Hacked?

Hello

I think someone hacked my old asterisk :frowning: I supose Someone make unauthorized call to diffrent countries. I’d like know how he connect and what i should reconfigure in my asterisk. HAcker’s ip address is 113.105.152.x ? It’s not assigned by Ripe/Iana…

my logs:

[Feb 21 06:25:08] VERBOSE[2961] logger.c: Asterisk Queue Logger restarted
[Feb 21 06:25:08] VERBOSE[2961] logger.c: – Remote UNIX connection disconnected
[Feb 21 18:06:14] VERBOSE[3368] logger.c: – Executing [900442033844680@default:1] Dial(“SIP/113.105.152.104-0845ba08”, “SIP/integral_122984020/004420338
44680”) in new stack
[Feb 21 18:06:14] VERBOSE[3368] logger.c: – Called integral_122984020/00442033844680
[Feb 21 18:06:14] VERBOSE[2227] logger.c: – Got SIP response 482 “Loop Detected” back from 87.204.129.4
[Feb 21 18:06:14] VERBOSE[3368] logger.c: – Now forwarding SIP/113.105.152.104-0845ba08 to ‘Local/00442033844680@default’ (thanks to SIP/integral_122984
020-083bc758)
[Feb 21 18:06:14] NOTICE[3368] cdr.c: CDR on channel ‘SIP/integral_122984020-083bc758’ not posted
[Feb 21 18:06:14] VERBOSE[3369] logger.c: – Executing [00442033844680@default:1] Dial(“Local/00442033844680@default-59a6,2”, “SIP/audiocodes/00442033844
680||W”) in new stack
[Feb 21 18:06:14] VERBOSE[3369] logger.c: – Called audiocodes/00442033844680
[Feb 21 18:06:21] VERBOSE[3369] logger.c: – SIP/audiocodes-0824ed08 is ringing
[Feb 21 18:06:21] VERBOSE[3368] logger.c: – Local/00442033844680@default-59a6,1 is ringing
[Feb 21 18:06:21] VERBOSE[3369] logger.c: – SIP/audiocodes-0824ed08 answered Local/00442033844680@default-59a6,2
[Feb 21 18:06:21] VERBOSE[3368] logger.c: – Local/00442033844680@default-59a6,1 stopped sounds
[Feb 21 18:06:21] VERBOSE[3368] logger.c: – Local/00442033844680@default-59a6,1 answered SIP/113.105.152.104-0845ba08
[Feb 21 18:06:21] VERBOSE[3368] logger.c: – Packet2Packet bridging SIP/113.105.152.104-0845ba08 and SIP/audiocodes-0824ed08
[Feb 21 18:06:21] VERBOSE[3369] logger.c: == Spawn extension (default, 00442033844680, 1) exited non-zero on ‘Local/00442033844680@default-59a6,2’
[Feb 21 18:06:59] VERBOSE[3368] logger.c: == Spawn extension (default, 900442033844680, 1) exited non-zero on ‘SIP/113.105.152.104-0845ba08’
[Feb 21 18:10:19] VERBOSE[3378] logger.c: – Executing [0442033844680@default:1] Dial(“SIP/113.105.152.102-081faf88”, “SIP/audiocodes/0442033844680||W”)
in new stack
[Feb 21 18:10:19] VERBOSE[3378] logger.c: – Called audiocodes/0442033844680
[Feb 21 18:10:20] VERBOSE[3378] logger.c: – SIP/audiocodes-0880dc50 answered SIP/113.105.152.102-081faf88
[Feb 21 18:10:20] VERBOSE[3378] logger.c: – Packet2Packet bridging SIP/113.105.152.102-081faf88 and SIP/audiocodes-0880dc50
[Feb 21 18:10:50] VERBOSE[3378] logger.c: == Spawn extension (default, 0442033844680, 1) exited non-zero on ‘SIP/113.105.152.102-081faf88’
[Feb 21 18:45:33] VERBOSE[3390] logger.c: – Executing [00000442033844680@default:1] Dial(“SIP/113.105.152.103-087a76c8”, “SIP/audiocodes/000004420338446
80||W”) in new stack
[Feb 21 18:45:33] VERBOSE[3390] logger.c: – Called audiocodes/00000442033844680
[Feb 21 18:45:34] VERBOSE[3390] logger.c: – SIP/audiocodes-0880dc50 answered SIP/113.105.152.103-087a76c8
[Feb 21 18:45:34] VERBOSE[3390] logger.c: – Packet2Packet bridging SIP/113.105.152.103-087a76c8 and SIP/audiocodes-0880dc50
[Feb 21 18:46:04] VERBOSE[3390] logger.c: == Spawn extension (default, 00000442033844680, 1) exited non-zero on ‘SIP/113.105.152.103-087a76c8’
[Feb 21 21:20:32] VERBOSE[3440] logger.c: – Executing [0011442033844680@default:1] Dial(“SIP/113.105.152.102-0845ba08”, “SIP/audiocodes/0011442033844680
||W”) in new stack

sip.conf
allow=g729
[authentication]
canreinvite=no
disallow=all
domain=pbx.mobiwide.com
[general]
register=>122984020:1234qwer@test.integralnet.com/122984020
register=>122984021:1234qwer@test.integralnet.com/122984021
register=>122984022:1234qwer@test.integralnet.com/122984022
register=>122984023:1234qwer@test.integralnet.com/122984023
register=>122984024:1234qwer@test.integralnet.com/122984024
register=>122984025:1234qwer@test.integralnet.com/122984025
register=>122984026:1234qwer@test.integralnet.com/122984026
register=>122984027:1234qwer@test.integralnet.com/122984027
register=>122984028:1234qwer@test.integralnet.com/122984028
register=>122984029:1234qwer@test.integralnet.com/122984029

thank You for any advice

What is the setting of allowguest? See recent forum archives for more details.

Is this +442033844680 called by the intruder?

It were chinese boys,

  • i had allowguest to default ( yes) now i set to “no”
  • i filter out 5060, permit only for my sip provider

Yes it was this number:

[Feb 21 18:06:14] VERBOSE[3369] logger.c: – Called audiocodes/00442033844680
[Feb 21 18:06:21] VERBOSE[3368] logger.c: – Local/00442033844680@default-59a6,1 is ringing
[Feb 21 18:06:21] VERBOSE[3369] logger.c: – SIP/audiocodes-0824ed08 answered Local/00442033844680@default-59a6,2
[Feb 21 18:06:21] VERBOSE[3368] logger.c: – Local/00442033844680@default-59a6,1 stopped sounds
[Feb 21 18:06:21] VERBOSE[3368] logger.c: – Local/00442033844680@default-59a6,1 answered SIP/113.105.152.104-0845ba08
[Feb 21 18:06:21] VERBOSE[3369] logger.c: == Spawn extension (default, 00442033844680, 1) exited non-zero on ‘Local/00442033844680@default-59a6,2’
[Feb 21 18:06:59] VERBOSE[3368] logger.c: == Spawn extension (default, 900442033844680, 1) exited non-zero on ‘SIP/113.105.152.104-0845ba08’

LOL …, I just called the +442033844680 number and got a british female voice recording says Your account has been disabled, please contact customer service … I don’t suppose your action to block this number caused this. :smiley: