3CX Management Console breached - license key visible to hackers

Status
Not open for further replies.

virtuoso

Customer
Basic Certified
Joined
Aug 26, 2014
Messages
2
Reaction score
0
Hi all,

Our 3CX Management Console was breached last weekend by a hacker gaining access to an insecure webclient that had 3CX Management Console access. The breach has been mitigated. The hackers possibly viewed and copied our license key. I want to understand the implications of this.

What can someone do with this key if it's not updated?
If I want to update my license key to a new one, how do I go about this?

Thanks all
 
Well, they could spin up a 3CX installation and use your key then you'll be playing tug of war with the FQDN changing WAN IPs. You'd need to speak with your account manager to see what they can do, if anything.
 
I would contact your partner and open a support ticket for this.
 
Hi
If they had access to the Management Console, I would be more concerned about your SIP Trunk Settings. I would ask the SIP Provider to change the Password for the SIP Trunk, or put an ACL on the trunk, only allowing your public IP to use this SIP Trunk.

Also, check (in the Audit Log) if they exported a list of your users, and if an older system the user's AuthID and Passwords. If they did, you should regenerate those users (Auth and Passwords).
 
  • Like
Reactions: N_G
If it's a FQDN managed by you (and not 3CX) impact of a leaked key is very limited. Key is bound to FQDN and DNS for that FQDN won't ever point to their PBX.

But as many others have stated, 3CX can change it for you (via a ticket) and you should check extension authentication and SIP authentication for credentials leak.
 
That's an interesting side effect of having extensions be system owners...people would tend to leave their web client logged in all the time. (to date we've set up separate system admin extensions)
 
That's an interesting side effect of having extensions be system owners...people would tend to leave their web client logged in all the time. (to date we've set up separate system admin extensions)
The separate extension for sys admin is a good workaround, but would also like to see a step up authentication option in the web client for sensitive functions. So for admins that are also system users, don't have the entire sys admin privileges (or boneheaded mistakes like deleting a SIP trunk) in the same UI as what I use to answer and make calls. Provide the ability to, when accessing the admin menu, require entry of a password or OAUTH/365 password or other way to prevent this new vulnerability. Make that an option so the people that will inevitably complain that they are admins and not users can keep it exactly the way it is today, but for others (like the poster here) that are admins AND users to keep the admin functions protected by something more than a mouse click.

Put another way, I might be a tenant administrator on MS365, but that doesn't mean I want to ability to do tenant admin features from my outlook client. I understand all the reasons why a separate admin interface is a headache and do not mind pushing that to a unified client, but it seems like that idea needs some work with regard to the issue here. A phone system user, in day to day use of the UI they use to make calls, should not also be tow or three clicks away from total system destruction. This is even more important for quasi-admins with the new department feature. I dont want the new department manager that might need to occasionally administer user functions to use the same UI to do their day to day call functions but has the ability to delete users and trunks they they manage.
 
@virtuoso, I would recommend that you contact the 3CX Customer service team and they can provide a replacement license key if you are still concerned. They can be reached at: [email protected]
 
  • Like
Reactions: NatalyS_3CX
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet