Is someone trying to connect to my PBX?

Status
Not open for further replies.

hainesk967

Joined
May 23, 2011
Messages
38
Reaction score
0
I saw this in my Server Activity Log and am confused by it. I am not using Asterisk PBX, and the ip address traces back to a onestop.net cloud server. What does this mean? Any help will be appreciated!


11:09:49.295 [CM500002]: Unidentified incoming call. Review INVITE and adjust source identification:
INVITE sip:[email protected] SIP/2.0
Via: SIP/2.0/UDP 74.208.238.66:36967;branch=z123RE8gBkor3;rport=36967
Max-Forwards: 70
Contact: <sip:[email protected]>
To: <sip:[email protected]>
From: "asterisk"<sip:[email protected]>;tag=z321RE8gBkor3
Call-ID: [email protected]
CSeq: 102 INVITE
Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, SUBSCRIBE, NOTIFY, INFO
Supported: replaces
User-Agent: Asterisk PBX
Content-Length: 0
 
I suppose someone might just be calling me from an Asterisk PBX? Is this what it would look like? Do I need to adjust my incoming call rules to accept these?
 
More likely someone is trying to take advantage of your PBX hospitality. The number they are attempting to call is interesting since it is made up of the US IDD code (011) and then a UK number which is for the Financial services Authority. Unless you know that this is a legitimate remote extensions then this is probably a probe to see if your PBX can be used to make free calls. Are you running a firewall?
 
Yes I am using a firewall and the only port that is forwarded to my server is 5060. I think that to dial the UK from the US you have to use 011+44. I didn't notice the number involved. It looks like it didn't go through anyway. Is there anyway to stop this from happening or will I just notice this from time to time?
 
Is there anyway to stop this from happening or will I just notice this from time to time?

On my firewall I block everything targeting port 5060 except packets coming from the known IP's of my VOIP providers. As I only have 2 providers this is easily done.
 
Ok, thanks a lot for the help!
 
I had one of those last night, same phone number (without the leading 9), which I looked up this morning. Will have to have a look and see if it came from the same IP as yours. (the attempt on mine came from 173.237.189.70 which translates to ..ajax.vivawebhost.com ) Someone is up to no good, i suspect....
 
Hey,
How do I go back further in my server activity log to check for any other instances of this happening?
 
http://www.3cx.com/forums/server-activity-log-historic-log-files-where-are-they-19768.html
 
Since I'm using server 2008, that doesn't help....
 
FYI: I was able to find it under c:\programdata\3cx\data\logs\3cxphonesystem.log

All dates are apparently combined into that one file.
 
@ Cjay
I get those attempts also once in a while. 3CX so fare had blocked all of them. What firewall do you use where you can block all traffic except the one coming from your VOIP provider??
 
I'm seeing that every once in a while too. Obviously from the same source as the phone number they are trying to "test" to is only slightly different. It's coming from various IP's in "bursts" of 5 or 6 "probes
 
Status
Not open for further replies.

Members Online Now

Forum statistics

Threads
111,860
Messages
589,437
Members
164,700
Latest member
Apollo Cloud