Country Code Not Blocking

Status
Not open for further replies.

sfernandes

Gold Partner
Basic Certified
Joined
Aug 28, 2020
Messages
24
Reaction score
5
Hello.

I had an event today where an extension on my 3CX system was breached.
They made a bunch of international calls with that extension. My 3CX system is
set to BLOCK all international country codes, and yet, they still manage to place a bunch of calls.
Most of them to the Cayman Islands. How is that even possible, since the 3CX system was suppose to block it?
 
do you have strong passwords everywhere? extensions, trunk, console ?
what have you done since you discover this ?
did you delete that extension ?
If this is from an extension is it possible to be a fraud from someone in the company ?

How did you seen they have done calls ? in logs ? your SIP provider didn't do some limitations automaticly?

Is it on premise or cloud pbx ?
Do you have a SIP Provider console to block all the calls on Provider side ?
 
Last edited:
do you have strong passwords everywhere? extensions, trunk, console ?
what have you done since you discover this ?
did you delete that extension ?
If this is from an extension is it possible to be a fraud from someone in the company ?

How did you seen they have done calls ? in logs ? your SIP provider didn't do some limitations automaticly?

Is it on premise or cloud pbx ?
Do you have a SIP Provider console to block all the calls on Provider side ?
Yes. All strong password.
First I changed the extension's ID and password. That didn't do much. A few minutes later they got back in the extension. And it was a hard random password to just guess.
On the Phones Tabs showed VitalPBX using that extension.
No, I don't believe that this is from anyone at the company. Very few and trust worthy people have access to this system. The same people that have access to our other systems (Company employees).
Our provider warned us first and blocked the calls, then we jumped on to check the 3CX side.
On the call logs, that specific extension was calling out to one particular number at first, then, to a whole bunch of international numbers. Once international was blocked. they called within the US.
Later, I deleted that extension and recreated it, and disabled it. Then hours later, around 12 to 1 am, there were a bunch of Anonymous calls to the IVR and to that same extension, but it was disabled, so extension did not answer.
PBX is on cloud on our Database.
And yes, SIP Trunk provider blocked the calls.
 
So your pbx is hosted on your servers? are they safe?
is it a Windows or linux pbx?
is it dedicated server ?
Perhaps you need some 3CX staff help to trap what happens on your PBX @JohnS_3CX or @YiannisH_3CX
First I changed the extension's ID and password. That didn't do much
if extension is set on app then it reprovision alone after you did the change, so my idea would be to delete that extension.
 
is there a firewall in front of PBX, did you set some restrictions on SIP provider IP for 5060 ?
 
So the calls were placed from a extension, after registering, or was this a direct SIP call? Was the originating IP, the same on all call attempts, did you attempt to blacklist that IP, or range?
Was this all happening from one extension number only?

If you have changed the set password, then unless someone else has admin access to 3CX, or have hacked into your network, or installed a key logger on your PC, I fail to understand how they could know the password and register a remote extension.
 
  • Like
Reactions: JohnS_3CX
Hi,

This is unfortunate to hear, but and extension can only make calls if they know the credentials, and if your outbound rules allow such calls in the first place.

- If remote access was disabled: perhaps the breach is indeed from within the the network since the the attacker was not blacklisted.

- For destinations that you do not allow: they also need a way to enable them on the PBX, so if this was not done then there's also the possibility that they stole trunk credentials, which means the PBX is not involved at all and they are registering directly on the provider (they provider should be able to see the IP of the one registering)
 
So the calls were placed from a extension, after registering, or was this a direct SIP call? Was the originating IP, the same on all call attempts, did you attempt to blacklist that IP, or range?
Was this all happening from one extension number only?

If you have changed the set password, then unless someone else has admin access to 3CX, or have hacked into your network, or installed a key logger on your PC, I fail to understand how they could know the password and register a remote extension.
Hi.
I blocked 3 different IPs, 2 from the same range, the other one was a different range. All of them showed as VitalPBX connected to that specific extension. I changed the extension's ID and password and made it very complex. In about an hour, they were connected to that extension again. Once I deactivated that extension, I saw a bunch of calls trying to call that extension at once, and calling into the IVR also.
The 3CX system is in the cloud and is very restricted, admin access only within our private network.
SIP Trunk is whitelisted with our IP, no way to be used by someone else directly.
I am just as stunned as you are.
But 3CX did confirm that they were not blocking that specific number or area code to Cayman Island, and they will be fixing that on the next release.
 
Hi,

This is unfortunate to hear, but and extension can only make calls if they know the credentials, and if your outbound rules allow such calls in the first place.

- If remote access was disabled: perhaps the breach is indeed from within the the network since the the attacker was not blacklisted.

- For destinations that you do not allow: they also need a way to enable them on the PBX, so if this was not done then there's also the possibility that they stole trunk credentials, which means the PBX is not involved at all and they are registering directly on the provider (they provider should be able to see the IP of the one registering)
Hey John.
We failed in strengthening our outbound rules, we are reviewing that. But 3CX support also confirmed that Cayman Island, or at least that specific number was not being blocked and they will fix it on the next release. The attacker was black listed 3 times, 2 IPs in the same range, 1 IP from another range, all with the same name (VitalPBX).
After disabling the extension, many calls as Anonymous tried calling that extension with no answer and calling the IVR. So I blocked Anonymous calls..

They used the extension and not the Trunk, the trunk is whitelisted with our IP, and the call log clearly showed that specific extension being used to dial out to many or specific numbers in a row, with a pattern. Even after blacklisting that IP and changing the ID and password of the extension, they were able to get in the extension after a few hours. That's when I completely disabled the extension.
 
Have you checked if the computer from where you did the change is out of leaks?
 
We work on a private network, VDIs connected on a cloud through a VPN on the same Clusters. So basically every change I did was within an internal network. But luckily the attacks have stopped. All I'm doing now is locking up the house and working on restricting the phone system as best as possible.
We have over 10 3CX sites, some are within the same public network range, others are part of another network. Only 1 specific IP from that range that received the attacks.
 
so strange you got that problem as you seem to be already in closed world, it's over my understanding:oops:
 
If I were 3CX, I'd be VERY interested in looking over the logs, in an attempt to understand how this was done, and prevent it in the future, Cayman Island number issue aside.
 
  • Like
Reactions: JohnS_3CX
@sfernandes

You can send an email to [email protected] and inform our data protection and security officer.

They may be able to see if they can assist you further.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,964
Messages
590,001
Members
164,869
Latest member
hpgitsupport