IP blacklist restart on march 30

Status
Not open for further replies.

AWS2P

Silver Partner
Basic Certified
Joined
Jan 9, 2014
Messages
5,076
Reaction score
1,096
Hi ,
since several months nothing new was collected in pbxs blacklist,(great) today march 30 i've seen 2 same IP blacklisted on several pbx.
1585605179639.png

Is there a way to know if these IPs had already been blocked in 3CX global blacklist and freed after a while and restarting to attack pbxs or if they are completely new ?

Could it be posible to give in 3CX console, in blacklist section, an history info on this in front of each IPs ?
 
You look? I thought the whole point of the global blacklist is so you don't have to look at it ever again :)
 
Leave the IPs there until they expire automatically. If they enter the global Blacklist they will not appear in the management console again any time soon.
 
Hi @JohnS_3CX can you explain the conditions of an IP hitting the global, what are the parameters?
 
I cannot get into details, but one thing is for sure, if we are talking about SIP attacks on 3CX systems where they would be banned by your own PBX's blacklist, they are eligible to enter the Global Blacklist.
 
if we are talking about SIP attacks on 3CX systems where they would be banned by your own PBX's blacklist, they are eligible to enter the Global Blacklist
Yes that's what happens, but what i wanted to know even if pbx blacklist was previously empty:
is this IP already been blacklisted in past and restart to do SIP attacks, or if it's new one never catched before.
 
You look?
No I don't, but received email alert so I knew ;)
Could be an help if you catch always same IPs every 3 months for example, could be a way to know this is an IP to bannish for eternity
 
Meh. I mean I understand the logic but I really don't care if they bang away and then get blocked for 3 months and then unblocked. Those aren't the guys you need to worry about. If there's an exploit that the script kiddies get their hands on then your screwed anyways and 3CX dropped the ball. It's the guys you don't see that you need to worry about :)
 
It's the guys you don't see that you need to worry about :)
i'm not able to catch fantoms :p and I prefer to see no increase in pbx blacklist, when this is the case i'm thinking 3CX catch them all so they are not bombarding our Pbxs.:)
 
Could it be possible 3CX Global Blacklist, if not the case right now, to keep recidivist IP attackers in jail for ever to remove ability to restart bombarding pbxs each periods they are released.
Since last days my pbxs blacklist restart to block a lot of IPs, but end of blocked status is in july, so it can be a no end job catching, releasing , catching always the same.
 
Blacklist increased in 2 days, even all my pbxs are on Global blacklist strangely only 3 are with same IP list.
blacklist.JPG
 
Both Static and Dynamic IPs can be hijacked, so they will probably be removed at some point if no further incursions happen
 
my question was about IPs that reoffend and end up in blacklists a few months later, can't we block them forever?
 
I think my answer above already covers your question ;)
 
Hello, hope you and team are fine
@JohnS_3CX
Just wanted to know if you can explain me why only 2 of my pbxs continue to daily increase blacklist with new IPs, these pbx are like the others with 3CX Global blacklist enabled.
see now the list of IPs blocked on pbxs (exact same list on second one) all others pbxs have empty blacklist

only common point they are cloud pbx , not same hoster one OVH, other AWS Lightsail

1586284516411.png
 
As confirmation to the prior post, this is also off a AWS LightSail hosted instance, that since the 31/3 (AU time) has had all the IP's below (many of which also appear above) auto added to its blacklist. Prior to this, Global Blacklist worked fine and never had a single IP flagged.

1586313629341.png
 
How is it possible this happens as we found same blocked IPs over the world (France and Australia) with global blacklist enabled.
 
Same here in Germany. Before April, blacklisted IPs were rare, thanks to the Global Blacklist, but then the number of attempts increased significantly. I started to block the entire networks, but then I gave up because it took too much of my time.

Did you notice that there is somehing in common for all these attempts:
User-Agent: 3CXPhoneSystem

Before April, the user agents were quite different: Asterisk, Linksys, random stuff... Seems this wave of attacks is actually performed using 3CX systems, at least it looks like an orchestrated attack.

EDIT: I just noticed that the order of my blacklisted IPs matches the order of the other two lists above. This really looks suspicious! The attempts are targeted to 3CX instances. The question is: where did these guys got the IPs of 3CX instances from?

Here is my current list, already streamlined since some individual IPs that were part of /24 nets have been removed.

80.246.28.24
200.25.0.0/17
103.137.12.0/24
103.209.252.0/24
45.10.233.0/24
104.238.44.0/24
77.243.191.0/24
138.122.0.0/16
217.138.202.0/24
216.151.184.0/24
195.47.194.11
185.216.35.204
185.174.159.22
185.117.118.185
87.239.248.30
5.183.92.0/23
37.120.144.231
81.17.246.0/24
157.157.87.181
87.239.255.26
45.56.137.84
173.245.217.38
80.246.31.37
185.153.151.10
202.176.4.169
185.163.46.155
176.67.84.22
45.252.191.12
102.165.25.20
 
Last edited:
Just some fundamentals of how attackers operate and why the Global Blacklist works.

To orchestrate an attack, all they need is a net of machines they control to scan public IPs indiscriminately (anything from compromised webservers to user pcs). They can scan well known ports, and common variants by sending invites to them. If they send 1-2 invites and get a response you might not even realize it but, they know now that a SIP machine is sitting behind that ip and at that port.

Once they compile a list of IPs that are alive, they start hacking with brute force and other "tricks" in the hopes that they will get a valid sip account. That's when your PBX blacklists them, and shares the IPs with the 3CX Anti Hacking Defense Program. With so many compromised machines, many of which are on dynamic public IPs that keep changing, the attackers can quickly avoid being banned permanently.

The Global Blacklist will defend you by not replying to the known bad IPs, but since these change constantly, and newer, larger attack campaigns are launched from time to time (especially now that people are sitting at home and have more "free time") it is just a fact of life that sooner or later you will see your PBX blacklisting attackers. This is sign that it does what it should do and block them.

This addresses ALL the above questions you had, it's never personal, it's just generic attacks by opportunistic hackers that want to steal accounts to use them or sell them.

1) why specifically 3CX? - it's not specifically 3CX, its any SIP system that is online
2) why now? - guess what, hackers are locked indoors now and have more time to attack
3) will these IPs get blocked? - they will if you enabled global blacklist, just give it some time
4) will they get blocked if they re-offend? - yes they will but they can change IP easily and attack again
5) why User-Agent: 3CXPhoneSystem? - because its a known user agent just like Asterisk, Cisco etc
6) why only 2 or 3 of my systems getting attacked? - because those were discovered. the other will also be attacked eventually when someone scans them

I hope the above has covered a lot of ground on this subject.If you want more answers, you will have to ask the attackers themselves ;)
 
  • Like
Reactions: accentlogic
1) why specifically 3CX? - it's not specifically 3CX, its any SIP system that is online
2) why now? - guess what, hackers are locked indoors now and have more time to attack
As a web developer i have created a ip blocking system, on any given day thousands of ip address are evolved with hacking attempts, i currently have over 2 million ips in my block list yet they keep coming, welcome to internet 3.0.
 
Status
Not open for further replies.

Forum statistics

Threads
112,031
Messages
590,388
Members
164,982
Latest member
Costa Georgijevski