Click Here To Visit SIP Broker  

Go Back   Voxalot / SIP Broker Support Forums > Voxalot Forums > Voxalot Support

Voxalot Support Support for the Voxalot service.

 
 
Reply
Thread Tools Display Modes
Unread 08-07-2007, 01:54 PM   #1
cpiga
Junior Member
 
Join Date: Aug 2007
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
cpiga is on a distinguished road
Default Security question.

This is a decoded ethernet frame sniffed from my ATA ethernet port:

Session Initiation Protocol
Status-Line: SIP/2.0 401 Unauthorized
Status-Code: 401
[Resent Packet: False]
Message Header
Via: SIP/2.0/UDP 192.168.10.71:5060;branch=z9hG4bK-a7ff22d5;rport=61264;received=89.149.202.61
Transport: UDP
Sent-by Address: 192.168.10.71
Sent-by port: 5060
Branch: z9hG4bK-a7ff22d5
RPort: 61264
Received: 89.149.202.61
From: Carlo <sip:2531**@64.34.173.199>;tag=7083ccabd59256aao 0
SIP Display info: Carlo
SIP from address: sip:2531**@64.34.173.199
SIP tag: 7083ccabd59256aao0
To: Carlo <sip:253104@64.34.173.199>;tag=c71e87f21af06a79a7f 28931077856d8.9273
SIP Display info: Carlo
SIP to address: sip:253104@64.34.173.199
SIP tag: c71e87f21af06a79a7f28931077856d8.9273
Call-ID: 3f043792-35d31042@192.168.*.*
CSeq: 36698 REGISTER
Sequence Number: 36698
Method: REGISTER
WWW-Authenticate: Digest realm="voxalot.com", nonce="46b86fcda130483fdea9a19e65a1dab74a04243e", stale=true
Authentication Scheme: Digest
Realm: "voxalot.com"
Nonce Value: "46b86fcda130483fdea9a19e65a1dab74a04243e"
Stale Flag: true
Server: OpenSer (1.1.0-notls (i386/linux))
Content-Length: 0
Warning: 392 64.34.173.199:5060 "Noisy feedback tells: pid=14861 req_src_ip=89.149.202.61 req_src_port=61264 in_uri=sip:64.34.173.199 out_uri=sip:64.34.173.199 via_cnt==1"

In the last line there is the source ip 89.149.202.61, it isn't my pubblic ip address, and a dns lookup tells:

61.202.149.89.in-addr.arpa. 41061 IN PTR 89-149-202-61.internetserviceteam.com.

There is someone registering to my voxalot account from that address??!!??
cpiga is offline   Reply With Quote
Unread 08-07-2007, 02:19 PM   #2
martin
 
Join Date: Feb 2006
Posts: 2,930
Thanks: 528
Thanked 646 Times in 340 Posts
martin is a jewel in the roughmartin is a jewel in the roughmartin is a jewel in the roughmartin is a jewel in the roughmartin is a jewel in the roughmartin is a jewel in the rough
Default

Questions:

1. Are you Carlo?
2. Is 192.168.10.71 your internal IP address?

Quote:
Originally Posted by cpiga View Post
This is a decoded ethernet frame sniffed from my ATA ethernet port:

Session Initiation Protocol
Status-Line: SIP/2.0 401 Unauthorized
Status-Code: 401
[Resent Packet: False]
Message Header
Via: SIP/2.0/UDP 192.168.10.71:5060;branch=z9hG4bK-a7ff22d5;rport=61264;received=89.149.202.61
Transport: UDP
Sent-by Address: 192.168.10.71
Sent-by port: 5060
Branch: z9hG4bK-a7ff22d5
RPort: 61264
Received: 89.149.202.61
From: Carlo <sip:2531**@64.34.173.199>;tag=7083ccabd59256aao 0
SIP Display info: Carlo
SIP from address: sip:2531**@64.34.173.199
SIP tag: 7083ccabd59256aao0
To: Carlo <sip:253104@64.34.173.199>;tag=c71e87f21af06a79a7f 28931077856d8.9273
SIP Display info: Carlo
SIP to address: sip:253104@64.34.173.199
SIP tag: c71e87f21af06a79a7f28931077856d8.9273
Call-ID: 3f043792-35d31042@192.168.*.*
CSeq: 36698 REGISTER
Sequence Number: 36698
Method: REGISTER
WWW-Authenticate: Digest realm="voxalot.com", nonce="46b86fcda130483fdea9a19e65a1dab74a04243e", stale=true
Authentication Scheme: Digest
Realm: "voxalot.com"
Nonce Value: "46b86fcda130483fdea9a19e65a1dab74a04243e"
Stale Flag: true
Server: OpenSer (1.1.0-notls (i386/linux))
Content-Length: 0
Warning: 392 64.34.173.199:5060 "Noisy feedback tells: pid=14861 req_src_ip=89.149.202.61 req_src_port=61264 in_uri=sip:64.34.173.199 out_uri=sip:64.34.173.199 via_cnt==1"

In the last line there is the source ip 89.149.202.61, it isn't my pubblic ip address, and a dns lookup tells:

61.202.149.89.in-addr.arpa. 41061 IN PTR 89-149-202-61.internetserviceteam.com.

There is someone registering to my voxalot account from that address??!!??
__________________
Martin

Please post support questions on the forum. Do not send PMs unless requested.
martin is offline   Reply With Quote
Unread 08-07-2007, 02:32 PM   #3
cpiga
Junior Member
 
Join Date: Aug 2007
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
cpiga is on a distinguished road
Default

Quote:
Originally Posted by martin View Post
Questions:

1. Are you Carlo?
2. Is 192.168.10.71 your internal IP address?
Yes I'm Carlo and 192.168.10.71 is my internal ip address, but my external address isn't the other one.
cpiga is offline   Reply With Quote
Unread 08-07-2007, 02:39 PM   #4
martin
 
Join Date: Feb 2006
Posts: 2,930
Thanks: 528
Thanked 646 Times in 340 Posts
martin is a jewel in the roughmartin is a jewel in the roughmartin is a jewel in the roughmartin is a jewel in the roughmartin is a jewel in the roughmartin is a jewel in the rough
Default

Quote:
Originally Posted by cpiga View Post
Yes I'm Carlo and 192.168.10.71 is my internal ip address, but my external address isn't the other one.
A traceroute to your IP address goes via the 89.149.*.* subnet. I suspect our NAT handling logic is deriving this address.
.
__________________
Martin

Please post support questions on the forum. Do not send PMs unless requested.
martin is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
A question about voice stream route using web callback? hust Voxalot Support 1 05-02-2007 08:03 AM
voicemail question jmstosch Voxalot Support 1 04-02-2007 10:37 PM


All times are GMT. The time now is 10:05 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.