fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

10K
active users

#apiban

0 posts0 participants0 posts today

Continued exploit of open relay REGISTER attack occurring, with increased activity over the last 12 hours. Most IP addresses have already been seen, and vast majority of systems (doing the relaying) are Ingate Systems (the SIParator SBC). No response from Ingate.

Help protect your systems with (apiban.org)-- a free service, thanks to our sponsors.

apiban.orgAPIBAN - 2024 year in reviewHappy New Year! Lets start 2025 off by looking at tha last year from an APIBAN point of view. The 2024 year in review.

Last night saw another round of open relay attacks. Most of the relaying appears to have been Ingate SIP Trunking Solutions' SIParator product.

APIBAN (apiban.org) is a free service (thanks to our sponsors) that you can implement on most *nix systems, some firewalls, etc to help protect yourself from these types of attacks.

For more information on SIP open relay attacks, there's a great article from Ivan Kwabena Nyarko:
kwancro.com/post/another-open-

apiban.orgAPIBAN - 2024 year in reviewHappy New Year! Lets start 2025 off by looking at tha last year from an APIBAN point of view. The 2024 year in review.

I really like the GitHub sponsor feature... nice, simple way to help an open source project you're using keep on keeping' on (as Joe Dirt would say).

For example. I love simplecss.com... and @kev made it easy to sponsor.

(By the way... you can sponsor if you're finding it helpful, or even if you're not... you can still sponsor)

Seeing a huge spike in REGISTER traffic attacking SIP servers out there. Many seem to be using Ingate SIParator SBC as an open relay.

APIBAN (apiban.org) is a free service to help protect you from these attacks.

Also, a good analysis of the last attack (written by Ivan Kwabena Nyarko) can be found here:
kwancro.com/post/another-open-

apiban.orgAPIBAN - 2024 year in reviewHappy New Year! Lets start 2025 off by looking at tha last year from an APIBAN point of view. The 2024 year in review.

A huge amount of unwanted / traffic coming out of Japan over the last few days. Since the 29th, over 2700 active ip addresses were added to the block list.

Some example networks:

122.214.163.128/25
122.219.179.0/25
59.87.14.0/25
122.219.179.128/25
58.13.250.128/25
59.87.50.0/25

If you're using , these have already been blocked. Not using APIBAN? Think again... it's free (thanks to our sponsors). apiban.org

apiban.orgAPIBAN - 2024 year in reviewHappy New Year! Lets start 2025 off by looking at tha last year from an APIBAN point of view. The 2024 year in review.