Getting Hacked several times

Status
Not open for further replies.

mohaked

New User
Joined
Jul 6, 2022
Messages
1
Reaction score
0
Hello,
we have been using the 3cx self hosted for a while. Recently we got hacked calles are being made to different country from extensions. The calles are happening during night or office closing hour. We have check our security starting from firewalls. Non of our other systems have been hacked. We have changed the admin and all provisioned phones password to complex. Still same thing. What is the solution for this vulnurability. Any one experienced sames issue?
 
Firstly, I would give this document a read.

https://www.3cx.com/3cxacademy/videos/advanced/security-with-3cx-phone-system/

3CX should not be the first line of defense against the internet.

Check that your extensions are using secure, generated passwords from 3CX.

assuming it's the same extension all the time?

I would set the logging to verbose and see how the attack is happening.

Also, look at modifying your outbound rule permissions and allowed country codes so that it's more restrictive.

you can also disable external calls out of hours.
 
If they have installed/connected an app, changing passwords doesn't disconnect them. Have a read through:

https://www.3cx.com/community/threads/disable-extension.79188/post-364333
https://www.3cx.com/community/threads/outbound-call-hack.113999/
https://www.3cx.com/community/threads/user-extension-regenerate.78460/

"grant the Extension your System Administrator uses the "Perform receptionist operations like set status, set reminders (wake-up call), Assign and Clear extensions (Check-in/out)" rights from the Extension Settings.

Then all the admin needs to do is:
  • Log in through their Web Client and press "Clear" for the Extension that was compromised (this changes the Provisioning File name).
  • Log into the Management Console and in Extensions, press the "Regenerate" button for this extension (changes SIP Username + Password)
This should both block an already provisioned client from being able to re-download its configuration and change the SIP Authentications credentials."

Also you can block calls to other countries. 3CX wrote several blog posts on hacking/security:
https://www.3cx.com/?s=Don’t+be+“THAT”+Guy+
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet