Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chriss Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Hacked Again

Status
Not open for further replies.

Thermus

Programmer
Jul 3, 2003
176
NZ
Hi Guys

A while back I found a third party SIP extn registered to our IPECs that none of my work mates had entered. It also had an IP address that originated in Egypt.

It seems that hackers come in on port 5060 and register a SIP extn by correctly guessing extn and password or some way that is unknown because all our passwords are now strong.
Fortunately we are toll barred in night service and have no SIP extn licences so getting out of our system can not happen.

The fact they got in this way in the first place is concerning though. And if you are a comms company that sells IPECs there is a chance you may be a target if your PABX is IPECs. We suspect they got to us by searching the web.

The fix is PGM 210 set REMOTE register to "Deny" ( not the default )
PGM 211 Select your entire extn range and check that 407 authentication is on ( should be on in default )

Hope this is useful.

 
Just so everyone knows this fix did not stop hackers getting into my system. I was able stop the calls because I was using NMS and got alerts
telling me my 3rd party SIP extensions were going up and down as the hackers registered different IP addresses. My IP addresses originated in Israel and Pennsylvania, USA.

So I am not sure what to do to stop this except toll restrict all these extensions.

nightwolf
 
Thermus

When I checked the pgm210 and denied remote, my 'IPECS COmmunicator' stopped registering. Is this correct or have I done something wrong?

Eats
 
Hi nightwolf

PGM 210 should stop the registration of new 3rd party SIP extns.

If hackers were getting onto existing SIP extns, then you may need to change all your passwords for those extns.

We have a minimum of 6 digit auth codes set up and no more problems...........yet.
 
Hi Thermus,

Well it was definitely week passwords that were the problem. I just thought that they would not be able to register to any sip extensions when I had remote register set to 'deny' in Pgm 210. I have now disabled all international calling in my COS.

nightwolf
 
It might be worth checking under PGM 211 (SIP Phone Attributes) and ensure that opt 12 - 407 Authentication is turned on for all of the 3rd party sip extensions. without this enabled, passwords are completely ignored for 3rd party sip extensions allowing devices to register with only the username.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top