<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>VoIP Tech Chat &#187; amazon ec2</title>
	<atom:link href="http://www.voiptechchat.com/tag/amazon-ec2/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.voiptechchat.com</link>
	<description>Patrick and Fred Chat... sometimes about VoIP</description>
	<lastBuildDate>Fri, 30 Dec 2011 01:34:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>SIP Attacks From Amazon EC2 Cloud Continue</title>
		<link>http://www.voiptechchat.com/voip/538/sip-attacks-from-amazon-ec2-cloud-continue/</link>
		<comments>http://www.voiptechchat.com/voip/538/sip-attacks-from-amazon-ec2-cloud-continue/#comments</comments>
		<pubDate>Sun, 16 May 2010 22:11:02 +0000</pubDate>
		<dc:creator>Fred</dc:creator>
				<category><![CDATA[tech]]></category>
		<category><![CDATA[VoIP]]></category>
		<category><![CDATA[amazon ec2]]></category>
		<category><![CDATA[brute force]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SIP]]></category>

		<guid isPermaLink="false">http://www.voiptechchat.com/?p=538</guid>
		<description><![CDATA[Just over a month ago, we reported that SIP attacks from the Amazon EC2 cloud were on the rise. While the attacks we received last month were limited to &#8220;extension only&#8221; registration attempts, one of the attacks we received this &#8230; <a href="http://www.voiptechchat.com/voip/538/sip-attacks-from-amazon-ec2-cloud-continue/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div id="attachment_458" class="wp-caption alignright" style="width: 174px"><a href="http://www.voiptechchat.com/wp-content/uploads/2010/04/aws.gif"><img class="size-full wp-image-458" title="aws" src="http://www.voiptechchat.com/wp-content/uploads/2010/04/aws.gif" alt="" width="164" height="60" /></a><p class="wp-caption-text">Attacks from the cloud.</p></div>
<p>Just over a month ago, we reported that SIP attacks from the Amazon EC2 cloud <a href="http://www.voiptechchat.com/voip/457/amazon-ec2-sip-brute-force-attacks-on-rise/">were on the rise</a>. While the attacks we received last month were limited to &#8220;extension only&#8221; registration attempts, one of the attacks we received this morning included what we assume was a standard dictionary attack.</p>
<p>The first attack came from 204.236.245.101. In less than 60 seconds, this IP attempted more than 11,500 registrations against our server. Most of these were 4 digit extensions (<a href="http://www.voiptechchat.com/20100516-204ec2.txt.zip">download the log (zipped) here</a>). The second attack came from 184.73.4.183. In less than 90 seconds, this IP attempted more than 21,000 registrations against our server; including what we think is a standard dictionary attack complete with root, postmaster, pixadmin, etc. (<a href="http://www.voiptechchat.com/20100516-184ec2.txt.zip">download the log (zipped) here</a>).</p>
<p><span id="more-538"></span>From past experience, Amazon will simply not do anything about these attacks. The only way to contact Amazon to report abuse is through their web form, which results with Amazon either completely ignoring you or sending a delayed response asking for the exact information you have already sent (and then ignoring you).</p>
<p>So, I’m looking for more ideas from the community on how we can get Amazon to help us stop their network from leveraging a very powerful attack against little ol’ SIP servers.</p>
<p>We are currently deploying a custom perl script to block these attackers via iptables (which is why the attacks registration attempts “stopped”).</p>
<p>Thanks for reading and we’ll be updating this as soon as more information comes in!</p>
<p class="note">Update #1</p>
<p>The first response from Amazon:</p>
<blockquote><p>Thank you for submitting your abuse report.</p>
<p>We have completed an initial investigation of the issue and learned that the IP address you reported did indeed belong an Amazon EC2 instance. These intrusion attempts that you report were not, however, initiated by Amazon.</p>
<p>One of the biggest advantages of Amazon EC2 is that developers are given complete control of their instances. While the IPs may indicate that the network is Amazon&#8217;s, our developer customers are the ones controlling the instances. You may learn more about EC2 at http://aws.amazon.com/ec2</p>
<p>That said, we do take reports of unauthorized network activity from our environment very seriously. It is specifically forbidden in our terms of use. We&#8217;ve already contacted the Amazon EC2 customer who controlled the instance in question and informed them that they are required to terminate their unauthorized interaction with your network, failing which we will terminate their instance. In cases of egregious abuse or as we otherwise deem appropriate, we will immediately terminate all their instances and suspend their account.</p>
<p>If you have blocked this address range, please be aware that usage on the address range is transient and new users may soon be operating from those addresses and may not be able to reach you; once you have confirmed that the activity has been ceased by our customer, you should open your filters to re-allow traffic.</p>
<p>Thanks again for alerting us to this issue.</p>
<p>Original report:</p>
<p>* Source IPs: 204.236.245.101<br />
* Abuse Time: Sun May 16 08:53:00 UTC 2010<br />
* NTP: Y</p>
<p><strong>How can I send a message to the EC2 customer?</strong><br />
Complete and submit the web form <a href="https://www.amazon.com/gp/html-forms-controller/AWSAbuseReporter" onclick="pageTracker._trackPageview('/outgoing/www.amazon.com/gp/html-forms-controller/AWSAbuseReporter?referer=');">here</a>.</p>
<p><strong>How can I contact a member of the Amazon EC2 abuse team?</strong><br />
Send an e-mail to ec2-abuse@amazon.com to contact a member of the Amazon EC2 abuse team.</p>
<p>Please note: This e-mail message was sent from a notification-only address that cannot accept incoming e-mail. Please do not reply to this message.</p>
<p><a href="http://www.amazon.com/aws" onclick="pageTracker._trackPageview('/outgoing/www.amazon.com/aws?referer=');">Amazon Web Services</a></p>
<p>If you feel you are receiving this email in error and do not wish to receive further notifications, send an e-mail to ec2-abuse@amazon.com.</p>
<p>Amazon Web Services LLC is a subsidiary of Amazon.com, Inc. Amazon.com is a registered trademark of Amazon.com, Inc. This message produced and distributed by Amazon Web Services, LLC, 1200 12th Ave South, Seattle, WA 98144.</p></blockquote>
<p>I really don&#8217;t need a sales pitch in my abuse response.</p>
<h4>Additional Information:</h4>
<ul>
<li><a href="http://www.teamforrest.com/blog/171/asterisk-no-matching-peer-found-block/" onclick="pageTracker._trackPageview('/outgoing/www.teamforrest.com/blog/171/asterisk-no-matching-peer-found-block/?referer=');">Automatically Block Failed SIP Peer Registrations</a> (Team Forrest)</li>
<li><a href="http://www.voiptechchat.com/voip/457/amazon-ec2-sip-brute-force-attacks-on-rise/">Amazon EC2 SIP Brute Force Attacks on Rise</a> (VoIP Tech Chat)</li>
<li><a href="http://www.stuartsheldon.org/blog/2010/04/sip-brute-force-attack-originating-from-amazon-ec2-hosts/" onclick="pageTracker._trackPageview('/outgoing/www.stuartsheldon.org/blog/2010/04/sip-brute-force-attack-originating-from-amazon-ec2-hosts/?referer=');">SIP Brute Force Attack Originating From Amazon EC2 Hosts</a> (Building The Net)</li>
<li><a href="http://jcs.org/notaweblog/2010/04/11/properly_stopping_a_sip_flood/" onclick="pageTracker._trackPageview('/outgoing/jcs.org/notaweblog/2010/04/11/properly_stopping_a_sip_flood/?referer=');">Properly stopping a SIP flood</a> (joshua stein)</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.voiptechchat.com/voip/538/sip-attacks-from-amazon-ec2-cloud-continue/feed/</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
		<item>
		<title>Amazon EC2 SIP Brute Force Attacks on Rise</title>
		<link>http://www.voiptechchat.com/voip/457/amazon-ec2-sip-brute-force-attacks-on-rise/</link>
		<comments>http://www.voiptechchat.com/voip/457/amazon-ec2-sip-brute-force-attacks-on-rise/#comments</comments>
		<pubDate>Sun, 11 Apr 2010 21:14:51 +0000</pubDate>
		<dc:creator>Fred</dc:creator>
				<category><![CDATA[VoIP]]></category>
		<category><![CDATA[amazon ec2]]></category>
		<category><![CDATA[brute force]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SIP]]></category>

		<guid isPermaLink="false">http://www.voiptechchat.com/?p=457</guid>
		<description><![CDATA[Update #1: 12 APR 2010. Amazon NOC&#8217;s response. Update #2: 12 APR 2010. Amazon Statement. Update #3: 13 APR 2010. Amazon Response. Complaints of rampant SIP Brute Force Attacks coming from servers with Amazon EC2 IP Addresses cause many admins &#8230; <a href="http://www.voiptechchat.com/voip/457/amazon-ec2-sip-brute-force-attacks-on-rise/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div id="attachment_458" class="wp-caption alignright" style="width: 174px"><a href="http://www.voiptechchat.com/wp-content/uploads/2010/04/aws.gif"><img class="size-full wp-image-458" title="aws" src="http://www.voiptechchat.com/wp-content/uploads/2010/04/aws.gif" alt="" width="164" height="60" /></a><p class="wp-caption-text">Attacks from the cloud.</p></div>
<p><strong>Update #1: 12 APR 2010. Amazon NOC&#8217;s response.<br />
Update #2: 12 APR 2010. Amazon Statement.<br />
Update #3: 13 APR 2010. Amazon Response. </strong></p>
<p>Complaints of rampant SIP Brute Force Attacks coming from servers with Amazon EC2 IP Addresses cause many admins to simply drop all Amazon EC2 traffic. Generally, SIP brute force attacks attempt to register various peer names to a system and/or attempt to guess passwords of known/guesses peers or endpoints.</p>
<p>The complaints mentioned this weekend show an excessive amount of traffic; with some providers claiming 6GB of traffic dedicated to such attacks. Since we ourselves received an attack from an Amazon hosted server, we also reported and complained to the Amazon NOC/Abuse depts. <del datetime="2010-04-12T12:15:37+00:00">As of this posting, no response or acknowledgement has been received from Amazon.</del> The response from Amazon is below. <span id="more-457"></span></p>
<p>There are various techniques to assist with minimizing DDoS and Brute Force attacks, such as limiting access via the public internet, using strong passwords, not mapping extension name to peer/endpoint name, limiting simultaneous calls, and aggressively monitoring usage. Automatic blocking of abusive IP&#8217;s (fail2ban, blockhosts, etc.) can also assist with minimizing damage.</p>
<p class="note">Update #1: 12 APR 2010. &#8220;Response&#8221; from Amazon&#8217;s NOC</p>
<p>So when this happened, I submitted a report to Amazon complaining of the attack. The report was sent to their abuse and noc mails and contained the standard abuse report, including their host, my host, the protocol, ports, and description of activity; as well as a sample log.</p>
<p>About 48 hours later, they sent this as a response:</p>
<blockquote><p>From: 	Amazon.com &lt;ec2-abuse@amazon.com&gt;<br />
Subject: 	Your Amazon EC2 Inquiry<br />
Date: 	April 12, 2010 7:31:59 AM EDT<br />
To:	Fred Posner</p>
<p>Hello.</p>
<p>Thank you for contacting Amazon Web Services. We take reports of unauthorized network activity from our environment very seriously. It is specifically forbidden in our terms of use.</p>
<p>Because Amazon EC2 Public IP addresses may change ownership frequently, without additional information we will be unable to identify the correct owner of the IP address for the period of time in question.</p>
<p>So that we can process your report and identify the actual customer in question, we require the following information. Please note that we will not open attachments under any circumstance</p>
<ul>
<li>Source IP</li>
<li>Destination IP (your IP)</li>
<li>Destination Port and Protocol</li>
<li>Accurate Date, Time and *Time Zone* of activity</li>
<li>Intensity and frequency of activity in short log extracts, no larger than 4KB</li>
<li>Your contact details (phone and email)</li>
</ul>
<p>For a faster response, please file your report using the AWS Abuse form at the link below:</p>
<p><a href="https://www.amazon.com/gp/html-forms-controller/AWSAbuse/" onclick="pageTracker._trackPageview('/outgoing/www.amazon.com/gp/html-forms-controller/AWSAbuse/?referer=');">https://www.amazon.com/gp/html-forms-controller/AWSAbuse/</a></p>
<p>We appreciate your help in providing the necessary information requested.</p>
<p>Best regards,</p>
<p>-EC2 Abuse Team</p></blockquote>
<p>So, their laziness aside (since the report to them included ALL the information requested), I filled out the form&#8211; which of course failed with an unknown error. (below)</p>
<p>For people interested in moving to Amazon&#8217;s cloud, this is a good example of the quality of people conducting your network administration. I&#8217;ve sent another response by email. Others have blocked the entire EC2 IP range and have requested their upstream providers do the same.</p>
<p><strong>So my question to you&#8230; What would </strong><em><strong>your </strong></em><strong>next step be?</strong></p>
<p class="note">Update #2: 12 APR 2010. Amazon Statement.</p>
<p>Following a request for interview/statement, VoIP Tech Chat received the following communication from Amazon&#8217;s Public Relations Manager:</p>
<blockquote><p>Hello Fred and thank you for contacting us.  Over the weekend, we received a report of a suspicious account and began an investigation.  Our normal process is to connect the two involved parties to give them an opportunity to talk in case the abuse is not malicious but is simply heavy traffic from a legitimate customer.  If that is not successful, we then move to isolate the traffic from the abusing party.  Normally this process works quite well for situations our customers have encountered, however this incident has highlighted the need for an escalation process to address potentially malicious attacks more quickly.  Additionally, we are working on quickly putting better protections and processes in place to better guard against unwanted SIP traffic.  We take the security of our customers and our quality of service very seriously, and will  continue to work to improve our processes and services for customers.</p>
<p>Thanks</p>
<p>Kay Kinton<br />
Public Relations Manager<br />
Amazon Web Services</p></blockquote>
<p>I&#8217;ve replied to again ask for an interview and will update if a response is received. The statement states this was over a weekend, however doesn&#8217;t address that the attacks continued today. It also states a &#8220;report&#8221; was received, but there were many reports submitted. That being said, at least they responded.</p>
<p class="note">Update #3: 13 APR 2010. Amazon Response. Decline of Interview.</p>
<p>After Kay Kinton&#8217;s statement, I asked her for a phone interview.</p>
<blockquote><p>Sent: Monday, April 12, 2010 2:00 PM<br />
To: Kinton, Kay<br />
Subject: Re: Amazon Web Services</p>
<p>Kay,</p>
<p>Thank you for your statement. I would like to interview you about this for VoIP Tech Chat&#8230; it would be an over-the-phone interview and would be for 5 minutes or however much longer you would like.</p>
<p>&#8212;fred</p></blockquote>
<p>Kay&#8217;s response was quick, and to the point:</p>
<blockquote><p>What else can I tell you Fred?</p></blockquote>
<p>I truly dislike email for interviews for no other reason that not getting the tone of that response. Did Kay mean that as &#8220;Sure, great! What else can I help you with?&#8221; Or, was it more along the lines of, &#8220;I answered you. What now?&#8221;</p>
<p>Giving her the benefit of the doubt, I replied:</p>
<blockquote><p>Date: April 12, 2010 5:24:14 PM EDT<br />
To: &#8220;Kinton, Kay&#8221;<br />
Subject: Re: Amazon Web Services</p>
<p>We would like to interview on this. I thank you for the statement, however I have additional questions:</p>
<p>I know of 12 complaints since Saturday (from different reporters) that were submitted regarding SIP attacks from EC2 to outside systems. How many complaints did you receive since Saturday?</p>
<p>I know attacks continued today and may even be ongoing. There were attacks as of 1pm EST hitting systems with over 640K of data. Are you still seeing attacks? How many hosts were identified?</p>
<p>Were the attacks submitted from one customer/client of yours or many?</p>
<p>Those are my initial questions, however I do request a phone interview rather than email. I find them much easier to exchange information as well as generally a better expressive forum for an interview.</p>
<p>&#8212;fred</p></blockquote>
<p>Good thing I didn&#8217;t hold my breath. The next day, after not receiving a response, I called Kay several times and emailed her for an update. Her response via email:</p>
<blockquote><p>Hello Fred. We believe that we&#8217;ve identified and shut down the illegal activity and are closing the loop with customers.  We&#8217;d certainly be interested in hearing of the cases you refer to below so we can follow up.</p></blockquote>
<p>I tried reaching out to her but have not had responses. Which leaves me with this&#8230;</p>
<p>Her response did not answer my question and I certainly have no basis to believe that Amazon is currently taking any interest in this matter. They&#8217;ve told us prior that they cannot pinpoint IP to timeframe as well as that during an attack, they&#8217;d try to mediate between parties rather than actually stopping the attack in progress (to give them an opportunity to talk). Sadly&#8230; when I&#8217;m being flooded, I want the flood to stop. Afterwards, I&#8217;ll be glad to talk. But I digress&#8230;</p>
<p>Since Kay did not answer any of the additional questions we asked, but did state that she&#8217;d be interested in hearing about the other cases, we will encourage anyone with information or feelings about this issue to contact Kay Kinton directly:</p>
<p style="padding-left: 30px;">Kay Kinton<br />
<strong><a href="mailto:kinton@amazon.com">kinton@amazon.com</a></strong><br />
Public Relations Manager<br />
Amazon Web Services<br />
<strong>Phone:  206-266-8387</strong></p>
<div class="topsy_widget_data" style="float: right; margin-left: 0.75em;"><script type="text/javascript">// <![CDATA[
   topsyWidgetPreload({ "url": "http://www.voiptechchat.com/voip/457/amazon-ec2-sip-brute-force-attacks-on-rise/", "title": "Amazon EC2 SIP Brute Force Attacks on Rise", "theme": "blue","style": "big", "nick": "fredposner" });
// ]]&gt;</script></div>
<p><strong>For More Information:</strong></p>
<ul>
<li><a href="http://lists.digium.com/pipermail/asterisk-users/2010-April/thread.html#247094" onclick="pageTracker._trackPageview('/outgoing/lists.digium.com/pipermail/asterisk-users/2010-April/thread.html_247094?referer=');">Asterisk User&#8217;s Mailing List Archives</a></li>
<li><a href="http://blogs.digium.com/2009/03/28/sip-security/" onclick="pageTracker._trackPageview('/outgoing/blogs.digium.com/2009/03/28/sip-security/?referer=');">7 Steps to Better SIP Security</a> (Digium)</li>
<li><a href="http://www.aczoom.com/cms/blockhosts" onclick="pageTracker._trackPageview('/outgoing/www.aczoom.com/cms/blockhosts?referer=');">Blockhosts</a></li>
<li><a href="http://www.voipsa.org/" onclick="pageTracker._trackPageview('/outgoing/www.voipsa.org/?referer=');">Voice over IP Security Alliance</a> (VOIPSA)</li>
<li><a href="http://www.stuartsheldon.org/blog/2010/04/sip-brute-force-attack-originating-from-amazon-ec2-hosts/" onclick="pageTracker._trackPageview('/outgoing/www.stuartsheldon.org/blog/2010/04/sip-brute-force-attack-originating-from-amazon-ec2-hosts/?referer=');">SIP Brute Force Attack Originating From Amazon EC2 Hosts</a> (Building The Net)</li>
<li><a href="http://jcs.org/notaweblog/2010/04/11/properly_stopping_a_sip_flood/" onclick="pageTracker._trackPageview('/outgoing/jcs.org/notaweblog/2010/04/11/properly_stopping_a_sip_flood/?referer=');">Properly stopping a SIP flood</a> (joshua stein)</li>
<li><a href="http://www.teamforrest.com/blog/171/asterisk-no-matching-peer-found-block/" onclick="pageTracker._trackPageview('/outgoing/www.teamforrest.com/blog/171/asterisk-no-matching-peer-found-block/?referer=');">Automatically Block Failed SIP Peer Registrations</a> (Team Forrest)</li>
</ul>
<div id="attachment_462" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.voiptechchat.com/wp-content/uploads/2010/04/amazon-ec2-noc.png"><img class="size-medium wp-image-462" title="amazon-ec2-noc" src="http://www.voiptechchat.com/wp-content/uploads/2010/04/amazon-ec2-noc-300x207.png" alt="" width="300" height="207" /></a><p class="wp-caption-text">Report your error with our form. Fail.</p></div>
]]></content:encoded>
			<wfw:commentRss>http://www.voiptechchat.com/voip/457/amazon-ec2-sip-brute-force-attacks-on-rise/feed/</wfw:commentRss>
		<slash:comments>53</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.362 seconds -->

