Forums Read-only archive

FYI: Block friendly-scanner and crawler

3 posts · Brekeke SIP Server Forum

lakeview Original post
1. Brekeke Product Name and Version:
Brekeke SIP Server ver3.2


Add following DialPlan rules in the [Dial Plan] -> [Preliminary] page.

---------------------------------------
[Matching Patterns]
$str.lowercase(User-Agent) = friendly-scanner|sundayddr

[Deploy Patterns]
$action = block


[Matching Patterns]
$str.lowercase(User-Agent) = sipcli

[Deploy Patterns]
$action = block
----------------------------------------

---------------------------------------
[Matching Patterns]
From = sipsscuser|sipvicious

[Deploy Patterns]
$action = block
----------------------------------------

---------------------------------------
[Matching Patterns]
$request = ^OPTIONS
From = sip:default@

[Deploy Patterns]
$action = block
----------------------------------------
mbylica
Hello,

Its fine. Besides Dial Plan i think good option is to setup iptables properly, of course if we are talking about wholesale voice traffic.
For class5 services good option is to use fail2ban.

Maciej.
Mike
The Block List has two plugin interfaces.
One is for querying to 3rd black list database.
Another is for notifying offending IP addresses to 3rd system in real-time.
This plugin interface will be used for updating "iptables".