6 Oct
2010
6 Oct
'10
3:16 p.m.
On 06/10/2010 17:15, William Herrin wrote:
I had my unpublished asterisk box up for all of two days before getting half a megabit per second worth of false SIP registration attempts.
The script kiddies and botnets seem to by trying hard. I started announcing a brand new RIR allocation about 4 days ago and decided to tcpdump the background noise on the prefix before it gets used in production. About 80% of the traffic is systematic scanning on port 5060 across the entire prefix. -- Graham Beneke