Just recently I've been seeing a lot of PBX: blocked for too many failed authentications; User-Agent: PolycomVVX-VVX_300-U"

Status
Not open for further replies.

greychain

Gold Partner
Advanced Certified
Joined
Jul 13, 2018
Messages
779
Reaction score
122
Just in the last few days (May 30th on) I've been seeing a lot of these from all over the world. Is anyone else getting this?

The number of blacklisted IP's are way more than I have had in the last several months altogether.

It would be nice if there was something like the "allow calls to countries" but to block calls from countries unless the IP is whitelisted.
 
Chances are this is a hacker using a VPN, TOR or botnet to target you.

Geolocating would only work if DNS registration / geolocation data is accurate and the point of origin can be guaranteed (i.e. the hacker isn't using a VPN, etc). Doing such a lookup takes a bit of network / computational time and a hacker using a VPN / TOR / botnet potentially negates the purpose of that lookup as they can appear to be coming from anywhere in the world.

The anti-hacking feature built-in to 3CX gives a decent degree of protection from IP addresses that target multiple 3CX installs (https://www.3cx.com/blog/voip-howto/anti-hacking-secure-3cx-pbx/).

Failing that, if you don't require mobile / remote access you could lock down the firewall on your server to only be open to IP addresses that are known to you.

It might be worth a bit of a search for more info on here - there's been some good stuff posted in the past about hardening your install against hackers.
 
I'm getting a lot of these failed attempts too.
 
I have an installation with an address mycompany.3cx.ru and I get several such attempts every day. and there is an installation with the address mycompany.ru and there is one such attempt every 6 months. could the reason be FQDN?
 
My pbx is at mypbx.mycompany.net so I don't think so. I was thinking of installing the GeoIP blocking software on the Debian system.
 
Just set restrictions on 5060 port to only allow SIP provider IP and this is end of attempts.

Other way during PBX install choose other port than standard 5060 , this is also a simple working solution.
 
My pbx is at mypbx.mycompany.net so I don't think so. I was thinking of installing the GeoIP blocking software on the Debian system.

Do not do this, 3CX has to be the only application running on the system - if you do you become unsupported in terms of any support you have from 3CX

Do any blocking at the firewall
 
Just recently opened my network up for remote and I am seeing a TON of those as well . They started hitting me with different extension numbers attempting to find my ext list numbers . Polycom telephone as well as I am now beefing up security and watching closely . I have a fios quantum router and am reviewing ALL port forwarding etc. and the logs in my router for failures and connections . Nothing yet but they are persistant ! Funny how I just opened the router and that Pm about 3 weeks ago I started getting them from sipvicious and others also ! They had to use some sort of scanner or other device and found my FQDN ! Can they do that via 3cx ? I enabled the 3cx blacklist ( Automatic Global 3CX IP Blacklist ) right away via my 3cx system . One odd thing is that I enter an ip address in the blacklist and it states its already added but I cannot see it in the list ...

I use my I Phone and have an employee working remote also ....

06/05/2020 9:10:42 AM - [CM102001]: Authentication failed for AuthFail Recv Req REGISTER from 193.148.16.250:60449 tid=294658020 Call-ID=698719782-257151855-1935564812: REGISTER sip:192.168.1.13:5060 SIP/2.0 Via: SIP/2.0/UDP 10.118.86.18:60449;branch=z9hG4bK294658020;received=193.148.16.250 Max-Forwards: 70 Contact: <sip:[email protected]:60449> To: <sip:[email protected]:5060> From: <sip:[email protected]:5060>;tag=2068283246 Call-ID: 698719782-257151855-1935564812 CSeq: 2 REGISTER Proxy-Authorization: Digest username="2006",uri="sip:96.252.49.78",algorithm=MD5,realm="3CXPhoneSystem",nonce="414d535c14ead55121:5b08f6b3f81a22bf5f00d1dde5d5f075",response="ddf08588472735869ca8ead9eaf5726a" User-Agent: PolycomVVX Content-Length: 0 ; Reason: Credentials don't match, check that authorization-ID and password match the ones in extension settings
 
I got annoyed at my alerts. It became 5 times per day. I changed my public ip address on the Amazon Lightsail server. All is calm now until the hackers probe and find the new public address.

3cx should provide more tips on best practices to secure a public facing 3cx server with remote and mobile phones.
 
Status
Not open for further replies.

Forum statistics

Threads
111,952
Messages
589,895
Members
164,845
Latest member
tdzski5