SIP Scanning and VoIP Security
A few months ago after I had setup my Asterisk box I started receiving strange calls from people in Colorado and started to check my call logs. I noticed that the night before someone had made calls from my box to many different numbers in succession. xxx-xxx-2401, xxx-xxx-2402, xxx-xxx-2403, etc. I knew that my box had been compromised.
I had set weak secrets for my extensions and they were able to brute the secret and start making calls from my machine. I immediately changed all the secrets and have not had a problem since, but this article will show you some tools that can be used to test your own box and some settings that should be changed in order to secure it.