Some strange Login Attempts. SIP Attack?

Found something wrong ?
Post Reply
wilbert
Posts: 66
Joined: Mon Dec 12, 2011 4:48 pm

Some strange Login Attempts. SIP Attack?

Post by wilbert » Wed Jan 29, 2014 4:42 pm

Hello Aaron,

Normally I'm not checking the console but today I was seeing loads of login attempts to my SS users. I was seeing loads of lines like this:

Warn 16:35:38:052 sip1(11308): Authentication token check failed for realm=sipsorcery.com, username=XXXXXX, uri=sip:sipsorcery.com, nonce=21030478501116396773, method=REGISTER.

Where XXXXXX are my SS users.

Please check if there's some wrong some where.

Thanks.

Aaron
Site Admin
Posts: 4652
Joined: Thu Jul 12, 2007 12:13 am

Re: Some strange Login Attempts. SIP Attack?

Post by Aaron » Thu Jan 30, 2014 10:03 am

That log message is unusual and could indeed indicate an attempt to get unauthorised access to your accounts.

Provided you don't have weak passwords you don't have to worry about it, see http://www.sipsorcery.com/mainsite/Help ... rdSecurity.

However if the messages do continue then please PM me with your sipsorcery username and I'll take a look and if needs be can block the originating IP address.

wilbert
Posts: 66
Joined: Mon Dec 12, 2011 4:48 pm

Re: Some strange Login Attempts. SIP Attack?

Post by wilbert » Thu Jan 30, 2014 12:29 pm

I've just changed all passwords just in case. Or at least, the ones that have Outbound access.

But, need to add something important. Some login attemps have been done over sip users I usually do not use. Which means that somebody is arbitrary scanning different sip users. I'm sure this is not only over my users as I've just suddenly discovered it in some special moment.

Post Reply