- Joined
- Aug 16, 2016
- Messages
- 58
- Reaction score
- 19
https://www.3cx.com/blog/voip-howto/call-fraud/
Just wanted to share with everyone that I have witnessed a call fraud on 3CX.
The attacker has managed to reach 3CX from inside LAN and have used "weak" credentials that were put in place by pre-v15.5SP6 version of 3CX.
You might have noticed that since the latest patch 3CX is forcing you to not only generate strong passwords for extensions but also to generate a strong user id used for the SIP registration so you cannot put the same user ID as is the number of the extension, for example.
3CX might have been on to something when they forced us to change all our passwords and usernames a few months back, so my advice to everyone is that if you haven't done it yet - go upgrade to the latest 3CX version and REGENERATE user ID's and passwords for all extensions.
Also, if anyone have had similar experience and is willing to share I would like to know because I'm still not sure how the attacker knew these passwords.
Just wanted to share with everyone that I have witnessed a call fraud on 3CX.
The attacker has managed to reach 3CX from inside LAN and have used "weak" credentials that were put in place by pre-v15.5SP6 version of 3CX.
You might have noticed that since the latest patch 3CX is forcing you to not only generate strong passwords for extensions but also to generate a strong user id used for the SIP registration so you cannot put the same user ID as is the number of the extension, for example.
3CX might have been on to something when they forced us to change all our passwords and usernames a few months back, so my advice to everyone is that if you haven't done it yet - go upgrade to the latest 3CX version and REGENERATE user ID's and passwords for all extensions.
Also, if anyone have had similar experience and is willing to share I would like to know because I'm still not sure how the attacker knew these passwords.