<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    Important&iacute;ssimas dicas Keller!&nbsp; Ja tenho algo a mais a implementar
    em meus servers com Asterisk a partir de agora..<br>
    Mas M&aacute;rcio e keller.<br>
    Quando citei as dicas, citei de forma que atenda ambientes de
    pequeno porte. Por exemplo, tenho um cliente c/ 1E1 e 30 ramais SIP
    internos e mais 26 externos(logando na central oriundo da Internet).<br>
    Eu jamais colocaria uma central de m&eacute;dio porte com IP-Publico.&nbsp; Se
    fosse necess&aacute;rio, colocaria um outro Asterisk c/ IP-Publico
    entroncado com o Asterisk principal via IAX, ISDN, sei
    la................<br>
    Mas imprecionante como ataques em cima de sess&otilde;es SIP derruba um
    servidor. Incrivelmente....&nbsp; Ataques em cima de SSH, Apache nunca
    derrubaram meus servers, apenas em cima de Asterisk.<br>
    &nbsp;&nbsp;&nbsp; Mas M&aacute;rcio e Keller, me considero um sysadmin mediano em
    Asterisk, bem longe da experi&ecirc;ncia de vc&acute;s, por&eacute;m em Security tenho
    uma boa experi&ecirc;ncia e podemos disuctir isso em PVT.&nbsp; <br>
    &nbsp;&nbsp;&nbsp; Quanto ao M&aacute;rcio desabafar aqui na Lista(rsrsrrsrs), eu concordo
    plenamente c/ suas considera&ccedil;&otilde;es.&nbsp; Pessoal da lista, vamos criar um
    segundo n&iacute;vel de tira-d&uacute;vidas aqui !!!&nbsp; Tem coisas que sujeito
    pergunta ja tendo a resposta na pr&oacute;pria lista!!&nbsp; Ou uma pequena
    pesquisa ter&aacute; a resposta! Meu Deus!!<br>
    <br>
    <br>
    <br>
    Em 31/07/2013 15:47, Alexandre Keller escreveu:
    <blockquote
      cite="mid:824AEDBD-5C0C-42F7-8670-22684B4664E4@gmail.com"
      type="cite">
      <meta http-equiv="Content-Type" content="text/html;
        charset=ISO-8859-1">
      Boa tarde Senhores.
      <div><br>
      </div>
      <div>Deixe-me dar um pitaco nas quest&otilde;es de seguran&ccedil;a.</div>
      <div><br>
      </div>
      <div>Al&eacute;m, &eacute; claro e &oacute;bvio, das quest&otilde;es associadas a rede,
        deve-se tamb&eacute;m tomar muito cuidado com os par&acirc;metros SIP e como
        o seu plano de discagem foi constru&iacute;do.</div>
      <div><br>
      </div>
      <div>A seguir, algumas dicas, que passo no treinamento avan&ccedil;ado de
        Asterisk que ministro.</div>
      <div><br>
      </div>
      <div>Espero que seja de alguma ajuda:</div>
      <div>
        <!--[if gte mso 9]><xml>
 <o:DocumentProperties>
  <o:Revision>0</o:Revision>
  <o:TotalTime>0</o:TotalTime>
  <o:Pages>1</o:Pages>
  <o:Words>227</o:Words>
  <o:Characters>1296</o:Characters>
  <o:Company>Asteriks Inform&aacute;tica Ltda.</o:Company>
  <o:Lines>10</o:Lines>
  <o:Paragraphs>3</o:Paragraphs>
  <o:CharactersWithSpaces>1520</o:CharactersWithSpaces>
  <o:Version>14.0</o:Version>
 </o:DocumentProperties>
 <o:OfficeDocumentSettings>
  <o:PixelsPerInch>96</o:PixelsPerInch>
 </o:OfficeDocumentSettings>
</xml><![endif]-->
        <!--[if gte mso 9]><xml>
 <w:WordDocument>
  <w:View>Normal</w:View>
  <w:Zoom>0</w:Zoom>
  <w:TrackMoves/>
  <w:TrackFormatting/>
  <w:PunctuationKerning/>
  <w:ValidateAgainstSchemas/>
  <w:SaveIfXMLInvalid>false</w:SaveIfXMLInvalid>
  <w:IgnoreMixedContent>false</w:IgnoreMixedContent>
  <w:AlwaysShowPlaceholderText>false</w:AlwaysShowPlaceholderText>
  <w:DoNotPromoteQF/>
  <w:LidThemeOther>EN-US</w:LidThemeOther>
  <w:LidThemeAsian>JA</w:LidThemeAsian>
  <w:LidThemeComplexScript>X-NONE</w:LidThemeComplexScript>
  <w:Compatibility>
   <w:BreakWrappedTables/>
   <w:SnapToGridInCell/>
   <w:WrapTextWithPunct/>
   <w:UseAsianBreakRules/>
   <w:DontGrowAutofit/>
   <w:SplitPgBreakAndParaMark/>
   <w:EnableOpenTypeKerning/>
   <w:DontFlipMirrorIndents/>
   <w:OverrideTableStyleHps/>
  </w:Compatibility>
  <m:mathPr>
   <m:mathFont m:val="Cambria Math"/>
   <m:brkBin m:val="before"/>
   <m:brkBinSub m:val="&#45;-"/>
   <m:smallFrac m:val="off"/>
   <m:dispDef/>
   <m:lMargin m:val="0"/>
   <m:rMargin m:val="0"/>
   <m:defJc m:val="centerGroup"/>
   <m:wrapIndent m:val="1440"/>
   <m:intLim m:val="subSup"/>
   <m:naryLim m:val="undOvr"/>
  </m:mathPr></w:WordDocument>
</xml><![endif]--><!--[if gte mso 9]><xml>
 <w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"
  DefSemiHidden="true" DefQFormat="false" DefPriority="99"
  LatentStyleCount="276">
  <w:LsdException Locked="false" Priority="0" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Normal"/>
  <w:LsdException Locked="false" Priority="9" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 1"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 2"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 3"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 4"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 5"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 6"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 7"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 8"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 9"/>
  <w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/>
  <w:LsdException Locked="false" Priority="10" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Title"/>
  <w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/>
  <w:LsdException Locked="false" Priority="11" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/>
  <w:LsdException Locked="false" Priority="22" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Strong"/>
  <w:LsdException Locked="false" Priority="20" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/>
  <w:LsdException Locked="false" Priority="59" SemiHidden="false"
   UnhideWhenUsed="false" Name="Table Grid"/>
  <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/>
  <w:LsdException Locked="false" Priority="1" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 1"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 1"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 1"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/>
  <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/>
  <w:LsdException Locked="false" Priority="34" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/>
  <w:LsdException Locked="false" Priority="29" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Quote"/>
  <w:LsdException Locked="false" Priority="30" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 1"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 1"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 2"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 2"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 2"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 2"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 2"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 3"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 3"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 3"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 3"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 3"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 4"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 4"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 4"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 4"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 4"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 5"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 5"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 5"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 5"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 5"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 6"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 6"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 6"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 6"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 6"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/>
  <w:LsdException Locked="false" Priority="19" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/>
  <w:LsdException Locked="false" Priority="21" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/>
  <w:LsdException Locked="false" Priority="31" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/>
  <w:LsdException Locked="false" Priority="32" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/>
  <w:LsdException Locked="false" Priority="33" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/>
  <w:LsdException Locked="false" Priority="37" Name="Bibliography"/>
  <w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/>
 </w:LatentStyles>
</xml><![endif]-->
        <!--[if gte mso 10]>
<style>
 /* Style Definitions */
table.MsoNormalTable
        {mso-style-name:"Table Normal";
        mso-tstyle-rowband-size:0;
        mso-tstyle-colband-size:0;
        mso-style-noshow:yes;
        mso-style-priority:99;
        mso-style-parent:"";
        mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
        mso-para-margin:0cm;
        mso-para-margin-bottom:.0001pt;
        mso-pagination:widow-orphan;
        font-size:12.0pt;
        font-family:Calibri;}
</style>
<![endif]-->
        <!--StartFragment-->
        <p class="TextoNormalPrimParag"><span lang="PT-BR"><b>Par&acirc;metros
              associados a
              seguran&ccedil;a do Servidor Asterisk, protocolo SIP. <o:p></o:p></b></span></p>
        <p class="SubItens"
          style="text-indent:0cm;mso-list:none;tab-stops:36.0pt"><span
            style="font-family:&quot;Wingdings
            2&quot;;mso-ascii-font-family:Garamond;
            mso-hansi-font-family:Garamond;mso-char-type:symbol;mso-symbol-font-family:
&quot;Wingdings
            2&quot;" lang="PT-BR">&#150;</span><span lang="PT-BR">&nbsp;&nbsp; <b>allowguest:</b>
            permite (yes) ou n&atilde;o (no) a conex&atilde;o sem autentica&ccedil;&atilde;o.
            Certos equipamentos SIP n&atilde;o suportam autentica&ccedil;&atilde;o, assim &eacute;
            necess&aacute;rio
            desabilitar este par&acirc;metro. Deve ser setado na se&ccedil;&atilde;o general
            do protocolo SIP.<o:p></o:p></span></p>
        <p class="SubItens"
          style="text-indent:0cm;mso-list:none;tab-stops:36.0pt"><b><span
              style="font-family:&quot;Wingdings 2&quot;;
              mso-ascii-font-family:Garamond;mso-hansi-font-family:Garamond;mso-char-type:
symbol;mso-symbol-font-family:&quot;Wingdings
              2&quot;" lang="PT-BR">&#150;</span><span lang="PT-BR">&nbsp;&nbsp;
              alwaysauthreject:</span></b><span lang="PT-BR">
            quando habilitado (yes) faz com que o Asterisk rejeite as
            requisi&ccedil;&otilde;es de
            autentica&ccedil;&atilde;o inv&aacute;lidas para usu&aacute;rios v&aacute;lidos, com as mesmas
            informa&ccedil;&otilde;es dos
            usu&aacute;rios inv&aacute;lidos; evitando assim que ataques de
            for&ccedil;a-bruta identifiquem
            quais extens&otilde;es s&atilde;o v&aacute;lidas ou n&atilde;o. Deve ser setado na se&ccedil;&atilde;o
            general do
            protocolo SIP.<o:p></o:p></span></p>
        <p class="SubItens"
          style="text-indent:0cm;mso-list:none;tab-stops:36.0pt"><span
            style="font-family:&quot;Wingdings
            2&quot;;mso-ascii-font-family:Garamond;
            mso-hansi-font-family:Garamond;mso-char-type:symbol;mso-symbol-font-family:
&quot;Wingdings
            2&quot;" lang="PT-BR">&#150;</span><span lang="PT-BR">&nbsp;&nbsp; <b>permit/deny:</b>
            limita a conex&atilde;o a um endere&ccedil;o IP ou faixa de
            endere&ccedil;os IP. Para bloquear qualquer conex&atilde;o deve-se
            utilizar </span><b><span style="font-size: 10pt;
              font-family: 'Lucida Console'; ">deny=0.0.0.0/0.0.0.0</span></b><span
            style="font-size: 10pt; font-family: 'Lucida Console'; "> </span><span
            lang="PT-BR">e ent&atilde;o permitir (</span><span
            style="font-size: 10pt; font-family: 'Lucida Console'; ">permit</span><span
            lang="PT-BR">) somente o IP desejado.<b><o:p></o:p></b></span></p>
        <p class="CdigoFonte1">deny = 0.0.0.0/0.0.0.0<o:p></o:p></p>
        <p class="CdigoFonte1">permit = 192.168.250.10/255.255.255.255<o:p></o:p></p>
        <p class="SubItens"
          style="text-indent:0cm;mso-list:none;tab-stops:36.0pt"><span
            style="font-family:&quot;Wingdings
            2&quot;;mso-ascii-font-family:Garamond;
            mso-hansi-font-family:Garamond;mso-char-type:symbol;mso-symbol-font-family:
&quot;Wingdings
            2&quot;" lang="PT-BR">&#150;</span><span lang="PT-BR">&nbsp;&nbsp; <b>contactpermit/contactdeny:</b>
            limita o registro a um endere&ccedil;o IP ou
            faixa de endere&ccedil;os IP. Utiliza&ccedil;&atilde;o &eacute; semelhante aos
            par&acirc;metros </span><span style="font-size: 10pt;
            font-family: 'Lucida Console'; ">permit/deny</span><span
            lang="PT-BR">.<b><o:p></o:p></b></span></p>
        <p class="CdigoFonte1">contactdeny = 0.0.0.0/0.0.0.0<o:p></o:p></p>
        <p class="CdigoFonte1">contactpermit =
          192.168.250.10/255.255.255.255<o:p></o:p></p>
        <p class="SubItens"
          style="text-indent:0cm;mso-list:none;tab-stops:36.0pt"><span
            style="font-family:&quot;Wingdings
            2&quot;;mso-ascii-font-family:Garamond;
            mso-hansi-font-family:Garamond;mso-char-type:symbol;mso-symbol-font-family:
&quot;Wingdings
            2&quot;" lang="PT-BR">&#150;</span><span lang="PT-BR">&nbsp;&nbsp; <b>md5secret:</b>
            permite o armazenamento da senha de autentica&ccedil;&atilde;o SIP em
            hash MD5, e n&atilde;o em texto puro, como &eacute; o padr&atilde;o no par&acirc;metro
          </span><span style="font-size: 10pt; font-family: 'Lucida
            Console'; ">secret</span><span lang="PT-BR">. Para gerar o
            hash MD5 adequado para cada
            cliente utilize a seguinte sintaxe:<o:p></o:p></span></p>
        <p class="CdigoFonte1">Sintaxe:<o:p></o:p></p>
        <p class="CdigoFonte1">echo -n "username:realm:secret" | md5sum&nbsp;</p>
        <p class="CdigoFonte1">Exemplo:<o:p></o:p></p>
        <p class="CdigoFonte1">echo -n "9001:asterisk:senha01" | md5sum<o:p></o:p></p>
        <p class="CdigoFonte1">cd69374645f11ccfcb8d53bd2f81253c&nbsp; -</p>
        <p class="CdigoFonte1">Utilize o valor <b>cd69374645f11ccfcb8d53bd2f81253c</b>
          no par&acirc;metro md5secret.</p>
        <div><br>
        </div>
        <div>
          <!--[if gte mso 9]><xml>
 <o:DocumentProperties>
  <o:Revision>0</o:Revision>
  <o:TotalTime>0</o:TotalTime>
  <o:Pages>1</o:Pages>
  <o:Words>291</o:Words>
  <o:Characters>1663</o:Characters>
  <o:Company>Asteriks Inform&aacute;tica Ltda.</o:Company>
  <o:Lines>13</o:Lines>
  <o:Paragraphs>3</o:Paragraphs>
  <o:CharactersWithSpaces>1951</o:CharactersWithSpaces>
  <o:Version>14.0</o:Version>
 </o:DocumentProperties>
 <o:OfficeDocumentSettings>
  <o:PixelsPerInch>96</o:PixelsPerInch>
 </o:OfficeDocumentSettings>
</xml><![endif]-->
          <!--[if gte mso 9]><xml>
 <w:WordDocument>
  <w:View>Normal</w:View>
  <w:Zoom>0</w:Zoom>
  <w:TrackMoves/>
  <w:TrackFormatting/>
  <w:PunctuationKerning/>
  <w:ValidateAgainstSchemas/>
  <w:SaveIfXMLInvalid>false</w:SaveIfXMLInvalid>
  <w:IgnoreMixedContent>false</w:IgnoreMixedContent>
  <w:AlwaysShowPlaceholderText>false</w:AlwaysShowPlaceholderText>
  <w:DoNotPromoteQF/>
  <w:LidThemeOther>EN-US</w:LidThemeOther>
  <w:LidThemeAsian>JA</w:LidThemeAsian>
  <w:LidThemeComplexScript>X-NONE</w:LidThemeComplexScript>
  <w:Compatibility>
   <w:BreakWrappedTables/>
   <w:SnapToGridInCell/>
   <w:WrapTextWithPunct/>
   <w:UseAsianBreakRules/>
   <w:DontGrowAutofit/>
   <w:SplitPgBreakAndParaMark/>
   <w:EnableOpenTypeKerning/>
   <w:DontFlipMirrorIndents/>
   <w:OverrideTableStyleHps/>
  </w:Compatibility>
  <m:mathPr>
   <m:mathFont m:val="Cambria Math"/>
   <m:brkBin m:val="before"/>
   <m:brkBinSub m:val="&#45;-"/>
   <m:smallFrac m:val="off"/>
   <m:dispDef/>
   <m:lMargin m:val="0"/>
   <m:rMargin m:val="0"/>
   <m:defJc m:val="centerGroup"/>
   <m:wrapIndent m:val="1440"/>
   <m:intLim m:val="subSup"/>
   <m:naryLim m:val="undOvr"/>
  </m:mathPr></w:WordDocument>
</xml><![endif]--><!--[if gte mso 9]><xml>
 <w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"
  DefSemiHidden="true" DefQFormat="false" DefPriority="99"
  LatentStyleCount="276">
  <w:LsdException Locked="false" Priority="0" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Normal"/>
  <w:LsdException Locked="false" Priority="9" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 1"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 2"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 3"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 4"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 5"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 6"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 7"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 8"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 9"/>
  <w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/>
  <w:LsdException Locked="false" Priority="10" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Title"/>
  <w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/>
  <w:LsdException Locked="false" Priority="11" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/>
  <w:LsdException Locked="false" Priority="22" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Strong"/>
  <w:LsdException Locked="false" Priority="20" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/>
  <w:LsdException Locked="false" Priority="59" SemiHidden="false"
   UnhideWhenUsed="false" Name="Table Grid"/>
  <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/>
  <w:LsdException Locked="false" Priority="1" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 1"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 1"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 1"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/>
  <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/>
  <w:LsdException Locked="false" Priority="34" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/>
  <w:LsdException Locked="false" Priority="29" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Quote"/>
  <w:LsdException Locked="false" Priority="30" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 1"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 1"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 2"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 2"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 2"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 2"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 2"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 3"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 3"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 3"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 3"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 3"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 4"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 4"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 4"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 4"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 4"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 5"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 5"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 5"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 5"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 5"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 6"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 6"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 6"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 6"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 6"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/>
  <w:LsdException Locked="false" Priority="19" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/>
  <w:LsdException Locked="false" Priority="21" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/>
  <w:LsdException Locked="false" Priority="31" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/>
  <w:LsdException Locked="false" Priority="32" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/>
  <w:LsdException Locked="false" Priority="33" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/>
  <w:LsdException Locked="false" Priority="37" Name="Bibliography"/>
  <w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/>
 </w:LatentStyles>
</xml><![endif]-->
          <!--[if gte mso 10]>
<style>
 /* Style Definitions */
table.MsoNormalTable
        {mso-style-name:"Table Normal";
        mso-tstyle-rowband-size:0;
        mso-tstyle-colband-size:0;
        mso-style-noshow:yes;
        mso-style-priority:99;
        mso-style-parent:"";
        mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
        mso-para-margin:0cm;
        mso-para-margin-bottom:.0001pt;
        mso-pagination:widow-orphan;
        font-size:12.0pt;
        font-family:Calibri;}
</style>
<![endif]-->
          <!--StartFragment-->
          <p class="Tt2"><span lang="PT-BR"><b>Vulnerabilidades
                associadas ao Plano de Discagem<o:p></o:p></b></span></p>
          <p class="TextoNormalPrimParag" style="page-break-after:avoid"><span
              lang="PT-BR">&nbsp;&#8211; N&atilde;o utilize o contexto </span><span
              style="font-size: 10pt; line-height: 120%; font-family:
              'Lucida Console'; ">[default]</span><span lang="PT-BR">,
              pois &eacute; o contexto padr&atilde;o do Asterisk, ou seja, caso o
              Asterisk n&atilde;o
              encontre um contexto associado a uma conta,
              automaticamente processar&aacute; a
              chamada no contexto </span><span style="font-size: 10pt;
              line-height: 120%; font-family: 'Lucida Console'; ">[default]</span><span
              lang="PT-BR">. Como sugest&atilde;o crie-o da seguinte maneira:<o:p></o:p></span></p>
          <p class="CdigoFonte1">[default]<o:p></o:p></p>
          <p class="CdigoFonte1">exten =&gt; _.,1,HangUP<o:p></o:p></p>
          <p class="TextoNormalPrimParag" style="page-break-after:avoid"><span
              lang="PT-BR">&#8211;
              A utiliza&ccedil;&atilde;o da m&aacute;scara de discagem </span><span
              style="font-size: 10pt; line-height: 120%; font-family:
              'Lucida Console'; ">.</span><span lang="PT-BR"> (ponto) ou
            </span><span style="font-size: 10pt; line-height: 120%;
              font-family: 'Lucida Console'; ">!</span><span
              lang="PT-BR">
              (exclama&ccedil;&atilde;o), permite o que &eacute; comumente chamado de
              &#8220;dialplan injection&#8221;, ou
              seja, a inser&ccedil;&atilde;o de caracteres a serem processados al&eacute;m
              dos desejados, como no
              exemplo na regra </span><span style="font-size: 10pt;
              line-height: 120%; font-family: 'Lucida Console'; ">exten=&gt;_X.,1,Dial(SIP/${EXTEN},30,tT)</span><span
              lang="PT-BR">, onde o uso do </span><span
              style="font-size: 10pt; line-height: 120%; font-family:
              'Lucida Console'; ">.</span><span lang="PT-BR"> (ponto)
              aceita qualquer caractere, num&eacute;rico ou n&atilde;o. Imagine ent&atilde;o
              se fosse enviada a seguinte sequ&ecirc;ncia de caracteres para
              ser processada </span><span style="font-size: 10pt;
              line-height: 120%; font-family: 'Lucida Console'; ">1234&amp;SIP/provedor/551135228446</span><span
              lang="PT-BR">, o Asterisk processaria a chamada e
              executaria </span><span style="font-size: 10pt;
              line-height: 120%; font-family: 'Lucida Console'; ">Dial(SIP/1234&amp;SIP/provedor/551135228446,30,tT)</span><span
              lang="PT-BR">, ou seja, uma discagem bastante indevida.
              Existem duas formas
              indicadas para evitar esta ocorr&ecirc;ncia:<o:p></o:p></span></p>
          <p class="SubItens"
            style="text-indent:0cm;mso-list:none;tab-stops:36.0pt"><span
              style="font-family:&quot;Wingdings
              2&quot;;mso-ascii-font-family:Garamond;
              mso-hansi-font-family:Garamond;mso-char-type:symbol;mso-symbol-font-family:
&quot;Wingdings
              2&quot;" lang="PT-BR">&#150;</span><span lang="PT-BR">&nbsp;&nbsp; N&atilde;o
              utilizar as m&aacute;scaras </span><span style="font-size: 10pt;
              font-family: 'Lucida Console'; ">.</span><span
              lang="PT-BR"> (ponto) ou </span><span style="font-size:
              10pt; font-family: 'Lucida Console'; ">!</span><span
              lang="PT-BR"> (exclama&ccedil;&atilde;o).<b><o:p></o:p></b></span></p>
          <p class="SubItens"
            style="text-indent:0cm;mso-list:none;tab-stops:36.0pt"><span
              style="font-family:&quot;Wingdings
              2&quot;;mso-ascii-font-family:Garamond;
              mso-hansi-font-family:Garamond;mso-char-type:symbol;mso-symbol-font-family:
&quot;Wingdings
              2&quot;" lang="PT-BR">&#150;</span><span lang="PT-BR">&nbsp;&nbsp;
              Utilizar a fun&ccedil;&atilde;o </span><span style="font-size: 10pt;
              font-family: 'Lucida Console'; ">FILTER()</span><span
              lang="PT-BR">, para filtrar apenas os caracteres
              num&eacute;ricos, como no exemplo a seguir:<o:p></o:p></span></p>
          <p class="CdigoFonte1">[meucontexto]<o:p></o:p></p>
          <p class="CdigoFonte1">exten =&gt;
            _X.,1,Set(SAFE_EXTEN=${FILTER(0-9,${EXTEN})})<o:p></o:p></p>
          <p class="CdigoFonte1">same =&gt;
            n,Dial(SIP/${SAFE_EXTEN},30,tT) <o:p></o:p></p>
          <p class="TextoNormalPrimParag" style="page-break-after:avoid"><span
              lang="PT-BR">&#8211;
              Sempre especifique um limite para a quantidade de chamadas
              iniciada por cada
              cliente. Pode-se utilizar as fun&ccedil;&otilde;es </span><span
              style="font-size: 10pt; line-height: 120%; font-family:
              'Lucida Console'; ">GROUP() </span><span lang="PT-BR">e</span><span
              style="font-size: 10pt; line-height: 120%; font-family:
              'Lucida Console'; "> GROUP_COUNT()</span><span
              lang="PT-BR"> para tal fun&ccedil;&atilde;o dentro do plano de discagem,
              como no exemplo a
              seguir:<o:p></o:p></span></p>
          <p class="CdigoFonte1">[meucontexto]<o:p></o:p></p>
          <p class="CdigoFonte1">exten =&gt;
            _X.,1,Set(GROUP(users)=${CHANNEL(peername)}) <o:p></o:p></p>
          <p class="CdigoFonte1">same =&gt; n,NoOp(Existem
            ${GROUP_COUNT(${CHANNEL(peername)})} chamadas para a conta
            ${CHANNEL(peername)}.)
            <o:p></o:p></p>
          <p class="CdigoFonte1">same =&gt;
            n,GotoIf($[${GROUP_COUNT(${CHANNEL(peername)})}
            &gt; 2]?proibido:continue)<o:p></o:p></p>
          <p class="CdigoFonte1">same =&gt; n(proibido),NoOp(Limite de
            chamadas alcan&ccedil;ado.)<br>
            same =&gt; n,HangUp()<br>
            same =&gt; n(continue),NoOp(Continue o processamento normal
            do plano de
            discagem.)<o:p></o:p></p>
          <p class="CdigoFonte1">same =&gt;
            n,Set(SAFE_EXTEN=${FILTER(0-9,${EXTEN})})<o:p></o:p></p>
          <p class="CdigoFonte1">same =&gt;
            n,Dial(SIP/${SAFE_EXTEN},30,tT)&nbsp;<o:p></o:p></p>
          <!--EndFragment--></div>
        <div apple-content-edited="true">
          <span class="Apple-style-span" style="border-collapse:
            separate; border-spacing: 0px; ">--&nbsp;<br>
            Atenciosamente,<br>
            <br>
            ALEXANDRE KELLER<br>
            <br>
            <a moz-do-not-send="true"
              href="http://twitter.com/alexandrekeller">http://twitter.com/alexandrekeller</a><br>
            <a class="moz-txt-link-freetext" href="http://www.facebook.com/alexandre.keller.BR">http://www.facebook.com/alexandre.keller.BR</a><br>
            <br>
            "Dinheiro &eacute; a consequ&ecirc;ncia de um&nbsp;trabalho bem feito e n&atilde;o o
            motivo&nbsp;para se fazer um bom trabalho."<br>
            <br>
            P Antes de imprimir pense em seu&nbsp;compromisso com o Meio
            Ambiente.</span>
        </div>
        <br>
        <div>
          <div>On 31/07/2013, at 15:23, Marcio - Google &lt;<a
              moz-do-not-send="true" href="mailto:marciorp@gmail.com">marciorp@gmail.com</a>&gt;
            wrote:</div>
          <br class="Apple-interchange-newline">
          <blockquote type="cite">
            <div dir="ltr">
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif">Guilherme,
                concordo com a sua coloca&ccedil;&atilde;o final. Seguran&ccedil;a &eacute; de suma
                import&acirc;ncia para telefonia IP! Complemente dizendo que a
                maioria nem sabe o que &eacute; isso!</div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif"><br>
              </div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif">O exemplo
                foi minimalista, e s&oacute; para demonstrar a necessidade de
                um "firewall" entre a rede externa e os servi&ccedil;os.</div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif"><br>
              </div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif">O grande
                problema &eacute; que a maioria mal sabe usar linux, n&atilde;o tem
                no&ccedil;&atilde;o dos conceitos b&aacute;sicos de rede e pioro de
                seguran&ccedil;a. Ai pega meia d&uacute;zia de receita de bolo na net
                e sai vendendo servi&ccedil;o, quando d&aacute; alguma "zica" a culpa
                &eacute; da tecnologia!</div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif"><br>
              </div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif">Quanto ao
                item 3.1, nunca fiz e me recusaria a fazer, pelo simples
                fato que qualquer empresa que queria isso tem que ter
                grana para pagar. Um dos principais erros do mundo
                "software livre", principalmente no Brasil, &eacute; a ideia de
                que o Linux/Asterisk s&atilde;o de gra&ccedil;a, ent&atilde;o as solu&ccedil;&otilde;es tem
                que ser baratas se n&atilde;o de gra&ccedil;a.</div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif"><br>
              </div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif">Falando
                dos itens 3.2 e 3.3, &eacute; uma seguran&ccedil;a a mais. Por&eacute;m n&atilde;o &eacute;
                100%, pode ser contornado, principalmente por algum
                ex-funcion&aacute;rio que tenha sa&iacute;do magoado da empresa e
                conhe&ccedil;a a estrutura. Muitas vezes ele pr&oacute;prio n&atilde;o faz,
                mas passas as informa&ccedil;&otilde;es para algu&eacute;m fazer.</div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif"><br>
              </div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif">Uso o
                item 3.4, com alguns detalhes a mais.</div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif">
                <br>
              </div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif">Pois &eacute;,
                chegamos ao item 3.5, e nesse caso se for um ataque de
                pequeno porte pra cima, a n&atilde;o ser que voc&ecirc; tenha um
                appliance bem dimensionado, as chances de algum problema
                s&atilde;o bem grandes. Por problemas n&atilde;o entendo apenas
                conseguir fazer liga&ccedil;&otilde;es, mas a pr&oacute;pria
                indisponibilidade do sistema ou queda do servi&ccedil;o &eacute; um
                problema.</div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif"><br>
              </div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif">Estrutura
                minima detalhada: Internet &lt;&gt; Router &lt;&gt;
                Firewall Generalista / Servi&ccedil;os / Aplica&ccedil;&otilde;es / Pacotes
                *1 &lt;&gt; IDS &lt;&gt; [Proxy SIP] &lt;&gt; Asterisk</div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif">*1 -
                Normalmente um appliance, pode ser dividido em mais de
                um hardware.</div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif">
                <br>
              </div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif">N&atilde;o to
                considerando ai DMZ, a parte isolada para os servi&ccedil;os
                que n&atilde;o s&atilde;o expostos e etc.</div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif">
                <br>
              </div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif">Se o
                individuo passar pelo Firewall, dificilmente ele passa
                pelo IDS. Se ainda assim passar pelo IDS, o Asterisk
                pode avisar o IDS de tentativas de conex&atilde;o
                mal-sucedidas, e esse por usa vez vai aumentar o rigor.
                O IDS tamb&eacute;m conversa com o Firewall, e esse por sua vez
                com o Router, que em ultima instancia isola determinadas
                rotas at&eacute; a a&ccedil;&atilde;o de um sysadmin.</div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif"><br>
              </div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif">O
                problema &eacute; que a maioria n&atilde;o tem a menor no&ccedil;&atilde;o disso,
                baixa a ISO de uma distro Linux qualquer, instala de
                qualquer jeito e normalmente mais pacotes que o
                necess&aacute;rio, baixa o Asterisk, usa uma receita de bolo
                para instalar e sobe ele como *root* mesmo. Dai pega um
                script de iptables pronto, que nem ao menos intende
                direito o que faz, e quando muito instala o Fail2Ban,
                com receita de bolo tamb&eacute;m, e acha que &eacute; o supra sumo do
                universo em Linux, Seguran&ccedil;a, Redes, Asterisk e tudo
                mais. T&aacute; feito a lamban&ccedil;a.</div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif"><br>
              </div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif">Na
                primeira *zica* que acontece, fica desesperado, n&atilde;o sabe
                nem os logs que tem e muito menos como usa-los, e vem
                pedir socorro na lista. E n&atilde;o estou falando s&oacute; sobre a
                quest&atilde;o de seguran&ccedil;a mesmo.</div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif"><br>
              </div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif">&Eacute; s&oacute;
                prestar aten&ccedil;&atilde;o nas "d&uacute;vidas" que s&atilde;o postadas, chega
                ser triste! Chega ao cumulo do cara postar a d&uacute;vida com
                um fragmento de log com a mensagem explicando o
                problema!</div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif"><br>
              </div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif">&Eacute; s&oacute;
                olhar a quantidade de gente cadastrada na lista, muitos
                antigos, que nem respondem mais. D&aacute; desanimo!</div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif"><br>
              </div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif">Eu mesmo
                s&oacute; voltei a ativa pra passar o tempo, e quando surge uma
                d&uacute;vida de algu&eacute;m que realmente demonstra ter interesse,
                tento ajudar.</div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif"><br>
              </div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif">&Eacute; isso,
                desculpe misturar a resposta a esse desabafo!</div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif">
                <br>
              </div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif"><br>
              </div>
              <div class="gmail_default"
                style="font-family:arial,helvetica,sans-serif"><br>
              </div>
            </div>
            <div class="gmail_extra"><br clear="all">
              <div>
                <div dir="ltr"><br>
                  [...]'s<br>
                  <br>
                  Marcio
                  <div><br>
                  </div>
                  <div>
                    <div style="font-family:arial;font-size:small">========================================</div>
                    <div style="font-family:arial;font-size:small">###########
                      Campanha Ajude o Marcio! ###########</div>
                    <div style="font-family:arial;font-size:small"><a
                        moz-do-not-send="true"
                        href="http://sosmarcio.blogspot.com.br/"
                        style="color:rgb(17,85,204)" target="_blank">http://sosmarcio.blogspot.com.br/</a></div>
                    <div style="font-family:arial;font-size:small">
                      <a moz-do-not-send="true"
                        href="http://www.vakinha.com.br/VaquinhaP.aspx?e=195793"
                        style="color:rgb(17,85,204)" target="_blank">http://www.vakinha.com.br/VaquinhaP.aspx?e=195793</a><br>
                    </div>
                    <div style="font-family:arial;font-size:small">========================================</div>
                  </div>
                </div>
              </div>
              <br>
              <br>
              <div class="gmail_quote">Em 31 de julho de 2013 13:31,
                Guilherme Rezende <span dir="ltr">&lt;<a
                    moz-do-not-send="true"
                    href="mailto:asterisk@guilherme.eti.br"
                    target="_blank">asterisk@guilherme.eti.br</a>&gt;</span>
                escreveu:<br>
                <blockquote class="gmail_quote" style="margin:0 0 0
                  .8ex;border-left:1px #ccc solid;padding-left:1ex">
                  <div bgcolor="#FFFFFF" text="#000000"> M&aacute;rcio, gerando
                    uma discurs&atilde;o saud&aacute;vel sobre aspecto seguran&ccedil;a:<br>
                    &nbsp;&nbsp;&nbsp; Trabalho a 13 anos c/ Linux e Firewall e a 4 c/
                    Asterisk.&nbsp; Ja trabalhei e ainda fa&ccedil;o algumas
                    instala&ccedil;&otilde;es(de vez em quando) de Fortinet, SonicWall
                    e Linux/Iptables/Snort. <br>
                    Bom, quando precisamos colocar uma m&aacute;quina Asterisk
                    exposta na Internet p/ que clientes externos possa
                    se logar via SIP, a melhor alternativa &eacute; criando
                    tuneis com OpenVPN usando TAP+SSL.&nbsp; Por&eacute;m nem sempre
                    em virtudes de custo essa solu&ccedil;&atilde;o torna-se vi&aacute;vel e
                    precisamos expor nosso Asterisk na Internet, tanto
                    diretamente c/ um IP P&uacute;blico ou conforme solu&ccedil;&atilde;o
                    apresentada por vc abaixo.<br>
                    &nbsp;&nbsp;&nbsp; Eu, particulamente discordo de sua solu&ccedil;&atilde;o que
                    postou abaixo e prefiro usar IP-P&uacute;blico no
                    Asterisk.&nbsp; Veja os motivos:<br>
                    <br>
                    1 - No modelo que apresenta, seu Asterisk n&atilde;o fica
                    livre de falhas ou Bugs no m&oacute;dulo SIP do Asterisk.&nbsp;
                    O protoco SIP/UDP na forma que apresenta abaixo fica
                    exposto na mesma forma como seu Asterisk estivesse
                    c/ IP-P&uacute;blico, al&eacute;m de poder gerar anomalias do NAT
                    com SIP.&nbsp; Se o SIP n&atilde;o estiver liberado externo
                    ningu&eacute;m externamente ir&aacute; se logar no seu server
                    correto? Um atacante pode facilmente fazer
                    BruteForce em seu servidor no modelo abaixo como se
                    o mesmo estivesse com IP-Publico.&nbsp; Uma ferramenta p/
                    isso e que uso em laborat&oacute;rio &eacute; o sipvicious.&nbsp;&nbsp;&nbsp; N&atilde;o
                    sei o porque, mas sempre quando sofro esses ataques,
                    todos s&atilde;o oriundos de redes externas, ou seja, fora
                    do Brasil.&nbsp; Acho que at&eacute; na lista todos os cologas
                    apenas sofrem ataques de brute force externo
                    tamb&eacute;m...<br>
                    <br>
                    2 - Bom, passando da esfera de um filtro de pacotes,
                    uma grande solu&ccedil;&atilde;o seria an&aacute;lise de cabe&ccedil;alho/string
                    de pacotes do SIP p/ identificar anomalia no mesmo e
                    ai sim bloquear, como ja existe p/ HTTP, SMTP,
                    etc...&nbsp; Infelizmente nenhum dos firewalls
                    propriet&aacute;rio que conhe&ccedil;o n&atilde;o possui essa t&eacute;cnica.<br>
                    <br>
                    3 - Bom, resumindo minhas coloca&ccedil;&otilde;es, eu monto meus
                    projetos da seguinte forma:<br>
                    &nbsp;&nbsp;&nbsp; 3.1 - Quando se torna necess&aacute;rio expor o
                    Asterisk ao IP P&uacute;blico.&nbsp; "Eu possuo 4 clientes c/
                    esse modelo e nunca tive problemas. Por&eacute;m tentativas
                    foram v&aacute;rias"<br>
                    &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Internet &lt;&gt; Router &lt;&gt;&nbsp;
                    Asterisk<br>
                    &nbsp;&nbsp;&nbsp; 3.2 - Se todos os ips p&uacute;blicos que ir&atilde;o se logar
                    via SIP s&atilde;o fixos, libero no firewall(iptables)
                    apenas esses IP&acute;s p/ se logarem.<br>
                    &nbsp;&nbsp;&nbsp; 3.3 - Caso n&atilde;o sei de onde esses IP&acute;s vir&atilde;o,
                    Libero a Range do BR conforme ja postei aqui e fecho
                    todas as portas TCP, abrindo apenas as que irei usar
                    como SSH, HTTP, etc..<br>
                    &nbsp;&nbsp;&nbsp; 3.4 - Depois do filtro de pacotes, instale um
                    IDS p/ analise de pacotes mal forjados em cima do
                    seu Asterisk e um bom exemplo p/ isso &eacute; usar o SNORT
                    c/ uma rule pronta Asterisk. <a
                      moz-do-not-send="true"
href="http://blog.sipvicious.org/2008/02/detecting-sip-attacks-with-snort.html"
                      target="_blank">http://blog.sipvicious.org/2008/02/detecting-sip-attacks-with-snort.html</a><br>
                    &nbsp;&nbsp;&nbsp; 3.5 - Em 95% dos casos os ataques em cima do
                    Asterisk s&atilde;o Brute-Force em cima do SIP p/ tentar se
                    logar.&nbsp; Dificilmente os ataques em cima do SIP s&atilde;o
                    de Stack-Overflow p/ se conseguir um shell no
                    sistema por falha do Asterisk.&nbsp; <br>
                    &nbsp;&nbsp;&nbsp; Enfim, s&atilde;o v&aacute;rios cen&aacute;rios e concordo com vc
                    quando diz p/ evitar expor seu Asterisk c/ IP
                    P&uacute;blico.&nbsp; Devemos expor o m&iacute;nimo.&nbsp; Por&eacute;m nem sempre
                    &eacute; poss&iacute;vel.......<br>
                    &nbsp;&nbsp;&nbsp; <br>
                    Desculpa se fugi um pouco do escopo da lista que &eacute;
                    Asterisk, mas creio que &eacute; um assunto de suma
                    import&acirc;ncia par telefonia IP.&nbsp; Que &eacute; a seguan&ccedil;a !!!<br>
                    <br>
                    <br>
                    <br>
                    Em 31/07/2013 13:51, Marcio - Google escreveu:
                    <div>
                      <div class="h5">
                        <blockquote type="cite">
                          <div dir="ltr">
                            <div class="gmail_default"
                              style="font-family:arial,helvetica,sans-serif">IP
                              p&uacute;blico no server?!?!?! My Good, algu&eacute;m
                              realmente faz uma sandice dessas???</div>
                            <div class="gmail_default"
                              style="font-family:arial,helvetica,sans-serif">
                              <br>
                            </div>
                            <div class="gmail_default"
                              style="font-family:arial,helvetica,sans-serif">Acho
                              que vou desencarnar e n&atilde;o terei lido tudo
                              ... rsrsrsrsrsr</div>
                            <div class="gmail_default"
                              style="font-family:arial,helvetica,sans-serif">
                              <br>
                            </div>
                            <div class="gmail_default"
                              style="font-family:arial,helvetica,sans-serif">No
                              m&iacute;nimo, mas m&iacute;nimo mesmo: Internet
                              &lt;&gt; Router &lt;&gt; Firewall &lt;&gt;
                              [NAT] &lt;&gt; Asterisk</div>
                            <div class="gmail_default"
                              style="font-family:arial,helvetica,sans-serif">
                              <br>
                            </div>
                          </div>
                          <div class="gmail_extra"><br clear="all">
                            <div>
                              <div dir="ltr"><br>
                                [...]'s<br>
                                <br>
                                Marcio
                                <div><br>
                                </div>
                                <div>
                                  <div
                                    style="font-family:arial;font-size:small">========================================</div>
                                  <div
                                    style="font-family:arial;font-size:small">
                                    ########### Campanha Ajude o Marcio!
                                    ###########</div>
                                  <div
                                    style="font-family:arial;font-size:small"><a
                                      moz-do-not-send="true"
                                      href="http://sosmarcio.blogspot.com.br/"
                                      style="color:rgb(17,85,204)"
                                      target="_blank">http://sosmarcio.blogspot.com.br/</a></div>
                                  <div
                                    style="font-family:arial;font-size:small"><a
                                      moz-do-not-send="true"
                                      href="http://www.vakinha.com.br/VaquinhaP.aspx?e=195793"
                                      style="color:rgb(17,85,204)"
                                      target="_blank">http://www.vakinha.com.br/VaquinhaP.aspx?e=195793</a><br>
                                  </div>
                                  <div
                                    style="font-family:arial;font-size:small">
========================================</div>
                                </div>
                              </div>
                            </div>
                            <br>
                            <br>
                            <div class="gmail_quote">Em 31 de julho de
                              2013 12:37, Danilo Almeida <span
                                dir="ltr">&lt;<a moz-do-not-send="true"
href="mailto:daniloricalmeida@gmail.com" target="_blank">daniloricalmeida@gmail.com</a>&gt;</span>
                              escreveu:<br>
                              <blockquote class="gmail_quote"
                                style="margin:0 0 0 .8ex;border-left:1px
                                #ccc solid;padding-left:1ex">
                                <div dir="ltr">surgiu uma d&uacute;vida
                                  referente a esses ataques, como sou
                                  inexperiente nessa parte de redes, n&atilde;o
                                  sei como funciona essas tentativas...
                                  <div><br>
                                  </div>
                                  <div>como que eles descobrem o
                                    servidor na rede?</div>
                                  <div>como conseguem fazer tantas
                                    tentativas de ataque
                                    simultaneamente?</div>
                                  <div><br>
                                  </div>
                                  <div>se algu&eacute;m puder me esclarecer um
                                    pouco sobre esse assunto eu
                                    agrade&ccedil;o... at&eacute; mesmo porque,
                                    precisamos conhecer as t&eacute;cnicas para
                                    nos proteger.</div>
                                  <div><br>
                                  </div>
                                  <div>Obrigado</div>
                                </div>
                                <div class="gmail_extra"> <br>
                                  <br>
                                  <div class="gmail_quote">Em 31 de
                                    julho de 2013 13:33, Guilherme
                                    Rezende <span dir="ltr">&lt;<a
                                        moz-do-not-send="true"
                                        href="mailto:asterisk@guilherme.eti.br"
                                        target="_blank">asterisk@guilherme.eti.br</a>&gt;</span>
                                    escreveu:
                                    <div>
                                      <div> <br>
                                        <blockquote class="gmail_quote"
                                          style="margin:0 0 0
                                          .8ex;border-left:1px #ccc
                                          solid;padding-left:1ex">
                                          <div bgcolor="#FFFFFF"
                                            text="#000000"> &nbsp;&nbsp;&nbsp; Gente,
                                            eu n&atilde;o uso Fail2ban.&nbsp;&nbsp; Como
                                            esses ataques s&atilde;o oriundos
                                            de redes externas ao BR, fiz
                                            o bloqueio de todas as redes
                                            cujam origem n&atilde;o s&atilde;o BR. E
                                            resolveu!!&nbsp; N&atilde;o tenho
                                            problemas c/ ataques
                                            mais...&nbsp; Os logs do meu
                                            Asterisk nunca mais exibiram
                                            tentativa de logar via sip
                                            nos meus servidores.&nbsp; Veja o
                                            c&oacute;digo abaixo que &eacute; bem
                                            simples, libero apenas as
                                            redes que est&atilde;o listadas,
                                            depois fecho tudo.&nbsp; Se n&atilde;o
                                            tiver necessidade de ter
                                            algu&eacute;m externo que logue no
                                            seu servidor, o c&oacute;digo
                                            abaixo resolve.&nbsp; Desative
                                            todas suas regras de
                                            iptables, desative todos os
                                            firewall&acute;s e rode o script
                                            abaixo.<br>
                                            <br>
                                            #!/bin/bash<br>
                                            ipt=/sbin/iptables<br>
                                            $ipt -F<br>
                                            $ipt -A INPUT -i eth2 -s <a
                                              moz-do-not-send="true"
                                              href="http://172.16.5.0/24"
                                              target="_blank">172.16.5.0/24</a>
                                            -p udp -j ACCEPT<br>
                                            $ipt -A INPUT -i eth2 -s <a
                                              moz-do-not-send="true"
                                              href="http://186.0.0.0/8"
                                              target="_blank">186.0.0.0/8</a>
                                            -p udp -j ACCEPT<br>
                                            $ipt -A INPUT -i eth2 -s <a
                                              moz-do-not-send="true"
                                              href="http://187.0.0.0/8"
                                              target="_blank">187.0.0.0/8</a>
                                            -p udp -j ACCEPT<br>
                                            $ipt -A INPUT -i eth2 -s <a
                                              moz-do-not-send="true"
                                              href="http://177.0.0.0/8"
                                              target="_blank">177.0.0.0/8</a>
                                            -p udp -j ACCEPT<br>
                                            $ipt -A INPUT -i eth2 -s <a
                                              moz-do-not-send="true"
                                              href="http://179.0.0.0/8"
                                              target="_blank">179.0.0.0/8</a>
                                            -p udp -j ACCEPT<br>
                                            $ipt -A INPUT -i eth2 -s <a
                                              moz-do-not-send="true"
                                              href="http://189.0.0.0/8"
                                              target="_blank">189.0.0.0/8</a>
                                            -p udp -j ACCEPT<br>
                                            $ipt -A INPUT -i eth2 -s <a
                                              moz-do-not-send="true"
                                              href="tel:198.50.96.130"
                                              value="+551985096130"
                                              target="_blank">198.50.96.130</a>
                                            -p udp -j ACCEPT<br>
                                            $ipt -A INPUT -i eth2 -s <a
                                              moz-do-not-send="true"
                                              href="http://200.0.0.0/8"
                                              target="_blank">200.0.0.0/8</a>
                                            -p udp -j ACCEPT<br>
                                            $ipt -A INPUT -i eth2 -s <a
                                              moz-do-not-send="true"
                                              href="http://201.0.0.0/8"
                                              target="_blank">201.0.0.0/8</a>
                                            -p udp -j ACCEPT<br>
                                            $ipt -A INPUT -i eth2 -p udp
                                            -j DROP<br>
                                            <br>
                                            <br>
                                            <br>
                                            Em 31/07/2013 13:12, Danilo
                                            Almeida escreveu:
                                            <div>
                                              <div>
                                                <blockquote type="cite">
                                                  <div dir="ltr">recebi
                                                    v&aacute;rias tentativas
                                                    neste final de
                                                    semana, por&eacute;m, o
                                                    fail2ban bloqueiou.
                                                    <div><br>
                                                    </div>
                                                    <div>DROP&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; all&nbsp;
                                                      --&nbsp; <a
                                                        moz-do-not-send="true"
href="tel:173.242.120.42" value="+17324212042" target="_blank">173.242.120.42</a>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;

                                                      anywhere<br>
                                                      <table border="0"
                                                        cellpadding="4"
                                                        cellspacing="0"
                                                        height="300"
                                                        width="297">
                                                        <tbody>
                                                          <tr>
                                                          <td
                                                          align="right">Nome
                                                          do Host:</td>
                                                          <td
                                                          align="left"
                                                          width="198"><a
moz-do-not-send="true" href="tel:173.242.120.42" value="+17324212042"
                                                          target="_blank">173.242.120.42</a></td>
                                                          </tr>
                                                          <tr>
                                                          <td
                                                          align="right">IP
                                                          Address:</td>
                                                          <td
                                                          align="left"><a
moz-do-not-send="true" href="tel:173.242.120.42" value="+17324212042"
                                                          target="_blank">173.242.120.42</a></td>
                                                          </tr>
                                                          <tr>
                                                          <td
                                                          align="right">Pa&iacute;s:</td>
                                                          <td
                                                          align="left"><a
moz-do-not-send="true"
                                                          href="http://en.wikipedia.org/wiki/united%20states"
target="_blank"> United States</a> <img moz-do-not-send="true"
                                                          alt="united
                                                          states"
                                                          align="absmiddle"></td>
                                                          </tr>
                                                          <tr>
                                                          <td
                                                          align="right">C&oacute;digo
                                                          do pa&iacute;s:</td>
                                                          <td
                                                          align="left">US
                                                          (USA)</td>
                                                          </tr>
                                                          <tr>
                                                          <td
                                                          align="right">Regi&atilde;o:</td>
                                                          <td
                                                          align="left"><a
moz-do-not-send="true" href="http://en.wikipedia.org/wiki/Pennsylvania"
target="_blank">Pennsylvania</a></td>
                                                          </tr>
                                                          <tr>
                                                          <td
                                                          align="right">Cidade:</td>
                                                          <td
                                                          align="left">Clarks
                                                          Summit</td>
                                                          </tr>
                                                          <tr>
                                                          <td
                                                          align="right">C&oacute;digo
                                                          postal:</td>
                                                          <td
                                                          align="left">18411</td>
                                                          </tr>
                                                          <tr>
                                                          <td
                                                          align="right">C&oacute;digo
                                                          tel.:</td>
                                                          <td
                                                          align="left"><a
moz-do-not-send="true"
                                                          href="http://en.wikipedia.org/wiki/Area_code#United_States"
target="_blank">+1</a></td>
                                                          </tr>
                                                          <tr>
                                                          <td
                                                          align="right">Longitude:</td>
                                                          <td
                                                          align="left">-75.728</td>
                                                          </tr>
                                                          <tr>
                                                          <td
                                                          align="right">Latitude:</td>
                                                          <td
                                                          align="left">41.4486<br>
                                                          </td>
                                                          </tr>
                                                        </tbody>
                                                      </table>
                                                    </div>
                                                    <div
                                                      class="gmail_extra"><br>
                                                    </div>
                                                    <div
                                                      class="gmail_extra">
                                                      <div
                                                        class="gmail_extra">[2013-07-27

                                                        15:09:35]
                                                        NOTICE[1775]
                                                        chan_sip.c:
                                                        Registration
                                                        from '"shuang" <a
moz-do-not-send="true">&lt;sip:shuang@IP-Servidor&gt;</a>' failed for '<a
moz-do-not-send="true" href="http://173.242.120.42:5061/"
                                                          target="_blank">173.242.120.42:5061</a>'
                                                        - Wrong password</div>
                                                      <div><br>
                                                      </div>
                                                      <div>
                                                        <div>[2013-07-28
                                                          15:09:43]
                                                          NOTICE[1775]
                                                          chan_sip.c:
                                                          Registration
                                                          from '"chu" <a
moz-do-not-send="true">&lt;sip:chu@IP-servidor&gt;</a>' failed for '<a
                                                          moz-do-not-send="true"
href="http://173.242.120.42:5081/" target="_blank">173.242.120.42:5081</a>'
                                                          - Wrong
                                                          password</div>
                                                      </div>
                                                      <div><br>
                                                      </div>
                                                      <div>[2013-07-29
                                                        15:09:45]
                                                        NOTICE[1775]
                                                        chan_sip.c:
                                                        Registration
                                                        from '"chu" <a
moz-do-not-send="true">&lt;sip:chu@IP-servidor&gt;</a>' failed for '<a
                                                          moz-do-not-send="true"
href="http://173.242.120.42:5081/" target="_blank">173.242.120.42:5081</a>'
                                                        - Wrong password<br>
                                                      </div>
                                                      <div><br>
                                                      </div>
                                                      <div>[2013-07-30
                                                        15:09:47]
                                                        NOTICE[1775]
                                                        chan_sip.c:
                                                        Registration
                                                        from '"chu" <a
moz-do-not-send="true">&lt;sip:chu@IP-servido&gt;</a>' failed for '<a
                                                          moz-do-not-send="true"
href="http://173.242.120.42:5081/" target="_blank">173.242.120.42:5081</a>'
                                                        - Wrong password</div>
                                                      <div
                                                        class="gmail_extra"><br>
                                                      </div>
                                                      se observarem, eu
                                                      bloqueio as
                                                      tentativas por 24
                                                      horas, sendo
                                                      assim, o invasor
                                                      permanecia
                                                      tentando no dia
                                                      seguinte, agora
                                                      dei um BAN
                                                      permanente nele...
                                                      rsrs</div>
                                                    <div
                                                      class="gmail_extra">
                                                      <br>
                                                    </div>
                                                    <div
                                                      class="gmail_extra"><br>
                                                      <div
                                                        class="gmail_quote">Em
                                                        31 de julho de
                                                        2013 12:50,
                                                        Thiago Anselmo <span
                                                          dir="ltr">&lt;<a
moz-do-not-send="true" href="mailto:thiagoo.anselmoo@gmail.com"
                                                          target="_blank">thiagoo.anselmoo@gmail.com</a>&gt;</span>
                                                        escreveu:<br>
                                                        <blockquote
                                                          class="gmail_quote"
                                                          style="margin:0px
                                                          0px 0px
0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">
                                                          <div dir="ltr">Amigo,

                                                          <div><br>
                                                          </div>
                                                          <div>J&aacute; teve
                                                          outro amigo
                                                          aqui da lista
                                                          que teve o
                                                          mesmo
                                                          problema, e o
                                                          mesmo o
                                                          fail2ban n&atilde;o
                                                          pegou, pois
                                                          eles n&atilde;o
                                                          atacam penas
                                                          5060, existe
                                                          outras
                                                          fomras!!&nbsp;<br>
                                                          <br>
                                                          Como est&aacute;
                                                          ligado seu
                                                          PABX? Est&aacute;
                                                          atr&aacute;s de NAT
                                                          ou diretamente
                                                          um IP p&uacute;blico
                                                          ligado a ele?</div>
                                                          <div><br>
                                                          </div>
                                                          <div>me diga
                                                          que podemos
                                                          realizar
                                                          formas de
                                                          fazer com o
                                                          IPTABLES!! E
                                                          fica bom!!!</div>
                                                          <div>Bloqueia
                                                          tudo e libera
                                                          apenas para
                                                          quem voc&ecirc;
                                                          deseja!</div>
                                                          </div>
                                                          <div
                                                          class="gmail_extra"><br>
                                                          <br>
                                                          <div
                                                          class="gmail_quote">
                                                          Em 31 de julho
                                                          de 2013 12:40,
                                                          Marcio -
                                                          Google <span
                                                          dir="ltr">&lt;<a
moz-do-not-send="true" href="mailto:marciorp@gmail.com" target="_blank">marciorp@gmail.com</a>&gt;</span>
                                                          escreveu:
                                                          <div>
                                                          <div><br>
                                                          <blockquote
                                                          class="gmail_quote"
                                                          style="margin:0px
                                                          0px 0px
0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">
                                                          <div dir="ltr">
                                                          <div
                                                          style="font-family:arial,helvetica,sans-serif">Exatamente


                                                          o que o Hudson
                                                          disse ...</div>
                                                          <div
                                                          style="font-family:arial,helvetica,sans-serif">Falha


                                                          no
                                                          dimensionamento
                                                          e
                                                          configura&ccedil;&atilde;o.</div>
                                                          </div>
                                                          <div
                                                          class="gmail_extra"><br
                                                          clear="all">
                                                          <div>
                                                          <div dir="ltr"><br>
                                                          [...]'s<br>
                                                          <br>
                                                          Marcio
                                                          <div><br>
                                                          </div>
                                                          <div>
                                                          <div
                                                          style="font-family:arial;font-size:small">========================================</div>
                                                          <div
                                                          style="font-family:arial;font-size:small">
                                                          ###########
                                                          Campanha Ajude
                                                          o Marcio!
                                                          ###########</div>
                                                          <div
                                                          style="font-family:arial;font-size:small"><a
moz-do-not-send="true" href="http://sosmarcio.blogspot.com.br/"
                                                          style="color:rgb(17,85,204)"
target="_blank">http://sosmarcio.blogspot.com.br/</a></div>
                                                          <div
                                                          style="font-family:arial;font-size:small"><a
moz-do-not-send="true"
                                                          href="http://www.vakinha.com.br/VaquinhaP.aspx?e=195793"
style="color:rgb(17,85,204)" target="_blank">http://www.vakinha.com.br/VaquinhaP.aspx?e=195793</a><br>
                                                          </div>
                                                          <div
                                                          style="font-family:arial;font-size:small">
========================================</div>
                                                          </div>
                                                          </div>
                                                          </div>
                                                          <br>
                                                          <br>
                                                          <div
                                                          class="gmail_quote">Em

                                                          31 de julho de
                                                          2013 11:06,
                                                          Hudson Cardoso
                                                          <span
                                                          dir="ltr">&lt;<a
moz-do-not-send="true" href="mailto:hudsoncardoso@hotmail.com"
                                                          target="_blank">hudsoncardoso@hotmail.com</a>&gt;</span>
                                                          escreveu:
                                                          <div>
                                                          <div> <br>
                                                          <blockquote
                                                          class="gmail_quote"
                                                          style="margin:0px
                                                          0px 0px
0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">
                                                          <div>
                                                          <div dir="ltr"><font
style="font-size:12pt" face="Arial" size="3">&nbsp; &nbsp;O Fail2ban n&atilde;o pegou,
                                                          porque ele ja
                                                          conseguiu
                                                          passar, isso
                                                          significa que
                                                          o teu firewall
                                                          n&atilde;o est&aacute;
                                                          corretamente</font>
                                                          <div><font
                                                          style="font-size:12pt"
                                                          face="Arial"
                                                          size="3">dimensionado,


                                                          e/ou
                                                          configurado.</font></div>
                                                          <div><font
                                                          style="font-size:12pt"
                                                          face="Arial"
                                                          size="3">&nbsp; No
                                                          meu se fizer 3
                                                          tentativas,
                                                          bloqueia por
                                                          15 minutos, e
                                                          quando um
                                                          guest pede
                                                          acesso ao
                                                          diaplan,
                                                          simplesmente&nbsp;</font></div>
                                                          <div><font
                                                          style="font-size:12pt"
                                                          face="Arial"
                                                          size="3">dou
                                                          HangUp em
                                                          todos os
                                                          Guest.<br>
                                                          </font><br>
                                                          <br>
                                                          <pre style="line-height:17px;color:rgb(42,42,42);white-space:normal">Hudson&nbsp;
<a moz-do-not-send="true" href="tel:%28048%29%208413-7000" value="+554884137000" target="_blank">(048) 8413-7000</a>
Para quem nao cre, nenhuma prova converte,Para aquele que cre, nenhuma prova precisa.&nbsp;</pre>
                                                          <br>
                                                          <br>
                                                          <div>&gt;
                                                          From: <a
                                                          moz-do-not-send="true"
href="mailto:caiopato@gmail.com" target="_blank">caiopato@gmail.com</a><br>
                                                          &gt; Date:
                                                          Wed, 31 Jul
                                                          2013 11:47:25
                                                          -0300<br>
                                                          &gt; To: <a
                                                          moz-do-not-send="true"
href="mailto:asteriskbrasil@listas.asteriskbrasil.org" target="_blank">asteriskbrasil@listas.asteriskbrasil.org</a><br>
                                                          &gt; Subject:
                                                          [AsteriskBrasil]


                                                          Ataque massivo
                                                          a partir do IP
                                                          <a
                                                          moz-do-not-send="true"
href="tel:67.207.137.49" value="+556720713749" target="_blank">67.207.137.49</a>
                                                          <div>
                                                          <div><br>
                                                          &gt; <br>
                                                          &gt; Eu estava
                                                          sendo v&iacute;tima
                                                          de uma
                                                          tentativa de
                                                          ataque a
                                                          partir do IP<br>
                                                          &gt; <a
                                                          moz-do-not-send="true"
href="tel:67.207.137.49" value="+556720713749" target="_blank">67.207.137.49</a>
                                                          (Rackspace
                                                          Cloud
                                                          Servers),<br>
                                                          &gt; Foram
                                                          3548
                                                          tentativas em
                                                          10 minutos at&eacute;
                                                          ser bloqueado
                                                          manualmente no
                                                          iptables.<br>
                                                          &gt; N&atilde;o
                                                          investiguei a
                                                          fundo o m&eacute;todo
                                                          do ataque, mas
                                                          basicamente
                                                          ele estava<br>
                                                          &gt; tentando
                                                          cavar uma
                                                          falha no
                                                          dialplan.<br>
                                                          &gt; <br>
                                                          &gt; No
                                                          console
                                                          apareceu:<br>
                                                          &gt; Jul 31
                                                          09:53:58
                                                          WARNING[18816]:
                                                          chan_sip.c:6903


                                                          get_destination:

                                                          Huh?<br>
                                                          &gt; Not a SIP
                                                          header
                                                          (tel:1900442075005000)?<br>
                                                          &gt; ...<br>
                                                          &gt; Jul 31
                                                          10:04:37
                                                          WARNING[18816]:
                                                          chan_sip.c:6903


                                                          get_destination:

                                                          Huh?<br>
                                                          &gt; Not a SIP
                                                          header
                                                          (tel:2440900442075005000)?<br>
                                                          &gt; <br>
                                                          &gt; Note que
                                                          o atacando
                                                          manteve o
                                                          sufixo e
                                                          alterava s&oacute; o
                                                          prefixo (19,
                                                          29,<br>
                                                          &gt; 39, ....
                                                          at&eacute; chegar no
                                                          24409 quando
                                                          eu bloqueei
                                                          via iptables.<br>
                                                          &gt; <br>
                                                          &gt; Esse tipo
                                                          de ataque N&Atilde;O
                                                          &Eacute; identificado
                                                          pelo fail2ban
                                                          pois n&atilde;o h&aacute;
                                                          logs gerados.<br>
                                                          &gt; <br>
                                                          &gt; O
                                                          telefone
                                                          00442075005000
                                                          pertence a um
                                                          banco (Citi)
                                                          em Londres.
                                                          Pode<br>
                                                          &gt; ser
                                                          apenas um
                                                          n&uacute;mero teste -
                                                          se o atacante
                                                          receber
                                                          "CONNECT", a<br>
                                                          &gt; tentativa
                                                          foi bem
                                                          sucedida e ele
                                                          descarrega um
                                                          caminh&atilde;o de
                                                          chamadas<br>
                                                          &gt; para
                                                          outros
                                                          destinos.<br>
                                                          &gt; <br>
                                                          &gt; Ent&atilde;o
                                                          vale o eterno
                                                          conselho:
                                                          fique de olho
                                                          - n&atilde;o confie
                                                          s&oacute; no
                                                          fail2ban.<br>
                                                          &gt;
                                                          _______________________________________________<br>
                                                          &gt; KHOMP:
                                                          completa linha
                                                          de placas
                                                          externas FXO,
                                                          FXS, GSM e E1;<br>
                                                          &gt; Media
                                                          Gateways de 1
                                                          a 64 E1s para
                                                          SIP com R2,
                                                          ISDN e SS7;<br>
                                                          &gt;
                                                          Intercomunicadores
                                                          para acesso
                                                          remoto via
                                                          rede IP.
                                                          Conhe&ccedil;a em <a
moz-do-not-send="true" href="http://www.khomp.com/" target="_blank">www.Khomp.com</a>.<br>
                                                          &gt;
                                                          _______________________________________________<br>
                                                          &gt; ALIGERA &#8211;
                                                          Fabricante
                                                          nacional de
                                                          Gateways
                                                          SIP-E1 para
                                                          R2, ISDN e
                                                          SS7.<br>
                                                          &gt; Placas de
                                                          1E1, 2E1, 4E1
                                                          e 8E1 para PCI
                                                          ou PCI
                                                          Express.<br>
                                                          &gt; Channel
                                                          Bank &#8211;
                                                          Appliance
                                                          Asterisk -
                                                          Acesse <a
                                                          moz-do-not-send="true"
href="http://www.aligera.com.br/" target="_blank">www.aligera.com.br</a>.<br>
                                                          &gt;
                                                          _______________________________________________<br>
                                                          &gt; Para
                                                          remover seu
                                                          email desta
                                                          lista, basta
                                                          enviar um
                                                          email em
                                                          branco para <a
moz-do-not-send="true"
                                                          href="mailto:asteriskbrasil-unsubscribe@listas.asteriskbrasil.org"
target="_blank">asteriskbrasil-unsubscribe@listas.asteriskbrasil.org</a><br>
                                                          </div>
                                                          </div>
                                                          </div>
                                                          </div>
                                                          </div>
                                                          </div>
                                                          <br>
_______________________________________________<br>
                                                          KHOMP:
                                                          completa linha
                                                          de placas
                                                          externas FXO,
                                                          FXS, GSM e E1;<br>
                                                          Media Gateways
                                                          de 1 a 64 E1s
                                                          para SIP com
                                                          R2, ISDN e
                                                          SS7;<br>
                                                          Intercomunicadores

                                                          para acesso
                                                          remoto via
                                                          rede IP.
                                                          Conhe&ccedil;a em <a
moz-do-not-send="true" href="http://www.khomp.com/" target="_blank">www.Khomp.com</a>.<br>
_______________________________________________<br>
                                                          ALIGERA &#8211;
                                                          Fabricante
                                                          nacional de
                                                          Gateways
                                                          SIP-E1 para
                                                          R2, ISDN e
                                                          SS7.<br>
                                                          Placas de 1E1,
                                                          2E1, 4E1 e 8E1
                                                          para PCI ou
                                                          PCI Express.<br>
                                                          Channel Bank &#8211;
                                                          Appliance
                                                          Asterisk -
                                                          Acesse <a
                                                          moz-do-not-send="true"
href="http://www.aligera.com.br/" target="_blank">www.aligera.com.br</a>.<br>
_______________________________________________<br>
                                                          Para remover
                                                          seu email
                                                          desta lista,
                                                          basta enviar
                                                          um email em
                                                          branco para <a
moz-do-not-send="true"
                                                          href="mailto:asteriskbrasil-unsubscribe@listas.asteriskbrasil.org"
target="_blank">asteriskbrasil-unsubscribe@listas.asteriskbrasil.org</a><br>
                                                          </blockquote>
                                                          </div>
                                                          </div>
                                                          </div>
                                                          <br>
                                                          </div>
                                                          <br>
_______________________________________________<br>
                                                          KHOMP:
                                                          completa linha
                                                          de placas
                                                          externas FXO,
                                                          FXS, GSM e E1;<br>
                                                          Media Gateways
                                                          de 1 a 64 E1s
                                                          para SIP com
                                                          R2, ISDN e
                                                          SS7;<br>
                                                          Intercomunicadores
                                                          para acesso
                                                          remoto via
                                                          rede IP.
                                                          Conhe&ccedil;a em <a
moz-do-not-send="true" href="http://www.khomp.com/" target="_blank">www.Khomp.com</a>.<br>
_______________________________________________<br>
                                                          ALIGERA &#8211;
                                                          Fabricante
                                                          nacional de
                                                          Gateways
                                                          SIP-E1 para
                                                          R2, ISDN e
                                                          SS7.<br>
                                                          Placas de 1E1,
                                                          2E1, 4E1 e 8E1
                                                          para PCI ou
                                                          PCI Express.<br>
                                                          Channel Bank &#8211;
                                                          Appliance
                                                          Asterisk -
                                                          Acesse <a
                                                          moz-do-not-send="true"
href="http://www.aligera.com.br/" target="_blank">www.aligera.com.br</a>.<br>
_______________________________________________<br>
                                                          Para remover
                                                          seu email
                                                          desta lista,
                                                          basta enviar
                                                          um email em
                                                          branco para <a
moz-do-not-send="true"
                                                          href="mailto:asteriskbrasil-unsubscribe@listas.asteriskbrasil.org"
target="_blank">asteriskbrasil-unsubscribe@listas.asteriskbrasil.org</a><br>
                                                          </blockquote>
                                                          </div>
                                                          </div>
                                                          </div>
                                                          <span><font
                                                          color="#888888">
                                                          <br>
                                                          <br
                                                          clear="all">
                                                          <div><br>
                                                          </div>
                                                          -- <br>
                                                          Thiago Anselmo
                                                          </font></span></div>
                                                          <br>
_______________________________________________<br>
                                                          KHOMP:
                                                          completa linha
                                                          de placas
                                                          externas FXO,
                                                          FXS, GSM e E1;<br>
                                                          Media Gateways
                                                          de 1 a 64 E1s
                                                          para SIP com
                                                          R2, ISDN e
                                                          SS7;<br>
                                                          Intercomunicadores
                                                          para acesso
                                                          remoto via
                                                          rede IP.
                                                          Conhe&ccedil;a em <a
moz-do-not-send="true" href="http://www.khomp.com/" target="_blank">www.Khomp.com</a>.<br>
_______________________________________________<br>
                                                          ALIGERA &#8211;
                                                          Fabricante
                                                          nacional de
                                                          Gateways
                                                          SIP-E1 para
                                                          R2, ISDN e
                                                          SS7.<br>
                                                          Placas de 1E1,
                                                          2E1, 4E1 e 8E1
                                                          para PCI ou
                                                          PCI Express.<br>
                                                          Channel Bank &#8211;
                                                          Appliance
                                                          Asterisk -
                                                          Acesse <a
                                                          moz-do-not-send="true"
href="http://www.aligera.com.br/" target="_blank">www.aligera.com.br</a>.<br>
_______________________________________________<br>
                                                          Para remover
                                                          seu email
                                                          desta lista,
                                                          basta enviar
                                                          um email em
                                                          branco para <a
moz-do-not-send="true"
                                                          href="mailto:asteriskbrasil-unsubscribe@listas.asteriskbrasil.org"
target="_blank">asteriskbrasil-unsubscribe@listas.asteriskbrasil.org</a><br>
                                                        </blockquote>
                                                      </div>
                                                      <br>
                                                      <br clear="all">
                                                      <div><br>
                                                      </div>
                                                      -- <br>
                                                      <div dir="ltr"><b><font
color="#0000ff">att</font></b>
                                                        <div><b><font
                                                          color="#0000ff">Danilo

                                                          Almeida</font></b></div>
                                                      </div>
                                                    </div>
                                                  </div>
                                                  <br>
                                                  <fieldset></fieldset>
                                                  <br>
                                                  <pre>_______________________________________________
KHOMP: completa linha de placas externas FXO, FXS, GSM e E1;
Media Gateways de 1 a 64 E1s para SIP com R2, ISDN e SS7;
Intercomunicadores para acesso remoto via rede IP. Conhe&ccedil;a em <a moz-do-not-send="true" href="http://www.khomp.com/" target="_blank">www.Khomp.com</a>.
_______________________________________________
ALIGERA &#8211; Fabricante nacional de Gateways SIP-E1 para R2, ISDN e SS7.
Placas de 1E1, 2E1, 4E1 e 8E1 para PCI ou PCI Express.
Channel Bank &#8211; Appliance Asterisk - Acesse <a moz-do-not-send="true" href="http://www.aligera.com.br/" target="_blank">www.aligera.com.br</a>.
_______________________________________________
Para remover seu email desta lista, basta enviar um email em branco para <a moz-do-not-send="true" href="mailto:asteriskbrasil-unsubscribe@listas.asteriskbrasil.org" target="_blank">asteriskbrasil-unsubscribe@listas.asteriskbrasil.org</a></pre>
                                                </blockquote>
                                                <br>
                                              </div>
                                            </div>
                                          </div>
                                          <br>
_______________________________________________<br>
                                          KHOMP: completa linha de
                                          placas externas FXO, FXS, GSM
                                          e E1;<br>
                                          Media Gateways de 1 a 64 E1s
                                          para SIP com R2, ISDN e SS7;<br>
                                          Intercomunicadores para acesso
                                          remoto via rede IP. Conhe&ccedil;a em
                                          <a moz-do-not-send="true"
                                            href="http://www.khomp.com/"
                                            target="_blank">www.Khomp.com</a>.<br>
_______________________________________________<br>
                                          ALIGERA &#8211; Fabricante nacional
                                          de Gateways SIP-E1 para R2,
                                          ISDN e SS7.<br>
                                          Placas de 1E1, 2E1, 4E1 e 8E1
                                          para PCI ou PCI Express.<br>
                                          Channel Bank &#8211; Appliance
                                          Asterisk - Acesse <a
                                            moz-do-not-send="true"
                                            href="http://www.aligera.com.br/"
                                            target="_blank">www.aligera.com.br</a>.<br>
_______________________________________________<br>
                                          Para remover seu email desta
                                          lista, basta enviar um email
                                          em branco para <a
                                            moz-do-not-send="true"
                                            href="mailto:asteriskbrasil-unsubscribe@listas.asteriskbrasil.org"
                                            target="_blank">asteriskbrasil-unsubscribe@listas.asteriskbrasil.org</a><br>
                                        </blockquote>
                                      </div>
                                    </div>
                                  </div>
                                  <span><font color="#888888"> <br>
                                      <br clear="all">
                                      <div><br>
                                      </div>
                                      -- <br>
                                      <div dir="ltr"><b><font
                                            color="#0000ff">att</font></b>
                                        <div><b><font color="#0000ff">Danilo

                                              Almeida</font></b></div>
                                      </div>
                                    </font></span></div>
                                <br>
_______________________________________________<br>
                                KHOMP: completa linha de placas externas
                                FXO, FXS, GSM e E1;<br>
                                Media Gateways de 1 a 64 E1s para SIP
                                com R2, ISDN e SS7;<br>
                                Intercomunicadores para acesso remoto
                                via rede IP. Conhe&ccedil;a em <a
                                  moz-do-not-send="true"
                                  href="http://www.khomp.com/"
                                  target="_blank">www.Khomp.com</a>.<br>
_______________________________________________<br>
                                ALIGERA &#8211; Fabricante nacional de
                                Gateways SIP-E1 para R2, ISDN e SS7.<br>
                                Placas de 1E1, 2E1, 4E1 e 8E1 para PCI
                                ou PCI Express.<br>
                                Channel Bank &#8211; Appliance Asterisk -
                                Acesse <a moz-do-not-send="true"
                                  href="http://www.aligera.com.br/"
                                  target="_blank">www.aligera.com.br</a>.<br>
_______________________________________________<br>
                                Para remover seu email desta lista,
                                basta enviar um email em branco para <a
                                  moz-do-not-send="true"
                                  href="mailto:asteriskbrasil-unsubscribe@listas.asteriskbrasil.org"
                                  target="_blank">asteriskbrasil-unsubscribe@listas.asteriskbrasil.org</a><br>
                              </blockquote>
                            </div>
                            <br>
                          </div>
                          <br>
                          <fieldset></fieldset>
                          <br>
                          <pre>_______________________________________________
KHOMP: completa linha de placas externas FXO, FXS, GSM e E1;
Media Gateways de 1 a 64 E1s para SIP com R2, ISDN e SS7;
Intercomunicadores para acesso remoto via rede IP. Conhe&ccedil;a em <a moz-do-not-send="true" href="http://www.khomp.com/" target="_blank">www.Khomp.com</a>.
_______________________________________________
ALIGERA &#8211; Fabricante nacional de Gateways SIP-E1 para R2, ISDN e SS7.
Placas de 1E1, 2E1, 4E1 e 8E1 para PCI ou PCI Express.
Channel Bank &#8211; Appliance Asterisk - Acesse <a moz-do-not-send="true" href="http://www.aligera.com.br/" target="_blank">www.aligera.com.br</a>.
_______________________________________________
Para remover seu email desta lista, basta enviar um email em branco para <a moz-do-not-send="true" href="mailto:asteriskbrasil-unsubscribe@listas.asteriskbrasil.org" target="_blank">asteriskbrasil-unsubscribe@listas.asteriskbrasil.org</a></pre>
                        </blockquote>
                        <br>
                      </div>
                    </div>
                  </div>
                  <br>
                  _______________________________________________<br>
                  KHOMP: completa linha de placas externas FXO, FXS, GSM
                  e E1;<br>
                  Media Gateways de 1 a 64 E1s para SIP com R2, ISDN e
                  SS7;<br>
                  Intercomunicadores para acesso remoto via rede IP.
                  Conhe&ccedil;a em <a moz-do-not-send="true"
                    href="http://www.khomp.com/" target="_blank">www.Khomp.com</a>.<br>
                  _______________________________________________<br>
                  ALIGERA &#8211; Fabricante nacional de Gateways SIP-E1 para
                  R2, ISDN e SS7.<br>
                  Placas de 1E1, 2E1, 4E1 e 8E1 para PCI ou PCI Express.<br>
                  Channel Bank &#8211; Appliance Asterisk - Acesse <a
                    moz-do-not-send="true"
                    href="http://www.aligera.com.br/" target="_blank">www.aligera.com.br</a>.<br>
                  _______________________________________________<br>
                  Para remover seu email desta lista, basta enviar um
                  email em branco para <a moz-do-not-send="true"
                    href="mailto:asteriskbrasil-unsubscribe@listas.asteriskbrasil.org">asteriskbrasil-unsubscribe@listas.asteriskbrasil.org</a><br>
                </blockquote>
              </div>
              <br>
            </div>
            _______________________________________________<br>
            KHOMP: completa linha de placas externas FXO, FXS, GSM e E1;<br>
            Media Gateways de 1 a 64 E1s para SIP com R2, ISDN e SS7;<br>
            Intercomunicadores para acesso remoto via rede IP. Conhe&ccedil;a
            em <a moz-do-not-send="true" href="http://www.Khomp.com">www.Khomp.com</a>.<br>
            _______________________________________________<br>
            ALIGERA &#8211; Fabricante nacional de Gateways SIP-E1 para R2,
            ISDN e SS7.<br>
            Placas de 1E1, 2E1, 4E1 e 8E1 para PCI ou PCI Express.<br>
            Channel Bank &#8211; Appliance Asterisk - Acesse <a
              moz-do-not-send="true" href="http://www.aligera.com.br">www.aligera.com.br</a>.<br>
            _______________________________________________<br>
            Para remover seu email desta lista, basta enviar um email em
            branco para <a moz-do-not-send="true"
              href="mailto:asteriskbrasil-unsubscribe@listas.asteriskbrasil.org">asteriskbrasil-unsubscribe@listas.asteriskbrasil.org</a></blockquote>
        </div>
        <br>
      </div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
KHOMP: completa linha de placas externas FXO, FXS, GSM e E1;
Media Gateways de 1 a 64 E1s para SIP com R2, ISDN e SS7;
Intercomunicadores para acesso remoto via rede IP. Conhe&ccedil;a em <a class="moz-txt-link-abbreviated" href="http://www.Khomp.com">www.Khomp.com</a>.
_______________________________________________
ALIGERA &#8211; Fabricante nacional de Gateways SIP-E1 para R2, ISDN e SS7.
Placas de 1E1, 2E1, 4E1 e 8E1 para PCI ou PCI Express.
Channel Bank &#8211; Appliance Asterisk - Acesse <a class="moz-txt-link-abbreviated" href="http://www.aligera.com.br">www.aligera.com.br</a>.
_______________________________________________
Para remover seu email desta lista, basta enviar um email em branco para <a class="moz-txt-link-abbreviated" href="mailto:asteriskbrasil-unsubscribe@listas.asteriskbrasil.org">asteriskbrasil-unsubscribe@listas.asteriskbrasil.org</a></pre>
    </blockquote>
    <br>
  </body>
</html>