Hack attempt on one PBX only

Status
Not open for further replies.

AWS2P

Silver Partner
Basic Certified
Joined
Jan 9, 2014
Messages
5,076
Reaction score
1,096
Hi ,
I have a 3CX hosted pbx on which i can't change anything on port settings and this alone pbx is blacklisting IPs everyday .
It's boring even they are stopped by pbx security, I'd like to be able to do like i do on self hosted to restrain 5060 to SIP provider on IPV4 and V6 and then this prevent infinite listing attempt on pbx side.
For now pbx has already internal 3CX security settings set at high level and just today I 'm up to 100 blacklisted IPs.

On that site I use some Fanvil deskphones , in event log I can see lots and lots of provisioning failure like: (phones are X3SG and X4U all in 2.4.12 fw)
Provisioning file /provisioning/qu4mxxxxxxx8o/firmware/fanvil/version.txt requested by 2a:27a1 could not be generated (deleted part of ipv6)
This tryes are always registred with same French IPV6 adress out of my customers and about 1000kms far from me, near the Germany border.


Of course the Pbx is since it's beginning added to automatic BL.
is there something that you 3CX could do on this ?
 
Last edited:
I'd like to be able to do like i do on self hosted to restrain 5060 to SIP provider on IPV4 and V6 and then this prevent infinite listing attempt on pbx side.
You'd have to use a firewall that whitelisted only the IP of your VoIP providers (and 3CX for maintenance/updates), blocking all others. All devices could use the tunnel. Unfortunately, when using hosted, you can't place a physical fire device wall in front of the PBX.

These hackers are scanning ports constantly, looking for a response. As long as a port (5060) does respond, no matter which port is used, they will attempt to register, and/or make a direct SIP call.

I use a dynamic IP, which normally won't change until I force it to, which I do about once a week. It only takes a couple of days before the attempts start again.

It gets annoying.
 
You'd have to use a firewall that whitelisted only the IP of your VoIP providers (and 3CX for maintenance/updates), blocking all others. All devices could use the tunnel. Unfortunately, when using hosted, you can't place a physical fire device wall in front of the PBX.

These hackers are scanning ports constantly, looking for a response. As long as a port (5060) does respond, no matter which port is used, they will attempt to register, and/or make a direct SIP call.

I use a dynamic IP, which normally won't change until I force it to, which I do about once a week. It only takes a couple of days before the attempts start again.

It gets annoying.
Thanks Lee,
I don't understand what is the need to keep 5060 open worldwide when Stun is not allowed on hosted 3CX, I receive lots of notifications at each attempt and this is a little stupid to let a chance for someone to break the door while you can threw them away before
 
Other than your VoIP trunk provider(s), (or any non-Tunnel devices), is it really necessary to have port 5060 open to all?

The real question is...Can we have an option, when using hosted, to enable a list of whitelisted IPs that have access to port 5060, as we are unable deploy a Firewall?

I can see that, in this thread, the question is asked, and not really answered, other than to say that the Global Blacklist should suffice, which is not what some people want to hear.

https://www.3cx.com/community/threads/3cx-hosted-port-5060.81161/
 
Now we are all dealing with a real scenario of hack, it could be nice to have an improvment on this.
 
The recent Supply Chain Attack is a completely different animal than the internet hack attempts on port 5060, which have been going on for years. But, any improvement in security is a good move.
 
Yes for sure that's not same category, but only for today, I've seen 33 new IPs being blacklisted, that's always tensing me to see all this without being able to do something to stop them trying.
 
Morning,
this night 10 more IPs on a total of 134 now in Blacklist, do we are making an olympic game about who is getting Blacklist fully filled ?
 
8 days after..... an average of 22 IPs blacklisted a day.
1681369689828.png
Is there a chance 3CX you close port 5060 to SIP provider or let us ability to do so, on 3CX hosted ?

This pbx is a new one , only 2 months online, may we have to think IP range used by 3CX VMs could be permanently scanned ?
 
Last edited:
three days more and now
1681680841838.png
Do we have as only solution to let blacklist everything over the world when 3CX hosted ?

Don't you think it's a stupid idea to let everyone try to open your door ? even if you have a reinforced one.
 
Is there a chance 3CX you close port 5060 to SIP provider or let us ability to do so, on 3CX hosted ?

This pbx is a new one , only 2 months online, may we have to think IP range used by 3CX VMs could be permanently scanned ?
This is not an option for 3CX hosted instances as it cannot be done per instance. Also the instances need to be the same for management purposes. Also your providers IPs may change without warning.
I understand your concerns and you have valid reasons to be worried. Nothing on the internet is safe anymore so if you are that worried perhaps you should switch to self hosted so you can have full control over your firewall.
From our end we keep updating our global blacklist to prevent attempts from known IPs and the next update is focused on security to help reinforce systems.
On your end make sure you do not have weak passwords and you follow basic security guidelines.
 
Hello @YiannisH_3CX
Well I understand this is industrial process to be done on all 3CX hosted Vms but my point is just to say why 3CX let this open to the world , as you ask us to use only SBCs in front of 3CX hosted , so no STUN.
Yes SIP provider could change their IP, but don't you think for end customer, receiving daily several email notifications with blacklisted IPs is a good feeling for security to let them have?

and when they ask you to do something, you can't answer, sorry I have no hand on that , just don't matter, it's safe enough.

You said new update will be on security, is that kind of point will be in the scope ?

I have no weak passwords everywhere it's needed, but as it is a 3CX hosted VM, this is also on your side not only mine, if something is hacked, who will be responsible ?
1681982738030.png
 
Last edited:
Can you explain if something is different , I setup 2 new hosted 3CX pbxs last 48h and until now they are always 0 blacklisted IPs while the one installed 2 months ago is daily targetted and with no end.

Last hit parade
1682059676698.png
 
Last edited:
I suspect that they haven't discovered the IPs of the new installations... yet. They will eventually.

After I change public IP's it can take a week or two before the attacks, from new IPs, start again.
 
@leejor
Hello , just to compare , what is the rythm of blacklist on your PBXs ?
do you see less than 20 IPs blacklisted a day ?
Do you feel it stay always same volume day after day ?

on my side I see always same volume of IPs and I don't see any improvment day after day.
Is the first task of a PBx to become a blacklist box ?

top of the day
1682319947436.png
 
Looking back at email notifications, the last new blacklisted IP was the 7th of April, and before that, the 4th. That doesn't mean that no one is trying. If I look at the Activity Log, i can see a lot of attempts, it is just that they are already on the list.

What I have been doing, for a long time (every week or so, when I have a few new blacklisted IPs) is changing the last number of the blacklisted IP to zero, and the subnet to 255.255.255.0, and blocking for 20 years. I've seen to many of them simply increment the IP by 1, once blocked, and try again.
 
Well Thanks for answer, in my case I don't see same range IP but a lot of different each day, always 15 to 20 ips more each day.
Blacklist rythmn is continuous for me , no break.
At the writing time PBX blacklist content is 520 IPs.

In same time new pbxs blacklist , that are on line since a week now, are always on score 0 ???
 
Tonight new value
1682629751133.png
is there a chance 3CX global blacklist isn't working, since 10 days 2 new pbxs are always 0 ip blacklisted.
 
IPs on the 3CX blacklist don't show up as blacklisted IPs. Blacklisted IPs are ones that are local to your instance, either added manually or ones that were blocked but not detected on enough systems to earn a spot on the 3CX blacklist. Any chance you just have this system set to higher sensitivity than the other ones?
 
Any chance you just have this system set to higher sensitivity than the other ones?
Hi Cobaltit,
no Pbxs security settings are set exactly on same values, the one concerned is targetted continuously , until now tries never decrease or break day after day. That pbx is hosted 3CX and online since 3 months.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet