{"id":464,"date":"2016-02-29T22:31:19","date_gmt":"2016-02-29T14:31:19","guid":{"rendered":"http:\/\/www.myvoipapp.com\/blog\/?p=464"},"modified":"2016-02-29T22:43:57","modified_gmt":"2016-02-29T14:43:57","slug":"anti-sip-scanning","status":"publish","type":"post","link":"https:\/\/www.myvoipapp.com\/blog\/2016\/02\/29\/anti-sip-scanning\/","title":{"rendered":"Anti SIP scanning"},"content":{"rendered":"<p>One of our customers reported that his extensions have been cracked. We checked its MSS CDR records. It seems someone has cracked one extension&#8217;s password and used this extension number to make lots of calls.<\/p>\n<p>Obveriously, it is a very dangerous problem. We think this &#8220;hacker&#8221; might send\u00a0lots of SIP messages to MSS to try such extension&#8217;s password. MSS previous version doesn&#8217;t consider this scenario and always permit the SIP phone to keep trying its password until it is authorized.<\/p>\n<p>To stop this, we upgrade V26 to support &#8220;fail to ban (F2B)&#8221; feature. Once SIP phone has failed to check\u00a0authorization for several times in one minute, MSS will detect it as &#8220;scanning&#8221; and ban its IP address for several hours. All SIP messages from such address will be rejected directly. Then\u00a0it is impossible for &#8220;hacker&#8221; to crack SIP passwords.<\/p>\n<p>This feature is enabled by default and need configure nothing for it.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>One of our customers reported that his extensions have been cracked. We checked its MSS CDR records. It seems someone has cracked one extension&#8217;s password and used this extension number to make lots of calls. Obveriously, it is a very dangerous problem. We think this &#8220;hacker&#8221; might send\u00a0lots of SIP messages to MSS to try such extension&#8217;s password. MSS previous version doesn&#8217;t consider this scenario and always permit the SIP phone to keep trying its password until it is authorized&#8230;.<\/p>\n<p class=\"read-more\"><a class=\"btn btn-default\" href=\"https:\/\/www.myvoipapp.com\/blog\/2016\/02\/29\/anti-sip-scanning\/\"> Read More<span class=\"screen-reader-text\">  Read More<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[35,137],"tags":[68,195,192,194,193,11],"class_list":["post-464","post","type-post","status-publish","format-standard","hentry","category-minisipserver","category-tech-documents","tag-authorization","tag-ban","tag-ddos","tag-hacker","tag-scanning","tag-sip"],"_links":{"self":[{"href":"https:\/\/www.myvoipapp.com\/blog\/wp-json\/wp\/v2\/posts\/464","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.myvoipapp.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.myvoipapp.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.myvoipapp.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.myvoipapp.com\/blog\/wp-json\/wp\/v2\/comments?post=464"}],"version-history":[{"count":3,"href":"https:\/\/www.myvoipapp.com\/blog\/wp-json\/wp\/v2\/posts\/464\/revisions"}],"predecessor-version":[{"id":467,"href":"https:\/\/www.myvoipapp.com\/blog\/wp-json\/wp\/v2\/posts\/464\/revisions\/467"}],"wp:attachment":[{"href":"https:\/\/www.myvoipapp.com\/blog\/wp-json\/wp\/v2\/media?parent=464"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.myvoipapp.com\/blog\/wp-json\/wp\/v2\/categories?post=464"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.myvoipapp.com\/blog\/wp-json\/wp\/v2\/tags?post=464"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}