IP has been blacklisted

Status
Not open for further replies.

TomH

Bronze Partner
Basic Certified
Joined
Feb 1, 2019
Messages
3
Reaction score
0
How is it that within seconds of each other the same IP address, not one associated with me, all hosted at different locations, for different clients, using different IP providers, tried to connect to three different 3CX systems I manage? See the image below for the notices I received in my email from my deployed 3CX systems. The rules I have in place blocked the IP address from connecting for 10 years. :-)

This type of intrusion makes me wonder how they got either the static IP address of my clients, or got the FQDN from 3CX.

Can anyone explain?

3CX IP Blacklist.png
 
There are many publicly available, legitimate tools and websites that can be used to list all subdomains of any given valid domain registered in public DNS. The regional subdomains of 3CX.us (and 3CX global regions) are public so it would be simple for someone to dump all registered subdomains of xx.3CX.us and obtain the IP addresses.

Btw, you failed to completely redact your domains - each verbose message includes the domain you redacted on the “IP has been blacklisted on PBX” line.
Thank you.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet