call fraud

Status
Not open for further replies.

Zvjer

Gold Partner
Advanced Certified
Joined
Aug 16, 2016
Messages
58
Reaction score
19
https://www.3cx.com/blog/voip-howto/call-fraud/
Just wanted to share with everyone that I have witnessed a call fraud on 3CX.

The attacker has managed to reach 3CX from inside LAN and have used "weak" credentials that were put in place by pre-v15.5SP6 version of 3CX.
You might have noticed that since the latest patch 3CX is forcing you to not only generate strong passwords for extensions but also to generate a strong user id used for the SIP registration so you cannot put the same user ID as is the number of the extension, for example.

3CX might have been on to something when they forced us to change all our passwords and usernames a few months back, so my advice to everyone is that if you haven't done it yet - go upgrade to the latest 3CX version and REGENERATE user ID's and passwords for all extensions.

Also, if anyone have had similar experience and is willing to share I would like to know because I'm still not sure how the attacker knew these passwords.
 
3CX has always been recommending the use of strong passwords. The fact that they enforce and strengthen it every other version is totally normal and expected by a company who cares about the security of its product.

I don't believe they are up to anything else than protecting the users who wouldn't take the necessary steps to ensure the security of their PBX. Most people act based on what's convenient for them and not what's right/secure.

Weak passwords, as per blog post you mentioned, is the number one reason PBXs (and other systems) get hacked. Also the fact that the attacker was from inside the Lan is an issue that the affected company should address..

Also, if anyone have had similar experience and is willing to share I would like to know because I'm still not sure how the attacker knew these passwords.

This could have happened in many ways.. (most of which fall under the admin's responsibility).
 
I'm not saying this is a definite, but you can use tools like SIP Vicious to crack extension numbers and passwords: http://blog.sipvicious.org/

Originally it was designed for auditing but in the wrong hands can cause all sorts of issues like you have experienced recently.

Normally this sort of behaviour occurs outside of office hours - at times when your clients/or yourself wont be in the office to recognise anything going on. I would limit outbound calls to a minimum at a SIP trunk level during this time to avoid anything like this happening again in the future.
 
I'm not saying this is a definite, but you can use tools like SIP Vicious to crack extension numbers and passwords: http://blog.sipvicious.org/

Originally it was designed for auditing but in the wrong hands can cause all sorts of issues like you have experienced recently.

Normally this sort of behaviour occurs outside of office hours - at times when your clients/or yourself wont be in the office to recognise anything going on. I would limit outbound calls to a minimum at a SIP trunk level during this time to avoid anything like this happening again in the future.
3CX blocks the majority of this kind of tools. Unless an admin has made changes to the system which allows them to go through such as removing the blocked user-agents, weakened the built-in security barriers etc
 
When you have installed the 3CX Windows Client, retrieving the password is very easy:
Get the provisioning URL from the following file:
C:\Users\[Username]\AppData\Roaming\3CXPhone for Windows\3CXPhone.xml
Get the provisioning file itself and the user/password will be available in clear text.
Also saved passwords in some browsers could easily be revealed.
 
C:\Users\[Username]\AppData\Roaming\3CXPhone for Windows\3CXPhone.xml
Get the provisioning file itself and the user/password will be available in clear text.
I'm aware of this and this is one thing I cannot fix on my own. The password actually isn't plain text, it's scrambled. But the config file that users get via email has password in plain text which is unfortunate.
 
When I get the provisioning file, I will get the passwords in clear text:
XML:
<AuthID>XXXXXXX</AuthID>
<AuthPass>XXXXXXX</AuthPass>
Is there a parameter to control this?
 
Provisioning file contains plaintext password, yes.
But after the 3CX client is configured - the password gets scrambled on HDD.
Unfortunately I don't know how to fix the plain text password "in tranzit".
 
Also, if anyone have had similar experience and is willing to share I would like to know because I'm still not sure how the attacker knew these passwords.
If you had random passwords in place, then you have to consider that it may very well be an "inside job". It might be disgruntled current, or former employee. Something such as that is a lot harder to guard against as they generally don't have to get by the firewall, for starters.
The real damage is done with long distance calls, so if your company does not call "everywhere", then limit what countries, or regions that can be reached. This is a good practice to follow normally, not just after you have found evidence of fraud. This can be done in 3CX, but also, in many cases, through your provider. Many will block calls over a set value, or to certain prefixes. This prevents premium value calls to certain countries, or even foreign mobile numbers which can be many times the cost of a land line call.
 
  • Like
Reactions: nub
But after the 3CX client is configured - the password gets scrambled on HDD.
Unfortunately I don't know how to fix the plain text password "in tranzit".
But the used provisioning file rest available, so it doesn't matter when the client itself is encrypting it, as the provisioning file can be revealed as long as the extension exists. I have not seen a mechanism, where the provisioning file will be inaccessible after it is once applied.
 
We manage our own SIP trunk portal too, so on the trunks we put daily spend plans which also helps. In this case IF you get hacked the cost is not so high.
It would be great if 3CX can build something like this daily spend plan on the trunk or extension side.
 
  • Like
Reactions: upCOM Labs
Status
Not open for further replies.

Forum statistics

Threads
111,916
Messages
589,717
Members
164,785
Latest member
Texas Clay -