6 ms·
They are probably trying to reduce SIP abuse. It's a big problem.
by _wldu 4y ago
They are probably trying to reduce SIP abuse. It's a big problem.
- josephcsible 4y agoThat doesn't make what they're doing okay. To see why, imagine that they instead blocked access to all email services except their own, since spam is a big problem.
- Gordonjcp 4y agoThat's basically what domestic ISPs do. You will probably find that outbound traffic on port 25 is blocked, because all of your pwn3d inadequately-patched Windows machines are spam cannons now.
- bombcar 4y agoYep - some block it so hard you have to use other ports to communicate with offsite mail servers (and why various other ports are found, now). Some ISPs will remove the block if you ask.
- chrismeller 4y agoI’ve come to treat residential ISPs as basically a transit for HTTP. As someone else in the thread pointed out that’s all that 99.99% of customers care about, and unfortunately you’re talking about a lowest common denominator here.
- im3w1l 4y agoAnd this is (one of the reasons) why you should design modern protocols to use https as transport layer.
- nousermane 4y agoAh, yes. The classic "all our customers are morons" approach, with no opt-out for those 0.1% who, in fact, are not. Very typical among ISPs/Telcos. Where I am, we used to have a different, "nerdy" ISP [0], where customer was allowed to bring their own modem; they also provided real IPv4/v6 dual-stack since forever, easy to request a /29, tech-support that's realistic to reach, and staffed with people who know what they are talking about, no bulk-firewalling port-25, etc... All for a modest 2x price increase over market average. Alas, they're out of business now. [0] https://en.wikipedia.org/wiki/Xs4all https://en.wikipedia.org/wiki/Xs4all
- kmeisthax 4y agoThe opt-out is buy business-class service[0]. My guess is that the 2x price increase Xs4all was charging for their plan was a bridge too far for most customers. It's important to keep in mind that the vast majority of people rent their modem, don't know or care what a /29 is, and is calling tech support because the plug is loose or the modem needs a power cycle. Bulk-blocking SMTP happened because open ports are botnet ports, and the average customer does not know how to identify and shut down zombies on their network. [0] Assuming your provider isn't stupidly committed to "you can't have business class because you're in a residential area, WFH doesn't exist, and the zoning code is gospel, all hail Robert Moses"
- deleted 4y ago[deleted]
- bitwize 4y agoI still get emails from Comcrap because once I had a business internet plan with them in a residential area -- an apartment no less. When it comes to internet service, "giving a crap about the customer" is a premium add-on from Comcast, but once you commit to opening your wallet for that, they do deliver.
- voidwtf 4y agoWhat Comcast did you do business with? Comcast doesn’t give a crap about customers, full stop. Oh yes, they’ll send “technicians” out 3 to 4 times a month to tell you everything tested perfectly. But get them to put a line monitor on your connection, provide them logs that you have over 5% packet loss that doesn’t start until after the CMTS, and they’ll get an “engineer” involved who will come out and leave some testing equipment which will confirm the issue. Over a year later, the issue will remain unresolved. My aunt bought a house where, at the best of times, her kids can finish a game with only a handful of disconnects. The other 20% of the time they can’t even watch Netflix or streaming sports. They tried the “business connection” trick already, at a cost of $300 a month for 150mbps. That didn’t improve anything. The “investigation” remains open, and the “engineer” just doesn’t bother updating them anymore. My cousin went door-to-door only to discover the whole neighborhood is having the same types of issues. It’s just the new normal.
- 3np 4y agoYou mean mass spam calling? Or what kind of abuse?
- kkielhofner 4y agoGlad this is at the top. The linked Reddit thread demonstrates a common but fundamental misunderstanding of SIP. Port 5060 is used for call control and is very low traffic. At most you may have timed OPTIONS messages but a “standard” SIP deployment is at most a handful of (small) packets per second per call setup and tear down with occasional REGISTER messages on an interval measured in seconds. Very low traffic and very low bandwidth. Obviously with more devices you get multiples of these numbers but still very low. 15 kbps is a pretty significant amount of SIP traffic. This is most likely targeting VoIP abuse from tools like sipvicious. In a nutshell they scan the internet looking for open SIP ports. They then try to brute force credentials to place calls. Why? Toll fraud. The scam works like this: 1) Setup an international toll charge number in some country. Let’s say it charges $5/min. For those that don’t know calls to these numbers get charged to the person placing the call from their phone company and end up on their phone bill with the amount getting paid out (less a cut) to the operator of the number. 2) Compromise a bunch of random exposed SIP implementations on the internet. 3) Place calls to your (or a partners) toll number. 4) Get paid from the toll charges. 5) Some time later the owner of the compromised system gets a huge bill depending on fraud detection systems at the carrier, how fast you could pump calls, etc. It’s gotten so bad many VoIP providers block international calls by default and now (apparently) might be blocking 5060 traffic in some way. This isn’t that different to what’s happened with SMTP over the years. To combat spam many last mile ISPs started blocking outbound TCP port 25 so compromised machines couldn’t directly send spam. This is where port 465/587 for SMTP “submission” came from.
- deleted 4y ago[deleted]
- TheWoodsy 4y agoPerfect example of one of the many SIP abuses I have personally seen here in Australia. Don't get me started on the bajillion 3G+ modems here with default passwords.
- devwastaken 4y agoNot the ISP's responsibility.
- megous 4y agoYeah, running SIP on a standard port without some serious firewall based rate limiting for unknown traffic is almost impossible. I tried running a PBX on UDP 5060 and got >4GiB of logged register attempts in a few hours after opening the port, while asterisk was running at 100% CPU just rejecting the registration attempts the whole time. It's insane compared to any other public service I run.
- kkielhofner 4y agoHave you tried fail2ban[0]? It can take log output from Asterisk and automatically insert iptables DROP rules for the source IP to block the traffic in the kernel. It still shows up on your interface and uses your bandwidth but dropping the packet in the kernel is much more efficient than Asterisk dealing with it (not to mention safer). It should also cause the bad actor to eventually give up on you and move elsewhere. [0] - https://github.com/fail2ban/fail2ban/ https://github.com/fail2ban/fail2ban/
- deleted 4y ago[deleted]
- blablablub 4y agoIf you use fail2ban and asterisk you will probably have to rewrite the asterisk regex rules in fail2ban. Not a big thing, but it will probably not work out of the box.
- megous 4y agoNo, I rate limit everything by default (per IP address, via a few nftables rules), until the user logs in, at which point I add the IP address to a whitelist. I also run SIP on non-default port and use SRV records to point the client to the right port. Helps with blind IP scans. I don't really like the fail2ban approach.
- another_comment 4y agoI'm not running my own service. I'm using www.iptel.org, they offer a free sip account. Under the hood they use the Kamailio sip server. It is pretty darn reliable for a free service. Every few months iptel.org goes down for a few hours and I get 408 request timeouts. When Spectrum blocked 5060 UDP, I got 408 request timeouts for a week. It finally dawned on me to try my iptel account on my VPS and my SIP register succeeded. That's when I knew Spectrum had shut 5060 UDP. I tried 5060 TCP and that didn't work either.
- im3w1l 4y agoIt doesn't fit. The reddit thread describes inbound traffic being rate limited. But SIP abuse would be outbound traffic.