- Joined
- Nov 2, 2020
- Messages
- 5
- Reaction score
- 0
Hey everyone, I recently began playing around with 3cx deployment after having been using the system at my employers place for the past year or so... and we like it.
Yesterday my test system lost all of its config from the previous week, it looked like it had been setup brand new.. all trunks, sbc's, phones and extensions had been lost.
After having provisioned 10 or so phones, I left the office for the night. When my coworker came in the next morning, he called and asked me what the password had been changed to. I hadn't changed the password. After troubleshooting for a bit, I created a backup via ssh and checked the password in the config file, which was the same password we had on file.
I then realized there was a password reset link on the front page, so we were eventually able to get back in. After logging back in though, all config had seemingly been lost.
Im less worried about the setup and more worried about teh possibility that someone is hacking in....
Looking in the activity log I see something about 'sipvicious' which is a tool for pbx penetration testing it turns out...
Could a bad actor get in using sipvicious? What else could have happened?
Thanks for any help!
Yesterday my test system lost all of its config from the previous week, it looked like it had been setup brand new.. all trunks, sbc's, phones and extensions had been lost.
After having provisioned 10 or so phones, I left the office for the night. When my coworker came in the next morning, he called and asked me what the password had been changed to. I hadn't changed the password. After troubleshooting for a bit, I created a backup via ssh and checked the password in the config file, which was the same password we had on file.
I then realized there was a password reset link on the front page, so we were eventually able to get back in. After logging back in though, all config had seemingly been lost.
Im less worried about the setup and more worried about teh possibility that someone is hacking in....
Looking in the activity log I see something about 'sipvicious' which is a tool for pbx penetration testing it turns out...
Could a bad actor get in using sipvicious? What else could have happened?
Thanks for any help!