<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Asterisk PBX Hack Attack (or, how scammers hijacked my phone system to place unauthorized calls)</title>
	<atom:link href="http://deepliquid.com/blog/archives/19/feed" rel="self" type="application/rss+xml" />
	<link>http://deepliquid.com/blog/archives/19</link>
	<description>Just another WordPress weblog</description>
	<pubDate>Wed, 10 Mar 2010 17:39:16 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: RaiulBaztepo</title>
		<link>http://deepliquid.com/blog/archives/19/comment-page-1#comment-6730</link>
		<dc:creator>RaiulBaztepo</dc:creator>
		<pubDate>Sun, 29 Mar 2009 06:45:31 +0000</pubDate>
		<guid isPermaLink="false">http://deepliquid.com/blog/?p=19#comment-6730</guid>
		<description>Hello!
Very Interesting post! Thank you for such interesting resource! 
PS: Sorry for my bad english, I'v just started to learn this language ;)
See you! 
Your, Raiul Baztepo</description>
		<content:encoded><![CDATA[<p>Hello!<br />
Very Interesting post! Thank you for such interesting resource!<br />
PS: Sorry for my bad english, I&#8217;v just started to learn this language ;)<br />
See you!<br />
Your, Raiul Baztepo</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CocoonEx VOIP Service &#187; Blog Archive &#187; SIP HACKING&#8230;</title>
		<link>http://deepliquid.com/blog/archives/19/comment-page-1#comment-305</link>
		<dc:creator>CocoonEx VOIP Service &#187; Blog Archive &#187; SIP HACKING&#8230;</dc:creator>
		<pubDate>Wed, 12 Nov 2008 03:51:16 +0000</pubDate>
		<guid isPermaLink="false">http://deepliquid.com/blog/?p=19#comment-305</guid>
		<description>[...] http://deepliquid.com/blog/archives/19 [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://deepliquid.com/blog/archives/19" rel="nofollow">http://deepliquid.com/blog/archives/19</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://deepliquid.com/blog/archives/19/comment-page-1#comment-36</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Wed, 01 Oct 2008 16:43:16 +0000</pubDate>
		<guid isPermaLink="false">http://deepliquid.com/blog/?p=19#comment-36</guid>
		<description>Thanks for posting your experiences. I did not contact abuse, but I also had no idea that this IP would be in business for so long.

I've been consistently getting hits from people searching for that IP address, so this guy is prolific. I saw the IP address when so many calls were being placed, many were failing, and the IP address was in the error messages. (I did also subsequently see it in sip show peers.)

These servers don't *appear* to be in the same location as mine, for whatever good geoIP lookup services are.</description>
		<content:encoded><![CDATA[<p>Thanks for posting your experiences. I did not contact abuse, but I also had no idea that this IP would be in business for so long.</p>
<p>I&#8217;ve been consistently getting hits from people searching for that IP address, so this guy is prolific. I saw the IP address when so many calls were being placed, many were failing, and the IP address was in the error messages. (I did also subsequently see it in sip show peers.)</p>
<p>These servers don&#8217;t *appear* to be in the same location as mine, for whatever good geoIP lookup services are.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marco</title>
		<link>http://deepliquid.com/blog/archives/19/comment-page-1#comment-35</link>
		<dc:creator>Marco</dc:creator>
		<pubDate>Wed, 01 Oct 2008 16:03:38 +0000</pubDate>
		<guid isPermaLink="false">http://deepliquid.com/blog/?p=19#comment-35</guid>
		<description>The same people abused my asterisk box, found it out after getting some calls from people, and from not being able to dial out. 

Found out that they were also using an extension which wasn't used. I changed the passwords, and it got quiet. They were making about 10 calls a minute, I think I found it out fast enough.

Found their IP by using 'sip show peers', was easy to spot.

Where is your server located? Mine is in the same datacenter as the box abusing my box, which makes things a little bit more 'fishy', I have a feeling they might have used sniffers. But that's just a guess right now.

I did file it with abuse@theplanet.com, so hopefully something will come out of it.</description>
		<content:encoded><![CDATA[<p>The same people abused my asterisk box, found it out after getting some calls from people, and from not being able to dial out. </p>
<p>Found out that they were also using an extension which wasn&#8217;t used. I changed the passwords, and it got quiet. They were making about 10 calls a minute, I think I found it out fast enough.</p>
<p>Found their IP by using &#8217;sip show peers&#8217;, was easy to spot.</p>
<p>Where is your server located? Mine is in the same datacenter as the box abusing my box, which makes things a little bit more &#8216;fishy&#8217;, I have a feeling they might have used sniffers. But that&#8217;s just a guess right now.</p>
<p>I did file it with <a href="mailto:abuse@theplanet.com">abuse@theplanet.com</a>, so hopefully something will come out of it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Luke</title>
		<link>http://deepliquid.com/blog/archives/19/comment-page-1#comment-31</link>
		<dc:creator>Luke</dc:creator>
		<pubDate>Sat, 27 Sep 2008 15:45:35 +0000</pubDate>
		<guid isPermaLink="false">http://deepliquid.com/blog/?p=19#comment-31</guid>
		<description>Hi there, Thank you for posting this to your blog, did you by chance contact the abuse?

OrgAbuseHandle: ABUSE271-ARIN
OrgAbuseName:   The Planet Abuse 
OrgAbusePhone:  +1-281-714-3560
OrgAbuseEmail:  abuse@theplanet.com
216.40.234.82

I was happy I was able to Google your blog with the IP address, this server still seems to be doing the same old thing.. I had a couple extensions myself that were insecure and same deal.. I initially though it was another application but after about an 2 hours figured it out.  I disabled my trunks during debugging.  They got about 500 calls in early this morning.  5am on..</description>
		<content:encoded><![CDATA[<p>Hi there, Thank you for posting this to your blog, did you by chance contact the abuse?</p>
<p>OrgAbuseHandle: ABUSE271-ARIN<br />
OrgAbuseName:   The Planet Abuse<br />
OrgAbusePhone:  +1-281-714-3560<br />
OrgAbuseEmail:  <a href="mailto:abuse@theplanet.com">abuse@theplanet.com</a><br />
216.40.234.82</p>
<p>I was happy I was able to Google your blog with the IP address, this server still seems to be doing the same old thing.. I had a couple extensions myself that were insecure and same deal.. I initially though it was another application but after about an 2 hours figured it out.  I disabled my trunks during debugging.  They got about 500 calls in early this morning.  5am on..</p>
]]></content:encoded>
	</item>
</channel>
</rss>
