IP PBX Elastix для начинающих.Часть 17

Feb 20, 2013 09:27

FRAUD на VOIP сетях.Слив голосового трафика на Premium rate номера .Правила защиты Elastix от взлома.

По данным международной ассоциации COMMUNICATIONS FRAUD CONTROL ASSOCIATION  за 2011 - отраслевые потери от фрода в мире -- $ 40.1 миллиардов  , или 1,88 % общих доходов.
Из этих 40 миллиардов, 3 миллиарда приходится на потери связанные со ( Read more... )

защита Elastix от взлома

Leave a comment

fail2ban mapcuk666 July 17 2013, 03:41:31 UTC
не блокируется не отправляет письмо на почту в логах fail2ban нету

Reply

Re: fail2ban icluzo July 17 2013, 03:46:01 UTC
iptables может не запущена
service iptables stop
ок выдает ?

Reply

Re: fail2ban mapcuk666 July 17 2013, 04:25:11 UTC
все ok выдал что дальше?

Reply

Re: fail2ban icluzo July 17 2013, 04:26:29 UTC
запустить обратно и конфиги показать fail2ban a

Reply

Re: fail2ban mapcuk666 July 17 2013, 04:40:11 UTC
# Fail2Ban configuration file
#
#
# $Revision: 251 $
#
[INCLUDES]
# Read common prefixes. If any customizations available -- read them from
# common.local
before = common.conf
[Definition]
#_daemon = asterisk
# Option: failregex
# Notes.: regex to match the password failures messages in the logfile. The
# host must be matched by a group named "host". The tag "" can
# be used for standard IP/hostname matching and is only an alias for
# (?:::f{4,6}:)?(?P\S+)
# Values: TEXT
#
# Asterisk 1.8 uses Host:Port format which is reflected here
failregex = NOTICE.* .*: Registration from '.*' failed for ':.*' - Wrong password
NOTICE.* .*: Registration from '.*' failed for ':.*' - No matching peer found
NOTICE.* .*: Registration from '.*' failed for ':.*' - No matching peer found
NOTICE.* .*: Registration from '.*' failed for ':.*' - Username/auth name mismatch
NOTICE.* .*: Registration from '.*' failed for ':.*' - Device does not match ACL ( ... )

Reply

Re: fail2ban mapcuk666 July 17 2013, 04:40:54 UTC
[asterisk-iptables]
enabled = true
filter = asterisk
action = iptables-allports[name=ASTERISK, protocol=all]
sendmail-whois[name=ASTERISK,dest=ваш_емаил_куда_слать_сообщения_о_бане, sender=fail2ban@local]
logpath = /var/log/asterisk/full
maxretry = 3
bantime = 600

Reply

Re: fail2ban icluzo July 17 2013, 04:45:16 UTC
/etc/init.d/fail2ban status

Reply

Re: fail2ban mapcuk666 July 17 2013, 04:49:12 UTC
number of juil 3
jail list ssh-iptables asterisk-iptables named-refuse-tcp

Reply


Leave a comment

Up