3CX Phone System Anti Hacking – Whitelist/Blacklist

Status
Not open for further replies.

KaterinaK_3CX

Joined
Feb 24, 2016
Messages
246
Reaction score
36
Are there logs of what credentials were used? I see the IPs that are black listed, and some of the show the device that was used. Some of the blacklists don’t show anything, and I am guessing that an extension was tried. I haven’t yet found a log showing this, nor an email containing credentials.

Note: I am seeing “things” with my Cisco RV160 rules, and am planning a move to a pfSense+ device. I have to budget that in while I figure out how to deal with these bursts of blacklists.
 
Are there logs of what credentials were used? I see the IPs that are black listed, and some of the show the device that was used. Some of the blacklists don’t show anything, and I am guessing that an extension was tried. I haven’t yet found a log showing this, nor an email containing credentials.

Note: I am seeing “things” with my Cisco RV160 rules, and am planning a move to a pfSense+ device. I have to budget that in while I figure out how to deal with these bursts of blacklists.
Hi!

If you have the IP Address of the perpetrator, you can then go into Dashboard --> Activity Log and in the Search bar here put the IP Address and search (you may have to press the "Load More" button). This will show you the SIP messages that came from this IP and from this you can also determine what extension they were targeting.

Note that in order to see meaningful logs in "Activity Log", in Dashboard --> Activity Log --> Settings you may have to have had "Verbose" selected.
 
  • Like
Reactions: Jim.Lloyd
NickD_3CX, thank you for the reply. Sorry for the delayed reply... It has been one of those months! The perpetrators seem to have moved on to trying to authenticate as devices, such as IP phones and other PBX devices. I am moving on to trying to figure out how to stop that from being successful without killing my remote soft phones from logging in. Haven't gotten there, yet. I am about to travel for a few weeks, so I will have to hope the bad people are not successful!
 
The perpetrators seem to have moved on to trying to authenticate as devices, such as IP phones and other PBX devices.
That's actually quite a common practice hackers use, masking their requests as "Polycom" or "Cisco", etc.

I have to say that there comes a point where if you need to have 5060 open to the public internet, e.g. when you have remote STUN phones or providers that don't give you a fixed list of SIP Servers they use, where you just need to rely on the security of 3CX.

If you can do this, close 5060 UDP/TCP and only leave it open for the IP Addresses of your SIP Trunks Provider(s). All IP Phones via the SBC, the Mobile apps and the Webclient/Desktop App don't use this, so it can be an effective way.

But, even if you leave 5060 open, if all your Extensions have random passwords and usernames, like they are when auto-generated by 3CX, you should be very safe already and 3CX will continue to blacklist the IPs trying to penetrate into the system.
 
I am not intentionally leaving 5060 open to the public, though I have a router I am questioning. I have another thread running with a long explanation of what I think I am doing, so I won't go into it here.

That being said, one of my three monitored setups is not getting hammered, and that one fails Full Cone for STUN. I set that one up back in v15.5 days, and it has been upgrading to the current v18-SP2. I wish I could remember how I did that! I would like to disable STUN on the others (:>)

Thank you for the reply.
 
I may have figured out why so many attempts are being made on my 3CX installation... I think it is the difference between 'Static' and 'Dynamic' Public IP. I do have a dynamic public IP, but it only changes when I change routers (or the router MAC). That normally only happens every 3 to 5 years, but I programmed the 3CX truthfully... not sure why.

STUN servers are defined with the Network Settings group tab for Public IP. When I choose 'Static Public IP', the gray out. I guess I could have blanked them out or put in something unrouteable, but selecting the 'Static Public IP' button was one click that preserved the settings.

After 2 weeks of being bombarded with fake IP phones and phone switches trying to long in, my logs are only showing a long list of IPs banned because they are blacklisted by 3CX... not my PBX. It may be a coincidence, but today is different! It has only been 18 hours since I made the change. Over the weekend should prove this out. Let me know if you think I am on the correct path, here.
 
[ UPDATED 3 Hours Later ] - This is NOT the solution. I am down to the Cisco RV160 rules....
 
I could just test this I guess, however I thought a quick question on here instead would save me the trouble :) and maybe of interest to other users

Does white listing an IP address mean that IP address is then considered part of the 'network' i.e. once whitelisted you then wouldn't need to uncheck the extension option - "Disallow use of extension outside the LAN (Remote extensions using Direct SIP or STUN will be blocked)"? if using STUN on that extension of course.

If that's not the case, might be something worth considering as it would keep the network more secure if you had remote workers working at home (on fixed IP addresses). Obv a SBC would be preferred, but sometimes a little overkill for remote workers where only one device on the connection.

Dave.
 
I could just test this I guess, however I thought a quick question on here instead would save me the trouble :) and maybe of interest to other users

Does white listing an IP address mean that IP address is then considered part of the 'network' i.e. once whitelisted you then wouldn't need to uncheck the extension option - "Disallow use of extension outside the LAN (Remote extensions using Direct SIP or STUN will be blocked)"? if using STUN on that extension of course.

If that's not the case, might be something worth considering as it would keep the network more secure if you had remote workers working at home (on fixed IP addresses). Obv a SBC would be preferred, but sometimes a little overkill for remote workers where only one device on the connection.

Dave.
Dave, whitelisting just means that the IP(s) in question will not be locked out. Making them "part of the network" is basically done through your firewall.

I am still trying to figure out how to block all those fake devices trying to log into my 3CX. I have two others at the office, and one of them NEVER logs a foreign device login attempt. The other has just as many as my home PBX. I still don't know why that one device seems more secure, but I still occasionally look at the firewall, network & 3CX settings hoping to see what it is.
 
Hi 3cx Community, I wanted to briefly ask. Regarding the "BLOCK/ALLOW" list feature in 3cx. It appears to be based purely on numerical IP address. I am curious if a feature request is possible for Team@3cx to allow a DNS POINTER to be used for an "ALLOW" list entry here, instead of just a fixed numerical IP? I realize this requires some code/logic change to implement, since not simply an IP Number > punched into an iptables fitrewall rule. Use case scenario, is that I have multiple clients who have offices which have DynDNS / non-fixed IP address at their office. They do have a valid DynDNS service and the DNS name (for example "MYOffice.DYNDNSProvider.COM" is always ... the public IP of their office. Ideally it would be great if I can punch in the "MYOFFICE.DYNDNSProvider.COM" into the "ALLOW LIST" RULE instead of having to manually convert the DNS>Current IP address > Punch that in. Then wait a few weeks, some user at the office screws up and fails login 3 times, gets the whole office onto block list / and because the ISP changes their office IP a few times a year, it means inherently at least .. this many times a year, the phone system is borked until I manually go in and fix up the 'static IP number' designation of their office on the ALLOW listing rule. Whee.

In theory if 3cx admin tool had a way to do something like
-- tag a record as a DYNDNS pointer
-- ask 3cx to just refresh the DynDNS<>IP lookup - on a regular basis (ie, daily? is probably fine)
-- then the rule would 'auto correct' each time the office DynDNS pointer changes / a few times a year.

I realize this is a bit of an ask, but wanted to put it out there as a 'nice to have' feature, if 3cxTeam is feeling like they need another feature to add to the product. And maybe of course if lots and lots of other sites have this issue, maybe others might comment on this to 'up vote' it. Thanks!
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet