Displaying 20 results from an estimated 100 matches similar to: "Strange happenings"
2012 Nov 29
1
Hacked by Microsoft?
This morning someone tried to make sip call through my Asterisk. My
server just drop these calls and record them in CDR with IP address:
2012-11-28 06:30:51 SIP/216... 1000 "1000" <1000> Hangup
999011972592249388 ANSWERED 00:01 Hacker: 168.63.67.239
2. 2012-11-28 06:30:49 SIP/216... 1000 "1000" <1000> Hangup
88011972592249388 ANSWERED 00:01 Hacker:
2017 Dec 30
4
SIP invite timeouts : how is someone sending invites from our server ??
I've been getting a lot of timeouts on non-critical invite transactions.
I turned on sip debug. They were the result of SIP invites like this:
Retransmitting #10 (NAT) to 185.107.94.10:13057:
SIP/2.0 401 Unauthorized
Via: SIP/2.0/UDP
215.45.145.211:5060;branch=z9hG4bK-524287-1---zg4cfkl50hpwpv4p;received=185.107.94.10;rport=13057
From:
2018 Jan 02
2
SIP invite timeouts : how is someone sending invites from our server ??
On 12/30/2017 08:18 PM, Dovid Bender wrote:
> Script kiddies trying to find vulnerable systems that they can make
> calls on. Lock down the box with iptables and use fail2ban to block
> them. The via is probably bogus unless a box at the DoD was comprimised.
>
>
>
> On Sat, Dec 30, 2017 at 6:49 PM, sean darcy <seandarcy2 at gmail.com
> <mailto:seandarcy2 at
2010 Sep 09
1
URL error when trying to use help function in R [Sec: UNOFFICIAL]
Greetings,
I am using R version 2.11.1 on a Dell computer, via a VMware connection to a remote server. My browser version is IE 8.0.6001.18702 and the OS is some corporate version of Microsoft XP.
I'm trying to learn more about the tapply function , so I typed ?tapply into the command line. This opened up a browser window with url http://127.0.0.1:28138/library/base/html/tapply.html which is
2019 Nov 22
2
sendmail on Centos 7.7
On Fri, 2019-11-22 at 10:55 -0500, Stephen John Smoogen wrote:
> [smooge at smoogen-laptop ~]$ host -t MX smtp-relay.gmail.com.com
> smtp-relay.gmail.com.com mail is handled by 10 mx203.inbound-mx.org.
> smtp-relay.gmail.com.com mail is handled by 10 mx203.inbound-mx.net.
.w smtp-relay.gmail.com.com
smtp-relay.gmail.com.com has address 79.124.78.105
smtp-relay.gmail.com.com has address
2019 Nov 22
0
sendmail on Centos 7.7
and, of course...
$ host smtp-relay.gmail.com
smtp-relay.gmail.com has address 74.125.142.28
smtp-relay.gmail.com has IPv6 address 2607:f8b0:400e:c08::1c
$ whois 74.125.142.28
...
NetRange: 74.125.0.0 - 74.125.255.255
CIDR: 74.125.0.0/16
NetName: GOOGLE
NetHandle: NET-74-125-0-0-1
Parent: NET74 (NET-74-0-0-0-0)
NetType: Direct Allocation
OriginAS:
2004 Jul 05
3
Randy Bush is a destructive force with a hidden professional agenda
. Monday, July 5, 2004
15:50:06 (-08:00hrs UTC)
Hello asterisk-users,
From the following post:
On Mon, 5 Jul 2004, Joe Baptista wrote:
> On Mon, 5 Jul 2004, Randy Bush wrote:
>> i did not criticize the protocol. remember, my question started
>> with
>>
>> >> i am looking at iax to
2014 Dec 03
5
partedmagic connecting to a comcast address
i have been noticing a short connection burst in system monitor every
time i connect to internet.
i got curious and decided to run wireshark to see what was happening.
seems that i am connecting to 96.195.141.178 with destination of
"PartedMagic".
this seemed strange because i do not have PartedMagic installed, so
i ran a 'whois' check.
this is what it showed:
IP Location
2014 Dec 03
0
partedmagic connecting to a comcast address
On Wed, Dec 3, 2014 at 5:49 AM, g <geleem at bellsouth.net> wrote:
> i have been noticing a short connection burst in system monitor every
> time i connect to internet.
>
> i got curious and decided to run wireshark to see what was happening.
>
> seems that i am connecting to 96.195.141.178 with destination of
> "PartedMagic".
>
> this seemed strange
2007 Jun 01
2
how to specify starting values in varIdent() of lme()
I was reading the help but just did not get how to specify starting values for
varIdent() of the lme() function, although I managed to do it for corSymm().
Do I specify the values just as they are printed out in an output, like c(1,
1.3473, 1.0195). Or do I need to take the residual and multiply it with these
like c(0.2235, 0.2235*1.3473, 0.2235*1.0195)
or any other form that I dont know of?
2005 Apr 06
8
What is this Very Stupid DOS Attack Script?
We have been noticing flurries of sshd reject messages in
which some system out there in the hinterlands hits us with a flood of
ssh login attempts. An example:
Apr 6 05:41:51 dc sshd[88763]: Did not receive identification
string from 67.19.58.170
Apr 6 05:49:42 dc sshd[12389]: input_userauth_request: illegal
user anonymous
Apr 6 05:49:42 dc sshd[12389]: Failed password for illegal user
2009 Aug 11
4
func_odbc insert with mssql
I'm trying to use func_odbc to write to a MS SQL db.
Here's my func_odbc conf:
[OPTIN]
dsn=MSSQL-Optin
write=INSERT into OptIn (orgID) values (${VAL1})
Dial Plan
exten => +18665551212,n,Set(ODBC_OPTIN()=dave)
When I do an odbc show, it shows that I am connected to the db. If I use isql, I can write to the db, however, when I use func_odbc, a record will not write. I'm using
2010 Apr 10
10
Being attacked by an Amazon EC2 ...
Just a "heads-up" ... my home asterisk server is being flooded by someone
from IP 184.73.17.150 which is an Amazon EC2 instance by the looks of it -
they're trying to send SIP subscribes to one account - and they're
flooding the requests in - it's averaging some 600Kbits/sec of incoming
UDP data or about 200 a second )-:
This is much worse than anything else I've
2007 Apr 24
1
dundi problem * 1.4.2
Hi All,
I've been banging my head on a small dundi problem...
I have two * servers setup, both have almost identical dundi.conf files:
root@tsjonge:/opt/asterisk/etc# cat dundi.conf
[general]
department=thuis
organization=pipsworld
locality=Amsterdam
stateprov=NH
country=NL
email=remco@pipsworld.nl
phone=+31207508308
;bindaddr=0.0.0.0
;port=4520
entity=00:02:b3:49:69:5e
ttl=16
2008 Feb 24
2
DUNDi with two servers
Hi,
I'm having difficulties with using DUNDi between two servers. If it were
three I think I could control looping by limiting TTL, but with two I'm not
sure how to prevent a loop causing bad things to happen. I've tried ttl=1
but things still blow up.
The DUNDi configurations are pretty simple and work just fine in both
directions as long as only one of them is using the switch
2011 Aug 15
0
1.4.38 passing a Regular expression containing a pipe character to a macro ?
Howdy,
I'm working on a macro that authenticates the calling extension against a
list of allowed extensions but it looks like the Expression I'm attempting
to send of pipe separated extensions is showing up as additional arguments
to my macro.
I expected to have 4 arguments to the below macro, Instead it looks like I'm
actually getting 6.
I'm open to suggestions to other ways
2019 Apr 11
1
Tinc sudden spike in traffic usage
I just encountered a weird issue on my servers - Tinc was using a constant
10-50% CPU on several servers, and these servers were also receiving a
constant ~3 Mb/s of data over the Tinc interface, which is usually
otherwise pretty quiet.
Example: https://d.sb/2019/04/firefox_11-15.54.22.png
Grafana dashboard:
https://dash.d.sb/dashboard/snapshot/6nWZqagpgxzxUrybDZkNbF6JSflLlKmO?orgId=1
This seems
2008 Jul 12
1
a warning message from lmer
Hi all,
I have a problem when running lmer.
In my data set, Agree is a binary(0/1) response. WalkerID and ObsID is
the identification number of the subjects. the description of the
other variables are as follows:
> levels(regdat$Display)
[1] "Dynamic" "Static"
> levels(regdat$Survey)
[1] "HM1_A" "HM1_B" "HM1_C" "HM2_A"
2020 Feb 25
0
Replication failing with Win 2012 R2 (maybe)
Hello All,
WIndows DC reports (not for the entire directory, just a portion. See outputs below).
"The replication operation failed because of a schema mismatch between the servers involved.?
I suspect the error is a red herring.
Running several Samba DCs at multiple sites.
Version 4.11.6-Debian from Louis?s repo (on Ubuntu 18)
?vdcw00? is the Windows 2012 R2 server
?cdcx15? is the Samba
2005 Mar 04
9
strange behaviour with rulesets
hi,
i have a strange situtation. i try to connect to my machine with ssh and
the packets are dropped but i have at the top of my rules an accept.
the configuration looks like:
rules-file:
-----------
ACCEPT net fw tcp 22 -
TCPDUMP-log:
------------
12:16:08.153934 84.153.98.30.1322 > [my-destination-machine].ssh: S
3717288415:3717288415(0) win 64240 <mss