[113560] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: SIP - perhaps botnet? anyone else seeing this?

daemon@ATHENA.MIT.EDU (Andy Davidson)
Wed Apr 15 13:51:41 2009

Date: Wed, 15 Apr 2009 18:49:25 +0100
To: Dane <dane@pktloss.net>
In-Reply-To: <37c351df0904150935v462e602bqaa65d98275c07efd@mail.gmail.com>
From: Andy Davidson <andy@nosignal.org>
Cc: nanog@nanog.org
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org

On Wed, Apr 15, 2009 at 11:35:43AM -0500, Dane wrote:
> Today I heard from someone who says Verizon is telling them they see
> about 700 calls per hour to Cuba originating from their PRI.
> Obviously some type of toll fraud. 

In the same way that it's possible to configure a mail relay as a
device that forwards mail between unintended parties, it is possible 
to configure a SIP proxy as a device that causes calls to be 
forwarded between unintended parties too.

Likewise, in the same way that spammers scan network ranges for these
misconfigured mail gateways, thieves look for unsecured SIP gateways
to relay calls through.

The SIP traffic mentioned at the start of this thread doesn't follow
the pattern of this constant background noise.


Kind regards,
Andy


home help back first fref pref prev next nref lref last post