define('DISALLOW_FILE_EDIT', true);
define('DISALLOW_FILE_MODS', true);{"id":74,"date":"2011-02-25T23:17:00","date_gmt":"2011-02-25T22:17:00","guid":{"rendered":"http:\/\/www.monovarlinux.org\/?p=74"},"modified":"2012-05-29T02:14:20","modified_gmt":"2012-05-29T01:14:20","slug":"intento-hack-asterisk-fuerza-bruta-contra-asterisk","status":"publish","type":"post","link":"http:\/\/www.monovarlinux.org\/?p=74","title":{"rendered":"Intento Hack Asterisk. Fuerza Bruta contra Asterisk"},"content":{"rendered":"<p>Hoy me encontraba navegando tranquilamente y monitorizando todos los servidores propios, cuando de repente en la consola de asterisk me aparece lo siguiente:<\/p>\n<blockquote><p>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5465&#8243;&lt;sip:5465@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5466&#8243;&lt;sip:5466@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5467&#8243;&lt;sip:5467@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5468&#8243;&lt;sip:5468@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb44114411&#8243;&lt;sip:44114411@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5469&#8243;&lt;sip:5469@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5470&#8243;&lt;sip:5470@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb44124412&#8243;&lt;sip:44124412@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5471&#8243;&lt;sip:5471@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5472&#8243;&lt;sip:5472@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5473&#8243;&lt;sip:5473@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb44134413&#8243;&lt;sip:44134413@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5474&#8243;&lt;sip:5474@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5475&#8243;&lt;sip:5475@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5476&#8243;&lt;sip:5476@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb44144414&#8243;&lt;sip:44144414@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5477&#8243;&lt;sip:5477@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5478&#8243;&lt;sip:5478@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5479&#8243;&lt;sip:5479@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5480&#8243;&lt;sip:5480@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5481&#8243;&lt;sip:5481@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5482&#8243;&lt;sip:5482@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5483&#8243;&lt;sip:5483@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5484&#8243;&lt;sip:5484@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5485&#8243;&lt;sip:5485@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5486&#8243;&lt;sip:5486@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5487&#8243;&lt;sip:5487@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5488&#8243;&lt;sip:5488@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5489&#8243;&lt;sip:5489@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5490&#8243;&lt;sip:5490@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5491&#8243;&lt;sip:5491@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5492&#8243;&lt;sip:5492@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5493&#8243;&lt;sip:5493@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5494&#8243;&lt;sip:5494@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found<br \/>\n[Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5495&#8243;&lt;sip:5495@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found\n<\/p><\/blockquote>\n<p>Es obvio que estan atacando a nuestro asterisk con un ataque Brute Force (Fuerza bruta).<br \/>\nSeguro que no es ning\u00fana persona fisica si no cualquier m\u00e1quina comprometida con software instalado para tal fin<br \/>\n(Encontrar m\u00e1quinas con asterisk y realiz\u00e1r ataques de fuerza bruta).<br \/>\nCon la cual pueden intentar millones de combinaciones para autentificarse en nuestro Asterisk.<\/p>\n<p>La ip que generaba esto era la: 139.153.12.78 y seg\u00fan he podido averiguar es de una universidad de UK la cual tiene asignado un rango de ips que es el siguiente: <\/p>\n<blockquote><p>\n139.153.0.0\/16\n<\/p><\/blockquote>\n<p>\nLa soluci\u00f3n fu\u00e9 sencilla, para este tema, Iptables como no \ud83d\ude1b<\/p>\n<blockquote><p>\niptables -t filter -A INPUT -s 139.153.0.0\/16 -j DROP\n<\/p><\/blockquote>\n<p>\nTodo el tr\u00e1fico que venga de ese rango, lo dropear\u00e1.<\/p>\n<p>Ya he informado a la gente que administra dicha red y se han puesto manos a la obra para solventar el problema.<\/p>\n<p>Saludos.<\/p>\n<div class=\"be-social\" data-url=\"http:\/\/www.monovarlinux.org\/?p=74\" data-base=\"\" data-title=\"Intento Hack Asterisk. Fuerza Bruta contra Asterisk\" data-track=\"true\" data-via=\"\" data-show=\"{&quot;facebook&quot;:true,&quot;twitter&quot;:true,&quot;google&quot;:true,&quot;reddit&quot;:true,&quot;linkedin&quot;:true,&quot;meneame&quot;:true}\" ><h2 class=\"be-social-title\">Share<\/h2><\/div>","protected":false},"excerpt":{"rendered":"<p>Hoy me encontraba navegando tranquilamente y monitorizando todos los servidores propios, cuando de repente en la consola de asterisk me aparece lo siguiente: [Feb 26 00:54:13] NOTICE[8658]: chan_sip.c:21821 handle_request_register: Registration from &#8216;\u00bb5465&#8243;&lt;sip:5465@81.56.122.35&gt;&#8217; failed for &#8216;139.153.12.78&#8217; &#8211; No matching peer found &hellip; <a href=\"http:\/\/www.monovarlinux.org\/?p=74\">Sigue leyendo <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[8],"tags":[],"_links":{"self":[{"href":"http:\/\/www.monovarlinux.org\/index.php?rest_route=\/wp\/v2\/posts\/74"}],"collection":[{"href":"http:\/\/www.monovarlinux.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.monovarlinux.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.monovarlinux.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.monovarlinux.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=74"}],"version-history":[{"count":5,"href":"http:\/\/www.monovarlinux.org\/index.php?rest_route=\/wp\/v2\/posts\/74\/revisions"}],"predecessor-version":[{"id":77,"href":"http:\/\/www.monovarlinux.org\/index.php?rest_route=\/wp\/v2\/posts\/74\/revisions\/77"}],"wp:attachment":[{"href":"http:\/\/www.monovarlinux.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=74"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.monovarlinux.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=74"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.monovarlinux.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=74"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}