Hello,
Yesterday, I ve authorized acess of my Oxe R11 to the Internet world. I ve also configured a redirection of the port 5060 to the OXE. Because, I would like to test public SIP trunk but, for the moment, I ve not configured the External gateway. I ve only a local sip gateway configured for my sip phones and for the link with my otms.
This morning, I discover that you have received a lot of calls by the trunk sip (9500 calls). The calling number is 0100 and the call type is PrivateNetworkIncomingCall (on accounting ticket)
On accouting ticket, I find also outgoing calls by my T2 trunk to internationals number (macedonia, israel, ...). The call type is ISDNCircuitSwitchedCall.
Do you know how the kackers get through my trunk sip to calls by my ISDN trunk. For information, the operatrice phone had a lot of calls of 0100.
Example of tickets :
----[/DHS3dyn/account/TAXADJDD.DAT : Ticket number 601/601/607]-----------------
(00) TicketVersion = ED5.2 (01) CalledNumber = 0100
(02) ChargedNumber = FS110 (03) ChargedUserName = SIP
(04) ChargedCostCenter = (05) ChargedCompany =
(06) ChargedPartyNode = 103 (07) Subaddress =
(08) CallingNumber =
(09) CallType = PrivateNetworkIncomingCall
(10) CostType = Unspecified (11) EndDateTime = 20140801 07:27:54
(12) ChargeUnits = 0 (13) CostInfo = 0
(14) Duration = 0 (15) TrunkIdentity = 629
(16) TrunkGroupIdentity = 110 (17) TrunkNode = 103
(18) PersonalOrBusiness = Normal (19) AccessCode =
(20) SpecificChargeInfo = (21) BearerCapability = Speech
(22) HighLevelComp = Telephony (23) DataVolume = 0
(24) UserToUserVolume = 0 (25) ExternFacilities =
(26) InternFacilities = OperatorFacility
(27) CallReference = 0 (28) SegmentsRate1 = 0
(29) SegmentsRate2 = 0 (30) SegmentsRate3 = 0
(31) ComType = Voice (32) X25IncomingFlowRate = Unspecified
(33) X25OutgoingFlowRate = Unspecified (34) Carrier = 0
(35) InitialDialledNumber = 00393199 (36) WaitingDuration = 1
(37) EffectiveCallDuration = 0 (38) RedirectedCallIndicator = 1
(39) StartDateTime = 20140801 07:27:54 (40) ActingExtensionNumber =
(41) CalledNumberNode = 9999 (42) CallingNumberNode = 9999
(43) InitialDialledNumberNode = 9999 (44) ActingExtensionNumberNode = 9999
(45) TransitTrunkGroupIdentity = 32767 (46) NodeTimeOffset = 0
(47) TimeDlt = 0
----[/DHS3dyn/account/TAXADJDD.DAT : Ticket number 602/602/607]-----------------
(00) TicketVersion = ED5.2 (01) CalledNumber = 00393199053246
(02) ChargedNumber = FS110 (03) ChargedUserName = SIP
(04) ChargedCostCenter = (05) ChargedCompany =
(06) ChargedPartyNode = 103 (07) Subaddress =
(08) CallingNumber = (09) CallType = Unspecified
(10) CostType = ISDNCircuitSwitchedCall (11) EndDateTime = 20140801 07:27:54
(12) ChargeUnits = 0 (13) CostInfo = 0
(14) Duration = 0 (15) TrunkIdentity = 4
(16) TrunkGroupIdentity = 100 (17) TrunkNode = 103
(18) PersonalOrBusiness = Normal (19) AccessCode =
(20) SpecificChargeInfo = (21) BearerCapability = Speech
(22) HighLevelComp = Telephony (23) DataVolume = 0
(24) UserToUserVolume = 0
(25) ExternFacilities = CallingLineIdentificationPresentation
(26) InternFacilities = Transit ARSService
(27) CallReference = 0 (28) SegmentsRate1 = 0
(29) SegmentsRate2 = 0 (30) SegmentsRate3 = 0
(31) ComType = Voice (32) X25IncomingFlowRate = Unspecified
(33) X25OutgoingFlowRate = Unspecified (34) Carrier = 0
(35) InitialDialledNumber = 00393199053246
(36) WaitingDuration = 0 (37) EffectiveCallDuration = 0
(38) RedirectedCallIndicator = 0 (39) StartDateTime = 20140801 07:27:54
(40) ActingExtensionNumber = (41) CalledNumberNode = 9999
(42) CallingNumberNode = 9999 (43) InitialDialledNumberNode = 9999
(44) ActingExtensionNumberNode = 9999 (45) TransitTrunkGroupIdentity = 32767
(46) NodeTimeOffset = 0 (47) TimeDlt = 0
----[/DHS3dyn/account/TAXADJDD.DAT : Ticket number 603/603/607]-----------------
(00) TicketVersion = ED5.2 (01) CalledNumber = 00393199053246
(02) ChargedNumber = FS110 (03) ChargedUserName = SIP
(04) ChargedCostCenter = (05) ChargedCompany =
(06) ChargedPartyNode = 103 (07) Subaddress =
(08) CallingNumber = (09) CallType = Unspecified
(10) CostType = ISDNCircuitSwitchedCall (11) EndDateTime = 20140801 07:28:03
(12) ChargeUnits = 0 (13) CostInfo = 0
(14) Duration = 0 (15) TrunkIdentity = 6
(16) TrunkGroupIdentity = 100 (17) TrunkNode = 103
(18) PersonalOrBusiness = Normal (19) AccessCode =
(20) SpecificChargeInfo = (21) BearerCapability = Speech
(22) HighLevelComp = Telephony (23) DataVolume = 0
(24) UserToUserVolume = 0
(25) ExternFacilities = CallingLineIdentificationPresentation
(26) InternFacilities = Transit ARSService
(27) CallReference = 0 (28) SegmentsRate1 = 0
(29) SegmentsRate2 = 0 (30) SegmentsRate3 = 0
(31) ComType = Voice (32) X25IncomingFlowRate = Unspecified
(33) X25OutgoingFlowRate = Unspecified (34) Carrier = 0
(35) InitialDialledNumber = 00393199053246
(36) WaitingDuration = 0 (37) EffectiveCallDuration = 0
(38) RedirectedCallIndicator = 0 (39) StartDateTime = 20140801 07:28:03
(40) ActingExtensionNumber = (41) CalledNumberNode = 9999
(42) CallingNumberNode = 9999 (43) InitialDialledNumberNode = 9999
(44) ActingExtensionNumberNode = 9999 (45) TransitTrunkGroupIdentity = 32767
(46) NodeTimeOffset = 0 (47) TimeDlt = 0
----[/DHS3dyn/account/TAXADJDD.DAT : Ticket number 604/604/607]-----------------
(00) TicketVersion = ED5.2 (01) CalledNumber = 0023221101438
(02) ChargedNumber = FS110 (03) ChargedUserName = SIP
(04) ChargedCostCenter = (05) ChargedCompany =
(06) ChargedPartyNode = 103 (07) Subaddress =
(08) CallingNumber = (09) CallType = Unspecified
(10) CostType = ISDNCircuitSwitchedCall (11) EndDateTime = 20140801 07:28:16
(12) ChargeUnits = 0 (13) CostInfo = 0
(14) Duration = 0 (15) TrunkIdentity = 6
(16) TrunkGroupIdentity = 100 (17) TrunkNode = 103
(18) PersonalOrBusiness = Normal (19) AccessCode =
(20) SpecificChargeInfo = (21) BearerCapability = Speech
(22) HighLevelComp = Telephony (23) DataVolume = 0
(24) UserToUserVolume = 0
(25) ExternFacilities = CallingLineIdentificationPresentation
(26) InternFacilities = Transit ARSService
(27) CallReference = 0 (28) SegmentsRate1 = 0
(29) SegmentsRate2 = 0 (30) SegmentsRate3 = 0
(31) ComType = Voice (32) X25IncomingFlowRate = Unspecified
(33) X25OutgoingFlowRate = Unspecified (34) Carrier = 0
(35) InitialDialledNumber = 0023221101438
(36) WaitingDuration = 0 (37) EffectiveCallDuration = 0
(38) RedirectedCallIndicator = 0 (39) StartDateTime = 20140801 07:28:16
(40) ActingExtensionNumber = (41) CalledNumberNode = 9999
(42) CallingNumberNode = 9999 (43) InitialDialledNumberNode = 9999
(44) ActingExtensionNumberNode = 9999 (45) TransitTrunkGroupIdentity = 32767
(46) NodeTimeOffset = 0 (47) TimeDlt = 0
I have delete the redirection of the port 5060 and since I
OXE HACKED BY INTERNET
-
cavagnaro
Re: OXE HACKED BY INTERNET
Post by cavagnaro »
Lol...so...firewall? neee .... SBC?? nee.....activate security on SIP?? Neeee...
There are thousands of hackers everyday scanning for port 5060...the most obvious one...
Get a security expert consultant to advice you how to put your OXE on internet. First step...just don't.
There are thousands of hackers everyday scanning for port 5060...the most obvious one...
Get a security expert consultant to advice you how to put your OXE on internet. First step...just don't.
Re: OXE HACKED BY INTERNET
hehe... some times ago, i've placed an debian-asterisk installation with port 5060 in the internet world.... after this i've got an default-password list in my log-file. the initiator was an ip address from china... but ha has no sucess 
thats why i say never do connect an oxe system without an sbc...
regards...
thats why i say never do connect an oxe system without an sbc...
regards...
--- back to basics... focus your eyes to the essential things... ---
Jump to
- General topics
- ↳ Talk to the admins
- ↳ GENERAL
- ↳ Outside World
- ↳ PARTS
- ↳ Pre-Sales
- ↳ JOBS
- ↳ Remote assistance contracts
- ↳ Actis
- ↳ Equipement Pictures
- ↳ OT/OXE/OXO FEATURES REQUESTS
- ↳ Lucent Technologies
- IF YOU ARE NOT TECHNICALLY TRAINED ON THOSE PBX, PLEASE POST IN ONE OF THOSE FORUMS
- ↳ Beginner's questions about the Crystal Hardware
- ↳ Beginner's questions about the Common Hardware
- ↳ Beginner's questions about the (4400 / Enterprise) PHONE APPLICATION or OPERATING SYSTEM
- ↳ Beginner's questions about the OmniPCX OFFICE
- VOICE - Documentation
- ↳ OXE (Crystal / Common) - System Documentation
- ↳ 4760
- ↳ OXO - System Documentation
- ↳ Documentation
- VOICE - OXE (OmniPCX Enterprise)
- ↳ Shelf
- ↳ Media Gateway
- ↳ PWT/DECT System
- ↳ System
- ↳ Translator
- ↳ Classes of Services
- ↳ Attendant
- ↳ Users
- ↳ Users by profile
- ↳ Set Profile
- ↳ Groups
- ↳ Speed Dialing
- ↳ Phone Book
- ↳ Entities
- ↳ Trunk Groups
- ↳ External Services
- ↳ Inter-Node Links
- ↳ X25
- ↳ Data
- ↳ Application
- ↳ Specific Telephone Services
- ↳ ATM
- ↳ Event Routing Discriminator
- ↳ Security and Access Control
- ↳ IP
- ↳ SIP
- ↳ DHCP Configuration
- ↳ Alcatel-Lucent Series 8&9
- ↳ SIP Extension
- ↳ Encryption
- ↳ Passive Communication Server
- ↳ SNMP Configuration
- VOICE - OXE - Common topics
- ↳ MAIN
- ↳ ACTIS
- ↳ Asterisk
- ↳ Boards
- ↳ Bugs & Security issues
- ↳ Equipment Pictures
- ↳ Feature Request
- ↳ H323 / Sip
- ↳ IP / VoIP
- ↳ IP SECURITY / ENCRYPTION (Thales)
- ↳ ipTouch (40x8) issues and tricks
- ↳ Linux tricks
- ↳ MOH
- ↳ ON SITE TROUBLES
- ↳ Phones
- ↳ Sipfoundry
- ↳ Software Loading
- ↳ Swinst
- ↳ System Hacking
- ↳ Traces
- ↳ Usefull commands
- ↳ Voice Guides
- ↳ Wireless configuration and sets
- VOICE - OpenTouch
- ↳ MAIN
- ↳ OTEC - OpenTouch Enterprise Cloud
- ↳ OTBE - OpenTouch Business Edition
- ↳ OTMS - OpenTouch Multimedia Services
- ↳ OTSBC - OpenTouch Session Border Controller
- ↳ OTNS - OpenTouch Notification Service
- ↳ OTMC - OpenTouch Message Center
- ↳ OTFC - OpenTouch Fax Center
- ↳ OpenTouch Conversation
- ↳ Smart Guest Applications
- VOICE - BiCS
- ↳ MAIN
- VOICE - OXO
- ↳ MAIN
- ↳ Configuration
- ↳ 42xx Systems
- ↳ Networking
- ↳ H323 / IP / Pimphony
- ↳ Internet and related
- ↳ Applications
- ↳ Hotel mode
- ↳ DECT
- ↳ Hardware
- VOICE - Omni Suite
- ↳ OmniTouch 8400 Instant Communication Suite
- ↳ OmniTouch 8410 Instant Communication Web Services
- ↳ OmniTouch 8440 Messaging Software
- ↳ OmniTouch 8450 Fax Software
- ↳ OmniTouch 8460 Advanced Communication Server
- ↳ OmniTouch 8464 Meet-me Audio Conference Bridge
- ↳ OmniTouch 8660 My Teamwork Conferencing and Collaboration
- ↳ OmniTouch 8670 Automated Message Delivery System
- ↳ OmniTouch Contact Center Standard Edition
- ↳ OmniTouch Contact Center Premium Edition
- VOICE - Applications
- ↳ AECS - Alcatel Extended Communication Server
- ↳ Alcatel OpenTouch Customer Service
- ↳ Aviso
- ↳ Call Center SoftPanel (ALU ProServices)
- ↳ CCD / CCS / CCIVR
- ↳ Free Desktop
- ↳ GENESYS
- ↳ Hotel / Hospital
- ↳ Ip Desktop Softphone
- ↳ IpTouch Phones XML Applications
- ↳ MSAD
- ↳ MyIC (My Instant Communicator)
- ↳ My Messaging / IMAP
- ↳ My Teamwork (ex-eDial)
- ↳ OmniPCX Record
- ↳ OmniVista 4760
- ↳ OmniVista 8770
- ↳ OTUC
- ↳ PREMIUM / GCE
- ↳ Rainbow
- ↳ Ubiquity
- ↳ ENS - Emergency Notification Server
- ↳ VNA - Visual Notification Assistant
- ↳ VAA - Visual Auto Attendant
- ↳ VitalSuite
- ↳ VitalQIP
- ↳ Voicemail (46x5)
- ↳ XML Presentation Server & TAPI Server
- ↳ 4980 - WebSoftPhone
- ↳ 4625 Interactive Voice Response
- VOICE - Third Party Applications
- ↳ AGITO NETWORKS
- ↳ AUDIOCODES
- ↳ ASTERISK
- ↳ AVST
- ↳ CDR Real time on Ethernet
- ↳ CISCO
- ↳ NGINX
- ↳ NICE
- ↳ Notification Systems
- ↳ OAK
- ↳ SOURCE TECH
- ↳ systel
- ↳ IP Touch apps
- ↳ Click2Dial
- ↳ MYIC apps
- Voice - Virtualization
- ↳ AWS
- ↳ HyperV
- ↳ Linux KVM
- ↳ Proxmox
- ↳ VmWare
- ↳ Other
- Alcatel Unleashed tools, documentations, and misc files...
- ↳ GitHub Script Repository
- ↳ "Home Made" documentations
- ↳ Alcatel Misc Documentation
- ↳ OFFICIAL TC's
- ↳ DIALER
- ↳ infocollect
- ↳ ipview analyzer
- ↳ motview
- ↳ sngrep
- ↳ VM_BACKUP
- ↳ Other Alcatel-Lucent tools
- Developer's corner
- ↳ AHL / OHL
- ↳ Alarming, Notification & Location
- ↳ CCTI / CCA
- ↳ CSTA
- ↳ My IC Phone
- ↳ My IP Touch Service for Enterprise
- ↳ O2G
- ↳ OmniVista 8770 User Provisioning
- ↳ SIP
- ↳ TAPI
- ↳ TSAPI
- ↳ Web Services
- Alcatel Data Equipment
- ↳ Security
- ↳ OmniAccess 3500 Nonstop Laptop Guardian
- ↳ Mobility
- ↳ OmniAccess WLAN Switching Systems
- ↳ OmniAccess WLAN 4302
- ↳ OmniAccess Wireless Access Points 41
- ↳ OmniAccess Wireless Access Points 65
- ↳ OmniAccess Wireless Access Points 60/61/70
- ↳ OmniAccess Wireless Access Points 80M
- ↳ Mobile IP Phones
- ↳ OmniAccess Devices
- ↳ OmniAccess 5780
- ↳ OmniAccess 5740
- ↳ OmniAccess 5510
- ↳ Network Management
- ↳ Omnivista
- ↳ Omnivista Mobility Manager
- DATA - Documentation
- ↳ Technical papers
- ↳ Troubleshooting guides
- DATA - Lan Switching
- ↳ OmniSwitch 10k
- ↳ OmniSwitch 9900
- ↳ OmniSwitch 9000 / 9000E
- ↳ OmniSwitch 6900
- ↳ OmniSwitch 6865
- ↳ OmniSwitch 6870
- ↳ OmniSwitch 6860 / 6860E
- ↳ OmniSwitch 6855
- ↳ OmniSwitch 6850 / 6850E
- ↳ OmniSwitch 6560 / 6570M
- ↳ OmniSwitch 6465
- ↳ OmniSwitch 6450
- ↳ OmniSwitch 6400
- ↳ OmniSwitch 6360
- ↳ OmniSwitch 6350
- ↳ OmniSwitch 6250
- ↳ OmniSwitch 2220
- ↳ OmniSwitch 2260 / 2360
- ↳ Legacy Devices (OS4024, XOS, OmniCore)
- ↳ OmniSwitch 6600 / 7000 / 8800
- ↳ OmniSwitch 6800
- ↳ OmniStack LS 6200
- ↳ Misc
- DATA - WLAN, Mobility and WAN
- ↳ OmniAccess WLAN Switching Systems (OEM)
- ↳ OmniAccess Wireless Access Points
- ↳ Mobile IPTouch Phones (MIPT)
- ↳ OmniAccess Stellar Express
- ↳ OmniAccess Stellar Enterprise
- ↳ OmniAccess 3500 Nonstop Laptop Guardian
- ↳ Brick VPN Firewall
- ↳ OmniAccess 5740/5780
- ↳ OmniAccess ESR 5720
- ↳ OmniAccess 5510
- DATA - Network Management
- ↳ OmniVIsta 3600 Air Manager
- ↳ OmniVista 2500 v4.x
- ↳ OmniVista 2500 v3.5
- ↳ OmniVista 2500/2700 v3.4 and older
- ↳ OmniVista Cirrus
- ↳ Alcatel Quarantine Manager
- ↳ Fortigate Security
- DATA - Service Provider
- ↳ 5520 ASAM
- ↳ 5620 SAM
- ↳ 5650 CPAM
- ↳ 5670 RAM
- ↳ 5750 SSC
- ↳ 7210 SAS
- ↳ 7360 ISAM
- ↳ 7450 ESS
- ↳ 7450 Ethernet Service Switch
- ↳ 7750 Service Router
- ↳ 7705 SAR
- ↳ 7750 SR
