Page 1 of 1

what is this i saw??

PostPosted: Thu Sep 26, 2013 1:27 pm
by sigbinme
what is this i saw on my CLI

please xplain

817@115.85.1.226>' failed for '199.19.111.221' - No matching peer found
[Sep 27 02:24:40] NOTICE[1571]: chan_sip.c:16835 handle_request_register: Registration from '"1004" <sip:1004@115.85.1.226>' failed for '199.19.111.221' - Wrong password
[Sep 27 02:24:40] NOTICE[1571]: chan_sip.c:16835 handle_request_register: Registration from '"323818"<sip:323818@115.85.1.226>' failed for '199.19.111.221' - No matching peer found
[Sep 27 02:24:40] NOTICE[1571]: chan_sip.c:16835 handle_request_register: Registration from '"1004" <sip:1004@115.85.1.226>' failed for '199.19.111.221' - Wrong password
[Sep 27 02:24:40] NOTICE[1571]: chan_sip.c:16835 handle_request_register: Registration from '"323819"<sip:323819@115.85.1.226>' failed for '199.19.111.221' - No matching peer found
[Sep 27 02:24:40] NOTICE[1571]: chan_sip.c:16835 handle_request_register: Registration from '"1004" <sip:1004@115.85.1.226>' failed for '199.19.111.221' - Wrong password
[Sep 27 02:24:40] NOTICE[1571]: chan_sip.c:16835 handle_request_register: Registration from '"323821"<sip:323821@115.85.1.226>' failed for '199.19.111.221' - No matching peer found
[Sep 27 02:24:40] NOTICE[1571]: chan_sip.c:16835 handle_request_register: Registration from '"323822"<sip:323822@115.85.1.226>' failed for '199.19.111.221' - No matching peer found
[Sep 27 02:24:40] NOTICE[1571]: chan_sip.c:16835 handle_request_register: Registration from '"1004" <sip:1004@115.85.1.226>' failed for '199.19.111.221' - Wrong password
[Sep 27 02:24:40] NOTICE[1571]: chan_sip.c:16835 handle_request_register: Registration from '"323823"<sip:323823@115.85.1.226>' failed for '199.19.111.221' - No matching peer found
[Sep 27 02:24:40] NOTICE[1571]: chan_sip.c:16835 handle_request_register: Registration from '"1004" <sip:1004@115.85.1.226>' failed for '199.19.111.221' - Wrong password
[Sep 27 02:24:40] NOTICE[1571]: chan_sip.c:16835 handle_request_register: Registration from '"323824"<sip:323824@115.85.1.226>' failed for '199.19.111.221' - No matching peer found
[Sep 27 02:24:40] NOTICE[1571]: chan_sip.c:16835 handle_request_register: Registration from '"1004" <sip:1004@115.85.1.226>' failed for '199.19.111.221' - Wrong password
[Sep 27 02:24:40] NOTICE[1571]: chan_sip.c:16835 handle_request_register: Registration from '"323825"<sip:323825@115.85.1.226>' failed for '199.19.111.221' - No matching peer found
[Sep 27 02:24:40] NOTICE[1571]: chan_sip.c:16835 handle_request_register: Registration from '"323826"<sip:323826@115.85.1.226>' failed for '199.19.111.221' - No matching peer found
[Sep 27 02:24:40] NOTICE[1571]: chan_sip.c:16835 handle_request_register: Registration from '"323827"<sip:323827@115.85.1.226>' failed for '199.19.111.221' - No matching peer found
[Sep 27 02:24:40] NOTICE[1571]: chan_sip.c:16835 handle_request_register: Registration from '"323828"<sip:323828@115.85.1.226>' failed for '199.19.111.221' - No matching peer found
[Sep 27 02:24:40] NOTICE[1571]: chan_sip.c:16835 handle_request_register: Registration from '"323829"<sip:323829@115.85.1.226>' failed for '199.19.111.221' - No matching peer found
[Sep 27 02:24:40] NOTICE[1571]: chan_sip.c:16835 handle_request_register: Registration from '"323830"<sip:323830@115.85.1.226>' failed for '199.19.111.221' - No matching peer found
[Sep 27 02:24:40] NOTICE[1571]: chan_sip.c:16835 handle_request_register: Registration from '"323831"<sip:323831@115.85.1.226>' failed for '199.19.111.221' - No matching peer found
[Sep 27 02:24:40] NOTICE[1571]: chan_sip.c:16835 handle_request_register: Registration from '"1004" <sip:1004@115.85.1.226>' failed for '199.19.111.221' - Wrong password
dbserver*CLI>

Re: what is this i saw??

PostPosted: Thu Sep 26, 2013 2:22 pm
by callcrazy
A script is most likely attempting to gain entry to your server to hack your system.

I run a script that checks the logs every minute for failed registrations then adds the IP to iptable reject list.

Intrusion detection is what you're looking for.

Re: what is this i saw??

PostPosted: Thu Sep 26, 2013 2:28 pm
by sigbinme
thank you so much callcrazy
im a newbie.
I'll try to read IPtable reject... is that the one that black the IP of the intruder
right?