3CX phone client spam registration

Status
Not open for further replies.

corporate13

Gold Partner
Advanced Certified
Joined
Sep 8, 2014
Messages
6
Reaction score
6
We are experiencing some fun spam here and I am not sure there is much we can do about it, but wanted to maybe make a suggestion or see if anyone else has come across this and found a way to deal with it.

We have a client who had an employee with a 3CX mobile client installed on their cell phone. This employee was terminated from the company on bad grounds. To prevent the employee from utilizing the company's phone system via their phone app, we modified the username and password (then eventually deleted the extension) so their client would no longer connect.

However, in doing this we ran into our issue. By removing the credentials the 3cx client used to connect successfully, it is now failing to connect (yay, right?). This causes an abnormal about of spam email messages for registration failures, one ever 15 minutes or so. The real issue is, as that cell phone roams around the world, it is picking up different IP address everywhere it goes so it makes it near impossible to blacklist it. Also, because it is simply a failed registration 3CX does not apply the blacklist time (set to some 9000000 minutes or something) to it and apparently has a back-end timer of about 15 minutes that it applies.

So, on to the suggestion:
If a 3CX client, phone or desktop since 3CX has access to modify those and they are rather mobile, is banned for 15 minutes for registration failure, 3CX should send a message to that client to delete the provisioning. I am sure there is some reason it doesn't already do it, but I cannot think of one.
 
Hello @corporate13

For the former employee to be sending registrations to the system that means that he would have to keep the app running on the foreground on his phone so that the client is trying to register. Is he that committed to spam you that he roams around the world with the 3CX app on the foreground so that he tries to register?
Are you sure that what you are seeing aren't registration attempts by hackers scanning the system?

If it is the the specific mobile client that causes this then i would recommend changing the tunnel password and re-provisioning the rest of your clients. If you are using SBC's you will need to adjust those as well. Note that if the client does not have the option "Use the tunnel" enabled then registration attempts will still arrive at the PBX.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,885
Messages
589,547
Members
164,745
Latest member
Herm77