Blacklisted Ip's

Status
Not open for further replies.

i3

Silver Partner
Basic Certified
Joined
Jun 6, 2012
Messages
50
Reaction score
4
Has anyone else been receiving an increase of blacklisted ip notices? I have a handful of systems some in the cloud and some onsite. Sunday and Monday night I got a handful of blacklisted notices across some of these machines all from the same ip address which resolves to an Italian ip address. I can't seem to find any kind of relation between the affected systems/clients.
 
Yes. We saw blacklist notices from multiple systems, across both on-premise and cloud hosted systems, from one IP address.

Is it possible that the attacker has accessed the 3CX DNS records (ours are all *.3cx.com.au).

Frank
 
Same here - Mostly European ip addresses
 
Hackers will typically scan sequential IP's looking for a response. If they get one, even if it is blocked (for a time), by 3CX, or your router/firewall, they will no doubt try again (they now know you're there), usually from a similar originating IP. That re-try can happen almost immediately (from a similar IP), or come a week or so later. Over the last month , while retaining the same (dynamic IP), I have only seen about 6 attempts. Over the years I have had to block a lot of IP ranges, which, I'm sure, has cuts down on hack attempts.
 
Over the years I have had to block a lot of IP ranges, which, I'm sure, has cuts down on hack attempts.

Should it be possible you share a listing of all those ranges?

The 3cx IP Blacklist process, keep us blind about what's done, we don't need technical details but almost general lines would be useful, for now we just need to trust 3CX is doing the best for us (surely real), this is a little bit short to stay fully zen.
Sometimes in less than 10 minutes all my 3cx are scanned by the same IP.

I'd love to know for example:
  1. how many simultaneous attacks are needed before an ip is blocked by 3CX?
  2. How much time before this blocked IP is propagated to World PBX?
  3. How many time those IP stay in Blacklist? For ever? or few time ?
I know that we are primarily responsible for the security of our facilities, but it would comfort to know at least what the overlay protection offered by 3cx, does.
 
Unfortunatly, i have about 7 pages of blacklisted IPs, singles, and multiple subnets, and you can't cut and paste them.
 
how are you duplicating them on your 3CX sites, you don't do this manually ?
 
Yes, I do. Although one site (of 3) has almost no traffic or outside trunks, so It is not a priority.
 
is there a way to share a list of black listed IP address which would then be share all on 3cx?
 
That is the way the new feature on Version 16 would appear to work. Look for Global 3CX IP Blacklist in the security settings.
 
Should it be possible you share a listing of all those ranges?

The 3cx IP Blacklist process, keep us blind about what's done, we don't need technical details but almost general lines would be useful, for now we just need to trust 3CX is doing the best for us (surely real), this is a little bit short to stay fully zen.
Sometimes in less than 10 minutes all my 3cx are scanned by the same IP.

I'd love to know for example:
  1. how many simultaneous attacks are needed before an ip is blocked by 3CX?
  2. How much time before this blocked IP is propagated to World PBX?
  3. How many time those IP stay in Blacklist? For ever? or few time ?
I know that we are primarily responsible for the security of our facilities, but it would comfort to know at least what the overlay protection offered by 3cx, does.

1- I have set mine to 3 wrong login attempts
2- not sure
3- i set mine to the year 2040

I have also added entire ip ranges blocked. Once an new blacklisted ip pops up, i block the entire range.
 
@PCX101

Local security settings for 3cx is not what i'm asking, just wanted to know a minimum about 3CX blacklisting process
 
If you are using the Debian version, do your self a favor and install DenyIP and IPSet. There is ZERO reason for any PBX to be exposed to ANY other IP attached devices with the exception of the Hosted users and the SIP provider and the 3CX servers for updates. Oh and the Debain mirrors for updates. Do not rely on 3CX to be the sole source of security for your business or your customers. Do your due diligence and setup IPSet to geo-block, you can pull down a complete list of every subnet per country from a number of sources at no cost. I run a negative filter that blocks everything except the USA. Then I use DenyIP to nail the SSH requests. Spent a couple of hours testing and figuring out the details and the results are excellent.

3CX has improved the security capabilities significantly but it is NOT their primary focus, it is yours and yours alone. Now I have three layers of defense versus just one so and you should too.
 
I have a mix of debian and windows machines, 3CX ask to use dedicated PC to phone system without other process so even if it's good job to enforce security with added software is it always a 3CX supported solution ?
 
I have a mix of debian and windows machines, 3CX ask to use dedicated PC to phone system without other process so even if it's good job to enforce security with added software is it always a 3CX supported solution ?

Security is one of our primary focus points, but the PBX was built with the customer having an external firewall in mind.

We do not recommend to install additional software on the PBX machine because it could cause unexpected behavior. You can do it of course if you want but in answer to your question, this is not a supported scenario for the above reason.
 
Yes I get it but clearly this thread speaks to the contrary for a variety of reasons. We are dealing with two different animals: Windows and Linux, I stopped using Windows server for 3CX a while back so my focus and responses are based on Debian. Both OS's have a firewall capabilities built in and they are tools to be used to the advantage of the implementer not the exploiter. 3Cx's position is don't make it harder for us to support you, I get that as well. IPTables is a very powerful tool when you know what you are doing, it will also lock you out if you don't.

Not using it to your own security advantage is a fallacy on your own behalf. Adding one line: 10865 in-conjunction with IPset will dramatically improve your security and all most eliminate the security issue folks are discussing in this forum. Shrugging off the responsibility that security is the on firewall is again a fools choice, the majority of folks who have to deal with VoIP are out of their element and need help. 3CX is aiding them by adding in new features but it still does not solve the problem as it exists today.

The majority of the people who use this forum believe that the 3CX server should solve all their issues related to VoIP. Whether it be routing, DHCP, security, interoperability, Custom Phone Templates, etc.. 3CX is just an application running on a server and the focus should be how to make it run better and more secure. The Debian OS provides many simple easy to implement solutions that do just that without compromising 3CX support efforts or chewing up CPU cycles or memory on the server.

The 3CX Debian installation script manipulates the IPTables rules to its advantage. Leaving those changes in place and tweaking a couple other things again will improve security dramatically.
 
Status
Not open for further replies.

Forum statistics

Threads
111,926
Messages
589,762
Members
164,799
Latest member
RicoDinero