- Joined
- Mar 30, 2023
- Messages
- 3
- Reaction score
- 0
I have been getting alerts of failed authentications from numerous IP addresses on my client system.
They are on the 3CX hosted platform.
The emails says:
----------------------------------------------------------
Affected Module: SIP Server
User agent: 3CX Phone System
Reason: Too many failed authentications!
This IP Address XXX.XXX.XXX.XXX has made numerous attempts to authenticate with 3CX using invalid credentials. In response, 3CX has blacklisted this IP and denied any further requests.
No action is required on your behalf.
-------------------------------------------------------------
Even though it says that no action is required.
I still think that there has to be something that needs to be done or eventually they will be able to log in.
This started on 03/31 not sure if this is related to the supply chain attack or if this is just a coincidence but I do know that they have been live for 3 months and this is the first time this happend.
Here is the list of the blocked IP addresses:
201.184.68.66
103.47.242.155
51.148.65.131
221.224.68.138
146.70.137.226
43.159.46.239
123.130.41.153
170.0.61.70
146.70.137.130
72.8.219.182
81.138.18.84
146.70.137.154
193.160.129.220
51.105.247.248
102.37.219.234
20.117.118.61
20.55.96.89
20.91.188.27
146.70.137.210
Anyone has experience with these things that has some advice on what to do about this?
Should I change the passwords on all the users to a longer / stronger passwords?
Is there a way to change the IP address / subdomain of the cloud host of the system?
They are on the 3CX hosted platform.
The emails says:
----------------------------------------------------------
Affected Module: SIP Server
User agent: 3CX Phone System
Reason: Too many failed authentications!
This IP Address XXX.XXX.XXX.XXX has made numerous attempts to authenticate with 3CX using invalid credentials. In response, 3CX has blacklisted this IP and denied any further requests.
No action is required on your behalf.
-------------------------------------------------------------
Even though it says that no action is required.
I still think that there has to be something that needs to be done or eventually they will be able to log in.
This started on 03/31 not sure if this is related to the supply chain attack or if this is just a coincidence but I do know that they have been live for 3 months and this is the first time this happend.
Here is the list of the blocked IP addresses:
201.184.68.66
103.47.242.155
51.148.65.131
221.224.68.138
146.70.137.226
43.159.46.239
123.130.41.153
170.0.61.70
146.70.137.130
72.8.219.182
81.138.18.84
146.70.137.154
193.160.129.220
51.105.247.248
102.37.219.234
20.117.118.61
20.55.96.89
20.91.188.27
146.70.137.210
Anyone has experience with these things that has some advice on what to do about this?
Should I change the passwords on all the users to a longer / stronger passwords?
Is there a way to change the IP address / subdomain of the cloud host of the system?