On 06/10/2010 17:15, William Herrin wrote:
I had my unpublished asterisk box up for all of two days before
getting half a megabit per second worth of false SIP registration
attempts.

The script kiddies and botnets seem to by trying hard.

I started announcing a brand new RIR allocation about 4 days ago and decided to tcpdump the background noise on the prefix before it gets used in production. About 80% of the traffic is systematic scanning on port 5060 across the entire prefix.

--
Graham Beneke

Reply via email to