Суть проблемы в том что для обзвона использовался IP моего астериска. Никто ничего не слил, но факт остается фактом. фейл2бан и iptables работают, но как отловить? MY_IP - это соответственно IP моего asterisk.
[Oct 31 02:56:48] VERBOSE[25600] pbx.c: -- Executing [1635350489@from-sip-external:1] NoOp("SIP/MY_IP-000000c5", "Received incoming SIP connection from unkn
own peer to 1635350489") in new stack
[Oct 31 02:56:48] VERBOSE[25600] pbx.c: -- Executing [1635350489@from-sip-external:2] Set("SIP/MY_IP-000000c5", "DID=1635350489") in new stack
[Oct 31 02:56:48] VERBOSE[25600] pbx.c: -- Executing [1635350489@from-sip-external:3] Goto("SIP/MY_IP-000000c5", "s,1") in new stack
[Oct 31 02:56:48] VERBOSE[25600] pbx.c:
-- Goto (from-sip-external,s,1)
[Oct 31 02:56:48] VERBOSE[25600] pbx.c: -- Executing [s@from-sip-external:1] GotoIf("SIP/MY_IP-000000c5", "1?checklang:noanonymous") in new stack
[Oct 31 02:56:48] VERBOSE[25600] pbx.c: -- Goto (from-sip-external,s,2)
[Oct 31 02:56:48] VERBOSE[25600] pbx.c: -- Executing [s@from-sip-external:2] GotoIf("SIP/MY_IP-000000c5", "1?setlanguage:from-trunk,1635350489,1") in new st
ack
[Oct 31 02:56:48] VERBOSE[25600] pbx.c: -- Goto (from-sip-external,s,3)
[Oct 31 02:56:48] VERBOSE[25600] pbx.c: -- Executing [s@from-sip-external:3] Set("SIP/MY_IP-000000c5", "CHANNEL(language)=ru") in new stack
[Oct 31 02:56:48] VERBOSE[25600] pbx.c: -- Executing [s@from-sip-external:4] Goto("SIP/MY_IP-000000c5", "from-trunk,1635350489,1") in new stack
[Oct 31 02:56:48] VERBOSE[25600] pbx.c: -- Goto (from-trunk,1635350489,1)
[Oct 31 02:56:48] VERBOSE[25600] pbx.c: -- Executing [1635350489@from-trunk:1] Set("SIP/MY_IP-000000c5", "__FROM_DID=1635350489") in new stack
[Oct 31 02:56:48] VERBOSE[25600] pbx.c: -- Executing [1635350489@from-trunk:2] NoOp("SIP/MY_IP-000000c5", "Received an unknown call with DID set to 16353504
89") in new stack
[Oct 31 02:56:48] VERBOSE[25600] pbx.c: -- Executing [1635350489@from-trunk:3] Goto("SIP/MY_IP-000000c5", "s,a2") in new stack
[Oct 31 02:56:48] VERBOSE[25600] pbx.c: -- Goto (from-trunk,s,2)
[Oct 31 02:56:48] VERBOSE[25600] pbx.c: -- Executing [s@from-trunk:2] Answer("SIP/MY_IP-000000c5", "") in new stack
Потом вместо DID 1635350489 были прозвонены все трехзначные номера с 100 по 800.
спросил
2011-10-31 10:29:21 +0400
etskh 326 ● 40 ● 19
отловить что?
zzuz ( 2011-10-31 10:40:52 +0400 )редактироватьотловить и заблокировать такой попытки высоса денег.
etskh ( 2011-10-31 11:58:41 +0400 )редактировать