Failed authentications

Status
Not open for further replies.

comp_plus

Customer
Joined
Mar 30, 2023
Messages
3
Reaction score
0
I have been getting alerts of failed authentications from numerous IP addresses on my client system.
They are on the 3CX hosted platform.
The emails says:
----------------------------------------------------------
Affected Module: SIP Server
User agent: 3CX Phone System

Reason: Too many failed authentications!

This IP Address XXX.XXX.XXX.XXX has made numerous attempts to authenticate with 3CX using invalid credentials. In response, 3CX has blacklisted this IP and denied any further requests.

No action is required on your behalf.

-------------------------------------------------------------

Even though it says that no action is required.
I still think that there has to be something that needs to be done or eventually they will be able to log in.

This started on 03/31 not sure if this is related to the supply chain attack or if this is just a coincidence but I do know that they have been live for 3 months and this is the first time this happend.

Here is the list of the blocked IP addresses:
201.184.68.66
103.47.242.155
51.148.65.131
221.224.68.138
146.70.137.226
43.159.46.239
123.130.41.153
170.0.61.70
146.70.137.130
72.8.219.182
81.138.18.84
146.70.137.154
193.160.129.220
51.105.247.248
102.37.219.234
20.117.118.61
20.55.96.89
20.91.188.27
146.70.137.210

Anyone has experience with these things that has some advice on what to do about this?
Should I change the passwords on all the users to a longer / stronger passwords?
Is there a way to change the IP address / subdomain of the cloud host of the system?
 
There is no relationship to the supply chain attack. This is very common and is the result of robotic agents that usually operate from compromised servers and workstations worldwide. An example of this is called SipVicious (google it). The "attacks" are harmless if you have 3CX configured normally and no red flags on any of your extensions.

Best,
 
There is no relationship to the supply chain attack. This is very common and is the result of robotic agents that usually operate from compromised servers and workstations worldwide. An example of this is called SipVicious (google it). The "attacks" are harmless if you have 3CX configured normally and no red flags on any of your extensions.

Best,
thank you I will keep monitoring it.

I got to say with 20 emails in 3 days for one client. How do you keep track of all these when you have 20 or more clients and all have these type of attacks?
 
thank you I will keep monitoring it.

I got to say with 20 emails in 3 days for one client. How do you keep track of all these when you have 20 or more clients and all have these type of attacks?
From my experience this comes always in waves, you got months where there are less attacks, and others with more.
There are some mechanics to help with that, especially with the messages from you, cause theese indicate that someone tries to autheticate against the sip port 5060:

-Check that under security->Anti Hacking The Automatic global 3CX Blacklist is active, so that your PBX will get blacklists with known attacking IPs
-make sure that for no, really no extension under Options--> Block remote extensions via STUN is enabled, always use the SBC protocol
-In the extension overview, check for red triangles with exclamation marks. That indicates weak passwords in the extension, if present click regenerate and create new credentials for that extension
-Double check the allowed country codes under Security. Just allow countrys you really need to call to

You could also use geoblocking on your firewall or just allow communication on port 5060 with your providers IPs and you can restrict management console access in 3CX admin panel to your internal subnet

Oh, and you can increase the Blacklist time interval in the security settings to for ex. 1 week or so and decrease the failed authentication protection (must be at least 3 if i'm correct)
 
Last edited:
From my experience this comes always in waves, you got months where there are less attacks, and others with more.
There are some mechanics to help with that, especially with the messages from you, cause theese indicate that someone tries to autheticate against the sip port 5060:

-Check that under security->Anti Hacking The Automatic global 3CX Blacklist is active, so that your PBX will get blacklists with known attacking IPs
-make sure that for no, really no extension under Options--> Block remote extensions via STUN is enabled, always use the SBC protocol
-In the extension overview, check for red triangles with exclamation marks. That indicates weak passwords in the extension, if present click regenerate and create new credentials for that extension
-Double check the allowed country codes under Security. Just allow countrys you really need to call to

You could also use geoblocking on your firewall or just allow communication on port 5060 with your providers IPs and you can restrict management console access in 3CX admin panel to your internal subnet

Oh, and you can increase the Blacklist time interval in the security settings to for ex. 1 week or so and decrease the failed authentication protection (must be at least 3 if i'm correct)
Thank you all good point.
I am already doing most of those except geoblocking since we use 3cx hosting and not self hosted so I have no control over that.
as far and management console access my ip address can change so limiting it would be a challenge
 
I'm getting same kind of attempts on one 3CX hosted PBx, almost 30 IPs a day are blacklisted and also I get provisioning tries from outside customer location .(tries are coming really far almost 1000 kms, and IPV6 seems located in France near German border)
There's no way to take action on 3CX hosted and this is something that makes me nervous.
 
I am going to move this thread if you dont mind as its not related to the supply chain attack @quadrant pointed out correctly . On Digital ocean 3CX hosted we block these at cloud provider level but we might have too check if this was implemented in france as well.
 
I started getting this wave late Thursday night, here in the US. They come in waves... Trying to connect bridges and trying to log into extensions (usually 3-digit and in the 100s).
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet