"Compromised" 3CX Server? Incoming call not coming from any registered trunk.

Status
Not open for further replies.

netval

New User
Joined
Mar 19, 2022
Messages
9
Reaction score
2
Hi everyone,
A couple of hours ago, I received a call on my extension (1000) registered on the Android App. Several trunks are configured on the system, but currently, only one entry route. Among other things, at the time in which I received the call 19:44 (Italian daylight saving time), if it had passed through the entry route, the call would have had to go through a Call Flow that manages IVR and opening/closing times, in that at the most it should have recited the closing time. But from the LOGs, there is no trace from which trunks the call came (it seems to me that it did not come from a trunk)

The only trace of the caller number + 393883832XXX can be found in CDRLogs. Below I report the trace in cdr.log

Call 274,00000180A9EBD9D4_4,00:00:45,2022/05/09 17:44:07,2022/05/09 17:44:27,2022/05/09 17:45:12,TerminatedBySrc,+393883832803,Ext.1000,10004,1000,1000,,,,,,,,Chain: +393883832803;Ext.1000;,Line,Extension,,+393883832XXX,UserName,,

I don't understand home has happened. Has the mobile app tunnel been compromised in some way? Who can help me? Please understand what happened and understand the above log track?

Thank you so much
 
Hi @netval

In your trunks page search for 10004. You should end up with one trunk. That is where the call came from according to the CDR log
 
Hi @YiannisH_3CX
You're absolutely right. I made a mistake!
Usually, even from reports called in the web interface, I am accustomed to seeing the input route's name on which the incoming call has passed. However, I see only the names with which they are renamed in the trunk list. I don't see the numeric identifier. How can I find the identifier?

I apologize for my blunder. In fact, by mistake on an unused trunk, but configured, I had let an incoming call be forwarded directly to the extension 1000 on my Mobile App.

Why in the call report if the call did not pass for a route do not indicate the name of the trunk, as in the logs is indicated numerical indicative?

I still apologize and confirm that 3CX is absolutely safe and a beautiful product!

Thank you very much for your quick and accurate response.
 
I see only the names with which they are renamed in the trunk list. I don't see the numeric identifier. How can I find the identifier?
You mean the 10004 number? That is an internal extension number assigned to the trunk by the system and you can only see that in logs. It will not be visible in reports.

I am glad you were able to identify the cause and happy I could assist.
 
Hi @YiannisH_3CX
Thanks again for your help.
One last question, but in this case, I had an application process that generates reports, would I not have been able to associate the call to the trunk of origin? To have a report that can associate this information, is it necessary that the call is necessarily destined for an entry route and not directly to an extension?
Thank you so much
 
I am not sure how you are generating your reports but if you are using the CDR data then you should be able to associate the call to a trunk. In the example you provided the trunk is the 10004 number displayed so you should be able to easily associate the call to a trunk even it the destination is an extension.
 
I am not sure how you are generating your reports but if you are using the CDR data then you should be able to associate the call to a trunk. In the example you provided the trunk is the 10004 number displayed so you should be able to easily associate the call to a trunk even it the destination is an extension.
Hi dear @YiannisH_3CX,
I mean that in this case, if I have to propose a report, the number "10004" means nothing to the reader. I would like to know if, from the trunk's internal identifier, it is possible to obtain the name assigned during the creation phase in 3CX. In short, a report must in some cases, show "talking labels."
Is there a solution to this circumstance?
Thank you very much for your patience and the time you have dedicated to me.
Thanks again!
 
I am afraid that by default you can either match the call to the trunk by the called number or by the internal extension number. If you preparing reports manually using the CDR you can always replace the 10004 with the trunk name before the creation of the report.
I cannot think of another way to do so.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,973
Messages
590,074
Members
164,895
Latest member
jasonkkrause