[VoiceOps] Strange register attack

Colin zavoid at gmail.com
Thu Nov 25 22:02:26 EST 2010

Tonight i'm seeing hundreds of register attempts per second to one of my SBC's from an IP in china  

the From: and to: line is always  one of these 2 below.

\"118\" <sip:118 at my SBC IP>;    source port  5063
\"qwerty\" <sip:qwerty at my SBC IP>;  source port 5067

user-agent: friendly-scanner is always.

Looks like sipvicious default user agent. Anyone seen a register flood like this before?


More information about the VoiceOps mailing list