
|
May
(26) |
Jun
(8) |
Jul
(9) |
Aug
(10) |
Sep
(15) |
Oct
(2) |
Nov
(30) |
Dec
(33) |
2016 |
Jan
(1) |
Feb
(24) |
Mar
(19) |
Apr
(1) |
May
|
Jun
(3) |
Jul
(1) |
Aug
(1) |
Sep
(20) |
Oct
(5) |
Nov
(14) |
Dec
(4) |
2017 |
Jan
(15) |
Feb
(35) |
Mar
(10) |
Apr
(9) |
May
(14) |
Jun
(33) |
Jul
(1) |
Aug
(27) |
Sep
(7) |
Oct
|
Nov
(10) |
Dec
(15) |
2018 |
Jan
(29) |
Feb
|
Mar
(2) |
Apr
(1) |
May
(11) |
Jun
|
Jul
(1) |
Aug
(8) |
Sep
(11) |
Oct
(22) |
Nov
(9) |
Dec
(13) |
2019 |
Jan
(1) |
Feb
(7) |
Mar
(3) |
Apr
(21) |
May
(34) |
Jun
(36) |
Jul
(18) |
Aug
(17) |
Sep
(19) |
Oct
(8) |
Nov
(3) |
Dec
|
2020 |
Jan
|
Feb
(4) |
Mar
(8) |
Apr
(29) |
May
(50) |
Jun
(8) |
Jul
(2) |
Aug
(10) |
Sep
(1) |
Oct
(7) |
Nov
(9) |
Dec
(19) |
2021 |
Jan
(2) |
Feb
(9) |
Mar
(6) |
Apr
(21) |
May
(13) |
Jun
(11) |
Jul
(2) |
Aug
(1) |
Sep
(3) |
Oct
(26) |
Nov
(2) |
Dec
(16) |
2022 |
Jan
(8) |
Feb
(7) |
Mar
(1) |
Apr
(13) |
May
(1) |
Jun
(4) |
Jul
(4) |
Aug
(1) |
Sep
(1) |
Oct
|
Nov
|
Dec
(1) |
2023 |
Jan
(2) |
Feb
(3) |
Mar
(16) |
Apr
|
May
(2) |
Jun
(1) |
Jul
(4) |
Aug
(13) |
Sep
(8) |
Oct
(6) |
Nov
(4) |
Dec
|
2024 |
Jan
(3) |
Feb
(3) |
Mar
|
Apr
|
May
(1) |
Jun
|
Jul
(5) |
Aug
|
Sep
(1) |
Oct
|
Nov
(5) |
Dec
|
2025 |
Jan
(4) |
Feb
(2) |
Mar
|
Apr
(11) |
May
(1) |
Jun
(9) |
Jul
(18) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
S | M | T | W | T | F | S |
---|---|---|---|---|---|---|
|
|
1
|
2
|
3
|
4
|
5
|
6
|
7
|
8
|
9
|
10
|
11
|
12
|
13
|
14
|
15
|
16
|
17
|
18
|
19
|
20
|
21
|
22
|
23
|
24
|
25
|
26
(3) |
27
(3) |
28
|
29
|
30
|
31
|
|
|
From: David K. <da...@ke...> - 2013-01-27 15:14:11
|
Michael, Thats a good suggestion, not sure that it is the approach I will take, but good idea. David On Sun, Jan 27, 2013 at 6:26 AM, Michael Keuter <li...@mk...>wrote: > > Am 27.01.2013 um 01:49 schrieb David Kerr: > > > Lonnie, > > Thanks... that was why I posted my sip.conf, I was afraid that perhaps > I had something in there that would allow calls without > registration/authentication. I've removed the insecure= statement. I need > to permit international calls to at least two countries as we have family > living overseas. I might put something in my dialplan to limit exactly > which countries are permitted. > > > > David > > Hi David, > > sorry to hear that you got hacked. > Can't you call those overseas family members via "Speed Dial" or similar. > That's much easier than using a database. > > |
From: Michael K. <li...@mk...> - 2013-01-27 11:27:05
|
Am 27.01.2013 um 01:49 schrieb David Kerr: > Lonnie, > Thanks... that was why I posted my sip.conf, I was afraid that perhaps I had something in there that would allow calls without registration/authentication. I've removed the insecure= statement. I need to permit international calls to at least two countries as we have family living overseas. I might put something in my dialplan to limit exactly which countries are permitted. > > David Hi David, sorry to hear that you got hacked. Can't you call those overseas family members via "Speed Dial" or similar. That's much easier than using a database. > On Sat, Jan 26, 2013 at 6:39 PM, Lonnie Abelbeck <li...@lo...> wrote: > Hi David, > > Interesting, Adaptive Ban kicks in, so the attacker changes their IP address, many times. And since this is TCP they aren't spoofing the source address. > > I suppose adding "encryption=yes" would add another hurdle for the attacker's configuration, but I'm surprised how few attempts it took to brute force your password. > > Ahhh... you are including "insecure=port,invite", that does not seem like a good idea (particularly the 'invite' part) "Do not require authentication of incoming INVITEs" > > The only time "insecure=port,invite" is safe is for *incoming only* calls from a provider. > > Personally I disallow all international dialing. > > Lonnie > > PS: The "requirecalltoken" is an IAX2 thing not SIP. > > > > On Jan 26, 2013, at 4:46 PM, David Kerr wrote: > > > So. My asterisk was successfully compromised today. Someone successfully placed phone calls on the only extension I permit external access to, and make some calls (to the country of Guinea). I thought I had taken enough precautions, obviously not. > > > > I've attached my CDR (pdf file) and selections from my syslog (txt file). What is interesting is that syslog shows attempted logins failing with incorrect password, and adaptive ban (which I have set to trigger on 3 failed attempts) does kick in. But somehow they got through. Also attached are sections from my sip.conf... is there anything in here that I have wrong? > > > > Note that password in here I have already changed... to something even more non-trivial. > > > > Finally... extension '104' is the extension I used to test my iPhone softphone apps. Including Acrobits softphone -- and they provide a 'push' server with which I have tested this service. In other words my credentials 104/secret have been uploaded to Acrobits push server. Could their server have been compromised, or was I just unlucky. > > > > Comments welcome. > > > > Thanks > > David > > > > [general] > > context=default > > allowoverlap=no > > udpbindaddr=0.0.0.0:5060 > > tcpenable=yes > > tcpbindaddr=0.0.0.0:5060 > > tlsenable=yes > > tlsbindaddr=0.0.0.0:5061 > > tlscertfile=/mnt/kd/ssl/sip-tls/keys/server.crt > > tlsprivatekey=/mnt/kd/ssl/sip-tls/keys/server.key > > tlsdontverifyserver=no > > tlscipher=DES-CBC3-SHA > > tlsclientmethod=tlsv1 > > transport=udp > > srvlookup=yes > > alwaysauthreject = yes > > nat=force_rport,comedia > > canreinvite=nonat > > directmedia=nonat > > faxdetect = yes > > callcounter = yes > > progressinband=yes ; set while testing SLA > > tos_sip=cs3 ; Sets TOS for SIP packets. > > tos_audio=ef ; Sets TOS for RTP audio packets. > > tos_video=af41 ; Sets TOS for RTP video packets. > > tos_text=af41 ; Sets TOS for RTP text packets. > > > > [basic-extensions](!) > > dtmfmode=auto > > context=DefaultDialPlan > > type=friend > > call-limit=10 > > deny=0.0.0.0/0.0.0.0 > > permit=192.168.0.0/255.255.0.0 > > insecure=port,invite > > qualify=yes > > host=dynamic > > disallow=all > > allow=ulaw > > mailbox=101 > > > > [104](basic-extensions) > > fullname=David Kerr > > secret=tyecs6ook7 > > context=DialPlanSLA > > disallow=all > > allow=g722,ilbc,g729,gsm,ulaw > > qualify=yes > > requirecalltoken=no > > transport=tls > > permit=0.0.0.0/0.0.0.0 > > <syslog.txt><CDR-2013-01-26.pdf>------------------------------------------------------------------------------ > > Master Visual Studio, SharePoint, SQL, ASP.NET, C# 2012, HTML5, CSS, > > MVC, Windows 8 Apps, JavaScript and much more. Keep your skills current > > with LearnDevNow - 3,200 step-by-step video tutorials by Microsoft > > MVPs and experts. ON SALE this month only -- learn more at: > > http://p.sf.net/sfu/learnnow-d2d_______________________________________________ > > Astlinux-devel mailing list > > Ast...@li... > > https://lists.sourceforge.net/lists/listinfo/astlinux-devel > > > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > ------------------------------------------------------------------------------ > Master Visual Studio, SharePoint, SQL, ASP.NET, C# 2012, HTML5, CSS, > MVC, Windows 8 Apps, JavaScript and much more. Keep your skills current > with LearnDevNow - 3,200 step-by-step video tutorials by Microsoft > MVPs and experts. ON SALE this month only -- learn more at: > http://p.sf.net/sfu/learnnow-d2d > _______________________________________________ > Astlinux-devel mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-devel > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > ------------------------------------------------------------------------------ > Master Visual Studio, SharePoint, SQL, ASP.NET, C# 2012, HTML5, CSS, > MVC, Windows 8 Apps, JavaScript and much more. Keep your skills current > with LearnDevNow - 3,200 step-by-step video tutorials by Microsoft > MVPs and experts. ON SALE this month only -- learn more at: > http://p.sf.net/sfu/learnnow-d2d_______________________________________________ > Astlinux-devel mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-devel > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... Michael http://www.mksolutions.info |
From: David K. <da...@ke...> - 2013-01-27 00:49:58
|
Lonnie, Thanks... that was why I posted my sip.conf, I was afraid that perhaps I had something in there that would allow calls without registration/authentication. I've removed the insecure= statement. I need to permit international calls to at least two countries as we have family living overseas. I might put something in my dialplan to limit exactly which countries are permitted. David On Sat, Jan 26, 2013 at 6:39 PM, Lonnie Abelbeck <li...@lo...>wrote: > Hi David, > > Interesting, Adaptive Ban kicks in, so the attacker changes their IP > address, many times. And since this is TCP they aren't spoofing the source > address. > > I suppose adding "encryption=yes" would add another hurdle for the > attacker's configuration, but I'm surprised how few attempts it took to > brute force your password. > > Ahhh... you are including "insecure=port,invite", that does not seem like > a good idea (particularly the 'invite' part) "Do not require authentication > of incoming INVITEs" > > The only time "insecure=port,invite" is safe is for *incoming only* calls > from a provider. > > Personally I disallow all international dialing. > > Lonnie > > PS: The "requirecalltoken" is an IAX2 thing not SIP. > > > > On Jan 26, 2013, at 4:46 PM, David Kerr wrote: > > > So. My asterisk was successfully compromised today. Someone > successfully placed phone calls on the only extension I permit external > access to, and make some calls (to the country of Guinea). I thought I had > taken enough precautions, obviously not. > > > > I've attached my CDR (pdf file) and selections from my syslog (txt > file). What is interesting is that syslog shows attempted logins failing > with incorrect password, and adaptive ban (which I have set to trigger on 3 > failed attempts) does kick in. But somehow they got through. Also > attached are sections from my sip.conf... is there anything in here that I > have wrong? > > > > Note that password in here I have already changed... to something even > more non-trivial. > > > > Finally... extension '104' is the extension I used to test my iPhone > softphone apps. Including Acrobits softphone -- and they provide a 'push' > server with which I have tested this service. In other words my > credentials 104/secret have been uploaded to Acrobits push server. Could > their server have been compromised, or was I just unlucky. > > > > Comments welcome. > > > > Thanks > > David > > > > [general] > > context=default > > allowoverlap=no > > udpbindaddr=0.0.0.0:5060 > > tcpenable=yes > > tcpbindaddr=0.0.0.0:5060 > > tlsenable=yes > > tlsbindaddr=0.0.0.0:5061 > > tlscertfile=/mnt/kd/ssl/sip-tls/keys/server.crt > > tlsprivatekey=/mnt/kd/ssl/sip-tls/keys/server.key > > tlsdontverifyserver=no > > tlscipher=DES-CBC3-SHA > > tlsclientmethod=tlsv1 > > transport=udp > > srvlookup=yes > > alwaysauthreject = yes > > nat=force_rport,comedia > > canreinvite=nonat > > directmedia=nonat > > faxdetect = yes > > callcounter = yes > > progressinband=yes ; set while testing SLA > > tos_sip=cs3 ; Sets TOS for SIP packets. > > tos_audio=ef ; Sets TOS for RTP audio packets. > > tos_video=af41 ; Sets TOS for RTP video packets. > > tos_text=af41 ; Sets TOS for RTP text packets. > > > > [basic-extensions](!) > > dtmfmode=auto > > context=DefaultDialPlan > > type=friend > > call-limit=10 > > deny=0.0.0.0/0.0.0.0 > > permit=192.168.0.0/255.255.0.0 > > insecure=port,invite > > qualify=yes > > host=dynamic > > disallow=all > > allow=ulaw > > mailbox=101 > > > > [104](basic-extensions) > > fullname=David Kerr > > secret=tyecs6ook7 > > context=DialPlanSLA > > disallow=all > > allow=g722,ilbc,g729,gsm,ulaw > > qualify=yes > > requirecalltoken=no > > transport=tls > > permit=0.0.0.0/0.0.0.0 > > > <syslog.txt><CDR-2013-01-26.pdf>------------------------------------------------------------------------------ > > Master Visual Studio, SharePoint, SQL, ASP.NET, C# 2012, HTML5, CSS, > > MVC, Windows 8 Apps, JavaScript and much more. Keep your skills current > > with LearnDevNow - 3,200 step-by-step video tutorials by Microsoft > > MVPs and experts. ON SALE this month only -- learn more at: > > > http://p.sf.net/sfu/learnnow-d2d_______________________________________________ > > Astlinux-devel mailing list > > Ast...@li... > > https://lists.sourceforge.net/lists/listinfo/astlinux-devel > > > > Donations to support AstLinux are graciously accepted via PayPal to > pa...@kr.... > > > > ------------------------------------------------------------------------------ > Master Visual Studio, SharePoint, SQL, ASP.NET, C# 2012, HTML5, CSS, > MVC, Windows 8 Apps, JavaScript and much more. Keep your skills current > with LearnDevNow - 3,200 step-by-step video tutorials by Microsoft > MVPs and experts. ON SALE this month only -- learn more at: > http://p.sf.net/sfu/learnnow-d2d > _______________________________________________ > Astlinux-devel mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-devel > > Donations to support AstLinux are graciously accepted via PayPal to > pa...@kr.... > |
From: Lonnie A. <li...@lo...> - 2013-01-26 23:39:23
|
Hi David, Interesting, Adaptive Ban kicks in, so the attacker changes their IP address, many times. And since this is TCP they aren't spoofing the source address. I suppose adding "encryption=yes" would add another hurdle for the attacker's configuration, but I'm surprised how few attempts it took to brute force your password. Ahhh... you are including "insecure=port,invite", that does not seem like a good idea (particularly the 'invite' part) "Do not require authentication of incoming INVITEs" The only time "insecure=port,invite" is safe is for *incoming only* calls from a provider. Personally I disallow all international dialing. Lonnie PS: The "requirecalltoken" is an IAX2 thing not SIP. On Jan 26, 2013, at 4:46 PM, David Kerr wrote: > So. My asterisk was successfully compromised today. Someone successfully placed phone calls on the only extension I permit external access to, and make some calls (to the country of Guinea). I thought I had taken enough precautions, obviously not. > > I've attached my CDR (pdf file) and selections from my syslog (txt file). What is interesting is that syslog shows attempted logins failing with incorrect password, and adaptive ban (which I have set to trigger on 3 failed attempts) does kick in. But somehow they got through. Also attached are sections from my sip.conf... is there anything in here that I have wrong? > > Note that password in here I have already changed... to something even more non-trivial. > > Finally... extension '104' is the extension I used to test my iPhone softphone apps. Including Acrobits softphone -- and they provide a 'push' server with which I have tested this service. In other words my credentials 104/secret have been uploaded to Acrobits push server. Could their server have been compromised, or was I just unlucky. > > Comments welcome. > > Thanks > David > > [general] > context=default > allowoverlap=no > udpbindaddr=0.0.0.0:5060 > tcpenable=yes > tcpbindaddr=0.0.0.0:5060 > tlsenable=yes > tlsbindaddr=0.0.0.0:5061 > tlscertfile=/mnt/kd/ssl/sip-tls/keys/server.crt > tlsprivatekey=/mnt/kd/ssl/sip-tls/keys/server.key > tlsdontverifyserver=no > tlscipher=DES-CBC3-SHA > tlsclientmethod=tlsv1 > transport=udp > srvlookup=yes > alwaysauthreject = yes > nat=force_rport,comedia > canreinvite=nonat > directmedia=nonat > faxdetect = yes > callcounter = yes > progressinband=yes ; set while testing SLA > tos_sip=cs3 ; Sets TOS for SIP packets. > tos_audio=ef ; Sets TOS for RTP audio packets. > tos_video=af41 ; Sets TOS for RTP video packets. > tos_text=af41 ; Sets TOS for RTP text packets. > > [basic-extensions](!) > dtmfmode=auto > context=DefaultDialPlan > type=friend > call-limit=10 > deny=0.0.0.0/0.0.0.0 > permit=192.168.0.0/255.255.0.0 > insecure=port,invite > qualify=yes > host=dynamic > disallow=all > allow=ulaw > mailbox=101 > > [104](basic-extensions) > fullname=David Kerr > secret=tyecs6ook7 > context=DialPlanSLA > disallow=all > allow=g722,ilbc,g729,gsm,ulaw > qualify=yes > requirecalltoken=no > transport=tls > permit=0.0.0.0/0.0.0.0 > <syslog.txt><CDR-2013-01-26.pdf>------------------------------------------------------------------------------ > Master Visual Studio, SharePoint, SQL, ASP.NET, C# 2012, HTML5, CSS, > MVC, Windows 8 Apps, JavaScript and much more. Keep your skills current > with LearnDevNow - 3,200 step-by-step video tutorials by Microsoft > MVPs and experts. ON SALE this month only -- learn more at: > http://p.sf.net/sfu/learnnow-d2d_______________________________________________ > Astlinux-devel mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-devel > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: David K. <da...@ke...> - 2013-01-26 23:08:16
|
So. My asterisk was successfully compromised today. Someone successfully placed phone calls on the only extension I permit external access to, and make some calls (to the country of Guinea). I thought I had taken enough precautions, obviously not. I've attached my CDR and selections from my syslog. What is interesting is that syslog shows attempted logins failing with incorrect password, and adaptive ban (which I have set to trigger on 3 failed attempts) does kick in. But somehow they got through. Also attached are sections from my sip.conf... is there anything in here that I have wrong? Note that password in here I have already changed... to something even more non-trivial. Finally... extension '104' is the extension I used to test my iPhone softphone apps. Including Acrobits softphone -- and they provide a 'push' server with which I have tested this service. In other words my credentials 104/secret have been uploaded to Acrobits push server. Could their server have been compromised, or was I just unlucky. Comments welcome. Thanks David [general] context=default allowoverlap=no udpbindaddr=0.0.0.0:5060 tcpenable=yes tcpbindaddr=0.0.0.0:5060 tlsenable=yes tlsbindaddr=0.0.0.0:5061 tlscertfile=/mnt/kd/ssl/sip-tls/keys/server.crt tlsprivatekey=/mnt/kd/ssl/sip-tls/keys/server.key tlsdontverifyserver=no tlscipher=DES-CBC3-SHA tlsclientmethod=tlsv1 transport=udp srvlookup=yes alwaysauthreject = yes nat=force_rport,comedia canreinvite=nonat directmedia=nonat faxdetect = yes callcounter = yes progressinband=yes ; set while testing SLA tos_sip=cs3 ; Sets TOS for SIP packets. tos_audio=ef ; Sets TOS for RTP audio packets. tos_video=af41 ; Sets TOS for RTP video packets. tos_text=af41 ; Sets TOS for RTP text packets. [basic-extensions](!) dtmfmode=auto context=DefaultDialPlan type=friend call-limit=10 deny=0.0.0.0/0.0.0.0 permit=192.168.0.0/255.255.0.0 insecure=port,invite qualify=yes host=dynamic disallow=all allow=ulaw mailbox=101 [104](basic-extensions) fullname=David Kerr secret=tyecs6ook7 context=DialPlanSLA disallow=all allow=g722,ilbc,g729,gsm,ulaw qualify=yes requirecalltoken=no transport=tls permit=0.0.0.0/0.0.0.0 Jan 26 12:01:43 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '< sip:109@00.000.000.00>' failed for '37.8.35.31:14797' - No matching peer found Jan 26 12:01:43 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '< sip:109@00.000.000.00>' failed for '37.8.35.31:14797' - No matching peer found Jan 26 12:01:53 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '< sip:104@00.000.000.00>' failed for '37.8.35.31:14797' - Wrong password Jan 26 12:02:14 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '< sip:104@00.000.000.00>' failed for '37.8.35.31:14797' - Wrong password Jan 26 12:02:54 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '< sip:104@00.000.000.00>' failed for '37.8.35.31:14797' - Wrong password Jan 26 12:03:18 pbx user.info firewall: adaptive-ban: Banned IPv4 Host: 37.8.35.31 Filter Type: asterisk Jan 26 12:03:45 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=37.8.35.31 DST=00.000.000.00 LEN=794 TOS=0x00 PREC=0x20 TTL=111 ID=15277 PROTO=UDP SPT=14797 DPT=5060 LEN=774 Jan 26 12:07:43 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '< sip:104@00.000.000.00>' failed for '199.255.210.86:8395' - Wrong password Jan 26 12:08:06 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '< sip:104@00.000.000.00>' failed for '199.255.210.86:8395' - Wrong password Jan 26 12:08:18 pbx local0.warn asterisk[2521]: WARNING[11718]: app_meetme.c:3446 in conf_run: Channel changed in Meetme Conference to SIP/voipcheap-000000ad and CDR disposition ANSWERED Jan 26 12:08:38 pbx local0.warn asterisk[2521]: WARNING[11740]: app_meetme.c:3446 in conf_run: Channel changed in Meetme Conference to SIP/voipcheap-000000b0 and CDR disposition ANSWERED Jan 26 12:08:46 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '< sip:104@00.000.000.00>' failed for '199.255.210.86:8395' - Wrong password Jan 26 12:09:42 pbx user.info firewall: adaptive-ban: Banned IPv4 Host: 199.255.210.86 Filter Type: asterisk Jan 26 12:09:59 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=199.255.210.86 DST=00.000.000.00 LEN=355 TOS=0x00 PREC=0x20 TTL=114 ID=1309 PROTO=UDP SPT=8395 DPT=5060 LEN=335 Jan 26 12:14:35 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '< sip:104@00.000.000.00>' failed for '168.63.248.15:1032' - Wrong password Jan 26 12:14:55 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '< sip:104@00.000.000.00>' failed for '168.63.248.15:1032' - Wrong password Jan 26 12:15:36 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '< sip:104@00.000.000.00>' failed for '168.63.248.15:1032' - Wrong password Jan 26 12:16:01 pbx user.info firewall: adaptive-ban: Banned IPv4 Host: 168.63.248.15 Filter Type: asterisk Jan 26 12:16:57 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=168.63.248.15 DST=00.000.000.00 LEN=488 TOS=0x00 PREC=0x20 TTL=113 ID=27060 PROTO=UDP SPT=1032 DPT=5060 LEN=468 Jan 26 12:25:49 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '< sip:104@00.000.000.00>' failed for '37.8.0.253:10860' - Wrong password Jan 26 12:26:09 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '< sip:104@00.000.000.00>' failed for '37.8.0.253:10860' - Wrong password Jan 26 12:27:05 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '< sip:104@00.000.000.00>' failed for '37.8.0.253:10860' - Wrong password Jan 26 12:28:26 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '< sip:104@00.000.000.00>' failed for '37.8.0.253:10860' - Wrong password Jan 26 12:28:41 pbx user.info firewall: adaptive-ban: Banned IPv4 Host: 37.8.0.253 Filter Type: asterisk Jan 26 12:28:42 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=168.63.248.15 DST=00.000.000.00 LEN=486 TOS=0x00 PREC=0x20 TTL=113 ID=28043 PROTO=UDP SPT=1034 DPT=5060 LEN=466 Jan 26 12:34:34 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=168.63.248.15 DST=00.000.000.00 LEN=487 TOS=0x00 PREC=0x20 TTL=113 ID=28072 PROTO=UDP SPT=1032 DPT=5060 LEN=467 Jan 26 12:39:09 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=168.63.248.15 DST=00.000.000.00 LEN=487 TOS=0x00 PREC=0x20 TTL=112 ID=28334 PROTO=UDP SPT=1033 DPT=5060 LEN=467 Jan 26 12:40:40 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=168.63.248.15 DST=00.000.000.00 LEN=487 TOS=0x00 PREC=0x20 TTL=112 ID=28341 PROTO=UDP SPT=1033 DPT=5060 LEN=467 Jan 26 12:49:45 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=168.63.248.15 DST=00.000.000.00 LEN=488 TOS=0x00 PREC=0x20 TTL=113 ID=29594 PROTO=UDP SPT=1032 DPT=5060 LEN=468 Jan 26 12:56:00 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=168.63.248.15 DST=00.000.000.00 LEN=364 TOS=0x00 PREC=0x20 TTL=113 ID=29887 PROTO=UDP SPT=1032 DPT=5060 LEN=344 Jan 26 12:58:11 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=37.8.0.253 DST=00.000.000.00 LEN=487 TOS=0x00 PREC=0x20 TTL=111 ID=22313 PROTO=UDP SPT=16430 DPT=5060 LEN=467 Jan 26 13:10:39 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=168.63.248.15 DST=00.000.000.00 LEN=486 TOS=0x00 PREC=0x20 TTL=113 ID=9487 PROTO=UDP SPT=1032 DPT=5060 LEN=466 Jan 26 13:17:20 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=37.8.0.253 DST=00.000.000.00 LEN=487 TOS=0x00 PREC=0x20 TTL=111 ID=20256 PROTO=UDP SPT=19563 DPT=5060 LEN=467 Jan 26 13:23:43 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=168.63.248.15 DST=00.000.000.00 LEN=487 TOS=0x00 PREC=0x20 TTL=113 ID=23077 PROTO=UDP SPT=1032 DPT=5060 LEN=467 Jan 26 13:34:56 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=168.63.248.15 DST=00.000.000.00 LEN=487 TOS=0x00 PREC=0x20 TTL=113 ID=23104 PROTO=UDP SPT=1032 DPT=5060 LEN=467 Jan 26 13:47:18 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '< sip:104@00.000.000.00>' failed for '37.8.121.223:13550' - Wrong password Jan 26 13:47:37 pbx local0.warn asterisk[2521]: WARNING[24516]: app_meetme.c:3446 in conf_run: Channel changed in Meetme Conference to SIP/voipcheap-000000bc and CDR disposition ANSWERED Jan 26 13:47:39 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '< sip:104@00.000.000.00>' failed for '37.8.121.223:13550' - Wrong password Jan 26 13:47:45 pbx local0.warn asterisk[2521]: WARNING[24528]: app_meetme.c:3446 in conf_run: Channel changed in Meetme Conference to SIP/voipcheap-000000bf and CDR disposition ANSWERED Jan 26 13:48:20 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '< sip:104@00.000.000.00>' failed for '37.8.121.223:13550' - Wrong password Jan 26 13:49:33 pbx user.info firewall: adaptive-ban: Banned IPv4 Host: 37.8.121.223 Filter Type: asterisk Jan 26 13:49:33 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=37.8.121.223 DST=00.000.000.00 LEN=80 TOS=0x00 PREC=0x20 TTL=111 ID=2641 PROTO=UDP SPT=13493 DPT=16595 LEN=60 Jan 26 13:51:46 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=37.8.121.223 DST=00.000.000.00 LEN=782 TOS=0x00 PREC=0x20 TTL=111 ID=4058 PROTO=UDP SPT=13550 DPT=5060 LEN=762 Jan 26 13:52:09 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=37.8.121.223 DST=00.000.000.00 LEN=80 TOS=0x00 PREC=0x20 TTL=111 ID=4196 PROTO=UDP SPT=13493 DPT=16595 LEN=60 Jan 26 13:55:16 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=37.8.121.223 DST=00.000.000.00 LEN=491 TOS=0x00 PREC=0x20 TTL=111 ID=5224 PROTO=UDP SPT=13606 DPT=5060 LEN=471 Jan 26 13:55:24 pbx local0.warn asterisk[2521]: WARNING[24516]: app_meetme.c:4037 in conf_run: Unable to write frame to channel SIP/voipcheap-000000bc Jan 26 13:55:24 pbx local0.warn asterisk[2521]: WARNING[24527]: app_meetme.c:4947 in admin_exec: Conference number 'SLA_SLAtrunk2' not found! Jan 26 13:58:50 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=37.8.121.223 DST=00.000.000.00 LEN=491 TOS=0x00 PREC=0x20 TTL=111 ID=7034 PROTO=UDP SPT=13789 DPT=5060 LEN=471 Jan 26 14:04:24 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=37.8.121.223 DST=00.000.000.00 LEN=491 TOS=0x00 PREC=0x20 TTL=111 ID=9200 PROTO=UDP SPT=13904 DPT=5060 LEN=471 Jan 26 14:15:23 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=37.8.121.223 DST=00.000.000.00 LEN=491 TOS=0x00 PREC=0x20 TTL=111 ID=19214 PROTO=UDP SPT=14276 DPT=5060 LEN=471 Jan 26 14:19:03 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '< sip:104@00.000.000.00>' failed for '199.255.213.193:9078' - Wrong password Jan 26 14:19:23 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '< sip:104@00.000.000.00>' failed for '199.255.213.193:9078' - Wrong password Jan 26 14:20:04 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '< sip:104@00.000.000.00>' failed for '199.255.213.193:9078' - Wrong password Jan 26 14:21:00 pbx user.info firewall: adaptive-ban: Banned IPv4 Host: 199.255.213.193 Filter Type: asterisk Jan 26 14:21:13 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=199.255.213.193 DST=00.000.000.00 LEN=802 TOS=0x00 PREC=0x20 TTL=113 ID=532 PROTO=UDP SPT=9078 DPT=5060 LEN=782 Jan 26 14:22:12 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=199.255.213.193 DST=00.000.000.00 LEN=489 TOS=0x00 PREC=0x20 TTL=113 ID=565 PROTO=UDP SPT=9079 DPT=5060 LEN=469 104 i DefaultDialPlan "David Kerr" <104> SIP/104-0000009e Local/s@OutboundSLA-0000000c;2 Playback pbx-invalid 1/26/13 11:14 1/26/13 11:14 1/26/13 11:14 1 1 ANSWERED 104 i DefaultDialPlan "David Kerr" <104> SIP/104-0000009f Local/s@OutboundSLA-0000000d;2 Playback pbx-invalid 1/26/13 11:14 1/26/13 11:14 1/26/13 11:15 2 2 ANSWERED 104 i DefaultDialPlan "David Kerr" <104> SIP/104-000000a0 Local/s@OutboundSLA-0000000e;2 Playback pbx-invalid 1/26/13 11:15 1/26/13 11:15 1/26/13 11:15 1 1 ANSWERED 104 i DefaultDialPlan "David Kerr" <104> SIP/104-000000a1 Local/s@OutboundSLA-0000000f;2 Playback pbx-invalid 1/26/13 11:15 1/26/13 11:15 1/26/13 11:15 1 1 ANSWERED 104 00972599745284 OutboundSLA "David Kerr" <104> SIP/104-0000009b SIP/voipcheap-0000009d 1/26/13 11:15 1/26/13 11:15 1/26/13 11:15 8 8 ANSWERED 104 s OutboundSLA 104 Local/s@OutboundSLA-00000010;2 SIP/voipcheap-000000a4 Dial SIP/voipcheap/00972599745284,,Tr 1/26/13 12:01 1/26/13 12:02 19 0 BUSY 104 s OutboundSLA 104 Local/s@OutboundSLA-00000012;2 SIP/voipcheap-000000aa Dial SIP/voipcheap/00972599745284,,Tr 1/26/13 12:08 1/26/13 12:08 11 0 BUSY 104 002522133000 OutboundSLA "David Kerr" <104> SIP/104-000000ab SIP/voipcheap-000000ad 1/26/13 12:08 1/26/13 12:08 1/26/13 12:08 7 7 ANSWERED 104 0022478400000 OutboundSLA "David Kerr" <104> SIP/104-000000ae SIP/voipcheap-000000b0 1/26/13 12:08 1/26/13 12:08 1/26/13 12:08 3 3 ANSWERED 104 s OutboundSLA 104 Local/s@OutboundSLA-00000015;2 SIP/voipcheap-000000b3 Dial SIP/voipcheap/0037127694000,,Tr 1/26/13 12:08 1/26/13 12:08 0 0 FAILED 104 s OutboundSLA 104 Local/s@OutboundSLA-00000016;2 SIP/voipcheap-000000b6 Dial SIP/voipcheap/009609648060,,Tr 1/26/13 12:09 1/26/13 12:09 34 0 FAILED 104 s OutboundSLA 104 Local/s@OutboundSLA-00000017;2 SIP/voipcheap-000000b9 Dial SIP/voipcheap/002917385050,,Tr 1/26/13 12:09 1/26/13 12:11 122 0 FAILED 104 0022478400039 OutboundSLA "David Kerr" <104> SIP/104-000000bd SIP/voipcheap-000000bf 1/26/13 13:47 1/26/13 13:47 1/26/13 13:55 459 459 ANSWERED 104 0022478400039 OutboundSLA "David Kerr" <104> SIP/104-000000ba SIP/voipcheap-000000bc 1/26/13 13:47 1/26/13 13:47 1/26/13 13:55 467 467 ANSWERED 104 s OutboundSLA 104 Local/s@OutboundSLA-0000001a;2 SIP/voipcheap-000000c2 Dial SIP/voipcheap/002247800040,,Tr 1/26/13 14:20 1/26/13 14:20 1 0 FAILED 104 s OutboundSLA 104 Local/s@OutboundSLA-0000001b;2 SIP/voipcheap-000000c5 Dial SIP/voipcheap/002247800040,,Tr 1/26/13 14:20 1/26/13 14:20 1 0 FAILED |
From: David K. <da...@ke...> - 2013-01-26 22:47:04
|
Jan 26 12:01:43 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '<sip:109@00.000.000.00>' failed for '37.8.35.31:14797' - No matching peer found Jan 26 12:01:43 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '<sip:109@00.000.000.00>' failed for '37.8.35.31:14797' - No matching peer found Jan 26 12:01:53 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '<sip:104@00.000.000.00>' failed for '37.8.35.31:14797' - Wrong password Jan 26 12:02:14 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '<sip:104@00.000.000.00>' failed for '37.8.35.31:14797' - Wrong password Jan 26 12:02:54 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '<sip:104@00.000.000.00>' failed for '37.8.35.31:14797' - Wrong password Jan 26 12:03:18 pbx user.info firewall: adaptive-ban: Banned IPv4 Host: 37.8.35.31 Filter Type: asterisk Jan 26 12:03:45 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=37.8.35.31 DST=00.000.000.00 LEN=794 TOS=0x00 PREC=0x20 TTL=111 ID=15277 PROTO=UDP SPT=14797 DPT=5060 LEN=774 Jan 26 12:07:43 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '<sip:104@00.000.000.00>' failed for '199.255.210.86:8395' - Wrong password Jan 26 12:08:06 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '<sip:104@00.000.000.00>' failed for '199.255.210.86:8395' - Wrong password Jan 26 12:08:18 pbx local0.warn asterisk[2521]: WARNING[11718]: app_meetme.c:3446 in conf_run: Channel changed in Meetme Conference to SIP/voipcheap-000000ad and CDR disposition ANSWERED Jan 26 12:08:38 pbx local0.warn asterisk[2521]: WARNING[11740]: app_meetme.c:3446 in conf_run: Channel changed in Meetme Conference to SIP/voipcheap-000000b0 and CDR disposition ANSWERED Jan 26 12:08:46 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '<sip:104@00.000.000.00>' failed for '199.255.210.86:8395' - Wrong password Jan 26 12:09:42 pbx user.info firewall: adaptive-ban: Banned IPv4 Host: 199.255.210.86 Filter Type: asterisk Jan 26 12:09:59 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=199.255.210.86 DST=00.000.000.00 LEN=355 TOS=0x00 PREC=0x20 TTL=114 ID=1309 PROTO=UDP SPT=8395 DPT=5060 LEN=335 Jan 26 12:14:35 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '<sip:104@00.000.000.00>' failed for '168.63.248.15:1032' - Wrong password Jan 26 12:14:55 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '<sip:104@00.000.000.00>' failed for '168.63.248.15:1032' - Wrong password Jan 26 12:15:36 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '<sip:104@00.000.000.00>' failed for '168.63.248.15:1032' - Wrong password Jan 26 12:16:01 pbx user.info firewall: adaptive-ban: Banned IPv4 Host: 168.63.248.15 Filter Type: asterisk Jan 26 12:16:57 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=168.63.248.15 DST=00.000.000.00 LEN=488 TOS=0x00 PREC=0x20 TTL=113 ID=27060 PROTO=UDP SPT=1032 DPT=5060 LEN=468 Jan 26 12:25:49 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '<sip:104@00.000.000.00>' failed for '37.8.0.253:10860' - Wrong password Jan 26 12:26:09 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '<sip:104@00.000.000.00>' failed for '37.8.0.253:10860' - Wrong password Jan 26 12:27:05 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '<sip:104@00.000.000.00>' failed for '37.8.0.253:10860' - Wrong password Jan 26 12:28:26 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '<sip:104@00.000.000.00>' failed for '37.8.0.253:10860' - Wrong password Jan 26 12:28:41 pbx user.info firewall: adaptive-ban: Banned IPv4 Host: 37.8.0.253 Filter Type: asterisk Jan 26 12:28:42 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=168.63.248.15 DST=00.000.000.00 LEN=486 TOS=0x00 PREC=0x20 TTL=113 ID=28043 PROTO=UDP SPT=1034 DPT=5060 LEN=466 Jan 26 12:34:34 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=168.63.248.15 DST=00.000.000.00 LEN=487 TOS=0x00 PREC=0x20 TTL=113 ID=28072 PROTO=UDP SPT=1032 DPT=5060 LEN=467 Jan 26 12:39:09 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=168.63.248.15 DST=00.000.000.00 LEN=487 TOS=0x00 PREC=0x20 TTL=112 ID=28334 PROTO=UDP SPT=1033 DPT=5060 LEN=467 Jan 26 12:40:40 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=168.63.248.15 DST=00.000.000.00 LEN=487 TOS=0x00 PREC=0x20 TTL=112 ID=28341 PROTO=UDP SPT=1033 DPT=5060 LEN=467 Jan 26 12:49:45 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=168.63.248.15 DST=00.000.000.00 LEN=488 TOS=0x00 PREC=0x20 TTL=113 ID=29594 PROTO=UDP SPT=1032 DPT=5060 LEN=468 Jan 26 12:56:00 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=168.63.248.15 DST=00.000.000.00 LEN=364 TOS=0x00 PREC=0x20 TTL=113 ID=29887 PROTO=UDP SPT=1032 DPT=5060 LEN=344 Jan 26 12:58:11 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=37.8.0.253 DST=00.000.000.00 LEN=487 TOS=0x00 PREC=0x20 TTL=111 ID=22313 PROTO=UDP SPT=16430 DPT=5060 LEN=467 Jan 26 13:10:39 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=168.63.248.15 DST=00.000.000.00 LEN=486 TOS=0x00 PREC=0x20 TTL=113 ID=9487 PROTO=UDP SPT=1032 DPT=5060 LEN=466 Jan 26 13:17:20 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=37.8.0.253 DST=00.000.000.00 LEN=487 TOS=0x00 PREC=0x20 TTL=111 ID=20256 PROTO=UDP SPT=19563 DPT=5060 LEN=467 Jan 26 13:23:43 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=168.63.248.15 DST=00.000.000.00 LEN=487 TOS=0x00 PREC=0x20 TTL=113 ID=23077 PROTO=UDP SPT=1032 DPT=5060 LEN=467 Jan 26 13:34:56 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=168.63.248.15 DST=00.000.000.00 LEN=487 TOS=0x00 PREC=0x20 TTL=113 ID=23104 PROTO=UDP SPT=1032 DPT=5060 LEN=467 Jan 26 13:47:18 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '<sip:104@00.000.000.00>' failed for '37.8.121.223:13550' - Wrong password Jan 26 13:47:37 pbx local0.warn asterisk[2521]: WARNING[24516]: app_meetme.c:3446 in conf_run: Channel changed in Meetme Conference to SIP/voipcheap-000000bc and CDR disposition ANSWERED Jan 26 13:47:39 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '<sip:104@00.000.000.00>' failed for '37.8.121.223:13550' - Wrong password Jan 26 13:47:45 pbx local0.warn asterisk[2521]: WARNING[24528]: app_meetme.c:3446 in conf_run: Channel changed in Meetme Conference to SIP/voipcheap-000000bf and CDR disposition ANSWERED Jan 26 13:48:20 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '<sip:104@00.000.000.00>' failed for '37.8.121.223:13550' - Wrong password Jan 26 13:49:33 pbx user.info firewall: adaptive-ban: Banned IPv4 Host: 37.8.121.223 Filter Type: asterisk Jan 26 13:49:33 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=37.8.121.223 DST=00.000.000.00 LEN=80 TOS=0x00 PREC=0x20 TTL=111 ID=2641 PROTO=UDP SPT=13493 DPT=16595 LEN=60 Jan 26 13:51:46 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=37.8.121.223 DST=00.000.000.00 LEN=782 TOS=0x00 PREC=0x20 TTL=111 ID=4058 PROTO=UDP SPT=13550 DPT=5060 LEN=762 Jan 26 13:52:09 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=37.8.121.223 DST=00.000.000.00 LEN=80 TOS=0x00 PREC=0x20 TTL=111 ID=4196 PROTO=UDP SPT=13493 DPT=16595 LEN=60 Jan 26 13:55:16 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=37.8.121.223 DST=00.000.000.00 LEN=491 TOS=0x00 PREC=0x20 TTL=111 ID=5224 PROTO=UDP SPT=13606 DPT=5060 LEN=471 Jan 26 13:55:24 pbx local0.warn asterisk[2521]: WARNING[24516]: app_meetme.c:4037 in conf_run: Unable to write frame to channel SIP/voipcheap-000000bc Jan 26 13:55:24 pbx local0.warn asterisk[2521]: WARNING[24527]: app_meetme.c:4947 in admin_exec: Conference number 'SLA_SLAtrunk2' not found! Jan 26 13:58:50 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=37.8.121.223 DST=00.000.000.00 LEN=491 TOS=0x00 PREC=0x20 TTL=111 ID=7034 PROTO=UDP SPT=13789 DPT=5060 LEN=471 Jan 26 14:04:24 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=37.8.121.223 DST=00.000.000.00 LEN=491 TOS=0x00 PREC=0x20 TTL=111 ID=9200 PROTO=UDP SPT=13904 DPT=5060 LEN=471 Jan 26 14:15:23 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=37.8.121.223 DST=00.000.000.00 LEN=491 TOS=0x00 PREC=0x20 TTL=111 ID=19214 PROTO=UDP SPT=14276 DPT=5060 LEN=471 Jan 26 14:19:03 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '<sip:104@00.000.000.00>' failed for '199.255.213.193:9078' - Wrong password Jan 26 14:19:23 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '<sip:104@00.000.000.00>' failed for '199.255.213.193:9078' - Wrong password Jan 26 14:20:04 pbx local0.notice asterisk[2521]: NOTICE[2579]: chan_sip.c:27724 in handle_request_register: Registration from '<sip:104@00.000.000.00>' failed for '199.255.213.193:9078' - Wrong password Jan 26 14:21:00 pbx user.info firewall: adaptive-ban: Banned IPv4 Host: 199.255.213.193 Filter Type: asterisk Jan 26 14:21:13 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=199.255.213.193 DST=00.000.000.00 LEN=802 TOS=0x00 PREC=0x20 TTL=113 ID=532 PROTO=UDP SPT=9078 DPT=5060 LEN=782 Jan 26 14:22:12 pbx user.info kernel: AIF:Adaptive-Ban host: IN=eth0 OUT= MAC=00:0d:b9:12:e9:38:1c:df:0f:02:2a:e2:08:00 SRC=199.255.213.193 DST=00.000.000.00 LEN=489 TOS=0x00 PREC=0x20 TTL=113 ID=565 PROTO=UDP SPT=9079 DPT=5060 LEN=469 |