Someone has to know the PBX FQDN to start brute-forcing it: Easy going! Just use a 3cx header + Shodan
I know, but if your users are properly trained and use a password manager and change their password every 45-90 days, the risk is extremely low --> It's just not practical without 2FA. I don't know where the problem is to add a simple 2FA authentication. You can talk everything up here but a 2FA is missing and therefore 3cx is not up-to-date in my opinion!
the FQDN is not needed to brute force a server, just its IP Address is sufficient, This whole arguement is moot however, there exists several strong security plans already doable that tons of people are in fact already using, not to mention 3CX blocks brute force attempts so quickly that they have less than 1% chance of success.
1. Console Restrictions - This literally blocks login to the admin panel to IPs that are not in the Console Restrictions Allow List. This is what everyone who is paranoid about security should be using. Why do they not? 2 Reasons usually based on my talks with lots of 3CX Resellers.
A. They need to be able to access the 3CX Servers in an emergency from WiFi, Mobile Hotspots, etc.
B. They did not realize this feature existed in 3CX, because they do not fully read about the new features all the time.
Fixing B is as simple as explaining it to them, and they realize it helps security problems a ton.
Fixing A is actually as simple as cake now too. Because wait for it. PBXMonitor has this neat little feature now, that allows you to control the Console Restrictions setting on all your 3CX Servers remotely, From a secure mobile app, The app cannot add or remove allowed IPs, it can only turn the feature on, and off, meaning IF some emergency comes up, and you MUST access a PBX which has console restrictions in place from some random mobile hotspot in the middle of nowhere, You pull out your phone, login to the app, and flip a switch, and now as long as you know the PBXs credentials, you can login to it from your location. Then when your done, flip the switch back on, and the system is locked down again.
How does PBXMonitor do this, simple, You authorize PBXMonitors control IP in Console Restrictions when you first setup PBXMonitor, then from that point, the PBXMonitor Mobile app is able to toggle console restrictions for you.
The App i speak of, also requires 3 pieces of information to login, Your username, your password, AND, your PBXMonitor Account ID, meaning your account ID with us, that we use internally to identify your account. So the App is useless even if someone did have your username and password if they do not know your account id with us.
@hulk123 if you have any other curiosities around this subject feel free to ask, I am actually certified in:
CVA - System/Network Vulnerability Assessment
CPTE - Penetration Testing Engineer
CISSO - Information Systems Security Officer
Computer Forensics
Numerous others but those 4 are the ones pertinent to this discussion, i also work in the Critical Infrastructure field assisting the FBI, Infragard, regarding cyber security matters, and I have helped close cases across the US as a Computer Forensics Examiner. Little things like that...