OBiTALK Community

General Support => Feature Requests => Topic started by: lacibaci on December 23, 2012, 06:40:34 PM

Title: OBi, please help us defeat SIP scanners/spammers
Post by: lacibaci on December 23, 2012, 06:40:34 PM
OBi, please help us defeat SIP scanners/spammers by implementing one or both feature requests mentioned here:

Reject SIP requests except from registration server
(http://www.obitalk.com/forum/index.php?topic=4159.0)

Please allow IP range in X_Access List to stop SIP Scanners
(http://www.obitalk.com/forum/index.php?topic=3544.0)

Either would help out tremendously. Currently I have to resort to firewall rules and inbound rules. X_AccessList with its 512 character limit is not useful for VOIP providers with large number of servers.

Thanks
Lac
Title: Re: OBi, please help us defeat SIP scanners/spammers
Post by: carl on December 28, 2012, 09:22:39 AM
I second this request
Title: Re: OBi, please help us defeat SIP scanners/spammers
Post by: pbd3mon on December 30, 2012, 11:13:51 PM
A lot of users would benefit from this!
Title: Re: OBi, please help us defeat SIP scanners/spammers
Post by: Alaska99 on January 06, 2013, 07:59:51 PM
I second too!   >:(
Title: Re: OBi, please help us defeat SIP scanners/spammers
Post by: Dav3yDark0 on February 04, 2013, 09:07:45 AM
Add me to the list of users requesting this feature. 
Title: Re: OBi, please help us defeat SIP scanners/spammers
Post by: Hyrules on February 12, 2013, 07:12:21 AM
add my voice to the list. Again last night I was scanned / spammed. I had to re add the x_accesslist to my latest setup. The phone would'nt stop ringing.
Title: Re: OBi, please help us defeat SIP scanners/spammers
Post by: Mango on February 22, 2013, 08:56:29 AM
For anyone having this problem, double check that you remembered to set:

Voice Services >> SPx Service >> X_UserAgentPort: (some random number greater than 1024 20000 and less than 65535)
Title: Re: OBi, please help us defeat SIP scanners/spammers
Post by: lacibaci on March 15, 2013, 06:34:53 PM
Another day and the phone rings in the middle of the night... :( Something should seriously by done about this.

How hard would it be to implement just ONE of the features mentioned above?

I am almost at the point of dumping this hardware and getting something else...
Title: Re: OBi, please help us defeat SIP scanners/spammers
Post by: Mango on March 15, 2013, 06:35:56 PM
What was your X_UserAgentPort set to?
Title: Re: OBi, please help us defeat SIP scanners/spammers
Post by: lacibaci on March 15, 2013, 06:46:44 PM
Quote from: Mango on March 15, 2013, 06:35:56 PM
What was your X_UserAgentPort set to?

It's not the default (5060) but changing the port and playing with access list/rules is not working for the long haul. For hackers it's very easy to scan other ports (or ranges)
What we need is a real fix from OBi. I doubt it would take more than a couple of hours to implement the first one (Reject SIP requests except from registration server)

How about that OBi?
Title: Re: OBi, please help us defeat SIP scanners/spammers
Post by: Mango on March 15, 2013, 07:15:32 PM
Out of curiosity, could you PM me what the port number was?  I'm curious because this is the first time I have heard of scanners using a nonstandard port.
Title: Re: OBi, please help us defeat SIP scanners/spammers
Post by: Mango on March 15, 2013, 08:29:16 PM
I thought better of my recommendation above.  Until you have another solution, you might want to try a random number between 20000 and 65535.
Title: Re: OBi, please help us defeat SIP scanners/spammers
Post by: lacibaci on March 19, 2013, 05:29:05 PM
Quote from: Mango on March 19, 2013, 05:46:13 AM
What was your X_UserAgentPort set to?

It was not the default, nor in the 506x range.
Title: Re: OBi, please help us defeat SIP scanners/spammers
Post by: Felix on March 20, 2013, 03:09:27 PM
Ironic, that we got a fairly sophisticated comment spam (konglo) in the thread discussing SIP spam.
Title: Re: OBi, please help us defeat SIP scanners/spammers
Post by: obmsonge on June 26, 2013, 06:43:20 PM
 I had to re add the x_accesslist to my latest setup.



Title: Re: OBi, please help us defeat SIP scanners/spammers
Post by: mayge on July 16, 2013, 10:59:33 AM
HOWTO: Thwarting SIP Scanners during Set-up
http://www.obitalk.com/forum/index.php?topic=5467.0

QuoteNote: Things changed for the better about June/July 2013. OBiTalk has been implementing method 4, Oleg method described below, for at least some of the SIP providers by default. If your provider is not one that OBiTalk lists or if you get a SIP scan, or if you have overridden the X_InboundCallRoute so that OBiTalk does not control the field, or if you choose to not use OBiTalk, the information below will still apply. (note #j)
     =========The need for the following has been reduced========


I'm assuming X_UserAgentPort needs to be unique when multiple obi on LAN (and unique among multiple IP phone control ports)

By using an X_UserAgentPort outside 5060-5080 what pfSense (http://pfsense.org) WAN- and LAN rules would the gurus suggest?

I'm using pfsense on the recommendation of one more tech than myself as my previous router had undisablable sip alg.


Title: Re: OBi, please help us defeat SIP scanners/spammers
Post by: squalk on August 09, 2013, 04:35:49 PM
are your OBIs not sitting behind a firewall?  (not routing, not-NAT, merely firewall IDS)