Failed register attempt results in random calls from extension

Status
Not open for further replies.

Mike O

Customer
Joined
Dec 7, 2020
Messages
3
Reaction score
0
We're experiencing an issue on 3CX v18.0.1.237 where a failed registration attempt results in multiple calls being created from the requested extension (which doesn't exist). This has happened twice now, first on [email protected], now on [email protected]. Both originated from the same IP range which we have blocked. This appears to be an active exploit as this wasn't an issue in v16.

Our host is anonymised to HOST.com and the external redirect to 00XXXXXXXXXX

Activity log:

Code:
01/12/2021 16:02:24 - [CM503003]: Call(C:2308): Call to <sip:[email protected]:0> has failed; Cause: 487 Request Terminated/INVITE from 127.0.0.1:5483
01/12/2021 16:02:24 - [CM503003]: Call(C:2308): Call to <sip:[email protected]:0> has failed; Cause: 487 Request Terminated/INVITE from 127.0.0.1:5483
01/12/2021 16:02:12 - [CM503003]: Call(C:2306): Call to <sip:[email protected]:0> has failed; Cause: 487 Request Terminated/INVITE from 127.0.0.1:5483
01/12/2021 16:02:12 - [CM503003]: Call(C:2306): Call to <sip:[email protected]:0> has failed; Cause: 487 Request Terminated/INVITE from 127.0.0.1:5483
01/12/2021 16:02:12 - [CM503003]: Call(C:2306): Call to <sip:[email protected]:0> has failed; Cause: 408 Request Timeout/INVITE from local
01/12/2021 16:02:00 - [CM503003]: Call(C:2306): Call to <sip:[email protected]:0> has failed; Cause: 487 Request Terminated/INVITE from 127.0.0.1:5483
01/12/2021 16:02:00 - [CM503003]: Call(C:2306): Call to <sip:[email protected]:0> has failed; Cause: 487 Request Terminated/INVITE from 127.0.0.1:5483
01/12/2021 16:01:51 - [CM503003]: Call(C:2306): Call to <sip:[email protected]:0> has failed; Cause: 408 Request Timeout/INVITE from local
01/12/2021 16:01:39 - [CM503003]: Call(C:2306): Call to <sip:[email protected]:0> has failed; Cause: 487 Request Terminated/INVITE from 127.0.0.1:5483
01/12/2021 16:01:39 - [CM503003]: Call(C:2306): Call to <sip:[email protected]:0> has failed; Cause: 487 Request Terminated/INVITE from 127.0.0.1:5483
01/12/2021 16:01:12 - [CM102001]: Authentication failed for AuthFail Recv Req REGISTER from 141.98.10.71:57511 tid=e16dc22e8455854f Call-ID=eM0R5vj4WeKMNIlOSy3i-A..:
REGISTER sip:HOST.com SIP/2.0
Via: SIP/2.0/TCP 141.98.10.71:6094;branch=z9hG4bK-524287-1---e16dc22e8455854f;rport=57511
Max-Forwards: 70
Contact: <sip:[email protected]:6094;transport=tcp>;+sip.instance="<urn:uuid:C6E26AAD-797A-24C0-90B4-69900D3BA796>"
To: "3155"<sip:[email protected]>
From: "3155"<sip:[email protected]>;tag=9a2d1002
Call-ID: eM0R5vj4WeKMNIlOSy3i-A..
CSeq: 2 REGISTER
Expires: 3000
Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, NOTIFY, MESSAGE, REGISTER, SUBSCRIBE, INFO
Proxy-Authorization: Digest username="3155",realm="3CXPhoneSystem",nonce="414d535961a79c4821:b45a0166aa2d7643abe6428b8cf69479",uri="sip:HOST.com",response="4855bd8c534e4c1ef188d6845de86e9c",algorithm=MD5
Supported: replaces
User-Agent: Yealink
Allow-Events: hold, talk, conference
Content-Length: 0

; Reason: Credentials don't match, check that authorization-ID and password match the ones in extension settings
01/12/2021 16:01:12 - Got REGISTER for foreign registrar: registrar host <sip:@HOST.com:0/UDP> is not mine!



Call log:

Code:
01/12/2021 16:02:00    3155:US Support (3001)    00XXXXXXXXXX    Not Answered
01/12/2021 16:02:00    3155    Q US Support (9941)    Not Answered
01/12/2021 16:01:48    3155    Q US Support (9941)    Not Answered
01/12/2021 16:01:40    3155:US Support (3001)    00XXXXXXXXXX    Not Answered
01/12/2021 16:01:36    3155    Q US Support (9941)    Not Answered
01/12/2021 16:01:24    3155    Q US Support (9941)    Not Answered
01/12/2021 16:01:20    3155:US Support (3001)    00XXXXXXXXXX    Not Answered
01/12/2021 16:01:12    3155    Q US Support (9941)    Not Answered
 
Hi!

So the REGISTER request you posted is handled correctly, the credentials don't match so the system, rejected it.

Now in what could have triggered calls would be an INVITE request. Contrary to what most people believe, you don't need to be registered to make a call, you can simply send an INVITE with authentication of course and that can also trigger a call.

So, check your logs to find an INVITE request and check the logs surrounding that.

If your logs are already set to Verbose in Dashboard --> Activity Log --> Settings, then in the upper-right corner click "Support" and then "Generate Support Info".
Open the email you get in the admin email inbox, download the file, upload it to a file sharing service of your choice (GDrive, Dropbox, WeTransfer, etc) and send me the download link in a PM.
 
Thanks @NickD_3CX - Logging is currently medium, will adjust to verbose in the hopes that this occurs again.

I understand you on the INVITE requests, they don't concern me, in this case it was because the phantom extension dialled our main queue (9941) in which 3001 is the primary agent. If you check the call log at the time of the failed registration you can see a call originating from 3155 an extension which doesn't exist on our platform. Is this possibly a logging issue?

This occurs until all concurrent calls are taken up, we then start receiving email errors. There is just silence on the other side of the line. This has occurred twice now, from the same IP range with the EXACT same modus operandi, different (non-existent) extensions each time.

Here are the logs from the previous incident:

Activity log:

Code:
30/11/2021 19:57:50 - [CM303003]: There are no available outbound lines on gateway BT at this time. First line: Lc:10002(@UK - BT[<sip:[email protected]:0/UDP>])
30/11/2021 19:57:49 - Call to T:Extn:1111@[Dev:sip:[email protected]:5483;rinstance=e49b6b8a4e974950] from L:2065.1[Line:10002<<00] failed, cause: Cause: 486 Busy Here/INVITE from 127.0.0.1:5483
30/11/2021 19:57:49 - [CM503003]: Call(C:2065): Call to <sip:[email protected]:0> has failed; Cause: 486 Busy Here/INVITE from 127.0.0.1:5483
30/11/2021 19:57:33 - [CM503003]: Call(C:2062): Call to <sip:[email protected]:0> has failed; Cause: 408 Request Timeout/INVITE from local
30/11/2021 19:57:16 - [CM503003]: Call(C:2060): Call to <sip:[email protected]:0> has failed; Cause: 408 Request Timeout/INVITE from local
30/11/2021 19:57:15 - [CM503003]: Call(C:2062): Call to <sip:[email protected]:0> has failed; Cause: 487 Request Terminated/INVITE from 127.0.0.1:5483
30/11/2021 19:56:51 - [CM503003]: Call(C:2060): Call to <sip:[email protected]:0> has failed; Cause: 487 Request Terminated/INVITE from 127.0.0.1:5483
30/11/2021 19:56:51 - [CM503003]: Call(C:2060): Call to <sip:[email protected]:0> has failed; Cause: 487 Request Terminated/INVITE from 127.0.0.1:5483
30/11/2021 19:56:41 - [CM503003]: Call(C:2058): Call to <sip:[email protected]:0> has failed; Cause: 408 Request Timeout/INVITE from local
30/11/2021 19:56:25 - [CM503003]: Call(C:2058): Call to <sip:[email protected]:0> has failed; Cause: 487 Request Terminated/INVITE from 127.0.0.1:5483
30/11/2021 19:56:01 - [CM102001]: Authentication failed for AuthFail Recv Req REGISTER from 141.98.10.154:61180 tid=9c592f63f921a92d Call-ID=uYPTrp-OnEh2b5iFUN-nVw..:
REGISTER sip:HOST.com SIP/2.0
Via: SIP/2.0/TCP 141.98.10.154:8221;branch=z9hG4bK-524287-1---9c592f63f921a92d;rport=61180
Max-Forwards: 70
Contact: <sip:[email protected]:8221;transport=tcp>;+sip.instance="<urn:uuid:0ECD6431-A344-74C5-F39D-34852461FD8D>"
To: "00"<sip:[email protected]>
From: "00"<sip:[email protected]>;tag=e6315f05
Call-ID: uYPTrp-OnEh2b5iFUN-nVw..
CSeq: 2 REGISTER
Expires: 2000
Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, NOTIFY, MESSAGE, REGISTER, SUBSCRIBE, INFO
Proxy-Authorization: Digest username="00",realm="3CXPhoneSystem",nonce="414d535961a681d125:205991da41d1ccc5923f5f0af7288aad",uri="sip:HOST.com",response="41d65c4767424f906015d47b776e4cdc",algorithm=MD5
Supported: replaces
User-Agent: Yealink
Allow-Events: hold, talk, conference
Content-Length: 0


; Reason: Credentials don't match, check that authorization-ID and password match the ones in extension settings
30/11/2021 19:56:01 - Got REGISTER for foreign registrar: registrar host <sip:@HOST.com:0/UDP> is not mine!



Call log:

Code:
30/11/2021 19:57:50    IVR (IVRForward)    00ANSWERINGSERVICE    Not Answered
30/11/2021 19:57:50    00    VMail (1111)    00:00:04
30/11/2021 19:57:50    00    IVR (IVRForward)    00:00:00
30/11/2021 19:57:49    00    9941    Not Answered
30/11/2021 19:57:49    00    ANSWERINGSERVICE (1111)    Not Answered
30/11/2021 19:57:40    00    ANSWERINGSERVICE (1111)    00:00:30
30/11/2021 19:57:39    00 (1111)    00ANSWERINGSERVICE    00:00:30
30/11/2021 19:57:37    00    Q US Support (9941)    00:00:53
30/11/2021 19:57:25    00    Q US Support (9941)    Not Answered
30/11/2021 19:57:15    00    US Staff (3001)    00:00:48
30/11/2021 19:57:15    00:US Support (3001)    00XXXXXXXXXX    00:00:48
30/11/2021 19:57:13    00    Q US Support (9941)    00:00:59
30/11/2021 19:57:01    00    Q US Support (9941)    Not Answered
30/11/2021 19:56:51    00    US Staff (3001)    00:00:10
30/11/2021 19:56:51    00:US Support (3001)    00XXXXXXXXXX    00:00:00
30/11/2021 19:56:49    00    Q US Support (9941)    Not Answered
30/11/2021 19:56:37    00    Q US Support (9941)    Not Answered
30/11/2021 19:56:25    00    Q US Support (9941)    00:00:50
30/11/2021 19:56:24    00:US Support (3001)    00XXXXXXXXXX    00:00:01
30/11/2021 19:56:24    00    US Staff (3001)    00:00:20
30/11/2021 19:56:13    00    Q US Support (9941)    00:00:38
30/11/2021 19:56:01    00    Q US Support (9941)    00:00:23
 
I understand you on the INVITE requests, they don't concern me, in this case it was because the phantom extension dialled our main queue (9941) in which 3001 is the primary agent. If you check the call log at the time of the failed registration you can see a call originating from 3155 an extension which doesn't exist on our platform. Is this possibly a logging issue?
I understand, technically speaking the authentication username and password could have been compromised without actually knowing the Extension Number, and it just happens the "3155" happens to match something else on the system, like a SIP Trunk DID (just an example).
When you create a brand new extension in 3CX, the Extension Number, Auth ID and Auth Password are 3 different values.

General advice in this case is:
  • Regenerate SIP ID and Auth Passwords for all extensions from the "Users" node in the Management Console. IF you are using IP Phones, reboot them so they pick up the new credentials via the provisioning link. For 3CX Apps, just instruct users to close the restart the apps.
    1638445223783.png
  • For all extensions that don't have a remote STUN IP Phone registered to them, enable option "Disallow use of extension outside the LAN" in the Extension Settings in the "Options" tab.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,083
Members
164,901
Latest member
Silent_Guru