security

  1. foobar

    Security Contact

    Hello I'm looking for a security contact at 3CX. I did not find any information on the pubic website, security.txt, in the customer dashboard or somewhere else. I also don't want to buy a support ticket. Is there a email address where I can reach technical people of 3CX regarding their...
  2. Patton 2 Port FXS: No administrator login in the provisioning file -> no Password set

    The provisioning file for the Patton 2 FXS don't include a administrator login (whle this is done for e.g. the Snom phones) - so they fall back to the default login admin/<empty password>, even if there was a password set before. Using current stable v16.
  3. Security concern about fixed meeting URL

    When doing a webmeeting (no scheduling) the url is fixed per user. We would suggest random URLs for each meeting.
  4. Why is the SIP Login and SIP Password stored in the "welcome mail" and accesible by "ProvisioningUrl" externally and internally in plain text?

    If you check the "welcome mail" .cofig file you can see all the password needed for a sip client to log in as extension and start doing calls needed in plain text... The same happens if you check this location on your computer after 3cx is installed and set up...
  5. NicholasBarnes

    Forbid all access from 3CX app for some users.

    Hi all, I have a client who has a requirement that it is not possible for some (but not all) of their users to log in using the 3CX app on their Android/iOS devices. These users should still receive the welcome e-mail, will have a desk phone (or desktop softphone) in the office, but must...
  6. Solved 3CX Hosted & Port 5060

    One of the concerns I have utilizing 3CX Hosted is the amount of junk that tries to register to my PBX, despite having set pretty strict auto-blacklist policies. Considering 3CX Hosted does not officially support STUN connections, why even have the port open and the option available? I would...
  7. SteveITS

    Debian security updates only installed via automatic updating

    Starting a new thread, from thread https://www.3cx.com/community/threads/3cx-debian-vm-crash.79543/post-366821 and and @ChrisC_3CX does this apply to SBC updates also? They need to be done automatically not manually?
  8. Solved Lots of IPs getting blacklisted > how to respond to the threat?

    We've started using 3CX in May 2020 and in July we started getting IP blacklisting notification mails. The amount of IPs being blacklisted has increased since then and over 200 IPs were blacklisted during the last three weeks. I already increased the blacklisting time from the inital 1 day to...
  9. Brandan Hermo

    MORE INFORMATION IN EVENTS LOGS

    Many clients ask for more detailed event information such as an IP added to the blacklist. Know which user tried to login, etc. Right now only the IP is known, but there is no information about the user / extension that tried to login.
  10. Implemented More Granular Permissions and 2FA

    We'd like to see an option that we can prohibit users from deleting their call logs/call records, etc. There doesn't appear to be a way to do that. Also, 2 factor authentication for the web portal login would be great.
  11. Solved IP blacklisted but doesnot show up in IP Blacklist

    I have several phones (android and ios) that cannot connect while on specific supplier network. However once they are on another network they connect. I am not even able to open the webclient page from that specific supplier network. however i can see that the port is open and the packets go...
  12. ArtR

    Calls from sipvicious on one users iPhone

    Hi All, We have one user that is getting sipvicious calls on their iPhone at random times. I can't see anything in our PBX logs (on maximum logging now) to say they have come via that, nor does the users 3CX client show these calls in their recent calls list. I'm working with the user to...
  13. Boschko

    3CX Access Control Levels

    Are there any solutions for implementing a more granular admin access in 3CX? How could we go about implementing multiple admins with different access levels? Can this be done?
  14. Blacklist / Whitelist

    I would like to see a Blacklist/Whitelist feature in Settings where the administrator can Blacklist offending IP's that keep trying to authenticate over SIP ports constantly should be automatically blacklisted after XX times. This Blacklist should be editable then by the administrator to...
  15. 3CX compromised and toll fraud

    We have some 3cx instances hosted with a 3rd party. Three times in the past six weeks are so, we have had extensions compromised and fraudulent toll calls were able to be placed until the sip provider noticed this and shut it down. (happened after hours and they caught it in about 4 hours)...
  16. SSL Cert Problem

    Hi there, I took up 3CX on the 1 year Google Cloud Hosting offer for my PBX. This worked fine for a few months, but now, for some reason, the SSL Cert has developed an error, making the entire system unusable. For some reason, when I go to ccits.3cx.co.uk, it says connection unsecured. Upon...
  17. I think someone is trying to hack me !

    I have been using 3CX for over 4 months now , I'm using the trial license (Still testing and seeing how 3CX works) . I have been getting a lot of "Too many failed authentications!" events (The IP of the performer does get blacklisted) from like the first month that I started using 3CX, I didn't...
  18. Fred2k

    Is it necessary to block all SIP traffic other than from provider?

    I'm currently setting up a test 3CX system, and was reading this article about setting up the firewall. From the below image it looks like your're supposed to lock down SIP and media traffic so that it only comes from your SIP provider: We use Gradwell as our SIP trunk provider, and I asked...
  19. New password/auth requirements in 15.5 SP6

    Hi, Is there a way to edit the policy that triggers the alert under Extensions since upgrading to SP6? We are able to change Auth and deskphone passwords but our Auth ID field is all numbers (it's the full phone number of the extension which is 10 digits, but contains no letters). It's...
  20. When are you finally going to support 2FA

    There's been so many new versions and in the 4 years that we use 3CX, I've not seen such an essential feature added. The security and user experience issue that 3CX has is that the login password of the admin web interface is exactly the same as the phone login. That inherently is a very...