Brekeke Forum Index » Brekeke SIP Server Forum

Post new topic   Reply to topic
FYI: Block friendly-scanner and crawler
Author Message
lakeview
Brekeke Master Guru


Joined: 15 Nov 2007
Posts: 319
Location: Florida

PostPosted: Mon Sep 23, 2013 3:55 pm    Post subject: FYI: Block friendly-scanner and crawler Reply with quote

1. Brekeke Product Name and Version:
Brekeke SIP Server ver3.2


Add following DialPlan rules in the [Dial Plan] -> [Preliminary] page.

Matching Patterns
$str.lowercase(User-Agent) = friendly-scanner|sundayddr
Deploy Patterns
$action = block


Matching Patterns
$str.lowercase(User-Agent) = sipcli
Deploy Patterns
$action = block


Matching Patterns
From = sipsscuser|sipvicious
Deploy Patterns
$action = block


Matching Patterns
$request = ^OPTIONS
From = sip:default@
Deploy Patterns
$action = block


Last edited by lakeview on Fri Oct 31, 2014 4:11 pm; edited 2 times in total
Back to top
View user's profile
mbylica
Brekeke Addict


Joined: 16 May 2011
Posts: 41
Location: Poland

PostPosted: Mon Sep 23, 2013 4:04 pm    Post subject: Reply with quote

Hello,

Its fine. Besides Dial Plan i think good option is to setup iptables properly, of course if we are talking about wholesale voice traffic.
For class5 services good option is to use fail2ban.

Maciej.
Back to top
View user's profile
Mike
Support Team


Joined: 07 Mar 2005
Posts: 731
Location: Sunny San Mateo

PostPosted: Tue Sep 24, 2013 7:04 pm    Post subject: Reply with quote

The Block List has two plugin interfaces.
One is for querying to 3rd black list database.
Another is for notifying offending IP addresses to 3rd system in real-time.
This plugin interface will be used for updating "iptables".
Back to top
View user's profile Visit poster's website
Display posts from previous:   
Post new topic   Reply to topic    Brekeke Forum Index » Brekeke SIP Server Forum All times are GMT - 7 Hours
Page 1 of 1