3CX Cloned?

Status
Not open for further replies.

Enzedder

Free User
Joined
Mar 29, 2020
Messages
3
Reaction score
1
Hi All,

Looking for help here please?

I've a strange situation that appears to have happened in the past couple of days and I'm hoping someone may have been able to shed a little light on it as I'm scratching my head with this one?

I have a hosted 3CX installation on Amazon Lightsail, all has been running well for the past few months and I was about to deploy it as a production system, I first noticed an issue when I checked my 3CX mobile app and found it unable to register? I logged into the management console using the PBX URL to be told my admin password was incorrect (this is a 25 character password!), I checked it again and same result? I initiated a 'forgot password' and had a new one emailed and was able to log in using the 3CX provided domain name?
Looking more closely at the PBX once I had logged in I found that some of the admin functionality was missing (network, license info etc) and the IP address was showing as dynamic, Lightsail's hosting provides a static IP!?
Checking the IP it resolved to a Google Hosted instance in an area of Asia rather than an Amazon host, what was strange was that it contained my configured extensions and SBCs although no VOIP provider or ring group info? What is more worrying for me is that this instance however or whoever created/cloned it (and how did they do it?) has now hijacked my 3CX domain, I'm unable to see or configure the network on the new instance to change it as I'm not the hosting admin?

I have absolutely no idea how this could have happened as I've never set up a hosted account on Google for 3CX nor made my config available outside through a back up or anything else, I'm at a loss to explain this?

If anyone any good pointers or seen anything like this before please let me know as I'd like to get this domain back if I can, I'm anal on password security (length & complexity) so am struggling to write it off as a hack?

Thanks in advance.
 
Forgot to mention I turned the Lightsail instance off just to make sure I wasn't going crazy?
 
I really doubt that any hack took place. But even if that is the case, why would that person keep your email address bound to the admin account? Also I can't see how you would be missing permissions on the admin account. That is only possible if you log in via an extension.

Did you check this on another computer as well from a different connection?

The only way this can happen is if you restore a backup on another instance. So if this actually happened, you need to check who had access to your instance and/or backups. (or your email..)

I initiated a 'forgot password' and had a new one emailed and was able to log in using the 3CX provided domain name?
3CX will send you the password already set, won't create a new one. So somehow it was changed.
 
I'm a bit embarrassed here but thought I would close this thread, thanks for the reply, seems I created a 3CX hosted demo using this FQDN and an express install at some point (although I don't remember doing it?) and it then assumed the lead role pinching the FQDN back, sort of explains why it only had a partial config? Anyway John3CX was kind enough to delete the demo instance and everything has returned to as it should be! :cool:
 
  • Like
Reactions: AWS2P
Status
Not open for further replies.