Solved Desktop app and Tunnel question

Status
Not open for further replies.

SirPcsvA

Free User
Joined
Aug 2, 2018
Messages
13
Reaction score
2
Hi
We get bruteforce attacks all the time on the webinterface (default port 5001), despite using beeing subscribed to the 3CX global ip blacklist. So we deactivated the port forwarding to this port and told the users who use the webinterface to connect to some VPN before using the webinterface.
But then we noticed that the Android app and also the windows desktop client cannot show the contents of "Team" and "Contacts" tab any more. Which means these functions do not use the 3CX native tunnel.
So we have to keep the port forwarding on port 5001 active and accept bruteforce attacks?
Any idea how to handle this better?
Thank you.
 
Quite long ago but I feel I have to update this:
At the very same day I posted the above, the bruteforce attacks stopped. We didn't get a single blacklist notification since then.

This is quite suspicious and the first reason for that that is coming to my mind is that the bruteforce is done by some 3cx internal(s) who can refer my forum post to our IP address.

Of course it's my mistake not using some other account to post here that is not connected to our 3cx account.

Happy headaches
 
Hi there.

This is quite suspicious and the first reason for that that is coming to my mind is that the bruteforce is done by some 3cx internal(s) who can refer my forum post to our IP address.
How did you conclude this, as you can always check the IP address?
 
Hi @SirPcsvA,

ich stimme meinem Kollegen hier zu und bin mir nicht sicher wie Sie auf eine solche Schlussfolgerung kommen...
Wie @OlegR_3CX erwähnt, sieht man die IP Adressen und kann darüber eine IP-Geolocation fahren und herauszufinden wo sich diese Leute befinden.

Ergänzend velleicht hat es eher mit der Änderung des Standard Ports zu tun?
Möchte jetzt ungern diesen hier erwähnen und es für diese Leute einfacher machen einen Portscan durchzuführen.

Gerne können Sie sich bei Ihrem 3CX Partner oder bei unserem Kundendienst melden sodass wir diese Diskussion weiterführen.


Viele Grüße,

Marcos
 
  • Like
Reactions: OlegR_3CX
Hi there.


How did you conclude this, as you can always check the IP address?
I don't understand your question completely. What you mean by I can check IP address? Which IP to check for what?
Ergänzend velleicht hat es eher mit der Änderung des Standard Ports zu tun?
Möchte jetzt ungern diesen hier erwähnen und es für diese Leute einfacher machen einen Portscan durchzuführen.
Die Änderung des Standard ports habe ich sofort bei meiner Ersten Installation von 3cx vorgenommen. Das ist schon Jahre her. Seit dem habe ich den Port nicht wieder geändert. Selbstverständlich sollten sie diesen hier nicht erwähnen.
Hätte ich den Port zum Zeitpunkt meines Posts hier geändert, wäre das eine Erklärung für das Ausbleiben der bruteforce Versuche, ja.
 
Wie gesagt, es nur die beste und einfachste Erklärung für die Beobachtungen. Ich kann das nicht beweisen.
 
I don't understand your question completely. What you mean by I can check IP address? Which IP to check for what?
Once the IP are blacklisted, you can check them from your end to see from where the attack is coming from.
 
@SirPcsvA,

Perhaps I am completely misunderstanding what you are suggesting. I'm under the impression that you think someone within 3CX is performing brute-force attacks on your system. That would require a huge mental leap and a gigantic dose of conspiracy-minded thinking to suggest this.

Doing so could only serve to damage the reputation of 3CX (let alone exposure to legal action) and threaten the person's job. How would 3CX benefit from something like this? I can only assume that I have completely misunderstood your comment. Having worked for a time in the 3CX Support team, I can assure you there is nobody within 3CX doing anything approaching what you seem to be suggesting.

I offer the suggestion that you look elsewhere for the source of your attacks.
 
Sure there was misunderstanding. I am very good in being misunderstood.

I did lookup the attackers IP in WHOIS and I could not see a relation to 3cx, thought it was not necessary to tell you, because if they were related, it would be a completly different thing.

I want to apologize for posting this here, it was a mistake. The outcome had to be like this.

I am quite confident with your product.

I know that protecting an infrastructure from internal attackers is one of the most challenging tasks.

I wish you all the best for the future.
 
Best wishes to you too, and I think we can now close this thread.
Have a nice weekend guys ahead guys.
 
Status
Not open for further replies.

Forum statistics

Threads
111,973
Messages
590,079
Members
164,898
Latest member
grahamaskew