invalid CONSOLE login attempts not considered in IP blacklist ?

Status
Not open for further replies.

kwen1x

Customer
Joined
Jun 5, 2020
Messages
55
Reaction score
12
Hi,

I see the eventlog that is (over)loaded with 30037 events: User or password is invalid from .. (3CX Phone System Management Console).
Console access has been restricted to limited list of IP addresses, yet console page is still 'accessible' from internet ??
However, if I try to connect with VALID admin credentials, the connection is refused.
Seems odd 'implementation' of this IP restriction option.

Furthermore an event 30037 is logged when INVALID credentials are detected, yet these attempts do not result in the IP address in question being put on the IP blacklist ??
Only events 12290 (as far as I've seen) trigger their IP address being added to blacklist...

Why not blacklist illegal admin console attempts ?
 
  • Like
Reactions: JosIPVG
Hello everyone

There is a point that no one discuss here. With the new U6 users can have some extend of admin rights and manage other extetions from the web client/desktop app.
this feature shoul simply disapear because if a sip account falls into the wrong hands within hours a company could have massif amounts of money losses in phone bills.
I upvoted the idia posted by bitn2 and i think another one should be created to get reed of this admin thing from the webclient
 
Hello everyone

There is a point that no one discuss here. With the new U6 users can have some extend of admin rights and manage other extetions from the web client/desktop app.
this feature shoul simply disapear because if a sip account falls into the wrong hands within hours a company could have massif amounts of money losses in phone bills.
I upvoted the idia posted by bitn2 and i think another one should be created to get reed of this admin thing from the webclient
The admin login from the webclient is only avaiable for extensions that have the rights to reach it. I dont see any problem there. To manage extensions are not the sip trunk..
 
The admin login from the webclient is only avaiable for extensions that have the rights to reach it. I dont see any problem there. To manage extensions are not the sip trunk..
You don't need to manage the SIP trunk you only need a sip account and make calls too those overcharged phone numbers.
i saw a phone bill off 3500 euros in 10 minutes once. And guess what, my companny add to pay the bill for the client because all the security meassures ad not been taken.
If your sip accaount gives you access to 5 or 6 more (because you can change the mail adress and send the welcome mail from the webclient) the monetary losses could be huge in a short period off time:
 
I am not sure that i understand you right... Just dont give admin access to some random user, just to admins...
 
for what is worth:

I wrote a sql query to dump from eventlog the events I need, together with offending IP addresses (looking for events 30037 and 12290, for the moment...) .
List is imported (and blocked) in my corporate firewall, regardless of what 3CX thinks they should do with those attempts.
 
This is utter BS...10 times "hardcoded" allowed attempts per IP address at Management Console Access before blacklisting? Get your shit together 3CX...
 
Does anyone know where the log files are saved on the system? I would like to add 3cx to CrowedSec but can't find the log files on the system drive :D
 
Does anyone know where the log files are saved on the system? I would like to add 3cx to CrowedSec but can't find the log files on the system drive :D
/var/lib/3cxpbx/Instanse1/Data/Logs and /var/lib/3cxpbx/Data/Logs
 
  • Love
Reactions: Puma7
/var/lib/3cxpbx/Instanse1/Data/Logs and /var/lib/3cxpbx/Data/Logs
Thanks, but is it possible that the login attempts are logged somewhere else? At least i can't find any log with the login attempts.
 
It's in the management console log file, at least invalid attempts are:
1679068879434.png
1679068895384.png
 
  • Like
Reactions: Puma7
It's in the management console log file, at least invalid attempts are:
View attachment 34704
View attachment 34705
I celebrated too early. In my 3cxManagementConsole.log file in the directory /var/lib/3cxpbx/Instance1/Data/Logs does not contain the invalid logins. Only the valid logins are listed. Do I need to change the way 3cx logs invalid attempts or why are only valid logins logged?
 
I celebrated too early. In my 3cxManagementConsole.log file in the directory /var/lib/3cxpbx/Instance1/Data/Logs does not contain the invalid logins. Only the valid logins are listed. Do I need to change the way 3cx logs invalid attempts or why are only valid logins logged?
As you can see in my screenshot, invalid logins are logged. There is setting to turn this off.
 
As you can see in my screenshot, invalid logins are logged. There is setting to turn this off.
Just for documentation:

If you want to see the invalid logins in the 3cxManagementConsole.log you need to set the activity log level at least to medium. I think in standard it is set to low.
 

Attachments

  • 3cxActivityLog.png
    3cxActivityLog.png
    44.5 KB · Views: 8
I think that's a wrong assumption there, never said that we dropped MC blacklisting.

It worked before, and it still works in U6 - Just go ahead and try it on a U5 and a U6 and you will get blacklisted on both occasions.
Hi John,

The main issue we have noticed is that since U6 it seems the blacklist time interval only seems to apply to SIP attempts, yet before, I'm fairly sure it also applied to MC/Webclient logon blacklisted IP's, in fact I have back to older emails from pre-U6 and have confirmed that Webclient blacklisted IP addresses were being blocked for the set 24 hours. See below. Something has changed.

Blacklist 3CX.png

The MC/Webclient blacklist now only blocks IP's for 15 min, regardless of the blacklist time interval, so this results in me waking up in the morning with the same IP blacklisted 27 times in 15min intervals.
 
for what is worth:

I wrote a sql query to dump from eventlog the events I need, together with offending IP addresses (looking for events 30037 and 12290, for the moment...) .
List is imported (and blocked) in my corporate firewall, regardless of what 3CX thinks they should do with those attempts.
Strange... now running v18.7.312 and no events 30037 any more ?!
did the 'attacks' at console logins stopped or did someone at 3CX dropped the 30037 logging ?
hmmmm
 
I don’t recall specifics offhand but:
“Removed event about username and passwords”
In https://www.3cx.com/blog/change-log/phone-system-change-log/
As I recall it was discussed a bit in various threads after update 6 and/or the u7 release thread.
Thanks for clarification SteveITS !
So now console can be attacked without us knowing about it... I don't think this issue is progressing in the right direction.
Maybe switching logging on/off could be a configuration parameter ?!
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet