OBiTALK Community

General Support => Day-to-Day Use => Topic started by: lacibaci on June 08, 2013, 06:31:27 AM

Title: Any way to disable "OPTIONS sip:"?
Post by: lacibaci on June 08, 2013, 06:31:27 AM
Is there any way to disable "OPTIONS sip:"? I'm getting following requests:

Jun  8 02:34:03 OPTIONS sip: 100@192.168.1.55:5060 SIP/2.0#015#012Via: SIP/2.0/UDP 199.180.116.133:5060;branch=z9hG4bK-3297657631;rport#015#012Content-Length: 0#015#012From: "sipvicious"<sip:100@1.1.1.1>;tag=3137313935303839313363340131323137313531343431#015#012Accept: application/sdp#015#012User-Agent: friendly-scanner#015#012To: "sipvicious"<sip:100@1.1.1.1>#015#012Contact: sip:100@199.180.116.133:5060#015#012CSeq: 1 OPTIONS#015#012Call-ID: 350570487260001251590293#015#012Max-Forwards: 70#015#012#015

I suspect this is what sip spammers use before they try to use the ATA/PBX. I have a good inbound route configured so no rogue calls but I would like to close this if possible.
Title: Re: Any way to disable "OPTIONS sip:"?
Post by: Shale on June 08, 2013, 06:45:03 AM
See http://advantia.ca/weblog/less-than-friendly-scanner--sipvicious  and http://blog.sipvicious.org/ for some info on the scanner.

Presuming you are talking about scanning of an OBi rather than you having an Asterisk server etc, see http://www.obitalk.com/forum/index.php?topic=5467.0 for information on how to thwart SIP scanners.
Title: Re: Any way to disable "OPTIONS sip:"?
Post by: hwittenb on June 08, 2013, 07:17:34 AM
Quote from: lacibaci on June 08, 2013, 06:31:27 AM
Is there any way to disable "OPTIONS sip:"? I'm getting following requests:

I would try changing the X_UserAgentPort under your SPx Service from 5060 to a non-standard port number.  You can use most any number you like.  Try 5099.

Title: Re: Any way to disable "OPTIONS sip:"?
Post by: lacibaci on June 08, 2013, 07:17:45 AM
My inbound route takes care of spammers, I just wanted to know if there is a way to disable OPTIONS command in OBi so sipvicious gets no reply.