- Joined
- Oct 27, 2011
- Messages
- 2
- Reaction score
- 0
Discovered yesterday that someone had "hacked" my 3CX and started to make calls. We caught it reasonably quickly, and then only racked up $150 of charges.
So, I had committed the unforgivable sin of not changing the default password for the extensions, so they easily guessed what they were! However, I had thought that I would be safe because the server is behind a NAT router, and there are no port forwarding rules setup on the router to the server. I was rather confused as to how they had managed to connect to the 3CX. My theory is that because the 3CX had talked to a STUN server, and also registered with an external VOIP provider, it had "punched" a hole in the firewall for these services, and therefore if someone managed to find the external port that the NAT router had assigned to deliver the UDP packets back to the 3CX, an external client would be able to logon to the 3CX server. Is this a correct assumption?
I have now changed the passwords for the extensions to be a lot more secure, and also changed some of the anti-hacking settings on 3CX to blacklist an IP after 3 failed logins.... and also ticked the box on the extensions to only allow logins from the LAN. Hopefully that will stop them!
Are there any ways of protecting at the NAT router level? As a port needs to be opened for return traffic from an external SIP provider, is there a way of only allowing this traffic, and not from anyone else? I am presuming that the NAT is a "full cone NAT", rather than restricted (address) cone NAT. The router is a Netgear DGN1000 router if that is any help!
Thanks
Paul
So, I had committed the unforgivable sin of not changing the default password for the extensions, so they easily guessed what they were! However, I had thought that I would be safe because the server is behind a NAT router, and there are no port forwarding rules setup on the router to the server. I was rather confused as to how they had managed to connect to the 3CX. My theory is that because the 3CX had talked to a STUN server, and also registered with an external VOIP provider, it had "punched" a hole in the firewall for these services, and therefore if someone managed to find the external port that the NAT router had assigned to deliver the UDP packets back to the 3CX, an external client would be able to logon to the 3CX server. Is this a correct assumption?
I have now changed the passwords for the extensions to be a lot more secure, and also changed some of the anti-hacking settings on 3CX to blacklist an IP after 3 failed logins.... and also ticked the box on the extensions to only allow logins from the LAN. Hopefully that will stop them!
Are there any ways of protecting at the NAT router level? As a port needs to be opened for return traffic from an external SIP provider, is there a way of only allowing this traffic, and not from anyone else? I am presuming that the NAT is a "full cone NAT", rather than restricted (address) cone NAT. The router is a Netgear DGN1000 router if that is any help!
Thanks
Paul