
Nov. 25, 2010
9:02 p.m.
Tonight i'm seeing hundreds of register attempts per second to one of my SBC's from an IP in china 61.142.250.96. the From: and to: line is always one of these 2 below. \"118\" <sip:118 at my SBC IP>; source port 5063 \"qwerty\" <sip:qwerty at my SBC IP>; source port 5067 user-agent: friendly-scanner is always. Looks like sipvicious default user agent. Anyone seen a register flood like this before? Colin