These are probably unmanned bots. The SIP implementation on a number of devices are known to have Denial of Service vulnerabilities that can crash the system, so the bad guys' bots like to look for that port. - Brian
On Sat, Apr 22, 2017 at 04:34:56PM +0000, R P wrote:
(Please trim inclusions from previous messages) _______________________________________________ I think I have asked it before but i see on the log a lot of incoming UDP port 5060 to all the hosts (even that are not active currently but defined in the AMPR dns and therefore have routing to my gateway ) from all over the world
What is it ? who have interest to look for SIP on my system ?
Is there a way to cut and paste part of the log of Mikrotik router ? i can not do it when i enter it from the web interface so could not copy the relevant log part
Thanks Forward
Ronen - 4Z4ZQ
Ronen Pinchooks (4Z4ZQ) WebSitehttp://www.ronen.org/ www.ronen.org ronen.org (Ronen Pinchooks (4Z4ZQ) WebSite) is hosted by domainavenue.com