{"id":941,"date":"2010-11-01T11:53:08","date_gmt":"2010-11-01T18:53:08","guid":{"rendered":"http:\/\/www.stuartsheldon.org\/blog\/?p=941"},"modified":"2010-11-01T13:34:51","modified_gmt":"2010-11-01T20:34:51","slug":"sip-brute-force-attacks-escalate-over-halloween-weekend","status":"publish","type":"post","link":"https:\/\/www.stuartsheldon.org\/blog\/2010\/11\/sip-brute-force-attacks-escalate-over-halloween-weekend\/","title":{"rendered":"SIP Brute Force Attacks Escalate Over Halloween Weekend."},"content":{"rendered":"<h2><em><strong>SIP brute force attacks escalate over Halloween weekend.<\/strong><\/em><\/h2>\n<p>Looks like the bad guys were up to no good again this weekend. SIP based PBX operators reported a huge increase in bogus registration attempts against their systems over the Halloween weekend. Our hosted PBX farm experienced this increase first hand. Logs showed an attack from a new and unique IP address about every minute. At the end of the weekend, over 1300 unique IP addresses were logged.<\/p>\n<p style=\"text-align: right;\"><!--more--><\/p>\n<h2><em><strong>Intense but different.<\/strong><\/em><\/h2>\n<p>This attack was intense in the number of source addresses being used, but much less of an &#8216;in your face&#8217; attack then we&#8217;ve seen previously. Previous attacks would use the same source address and hammer the servers with various generated registration and call requests. Up until this weekend, I could be reasonably sure that the IP address shown as the source address, was actually the system attacking me, and not a spoofed IP of an innocent node..<\/p>\n<h2><em><strong>Attack characteristics.<\/strong><\/em><\/h2>\n<p>Here is what we saw:<\/p>\n<ul>\n<li>All attempts appeared to be SIP registration attempts.<\/li>\n<li>Source IP address was only used once.<\/li>\n<li>SIP account was only used once.<\/li>\n<li>Attacks were spread out over 20 &#8211; 30 second intervals.<\/li>\n<\/ul>\n<p>From all the logs I reviewed, it would look as if they (the bad guys) knew what they were looking for&#8230;<\/p>\n<h2><em><strong>Possible goals of this attack.<\/strong><\/em><\/h2>\n<p>Figuring out someone&#8217;s motivation in attacking you is kinda like going to a restaurant and trying to guess what seasoning the chef is using. Sometimes it&#8217;s obvious, but most of the time, you&#8217;re just guessing. Anyways, here are some possibilities&#8230;<\/p>\n<ul>\n<li>Since the attackers never tried an account \/ IP address combination more then once, they:\n<ol>\n<li>Knew the account and password they were trying to attach with?<\/li>\n<li>Were only trying to discover if a SIP device was on the other end?<\/li>\n<li>Were attempting to flood a SIP device by spoofing it&#8217;s IP address, thus causing legitimate systems to spray UDP packets at it?<\/li>\n<li>Were using malformed packets that exploit a bug in a particular SIP device \/ software?<\/li>\n<li>Were trolling for open or mis-configured SIP devices?<\/li>\n<li>Were attempting to have systems that run security software block the source IPs of innocent spoofed hosts?<\/li>\n<li>Didn&#8217;t know what they were doing, and fired off a useless attack?<\/li>\n<\/ol>\n<\/li>\n<\/ul>\n<p>If I had to bet, I would say 3, 4 or 5. The fact that there was only one attempt, and that they didn&#8217;t bother to try a second time, leads me in that direction. I also think that it may have been lots of different attackers, and not a single bot net. But, I also thought there was cilantro in the clam chowder at the local restaurant&#8230; Boy was I wrong about that!<\/p>\n<h2><em><strong>Gone With The Wind&#8230;<\/strong><\/em><\/h2>\n<p>Just as it started from nowhere at around 10AM PDT on Saturday, so did it end a bit before 8AM Monday&#8230; Is it gone for good? who knows, but one thing is for sure&#8230; Good passwords and an eye out for software exploits is the order of the day&#8230;<\/p>\n<p>If you were hit by this attack, and have an opinion, or additional insight you would like to share, please feel free to comment!<\/p>\n<p>&#8212; Stu<\/p>\n","protected":false},"excerpt":{"rendered":"<p>SIP brute force attacks escalate over Halloween weekend. Looks like the bad guys were up to no good again this weekend. SIP based PBX operators reported a huge increase in bogus registration attempts against their systems over the Halloween weekend. Our hosted PBX farm experienced this increase first hand. Logs showed an attack from a [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25,125,4,30,12,182],"tags":[168,170,167,90,194,191,169],"class_list":["post-941","post","type-post","status-publish","format-standard","hentry","category-internet","category-it","category-linux","category-networking","category-security","category-voip","tag-abuse","tag-attack","tag-ddos","tag-dos","tag-internet","tag-linux","tag-sip-attack"],"_links":{"self":[{"href":"https:\/\/www.stuartsheldon.org\/blog\/wp-json\/wp\/v2\/posts\/941","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.stuartsheldon.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.stuartsheldon.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.stuartsheldon.org\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.stuartsheldon.org\/blog\/wp-json\/wp\/v2\/comments?post=941"}],"version-history":[{"count":11,"href":"https:\/\/www.stuartsheldon.org\/blog\/wp-json\/wp\/v2\/posts\/941\/revisions"}],"predecessor-version":[{"id":951,"href":"https:\/\/www.stuartsheldon.org\/blog\/wp-json\/wp\/v2\/posts\/941\/revisions\/951"}],"wp:attachment":[{"href":"https:\/\/www.stuartsheldon.org\/blog\/wp-json\/wp\/v2\/media?parent=941"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.stuartsheldon.org\/blog\/wp-json\/wp\/v2\/categories?post=941"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.stuartsheldon.org\/blog\/wp-json\/wp\/v2\/tags?post=941"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}