<div>Log do Asterisk segue ae para vc ver um ataque massivo chutando users sips, repare quantos users ele conseguiu chutar em apenas um segundo !!!</div>
<div> </div>
<div> </div>
<div>uma amostra do log referente ao ataque !!!<br> <br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"0"<sip:0@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"1"<sip:1@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"2"<sip:2@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"3"<sip:3@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"4"<sip:4@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"5"<sip:5@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"6"<sip:6@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"7"<sip:7@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"8"<sip:8@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"9"<sip:9@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"10"<sip:10@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"11"<sip:11@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"12"<sip:12@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"13"<sip:13@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"14"<sip:14@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"15"<sip:15@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"16"<sip:16@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"17"<sip:17@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"18"<sip:18@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"19"<sip:19@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"20"<sip:20@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"21"<sip:21@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"22"<sip:22@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"23"<sip:23@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"24"<sip:24@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"25"<sip:25@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"26"<sip:26@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"27"<sip:27@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"28"<sip:28@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"29"<sip:29@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"30"<sip:30@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"31"<sip:31@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"32"<sip:32@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"33"<sip:33@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"34"<sip:34@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"35"<sip:35@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"36"<sip:36@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"37"<sip:37@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"38"<sip:38@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"39"<sip:39@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"40"<sip:40@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"41"<sip:41@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"42"<sip:42@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"43"<sip:43@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"44"<sip:44@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"45"<sip:45@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"46"<sip:46@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"47"<sip:47@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"48"<sip:48@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"49"<sip:49@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"50"<sip:50@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"51"<sip:51@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"52"<sip:52@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"53"<sip:53@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"54"<sip:54@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"55"<sip:55@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"56"<sip:56@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"57"<sip:57@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"58"<sip:58@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:26] NOTICE[2751] chan_sip.c: Registration from '"59"<sip:59@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:27] NOTICE[2751] chan_sip.c: Registration from '"60"<sip:60@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:27] NOTICE[2751] chan_sip.c: Registration from '"61"<sip:61@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:27] NOTICE[2751] chan_sip.c: Registration from '"62"<sip:62@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:27] NOTICE[2751] chan_sip.c: Registration from '"63"<sip:63@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:27] NOTICE[2751] chan_sip.c: Registration from '"64"<sip:64@IP>' failed for '208.38.164.96' - No matching peer found<br>
[Oct 12 09:31:27] NOTICE[2751] chan_sip.c: Registration from '"65"<sip:65@IP>' failed for '208.38.164.96' - No matching peer found<br>[Oct 12 09:31:27] NOTICE[2751] chan_sip.c: Registration from '"66"<sip:66@IP>' failed for '208.38.164.96' - No matching peer found<br>
<br> <br> <br>Rastreando o IP do malvado <br> <br>Hostname:208.38.164.96<br>ISP:E Solutions Corporation<br>Organization:LIGHTPORT<br>Proxy:None detected<br>Type:Corporate<br> </div>
<div><br>Geo-Location Information <br>Country:United States <br>State/Region:FL<br>City:Holiday<br>Latitude:28.1994<br>Longitude:-82.7681<br>Area Code:727</div>
<div> <br></div>
<div>[]'s</div>
<div> </div>
<div> </div>
<div>Eng Eder de Souza<br></div>
<div class="gmail_quote">2009/11/4 Luciano Antonio Borguetti Faustino <span dir="ltr"><<a href="mailto:lucianoborguetti.listas@gmail.com">lucianoborguetti.listas@gmail.com</a>></span><br>
<blockquote style="BORDER-LEFT: #ccc 1px solid; MARGIN: 0px 0px 0px 0.8ex; PADDING-LEFT: 1ex" class="gmail_quote">Eder,
<div><br></div>
<div>Tentativas de entrada pela porta 5060/udp?</div>
<div>Qual log seria esse, do seu firewall, do asterisk?</div>
<div><br></div>
<div>Abraço, <br><br>
<div class="gmail_quote">2009/11/3 eder souza <span dir="ltr"><<a href="mailto:ederwander@yahoo.com.br" target="_blank">ederwander@yahoo.com.br</a>></span><br>
<blockquote style="BORDER-LEFT: #ccc 1px solid; MARGIN: 0px 0px 0px 0.8ex; PADDING-LEFT: 1ex" class="gmail_quote">
<table border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td valign="top">
<div>tbm acho q é falha humana, a duas semanas peguei e um log tentativa de entradas pela porta 5060, mas o kra nao obteve sucesso !!!</div>
<div> </div>
<div>Eng Eder de Souza<br><br>--- Em <b>ter, 20/10/09, Zavam, Vinícius <i><<a href="mailto:egypcio@secrel.com.br" target="_blank">egypcio@secrel.com.br</a>></i></b> escreveu:<br></div>
<blockquote style="BORDER-LEFT: rgb(16,16,255) 2px solid; PADDING-LEFT: 5px; MARGIN-LEFT: 5px"><br>De: Zavam, Vinícius <<a href="mailto:egypcio@secrel.com.br" target="_blank">egypcio@secrel.com.br</a>><br>Assunto: Re: [AsteriskBrasil] RES: Vulnerabilidade Asterisk
<div><br>Para: <a href="mailto:asteriskbrasil@listas.asteriskbrasil.org" target="_blank">asteriskbrasil@listas.asteriskbrasil.org</a><br></div>Data: Terça-feira, 20 de Outubro de 2009, 22:40
<div>
<div></div>
<div><br><br>
<div>Citando Josué Conti:<br><br>> Poderia ser o parâmetro allowguest setado como yes?<br>><br>> 2009/10/20 Alexandre Ricardo Souza Silva <<a href="http://br.mc522.mail.yahoo.com/mc/compose?to=alexandre@componentizar.com.br" target="_blank">alexandre@componentizar.com.br</a>>:<br>
>> Rafael,<br>>><br>>> Teria como vc descrever o seu ambiente, do tipo , o seu<br>>> pbx-ip esta na web ou nao e etc.<br>>><br>>> Fico no aguardo.<br>>><br>
>> Abraço<br>>> Alexandre<br>>><br>>><br>>><br>>><br>>> ----- Original Message -----<br>>> From: Rafael Alves Machado<br>>> To: <a href="http://br.mc522.mail.yahoo.com/mc/compose?to=asteriskbrasil@listas.asteriskbrasil.org" target="_blank">asteriskbrasil@listas.asteriskbrasil.org</a><br>
>> Sent: Tuesday, October 20, 2009 5:14 PM<br>>> Subject: [AsteriskBrasil] RES: Vulnerabilidade Asterisk<br>>><br>>> O ataque foi uma falha na segurança do asterisk alguma coisa com SSL, liguei<br>
>> no suporte trixbox no EUA e me passaram isso, utilizo trixbox 2.6.2.2<br>>> Asterisk 1.6 assim que capturar o log eu encaminho, mas é praticamente<br>>> assim, a pessoa invade o servidor consegue criar ramal e efetua diversas<br>
>> ligações para todo o mundo, rastreamos o ip que estava acessando e era da<br>>> China, ele conseguiu de alguma forma acessar pela porta 5060 e suas<br>>> derivadas.<br>>><br>>><br>>><br>
>><br>>><br>>> Rafael<br>>><br>>><br>>><br>>> De: <a href="http://br.mc522.mail.yahoo.com/mc/compose?to=asteriskbrasil-bounces@listas.asteriskbrasil.org" target="_blank">asteriskbrasil-bounces@listas.asteriskbrasil.org</a><br>
>> [mailto:<a href="http://br.mc522.mail.yahoo.com/mc/compose?to=asteriskbrasil-bounces@listas.asteriskbrasil.org" target="_blank">asteriskbrasil-bounces@listas.asteriskbrasil.org</a>] Em nome de Roniton<br>>> Rezende Oliveira<br>
>> Enviada em: terça-feira, 20 de outubro de 2009 17:21<br>>> Para: <a href="http://br.mc522.mail.yahoo.com/mc/compose?to=asteriskbrasil@listas.asteriskbrasil.org" target="_blank">asteriskbrasil@listas.asteriskbrasil.org</a><br>
>> Assunto: Re: [AsteriskBrasil] Vulnerabilidade Asterisk<br>>><br>>><br>>><br>>> Como foi o ataque? Você tem Log!!<br>>> Seu sistema está atualizado?<br>>> Seu firewall está bem configurado?<br>
>><br>>> Roniton Oliveira<br>>><br>>> 2009/10/20 Giancarlo Rubio <<a href="http://br.mc522.mail.yahoo.com/mc/compose?to=gianrubio@gmail.com" target="_blank">gianrubio@gmail.com</a>><br>>><br>
>> 2009/10/20 Rafael Alves Machado <<a href="http://br.mc522.mail.yahoo.com/mc/compose?to=rafael@aflsistemas.com.br" target="_blank">rafael@aflsistemas.com.br</a>>:<br>>><br>>>> Pessoal, passei por um problema a semana passada e esta semana um amigo<br>
>>> mesmo passou pelo mesmo problema, um acesso devido a uma falha de<br>>>> segurança<br>>>> do asterisk, permitiu um usuário remoto a acessar o pbx-ip e efetuar<br>>>> ligações para diversos países, e alem disso criar ramais sip no pbx para<br>
>>> efetuar as ligações.<br>>><br>>> Qual a falha?<br><br>humana, provavelmente.<br><br>>><br>>> --<br>>> Giancarlo Rubio<br><br>nao estou vendo justificativas plausiveis que me levem a crer o contrario.<br>
digo; ate o momento.<br><br>$ /usr/local/etc/rc.d/flames.sh > /dev/null<br><br><br><br>---------------------<br>Webmail SecrelNet<br><br><br><br>_______________________________________________<br><a href="http://www.voipmania.com.br/" target="_blank">http://www.voipmania.com.br</a><br>
Telefone IP sem fio Gigaset A580IP por 6 x R$59,90. <br>Promoção por tempo limitado!<br>Acesse agora <a href="http://promo.voipmania.com.br/" target="_blank">http://promo.voipmania.com.br</a><br><br>_______________________________________________<br>
Lista de discussões AsteriskBrasil.org<br><a href="http://br.mc522.mail.yahoo.com/mc/compose?to=AsteriskBrasil@listas.asteriskbrasil.org" target="_blank">AsteriskBrasil@listas.asteriskbrasil.org</a><br><a href="http://listas.asteriskbrasil.org/mailman/listinfo/asteriskbrasil" target="_blank">http://listas.asteriskbrasil.org/mailman/listinfo/asteriskbrasil</a><br>
</div></div></div></blockquote></td></tr></tbody></table>
<div><br>__________________________________________________<br>Fale com seus amigos de graça com o novo Yahoo! Messenger <br><a href="http://br.messenger.yahoo.com/" target="_blank">http://br.messenger.yahoo.com/</a> </div>
<br><br>_______________________________________________<br><a href="http://www.voipmania.com.br/" target="_blank">http://www.voipmania.com.br</a><br>Telefone IP sem fio Gigaset A580IP por 6 x R$59,90.<br>Promoção por tempo limitado!<br>
Acesse agora <a href="http://promo.voipmania.com.br/" target="_blank">http://promo.voipmania.com.br</a><br><br>_______________________________________________<br>Lista de discussões AsteriskBrasil.org<br><a href="mailto:AsteriskBrasil@listas.asteriskbrasil.org" target="_blank">AsteriskBrasil@listas.asteriskbrasil.org</a><br>
<a href="http://listas.asteriskbrasil.org/mailman/listinfo/asteriskbrasil" target="_blank">http://listas.asteriskbrasil.org/mailman/listinfo/asteriskbrasil</a><br></blockquote></div><br><br clear="all"><br>-- <br>#!/bin/bash<br>
<br>Luciano Antonio Borguetti Faustino<br>GNU/Linux user number: 339110<br>ICQ UIN number: 82092097 - ICQ ainda na atividade :)<br><a href="http://lucianoborguetti.blogspot.com/" target="_blank">http://lucianoborguetti.blogspot.com</a><br>
<br>Preconceito é opinião sem conhecimento.<br><br>:wq<br></div><br><br>_______________________________________________<br><a href="http://www.voipmania.com.br/" target="_blank">http://www.voipmania.com.br</a><br>Telefone IP sem fio Gigaset A580IP por 6 x R$59,90.<br>
Promoção por tempo limitado!<br>Acesse agora <a href="http://promo.voipmania.com.br/" target="_blank">http://promo.voipmania.com.br</a><br><br>_______________________________________________<br>Lista de discussões AsteriskBrasil.org<br>
<a href="mailto:AsteriskBrasil@listas.asteriskbrasil.org">AsteriskBrasil@listas.asteriskbrasil.org</a><br><a href="http://listas.asteriskbrasil.org/mailman/listinfo/asteriskbrasil" target="_blank">http://listas.asteriskbrasil.org/mailman/listinfo/asteriskbrasil</a><br>
</blockquote></div><br>