[113360] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: SIP - perhaps botnet? anyone else seeing this?

daemon@ATHENA.MIT.EDU (Roland Dobbins)
Fri Apr 10 05:21:15 2009

From: Roland Dobbins <rdobbins@cisco.com>
To: NANOG list <nanog@nanog.org>
In-Reply-To: <Pine.LNX.4.44.0904100838590.1184-100000@taranta.discpro.org>
Date: Fri, 10 Apr 2009 17:18:58 +0800
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org


On Apr 10, 2009, at 4:45 PM, Leland E. Vandervort wrote:

> UDP SIP Control traffic in our netflow data.

Have you grabbed some packets in order to ensure it's actually SIP,  
vs. something else on the same ports?

If it really is SIP-related, this could be caused by botted hosts  
launching a SIP DDoS, or brute-forcing said SIP services in order to  
steal service for resale, DoS someone else via the service at layer-7  
(i.e., call avallanche), sent VoIP spam, et. al.  You may have botted  
hosts in your hosting space, as well as hosts being scanned as  
potential targets for exploitation.

A quick search-engine query should reveal that this sort of thing has  
been going on for quite some time; I believe there were some  
convictions in NJ or somewhere else in the northeastern US within the  
last year or so.

-----------------------------------------------------------------------
Roland Dobbins <rdobbins@cisco.com> // +852.9133.2844 mobile

   Our dreams are still big; it's just the future that got small.

		   -- Jason Scott



home help back first fref pref prev next nref lref last post