Quantcast
Channel: FreePBX Community Forums - Latest posts
Viewing all articles
Browse latest Browse all 225776

Hacking attempts?

$
0
0

Hi all,

We've noticed something strange on our PBX recently, please see log below.
Unfortunately setting Allow SIP guests to No is not an option as the calls will fail as it's required by our SIP provider to be on.

[2015-10-28 10:54:09] VERBOSE[15220][C-000210cf] pbx.c: -- Executing [000972592115219@from-sip-external:1] NoOp("SIP/MY*****IP-000211ce", "Received incoming SIP connection from unknown peer to 000972592115219") in new stack
[2015-10-28 10:54:09] VERBOSE[15220][C-000210cf] pbx.c: -- Executing [000972592115219@from-sip-external:2] Set("SIP/ MY*****IP -000211ce", "DID=000972592115219") in new stack
[2015-10-28 10:54:09] VERBOSE[15220][C-000210cf] pbx.c: -- Executing [000972592115219@from-sip-external:3] Goto("SIP/ MY*****IP -000211ce", "s,1") in new stack
[2015-10-28 10:54:09] VERBOSE[15220][C-000210cf] pbx.c: -- Goto (from-sip-external,s,1)
[2015-10-28 10:54:09] VERBOSE[15220][C-000210cf] pbx.c: -- Executing [s@from-sip-external:1] GotoIf("SIP/ MY*****IP -000211ce", "1?checklang:noanonymous") in new stack
[2015-10-28 10:54:09] VERBOSE[15220][C-000210cf] pbx.c: -- Goto (from-sip-external,s,2)
[2015-10-28 10:54:09] VERBOSE[15220][C-000210cf] pbx.c: -- Executing [s@from-sip-external:2] GotoIf("SIP/ MY*****IP -000211ce", "0?setlanguage:from-trunk,000972592115219,1") in new stack
[2015-10-28 10:54:09] VERBOSE[15220][C-000210cf] pbx.c: -- Goto (from-trunk,000972592115219,1)
[2015-10-28 10:54:09] VERBOSE[15220][C-000210cf] pbx.c: -- Executing [000972592115219@from-trunk:1] Set("SIP/ MY*****IP -000211ce", "_FROMDID=000972592115219") in new stack
[2015-10-28 10:54:09] VERBOSE[15220][C-000210cf] pbx.c: -- Executing [000972592115219@from-trunk:2] NoOp("SIP/ MY*****IP -000211ce", "Received an unknown call with DID set to 000972592115219") in new stack
[2015-10-28 10:54:09] VERBOSE[15220][C-000210cf] pbx.c: -- Executing [000972592115219@from-trunk:3] Goto("SIP/ MY*****IP -000211ce", "s,a2") in new stack
[2015-10-28 10:54:09] VERBOSE[15220][C-000210cf] pbx.c: -- Goto (from-trunk,s,2)
[2015-10-28 10:54:09] VERBOSE[15220][C-000210cf] pbx.c: -- Executing [s@from-trunk:2] Answer("SIP/ MY*****IP -000211ce", "") in new stack
[2015-10-28 10:54:10] VERBOSE[15220][C-000210cf] pbx.c: -- Executing [s@from-trunk:3] Log("SIP/MY*****IP-000211ce", "WARNING,Friendly Scanner from 67.227.191.133") in new stack
[2015-10-28 10:54:10] WARNING[15220][C-000210cf] Ext. s: Friendly Scanner from 67.227.191.133
[2015-10-28 10:54:10] VERBOSE[15220][C-000210cf] pbx.c: -- Executing [s@from-trunk:4] Wait("SIP/ MY*****IP -000211ce", "2") in new stack
[2015-10-28 10:54:12] VERBOSE[15220][C-000210cf] pbx.c: -- Executing [s@from-trunk:5] Playback("SIP/ MY*****IP -000211ce", "ss-noservice") in new stack
[2015-10-28 10:54:12] VERBOSE[15220][C-000210cf] file.c: -- Playing 'ss-noservice.alaw' (language 'en')
[2015-10-28 10:54:17] VERBOSE[15220][C-000210cf] pbx.c: -- Executing [s@from-trunk:6] SayAlpha("SIP/MY*****IP-000211ce", "000972592115219") in new stack
[2015-10-28 10:54:17] VERBOSE[15220][C-000210cf] file.c: -- Playing 'digits/0.alaw' (language 'en')
[2015-10-28 10:54:18] VERBOSE[15220][C-000210cf] file.c: -- Playing 'digits/0.alaw' (language 'en')
[2015-10-28 10:54:18] VERBOSE[15220][C-000210cf] file.c: -- Playing 'digits/0.alaw' (language 'en')
[2015-10-28 10:54:19] VERBOSE[15220][C-000210cf] file.c: -- Playing 'digits/9.alaw' (language 'en')
[2015-10-28 10:54:20] VERBOSE[15220][C-000210cf] file.c: -- Playing 'digits/7.alaw' (language 'en')
[2015-10-28 10:54:21] VERBOSE[15220][C-000210cf] file.c: -- Playing 'digits/2.alaw' (language 'en')
[2015-10-28 10:54:21] VERBOSE[15220][C-000210cf] file.c: -- Playing 'digits/5.alaw' (language 'en')
[2015-10-28 10:54:22] VERBOSE[15220][C-000210cf] file.c: -- Playing 'digits/9.alaw' (language 'en')
[2015-10-28 10:54:23] VERBOSE[15220][C-000210cf] file.c: -- Playing 'digits/2.alaw' (language 'en')
[2015-10-28 10:54:23] VERBOSE[15220][C-000210cf] file.c: -- Playing 'digits/1.alaw' (language 'en')
[2015-10-28 10:54:24] VERBOSE[15220][C-000210cf] file.c: -- Playing 'digits/1.alaw' (language 'en')
[2015-10-28 10:54:25] VERBOSE[15220][C-000210cf] file.c: -- Playing 'digits/5.alaw' (language 'en')
[2015-10-28 10:54:25] VERBOSE[15220][C-000210cf] file.c: -- Playing 'digits/2.alaw' (language 'en')
[2015-10-28 10:54:26] VERBOSE[15220][C-000210cf] file.c: -- Playing 'digits/1.alaw' (language 'en')
[2015-10-28 10:54:27] VERBOSE[15220][C-000210cf] file.c: -- Playing 'digits/9.alaw' (language 'en')
[2015-10-28 10:54:27] VERBOSE[15220][C-000210cf] pbx.c: -- Executing [s@from-trunk:7] Hangup("SIP/MY*****IP-000211ce", "") in new stack
[2015-10-28 10:54:27] VERBOSE[15220][C-000210cf] pbx.c: == Spawn extension (from-trunk, s, 7) exited non-zero on 'SIP/MY*****IP-000211ce'
[2015-10-28 10:54:27] VERBOSE[15220][C-000210cf] pbx.c: -- Executing [h@from-trunk:1] Macro("SIP/MY*****IP-000211ce", "hangupcall,") in new stack
[2015-10-28 10:54:27] VERBOSE[15220][C-000210cf] pbx.c: -- Executing [s@macro-hangupcall:1] ExecIf("SIP/MY*****IP-000211ce", "0?Set(CDR(recordingfile)=.)") in new stack
[2015-10-28 10:54:27] VERBOSE[15220][C-000210cf] pbx.c: -- Executing [s@macro-hangupcall:2] GotoIf("SIP/MY*****IP-000211ce", "1?theend") in new stack
[2015-10-28 10:54:27] VERBOSE[15220][C-000210cf] pbx.c: -- Goto (macro-hangupcall,s,4)
[2015-10-28 10:54:27] VERBOSE[15220][C-000210cf] pbx.c: -- Executing [s@macro-hangupcall:4] Hangup("SIP/MY*****IP-000211ce", "") in new stack
[2015-10-28 10:54:27] VERBOSE[15220][C-000210cf] app_macro.c: == Spawn extension (macro-hangupcall, s, 4) exited non-zero on 'SIP/MY*****IP-000211ce' in macro 'hangupcall'
[2015-10-28 10:54:27] VERBOSE[15220][C-000210cf] pbx.c: == Spawn extension (from-trunk, h, 1) exited non-zero on 'SIP/MY*****IP-000211ce'
[2015-10-28 10:54:41] WARNING[9546] chan_sip.c: Retransmission timeout reached on transmission 9dfb5891f9008d0e7a99b97abdea31d2 for seqno 1 (Critical Response) -- See https://wiki.asterisk.org/wiki/display/AST/SIP+Retransmissions
Packet timed out after 31999ms with no response
[2015-10-28 10:56:48] VERBOSE[9546][C-000210d0] netsock2.c: == Using SIP RTP TOS bits 184
[2015-10-28 10:56:48] VERBOSE[9546][C-000210d0] netsock2.c: == Using SIP RTP CoS mark 5
[2015-10-28 10:56:48] VERBOSE[15304][C-000210d0] pbx.c: -- Executing [9007970598371060@from-sip-external:1] NoOp("SIP/MY*****IP-000211cf", "Received incoming SIP connection from unknown peer to 9007970598371060") in new stack
[2015-10-28 10:56:48] VERBOSE[15304][C-000210d0] pbx.c: -- Executing [9007970598371060@from-sip-external:2] Set("SIP/MY*****IP-000211cf", "DID=9007970598371060") in new stack
[2015-10-28 10:56:48] VERBOSE[15304][C-000210d0] pbx.c: -- Executing [9007970598371060@from-sip-external:3] Goto("SIP/MY*****IP-000211cf", "s,1") in new stack
[2015-10-28 10:56:48] VERBOSE[15304][C-000210d0] pbx.c: -- Goto (from-sip-external,s,1)
[2015-10-28 10:56:48] VERBOSE[15304][C-000210d0] pbx.c: -- Executing [s@from-sip-external:1] GotoIf("SIP/MY*****IP-000211cf", "1?checklang:noanonymous") in new stack
[2015-10-28 10:56:48] VERBOSE[15304][C-000210d0] pbx.c: -- Goto (from-sip-external,s,2)
[2015-10-28 10:56:48] VERBOSE[15304][C-000210d0] pbx.c: -- Executing [s@from-sip-external:2] GotoIf("SIP/MY*****IP-000211cf", "0?setlanguage:from-trunk,9007970598371060,1") in new stack
[2015-10-28 10:56:48] VERBOSE[15304][C-000210d0] pbx.c: -- Goto (from-trunk,9007970598371060,1)
[2015-10-28 10:56:48] VERBOSE[15304][C-000210d0] pbx.c: -- Executing [9007970598371060@from-trunk:1] Set("SIP/MY*****IP-000211cf", "_FROMDID=9007970598371060") in new stack
[2015-10-28 10:56:48] VERBOSE[15304][C-000210d0] pbx.c: -- Executing [9007970598371060@from-trunk:2] NoOp("SIP/MY*****IP-000211cf", "Received an unknown call with DID set to 9007970598371060") in new stack
[2015-10-28 10:56:48] VERBOSE[15304][C-000210d0] pbx.c: -- Executing [9007970598371060@from-trunk:3] Goto("SIP/MY*****IP-000211cf", "s,a2") in new stack
[2015-10-28 10:56:48] VERBOSE[15304][C-000210d0] pbx.c: -- Goto (from-trunk,s,2)
[2015-10-28 10:56:48] VERBOSE[15304][C-000210d0] pbx.c: -- Executing [s@from-trunk:2] Answer("SIP/MY*****IP-000211cf", "") in new stack
[2015-10-28 10:56:48] VERBOSE[15304][C-000210d0] pbx.c: == Spawn extension (from-trunk, s, 2) exited non-zero on 'SIP/MY*****IP-000211cf'
[2015-10-28 10:56:48] VERBOSE[15304][C-000210d0] pbx.c: -- Executing [h@from-trunk:1] Macro("SIP/MY*****IP-000211cf", "hangupcall,") in new stack
[2015-10-28 10:56:48] VERBOSE[15304][C-000210d0] pbx.c: -- Executing [s@macro-hangupcall:1] ExecIf("SIP/MY*****IP-000211cf", "0?Set(CDR(recordingfile)=.)") in new stack
[2015-10-28 10:56:48] VERBOSE[15304][C-000210d0] pbx.c: -- Executing [s@macro-hangupcall:2] GotoIf("SIP/MY*****IP-000211cf", "1?theend") in new stack
[2015-10-28 10:56:48] VERBOSE[15304][C-000210d0] pbx.c: -- Goto (macro-hangupcall,s,4)
[2015-10-28 10:56:48] VERBOSE[15304][C-000210d0] pbx.c: -- Executing [s@macro-hangupcall:4] Hangup("SIP/MY*****IP-000211cf", "") in new stack
[2015-10-28 10:56:48] VERBOSE[15304][C-000210d0] app_macro.c: == Spawn extension (macro-hangupcall, s, 4) exited non-zero on 'SIP/MY*****IP-000211cf' in macro 'hangupcall'
[2015-10-28 10:56:48] VERBOSE[15304][C-000210d0] pbx.c: == Spawn extension (from-trunk, h, 1) exited non-zero on 'SIP/MY*****IP-000211cf'
[2015-10-28 10:58:18] VERBOSE[9546][C-000210d1] netsock2.c: == Using SIP RTP TOS bits 184
[2015-10-28 10:58:18] VERBOSE[9546][C-000210d1] netsock2.c: == Using SIP RTP CoS mark 5
[2015-10-28 10:58:18] VERBOSE[15338][C-000210d1] pbx.c: -- Executing [60061261760726@from-sip-external:1] NoOp("SIP/MY*****IP-000211d0", "Received incoming SIP connection from unknown peer to 60061261760726") in new stack
[2015-10-28 10:58:18] VERBOSE[15338][C-000210d1] pbx.c: -- Executing [60061261760726@from-sip-external:2] Set("SIP/MY*****IP-000211d0", "DID=60061261760726") in new stack
[2015-10-28 10:58:18] VERBOSE[15338][C-000210d1] pbx.c: -- Executing [60061261760726@from-sip-external:3] Goto("SIP/MY*****IP-000211d0", "s,1") in new stack
[2015-10-28 10:58:18] VERBOSE[15338][C-000210d1] pbx.c: -- Goto (from-sip-external,s,1)
[2015-10-28 10:58:18] VERBOSE[15338][C-000210d1] pbx.c: -- Executing [s@from-sip-external:1] GotoIf("SIP/MY*****IP-000211d0", "1?checklang:noanonymous") in new stack
[2015-10-28 10:58:18] VERBOSE[15338][C-000210d1] pbx.c: -- Goto (from-sip-external,s,2)
[2015-10-28 10:58:18] VERBOSE[15338][C-000210d1] pbx.c: -- Executing [s@from-sip-external:2] GotoIf("SIP/MY*****IP-000211d0", "0?setlanguage:from-trunk,60061261760726,1") in new stack
[2015-10-28 10:58:18] VERBOSE[15338][C-000210d1] pbx.c: -- Goto (from-trunk,60061261760726,1)
[2015-10-28 10:58:18] VERBOSE[15338][C-000210d1] pbx.c: -- Executing [60061261760726@from-trunk:1] Set("SIP/MY*****IP-000211d0", "_FROMDID=60061261760726") in new stack
[2015-10-28 10:58:18] VERBOSE[15338][C-000210d1] pbx.c: -- Executing [60061261760726@from-trunk:2] NoOp("SIP/MY*****IP-000211d0", "Received an unknown call with DID set to 60061261760726") in new stack
[2015-10-28 10:58:18] VERBOSE[15338][C-000210d1] pbx.c: -- Executing [60061261760726@from-trunk:3] Goto("SIP/MY*****IP-000211d0", "s,a2") in new stack
[2015-10-28 10:58:18] VERBOSE[15338][C-000210d1] pbx.c: -- Goto (from-trunk,s,2)
[2015-10-28 10:58:18] VERBOSE[15338][C-000210d1] pbx.c: -- Executing [s@from-trunk:2] Answer("SIP/MY*****IP-000211d0", "") in new stack
[2015-10-28 10:58:18] VERBOSE[15338][C-000210d1] pbx.c: == Spawn extension (from-trunk, s, 2) exited non-zero on 'SIP/MY*****IP-000211d0'
[2015-10-28 10:58:18] VERBOSE[15338][C-000210d1] pbx.c: -- Executing [h@from-trunk:1] Macro("SIP/MY*****IP-000211d0", "hangupcall,") in new stack
[2015-10-28 10:58:18] VERBOSE[15338][C-000210d1] pbx.c: -- Executing [s@macro-hangupcall:1] ExecIf("SIP/MY*****IP-000211d0", "0?Set(CDR(recordingfile)=.)") in new stack
[2015-10-28 10:58:18] VERBOSE[15338][C-000210d1] pbx.c: -- Executing [s@macro-hangupcall:2] GotoIf("SIP/MY*****IP-000211d0", "1?theend") in new stack
[2015-10-28 10:58:18] VERBOSE[15338][C-000210d1] pbx.c: -- Goto (macro-hangupcall,s,4)
[2015-10-28 10:58:18] VERBOSE[15338][C-000210d1] pbx.c: -- Executing [s@macro-hangupcall:4] Hangup("SIP/MY*****IP-000211d0", "") in new stack
[2015-10-28 10:58:18] VERBOSE[15338][C-000210d1] app_macro.c: == Spawn extension (macro-hangupcall, s, 4) exited non-zero on 'SIP/MY*****IP-000211d0' in macro 'hangupcall'
[2015-10-28 10:58:18] VERBOSE[15338][C-000210d1] pbx.c: == Spawn extension (from-trunk, h, 1) exited non-zero on 'SIP/MY*****IP-000211d0'
[2015-10-28 10:59:04] VERBOSE[9546][C-000210d2] netsock2.c: == Using SIP RTP TOS bits 184
[2015-10-28 10:59:04] VERBOSE[9546][C-000210d2] netsock2.c: == Using SIP RTP CoS mark 5
[2015-10-28 10:59:04] VERBOSE[15369][C-000210d2] pbx.c: -- Executing [00972592634285@from-sip-external:1] NoOp("SIP/MY*****IP-000211d1", "Received incoming SIP connection from unknown peer to 00972592634285") in new stack
[2015-10-28 10:59:04] VERBOSE[15369][C-000210d2] pbx.c: -- Executing [00972592634285@from-sip-external:2] Set("SIP/MY*****IP-000211d1", "DID=00972592634285") in new stack
[2015-10-28 10:59:04] VERBOSE[15369][C-000210d2] pbx.c: -- Executing [00972592634285@from-sip-external:3] Goto("SIP/MY*****IP-000211d1", "s,1") in new stack
[2015-10-28 10:59:04] VERBOSE[15369][C-000210d2] pbx.c: -- Goto (from-sip-external,s,1)
[2015-10-28 10:59:04] VERBOSE[15369][C-000210d2] pbx.c: -- Executing [s@from-sip-external:1] GotoIf("SIP/MY*****IP-000211d1", "1?checklang:noanonymous") in new stack
[2015-10-28 10:59:04] VERBOSE[15369][C-000210d2] pbx.c: -- Goto (from-sip-external,s,2)
[2015-10-28 10:59:04] VERBOSE[15369][C-000210d2] pbx.c: -- Executing [s@from-sip-external:2] GotoIf("SIP/MY*****IP-000211d1", "0?setlanguage:from-trunk,00972592634285,1") in new stack
[2015-10-28 10:59:04] VERBOSE[15369][C-000210d2] pbx.c: -- Goto (from-trunk,00972592634285,1)
[2015-10-28 10:59:04] VERBOSE[15369][C-000210d2] pbx.c: -- Executing [00972592634285@from-trunk:1] Set("SIP/MY*****IP-000211d1", "_FROMDID=00972592634285") in new stack
[2015-10-28 10:59:04] VERBOSE[15369][C-000210d2] pbx.c: -- Executing [00972592634285@from-trunk:2] NoOp("SIP/MY*****IP-000211d1", "Received an unknown call with DID set to 00972592634285") in new stack
[2015-10-28 10:59:04] VERBOSE[15369][C-000210d2] pbx.c: -- Executing [00972592634285@from-trunk:3] Goto("SIP/MY*****IP-000211d1", "s,a2") in new stack
[2015-10-28 10:59:04] VERBOSE[15369][C-000210d2] pbx.c: -- Goto (from-trunk,s,2)
[2015-10-28 10:59:04] VERBOSE[15369][C-000210d2] pbx.c: -- Executing [s@from-trunk:2] Answer("SIP/MY*****IP-000211d1", "") in new stack
[2015-10-28 10:59:04] VERBOSE[15369][C-000210d2] pbx.c: == Spawn extension (from-trunk, s, 2) exited non-zero on 'SIP/MY*****IP-000211d1'
[2015-10-28 10:59:04] VERBOSE[15369][C-000210d2] pbx.c: -- Executing [h@from-trunk:1] Macro("SIP/MY*****IP-000211d1", "hangupcall,") in new stack
[2015-10-28 10:59:04] VERBOSE[15369][C-000210d2] pbx.c: -- Executing [s@macro-hangupcall:1] ExecIf("SIP/MY*****IP-000211d1", "0?Set(CDR(recordingfile)=.)") in new stack
[2015-10-28 10:59:04] VERBOSE[15369][C-000210d2] pbx.c: -- Executing [s@macro-hangupcall:2] GotoIf("SIP/MY*****IP-000211d1", "1?theend") in new stack
[2015-10-28 10:59:04] VERBOSE[15369][C-000210d2] pbx.c: -- Goto (macro-hangupcall,s,4)
[2015-10-28 10:59:04] VERBOSE[15369][C-000210d2] pbx.c: -- Executing [s@macro-hangupcall:4] Hangup("SIP/MY*****IP-000211d1", "") in new stack
[2015-10-28 10:59:04] VERBOSE[15369][C-000210d2] app_macro.c: == Spawn extension (macro-hangupcall, s, 4) exited non-zero on 'SIP/MY*****IP-000211d1' in macro 'hangupcall'
[2015-10-28 10:59:04] VERBOSE[15369][C-000210d2] pbx.c: == Spawn extension (from-trunk, h, 1) exited non-zero on 'SIP/MY*****IP-000211d1'
[2015-10-28 11:01:59] VERBOSE[9546][C-000210d3] netsock2.c: == Using SIP RTP TOS bits 184
[2015-10-28 11:01:59] VERBOSE[9546][C-000210d3] netsock2.c: == Using SIP RTP CoS mark 5

Any ideas on how to stop this?? it happens every 2-3 minutes flooding our PBX.
The PBX is sat behind the firewall and even though I have acl set to stop the traffic from specific IP's it still comes up on PBX for some reason.
FreePBX 12.0.76.2
PBX Firmware: 6.12.65-26

Also we have problem with below:

[2015-10-28 09:52:53] NOTICE[9546] chan_sip.c: Registration from '"100200" ' failed for '212.83.148.18:5067' - Wrong password
[2015-10-28 09:57:06] NOTICE[9546] chan_sip.c: Registration from '"ranjan" ' failed for '212.83.148.18:5069' - Wrong password
[2015-10-28 10:01:11] NOTICE[13184] manager.c: 84.244.139.25 tried to authenticate with nonexistent user 'user'
[2015-10-28 10:01:11] NOTICE[13184] manager.c: 84.244.139.25 failed to authenticate as 'user'
[2015-10-28 10:06:00] NOTICE[9546] chan_sip.c: Registration from '"sanjay" ' failed for '212.83.148.18:5081' - Wrong password
[2015-10-28 10:23:38] NOTICE[9546] chan_sip.c: Registration from '"19791" ' failed for '212.83.148.18:5065' - Wrong password
[2015-10-28 10:34:37] NOTICE[14236] manager.c: 84.244.139.25 tried to authenticate with nonexistent user 'mark'
[2015-10-28 10:34:37] NOTICE[14236] manager.c: 84.244.139.25 failed to authenticate as 'mark'
[2015-10-28 10:53:31] NOTICE[9546][C-000210ca] chan_sip.c: Failed to authenticate device 1111;tag=ac4d6f93
[2015-10-28 11:09:33] WARNING[15706][C-000210d8] Ext. s: Friendly Scanner from 5.189.190.120
[2015-10-28 11:09:39] WARNING[15713][C-000210d9] Ext. s: Friendly Scanner from 23.239.66.51

What worries me here is that one of the extensions actually exists on our system

Thanks for help in advance.


Viewing all articles
Browse latest Browse all 225776

Trending Articles