IP blacklist
IP Blacklist
This weekend a customer got victim of a fraud attack.
Damage sum is beyond € 10.000,- within one and a half day.
My I ask, how the IP blacklist feature
(Build '101072' - #118367: SIP: Blacklist for IP addresses to fight brute-force attacks following my feature request 113867 - This list is maintained automatically (hosts get on that list for a while if an invalid registration originated from there, even if they are part of the configurable registration white lists).
works and what it is good for, when
* one and the same attacker at address 212.129.49.53
* receives as many as 9734 REGISTER-REJ messages
* within the timeframe from 11.07.2015-01:46:03 to 12.07.2015-19:56:48
* that ist 30 hours
* giving an average of one failed register attempt every 10 secs
* and still receives 6 REGISTER-OKs,
* the first at 11.07.2015-08:10:57
* after almost 8 hours of constant brute force attack against the ip1060
* an still attackes after 30 hours ?
Isn't all that information enough, to clearly identify this IP-address as harmful and REALLY and EFFECTIVELY block it, ideally for eternity or at least until a manual intervention?
What about alarm entries and a Warning E-Mail whenever an IP Adress is blacklisted?
BTW, similar things happened within the same period of time, originating from the IP-Addresses 82.205.21.211 and 212.83.154.218
A good hint is to be found at http://stuffphilwrites.com/2013/03/permanently-ban-repeat-offenders-fail2ban/
Kurt Krenn
This weekend a customer got victim of a fraud attack.
Damage sum is beyond € 10.000,- within one and a half day.
My I ask, how the IP blacklist feature
(Build '101072' - #118367: SIP: Blacklist for IP addresses to fight brute-force attacks following my feature request 113867 - This list is maintained automatically (hosts get on that list for a while if an invalid registration originated from there, even if they are part of the configurable registration white lists).
works and what it is good for, when
* one and the same attacker at address 212.129.49.53
* receives as many as 9734 REGISTER-REJ messages
* within the timeframe from 11.07.2015-01:46:03 to 12.07.2015-19:56:48
* that ist 30 hours
* giving an average of one failed register attempt every 10 secs
* and still receives 6 REGISTER-OKs,
* the first at 11.07.2015-08:10:57
* after almost 8 hours of constant brute force attack against the ip1060
* an still attackes after 30 hours ?
Isn't all that information enough, to clearly identify this IP-address as harmful and REALLY and EFFECTIVELY block it, ideally for eternity or at least until a manual intervention?
What about alarm entries and a Warning E-Mail whenever an IP Adress is blacklisted?
BTW, similar things happened within the same period of time, originating from the IP-Addresses 82.205.21.211 and 212.83.154.218
A good hint is to be found at http://stuffphilwrites.com/2013/03/permanently-ban-repeat-offenders-fail2ban/
Kurt Krenn