How common are SIP attacks?

Status
Not open for further replies.

TecMate

Bronze Partner
Advanced Certified
Joined
Nov 17, 2017
Messages
38
Reaction score
24
Just wanted to get some of your opinions and experience.

Our 3CX systems are blacklisting between 10 and 50 IP address a day due to "PBX: blocked for too many failed authentications"

I've increased the blacklist time interval to 604800 seconds (1 week) to try and deter the attacks.

I'm considering adding some permanent firewall rules to block these attempts but it means retiring some our off-site legacy phones and relying on the 3CXTunnel for smartphones and softphones for off-site only.

Should I be worried about these attacks? They are constant and relentless and I have no way of knowing if they break through until it's too late... What else can I do?
 
VoIP is like anything else, it's all about defense in-depth. The only 100% certain security is to block all SIP access from the outside world except from your provider and known good actors. This would require using VPNs (Yealinks have OpenVPN built-in) or going SBC/3CX Phone for tunnel. Anything else is a calculated risk. The next safest bet is to put a SBC in front of your 3CX instance (real SBC, not the 3CX SBC). Then you start thinking about what is really at risk if your PBX is compromised? Typically if your system is compromised it just becomes an avenue for toll-fraud. If you have country blocking enabled in 3CX or disable after-hours calling on your extensions then there really isn't much to worry about. If you are still concerned you can switch to a pre-paid provider an then you can limit the dollar amount of damages. It's really not that big of an issue if setup properly.

And yes like anything else with easily available tools for script kiddies the attacks are very common.
 
Status
Not open for further replies.

Forum statistics

Threads
111,889
Messages
589,580
Members
164,754
Latest member
Louzan