<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: SIP scanning causes DDoS on IP 1.1.1.1</title>
	<atom:link href="http://www.usken.no/2010/02/sip-scanning-causes-ddos-on-ip-1-1-1-1/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.usken.no/2010/02/sip-scanning-causes-ddos-on-ip-1-1-1-1/</link>
	<description>VoIP news for VoIP people!</description>
	<lastBuildDate>Mon, 06 Sep 2010 11:10:08 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: sjur</title>
		<link>http://www.usken.no/2010/02/sip-scanning-causes-ddos-on-ip-1-1-1-1/comment-page-1/#comment-289</link>
		<dc:creator>sjur</dc:creator>
		<pubDate>Wed, 10 Feb 2010 19:09:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.usken.no/?p=331#comment-289</guid>
		<description>I saw 209.239.120.27 (SERVER4YOU) hit on the 31sth of January. They are probably scanning the whole IPv4 spectrum...  not the others... So if you have not secured your IP PBX now, there is no hiding...</description>
		<content:encoded><![CDATA[<p>I saw 209.239.120.27 (SERVER4YOU) hit on the 31sth of January. They are probably scanning the whole IPv4 spectrum&#8230;  not the others&#8230; So if you have not secured your IP PBX now, there is no hiding&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Coward Anonymously</title>
		<link>http://www.usken.no/2010/02/sip-scanning-causes-ddos-on-ip-1-1-1-1/comment-page-1/#comment-288</link>
		<dc:creator>Coward Anonymously</dc:creator>
		<pubDate>Wed, 10 Feb 2010 18:45:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.usken.no/?p=331#comment-288</guid>
		<description>I scanned all my netflows from March 2008 to present and found that on Feb 2nd and Feb 3rd 2010, my net was hit repeatedly on from 75.101.219.28 (Amazon-AES).  AFAIK, no one was running a SIP server on my net, so I didn&#039;t see any spray to 1.1.1.1.
209.239.120.27 (SERVER4YOU) hit my net on Jan 30 2010. 122.146.174.3 (NCIC-TW New Century InfoComm Tech Co., Ltd.) hit once on Jan 20th.  All other hits are over a year old.</description>
		<content:encoded><![CDATA[<p>I scanned all my netflows from March 2008 to present and found that on Feb 2nd and Feb 3rd 2010, my net was hit repeatedly on from 75.101.219.28 (Amazon-AES).  AFAIK, no one was running a SIP server on my net, so I didn&#8217;t see any spray to 1.1.1.1.<br />
209.239.120.27 (SERVER4YOU) hit my net on Jan 30 2010. 122.146.174.3 (NCIC-TW New Century InfoComm Tech Co., Ltd.) hit once on Jan 20th.  All other hits are over a year old.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
