Hacked ! ** NOTE: ALWAYS UPGRADE TO LATEST SP ASAP

Status
Not open for further replies.
Re: Hacked !

mattlandis said:
Absolutely essential to have passwords that are secure.

For those not convinced: monitor inbound traffice attempts on port 5060 on your firewall and see how soon some unknown IP from outside tries to login...I just tested a system and several attempts in about 15 minutes.

Security is no joke with ip pbx! ;-)
matt

Mattlandis has spoken!
 
Re: Hacked !

Hi,

seems as our system also got hacked and the group used the NYE weekend to place calls for €3000+..

I understand from this thread that the admin as well as extension passwords have to be secure.

What i dont get is the following:

Our system uses a Patton gateway to connect the ISDN network. The server running 3CX is not directly exposed to the internet and no VOIP provider is used.

Can hackers also target Patton gateways to gain access or how could they have hacked our system?

Thanks a lot, Sebastian
 
Re: Hacked !

If your gateways are configured on ext: 10000 and pass: 10000 then anyone can simply register on line 10000 and make free calls out of your PBX.
 
Re: Hacked !

Hi
I would like to comment on this :

Hi,
seems as our system also got hacked and the group used the NYE weekend to place calls for €3000+..
I understand from this thread that the admin as well as extension passwords have to be secure.
What i dont get is the following:

Our system uses a Patton gateway to connect the ISDN network. The server running 3CX is not directly exposed to the internet and no VOIP provider is used.

Can hackers also target Patton gateways to gain access or how could they have hacked our system?


If the 3CX is not exposed to the network, then this was an internal job.
if you have no voip provider then calls were not made out of a voip provider for sure. So the calls were made unlawfully through the patton isdn line.

Now question is this - do you have 5060 exposed to the internet? Can users connect remotely from outside to your pbx?

If they can, then they are going to try to authenticate and find your extension numbers you have in your system. they will start from 1 to whatever it takes until they find.

if they find a virtual extension 10000, with auth id 10000 and pass 10000 you are asking for it.

If your pbx is not exposed to the internet and there is no way that someone can come in your 3CX network area, then it has to be an internal job. I cannot find any other explanation for this.

In version 9 the default passwords for gateway creation are not the same so we are enforcing users to change them upon creation. However not to break working systems, gateways that were created with a default password are left up to the user to change them.

The logs wil give you more information on this abuse. Let me know if you need anything on this problem.
 
You know, I don't consider myself an incompetent boob.... but maybe I am.

Yesterday we were SIP hacked on one of our lines. We were two service packs back, but more importantly, we had not disabled the SIP ID's (as recommended by 3CX), simply because we didn't really understand the implications. arrrrrg.

A word of advice? Keep your 3CX upgraded and make sure all the extensions are shown in black instead of red in the management console. It's such a frustrating part of VOIP and 3CX. The software, price, flexibility, and features are great. The new world realities of these hacks is a real buzz-kill. Maybe we shoud downgrade to a string and two old soup cans.


(And yes, we're fully upgraded now. Is there any way to subscribe to email blasts about SP releases so we can be proactively notified instead of occasionally check the Management Console?)
 
I think you meant noob right? :)

This is like you complain to Microsoft because they hacked your IIS server and you left it with vulnerabilities or without updating to the latest updates just because you maybe didnt understand what the fix was.

OK this happens - but if 3CX says that it is RECOMMENDING to upgrade and sometimes we also say that you MUST upgrade, this means that you need to close your eyes and just do it.

Now lets put this behind us and move forward. Hope the cost was not much. If you want to send me some information on how they got in, or you want me to check the logs I will gladly offer to do this. I can offer tips on how to secure more your pbx.

If you are working with 3CX, you need to be subscribed to the 3CX Blog first of all. The moment we release something, an faq, a service pack - anything, you will get notified. This will make you up to date with what is going on.

Also in Version 10, we are going to be sending email notifications when abuse occurs. But if you dont upgrade - well the point is defeated. In V10 we are going to have an option that if out of office hours, you can disable all outgoing calls. So if they hack in, well - they can stay calling each other if they want and play between extensions. They will not be able to make outgoing calls because all the outgoing ports will be blocked.

We cannot do everything at once. And we miss stuff sometimes - also voip is getting much more exposed. Voip hacking Tools are coming out like viruses. Always update. Subscribe to the blog. You will be fine and 5 min of reading will save you costs.
 
Also comment on the blog of a service pack if you don't understand something. You will get answered and someone will explain to you on the spot anything you want.
 
I think my post was misinterpreted.

I did not in any possible way intend to disparage 3CX. I am not a Noob. I have been a licensed customer of yours since the early V3 days, and have been vocal reference for 3CX on behalf of your reseller partners in the USA. I didn't just fall off the turnip truck. I didn't expect 3CX to release a hardened nuclear silo. I know that. I know how software is designed, coded, tested and released. I was in the Enterprise Software world for 20 years.

My post was intended as a cautionary tale for other users who (like me) had upgraded to V9, but not applied all the service packs. Many 3CX users, I suspect are small companies who focus on running their businesses day-to-day, and simply don't apply service packs the moment they are released. Either we're not aware of a service pack release, or we've got our daily business operations that must be dealt with -- and frankly that does take a back seat to upgrading our phone system every 60-90 days.

My mistake. I apologize if the 3CX team felt I was disparaging their product.
 
HI

Thank you for your comments. We did not take it badly. We are also concerned with issues.

Your suggestions will be greatly appreciated - if you think we can do something more to improve updating please let us know.
 
Hey guys !
We got hacked too with long distances calls going to Dubai and Iran.

I reinforced our PBX and extensions passwords but that does not resolve the ridiculoous bill we received from our phone company, we use FXO gateway with pots lines and they are charging us 800$.

Is there any legal help I can get to save this ammount or at least reduce it to a reasonnable penality, I understand it is our system that was not secured enough but I beleive the phone company is going way too far with this ammount.

We are located in Qc, Canada, does anyone know of a CRTC laws for PBX attack ?
Any tip or help will be appreciated !

Thx !

LoOwEe
Louis Limoges
Domobec.com
819-762-8208 x103
 
Hey guys !
We got hacked too with long distances calls going to Dubai and Iran.

I reinforced our PBX and extensions passwords but that does not resolve the ridiculoous bill we received from our phone company, we use FXO gateway with pots lines and they are charging us 800$.

>>>Thank god its only 800. Consider yourself lucky. How long had this been going? When did you realize? How come no one from the telco informed you? They should have had alarms in place to protect you against this. Usually serious providers know the approximate rate you call. So they can make alarms that when they see that you are calling long distance or high toll premium numbers one after the other, they should disable international calling and inform you that you have your account disabled.

If you know the ip address from where the attack started, you can contact your local Cyber crime unit and issue a report.
Some telcos have insurances against these situations that cover them. It is possible that the telco company is insured and "MIGHT" consider forgiving a percentage of the bill. They should have alarms when they detect that all of a sudden there is abuse. I do not know - I have worked with a lot of telcos. Some have it, some do not even show you the bill before the end of the month even if you go on your knees. They are different - but you can loose nothing by trying.

Is there any legal help I can get to save this ammount or at least reduce it to a reasonable penality, I understand it is our system that was not secured enough but I believe the phone company is going way too far with this ammount.

>>> There were cases when companies overcharged on purpose. If you think that the amount is too high, get a statement and see how many minutes of calls were made. Ask around and make a calculation.

>>> You should make a police report first with your cyber crime. Detect the ip address and contact their provider. If provider is Palestine or China forget it. I just get the whole ip range and subnet for countries I do not work with and block them. This you can do it with V10.
If provider from where the attack came is in Europe, you might have chances as they are very serious on these things. States worth a try too.

We are located in Qc, Canada, does anyone know of a CRTC laws for PBX attack ?
Any tip or help will be appreciated !

>>> I do not know about canada, but when someone steals from you, there are some common grounds which are standard worldwide.
 
In general, when you apply for a service, of any kind, you agree to be responsible for any, and all charges incurred. That said, there have been some publicized cases recently where mobile users have racked up outrages bills using data when roaming in foreign countries. I seem to recall that bills in the thousands were reduced to hundreds after they went public with their "horror" story.

I have my doubts that a bill of $800 would get much sympathy from the general public in a news story, but you can always hope that the phone company might cut it in half as a sign of good faith. if you don't ask, then the answer is always "no".
 
This is a good instance of what to do when properly setting up outbound rules and security passwords on PBX's. I, by default, specify which phones can make long distance and international calls via the outbound rules extension field. by default it is blank and will allow any one or thing to use it.
 
Good point - outbound rule security is also important.
Also outbound rules can be assigned to a group. Example I create a sales group with my sales guys in and assign to them rights to dial out from an outbound rule.
 
Some VoIP LD providers allow multiple accounts and the ability to set the maximum per-minute-rate allowed. The rate to most commonly called countries is generally quite low, it's when calls are made to some of the more, shall we say, exotic regions, that the rate jumps, considerably. If your provider allows, set up the main account with a limit that will allow calls to the most common destinations that you call. Create a second account (trunk group) that has a higher limit and then assign a very complicated access prefix in 3CX, one that is only given on a need to know basis, and can be changed if needed.

This can also prevent overseas calls to mobile numbers (unknowingly) that can sometimes be 10 to 20 times the rate of a call to a landline in the same country.
 
Another good point mentioned here.

You can use the prefix in your outbound rule as a secure pin code. Then strip the pin code after the number has been processed.
 
nickybrg said:
Another good point mentioned here.

You can use the prefix in your outbound rule as a secure pin code. Then strip the pin code after the number has been processed.

This might sound stupid but after 3 years of VOIP installations, I have never been asked and never did an outbound rule for overseas calls, what is different with an oversea calls ?

Update: did a quick search while typing this but can anyone confirm the 011 ( 13 digits ) rule is the one I should set in my outbound rules ? Thx !
 
loowee said:
I have never been asked and never did an outbound rule for overseas calls, what is different with an oversea calls ?

It really depends on where you are located, how you dial local, national long distance and international calls, whether they all go out one route or several, and if you make use of an access digit. All of these variables will make outbound rules different for each PBX.
 
Unfortunately I became one of the unlucky few last week that didn't keep up with the latest versions and SP. Running V8 of the server cost me $100 in international calls before my voip provider disabled that capability. Since upgrading to V9 the IP's were being blacklisted as designed.

Still not feeling comfortable with the number of attempts at exploiting my installation.....I went ahead and placed a sonicwall firewall finally on the network (long overdue). Freakin love that thing.....everything is being dropped even before reaching the 3cx server.

Now my only problem is.....when dialing out sometimes.....I get a voice prompt simply stating "CANCELLED" then disconnect. I try the same exact number about 3 times...then it eventually dials out successfully.

Anyone ever experience that? I looked at the logs on the firewall to see if it was the culprit and was possibly dropping the outbound traffic...but nothing shows in there. I'm going to keep on digging.
 
But if you are still being targeted, then you have to stop it because yes the firewall blocks the traffic but it is going to waste your upload forbidding these attempts. I suggest that you contact your ISP and inform them of the problem. They can stop this and know exactly what to do. "Cancelled" could also be a timing issue. If traffic is going to take long to go out, certain timers will not be in sync and the VoIP call will not be good. So there are algorithms in sip that cancel the call because from how it is currently being built, it is not meeting the requirements for a VoIP call. The PBX and the VoIP Provider are aware of this and either one of them can CANCEl the call for you. This is why if you keep trying it will work. This is an intermittent problem being caused by a network scenario that is not stable.

I suggest that you change the sip port to something non default. Many attacks target networks on the default port to discover a PBX. If you change the port, you have 80% chance NOT to be discovered. The other 20% of attacks will come through port scanning however the firewall/router might detect this and stop it immediately depending on what firewall/router it is and if it is configured so. Like this they will just skip your ip/range and move to discover elsewhere.

But now if they found you once rest assured that your ip is listed somewhere and occasionally they will try and give it another shot.

YOU MUST USE LATEST VERSIONS. I also suggest you go to V10. In V10 there is more protection - this time on RTP streams. 3CX V10 will strictly check media streams and if the media was not sent from the pre negotiated ip:port, it will reject it.
 
Status
Not open for further replies.