Troubleshooting - Phantom Calls or SIP Attacks
==============================================

This guide will walk you through the proper identification and solution for phantom calls or SIP attacks.

How do I stop SIPVicious attacks?
---------------------------------

Problem
-------

Users are receiving multiple ghost calls on their <var class="keyword">
<div style="display: inline;">
RingCentral
</div></var> IP phones. When answered, there is no one on the other end of the call.

Symptom
-------

* IP phones would endlessly ring and will usually show calls from a 3 or 4-digit Caller ID (Ex. 101, 4001, etc.).
* These calls may sometimes show up a CallerID Name **SIPVicious** or something similar.
* These calls are not recorded on the <var class="keyword">
  <div style="display: inline;">
  RingCentral
  </div></var> server and do not show up in the <var class="keyword">
  <div style="display: inline;">
  RingCentral
  </div></var> account's Call Logs.

Cause
-----

Receiving multiple ghost or phantom calls are a result of malicious intent. "Hackers" use a program called **SIPVicious** to probe networks and compromise IP phones.

**SIPVicious** is a free SIP security testing suite, which scans IP addresses looking for SIP devices, helps identify active PBX extensions and provides a mechanism to crack SIP user passwords.

Solution
--------

The only stable resolution is to lock down the SIP ports on your router. The concept is to only allow inbound and outbound traffic on IP phones to go to and come from <var class="keyword">
<div style="display: inline;">
RingCentral
</div></var> IP addresses. You may need the help of an IT professional to do this.

The IP ranges you should be accepting traffic from are as follows:

80.81.128.0/20

103.44.68.0/22

104.245.56.0/21

185.23.248.0/22

192.209.24.0/21

199.68.212.0/22

199.255.120.0/22

208.87.40.0/22

To lock down the SIP ports on the router, your router must have a functionality commonly referred to as **Access Control List (ACL)** . This functionality allows a user to specifically set local IP Addresses to only communicate to the <var class="keyword">
<div style="display: inline;">
RingCentral
</div></var> IP addresses.

