- Joined
- Apr 24, 2012
- Messages
- 37
- Reaction score
- 14
Hi,
We get continuous login attemps on port 5061 of a customer, 3 tries per random internal number (both existing and non-extisting numbers).
But unsuccessful logins are not blacklisted by 3CX.
I see this in the log:
The attacking ip is 45.95.147.37 to 3CX on 81.83.x.x (I removed part of the external IP address of the customer). Firewall is 192.168.15.1.
This happens almost any second.
Currently I blocked the IP 45.95.147.37 on the main firewall, but I would expect 3CX automatically blacklists this IP.
Somebody any idea why this is not happening? Anti-hacking is enabled with default settings, except "Blacklist time interval" which is set to the maximum of 999999999.
Jos
We get continuous login attemps on port 5061 of a customer, 3 tries per random internal number (both existing and non-extisting numbers).
But unsuccessful logins are not blacklisted by 3CX.
I see this in the log:
| 07/14/2022 10:53:37 AM - [CM102001]: Authentication failed for AuthFail Recv Req REGISTER from 192.168.15.1:56202 tid=-d87543-7640593124-1--d87543- Call-ID=e5f4a740465243e4f7a: REGISTER sip:81.83.x.x:5061 SIP/2.0 Via: SIP/2.0/TLS 45.95.147.37:56202;branch=z9hG4bK-d87543-7640593124-1--d87543-;rport=56202;received=192.168.15.1 Max-Forwards: 70 Contact: <sip:[email protected]:56202> To: <sip:[email protected]> From: <sip:[email protected]>;tag=e5f4a7404651e4f7a Call-ID: e5f4a740465243e4f7a CSeq: 2 REGISTER Expires: 3600 Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, NOTIFY, MESSAGE, SUBSCRIBE, INFO Proxy-Authorization: Digest username="119",realm="3CXPhoneSystem",nonce="414d535962cfd99137:21824e751e89f8f71c062cac983b1f31",uri="sip:81.83.x.x:5061",response="28d465ed8a113100940eea503f3857b7",algorithm=MD5 User-Agent: 3CX Phone System Content-Length: 0 ; Reason: Credentials don't match, check that authorization-ID and password match the ones in extension settings |
| 07/14/2022 10:53:37 AM - Authetification failed: SI Recv Req REGISTER from 192.168.15.1:56202 tid=-d87543-7640593124-1--d87543- Call-ID=e5f4a740465243e4f7a: REGISTER sip:81.83.x.x:5061 SIP/2.0 Via: SIP/2.0/TLS 45.95.147.37:56202;branch=z9hG4bK-d87543-7640593124-1--d87543-;rport=56202;received=192.168.15.1 Max-Forwards: 70 Contact: <sip:[email protected]:56202> To: <sip:[email protected]> From: <sip:[email protected]>;tag=e5f4a7404651e4f7a Call-ID: e5f4a740465243e4f7a CSeq: 2 REGISTER Expires: 3600 Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, NOTIFY, MESSAGE, SUBSCRIBE, INFO Proxy-Authorization: Digest username="119",realm="3CXPhoneSystem",nonce="414d535962cfd99137:21824e751e89f8f71c062cac983b1f31",uri="sip:81.83.x.x:5061",response="28d465ed8a113100940eea503f3857b7",algorithm=MD5 User-Agent: 3CX Phone System Content-Length: 0 |
The attacking ip is 45.95.147.37 to 3CX on 81.83.x.x (I removed part of the external IP address of the customer). Firewall is 192.168.15.1.
This happens almost any second.
Currently I blocked the IP 45.95.147.37 on the main firewall, but I would expect 3CX automatically blacklists this IP.
Somebody any idea why this is not happening? Anti-hacking is enabled with default settings, except "Blacklist time interval" which is set to the maximum of 999999999.
Jos