"Call forbidden by administrator" when pressing 4 in voicemail via 999

Status
Not open for further replies.

SteveITS

3CX MVP
Silver Partner
Advanced Certified
Joined
Jun 20, 2018
Messages
4,424
Reaction score
2,153
The selected system for this post is not related to my testing but it's the only one that allows me to post here.

Issue was reported with Yealink phones, but I can replicate this on our system using my Desktop App, so at least two servers and multiple extensions.
  1. Receive voicemail from an external number
  2. Dial 999
  3. Listen to voicemail
  4. Press 4 to call back
  5. "Call forbidden by administrator" message plays
The same voicemail caller ID calls back successfully if I use the "phone" icon in the Desktop App for that voicemail entry. I do not see the failing outbound call attempt in the call log, at least on Medium.

It does work for internal call backs to voicemails left by other extensions.

Our client says this started about a week ago. Last week on the 16th we enabled automatic updates to install the recent security updates. Not sure how that would be related but that's the only change of which I'm aware.

Both our servers are 18u7, self hosted in our data center, KVM.
 
Last edited:
Under Settings then General Setting check
Enable Outgoing calls in Voicemail Menu

Though I would never do this it puts the system in jeopardy of call fraud
Use at your own risk
 
  • Like
Reactions: SteveITS
Will check. Did this change in u7? They say it used to work.
 
This may have, because like I said its a security issue for fraud. It is a use at your own risk feature
 
That works, thanks. Will relay pros and cons.

Seems like if that is off, 3CX shouldn't offer the call back choice.

How could that be exploited to a random number...spoof the inbound caller ID or have that number call, leave a short message, then the hacker calls that number back? (IOW separate the choices "call back from voicemail message" and "Enable Outgoing calls in Voicemail Menu")

Threw me when they said it used to work :rolleyes:
 
This may have, because like I said its a security issue for fraud. It is a use at your own risk feature
I keep seeing people say this without really giving a reason for how it can be used for fraud. Can you go into more detail or point me in the right direction to research this? I have been unable to find this information on my end.
 
I keep seeing people say this without really giving a reason for how it can be used for fraud. Can you go into more detail or point me in the right direction to research this? I have been unable to find this information on my end.
In my mind there are two things at play here...one is calling back from a voicemail someone left. The other is being able to log in from a non-3CX phone by calling in to the voicemail menu, logging in with a PIN, and making outbound calls. In other words someone just needs to guess your PIN to use your system to make calls. It seems 3CX covers both of those with the same allow/disallow setting. If they were separated that could allow the callback but not the new outbound call.
 
  • Like
Reactions: JordanDixon
Just be certain that your outbound rules disallow any "high value" calls, and that you regularly monitor long distance usage for any unusual increases..
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet