Login access denied

Status
Not open for further replies.

rado53

Free User
Joined
Jun 14, 2017
Messages
9
Reaction score
1
I can't log in to 3CX. I get: Login access denied. Too many incorrect login attempts. Try later or contact the Administrator.

In 3CX I set in Security Settings: Allow Access from specific IP Addresses. So I can only log in from a specific IP address. I'm not an incorrect login myself to cause a blockage myself. The hackers were probably trying to log in to 3CX. I did not receive email information from 3CX to block my allowed IP number. Because I can only access the PBX via one IP, I cannot log in from any IP address. Also, logging in 3CX will not be enabled after one day.
3Cx is installed on the VPS server.
I also reinstalled 3CX with the last backup, but even after reinstallation I get a response: Login access denied. Too many incorrect login attempts. Try later or contact the Administrator.

I wonder if there is any other way of web logging that I can set in Security Settings: Allow Access from everywhere. Or debug using debian console.
 
if you can access the debian shell, but your completely locked out of the web gui, i can probably break into it for you, feel free to PM me, i will need the debian root credentials, and to be able to SSH to the system.
 
  • Like
Reactions: Evolute IT
If memory serves, all RFC1918 addresses are default allowed. Meaning, unless you used the wrong password, if you are on the same lan,console restrictions won't stop you (however wrong password can ban the specific IP on that lan)
 
  • Like
Reactions: Evolute IT
So i would have also expected the same behavior as you described @SweetAction However it is simply not the case here, His server still has all the standard entries in the DB for the whitelist of the RFC1918 Addresses, however it most certainly was blocking them until i dropped into postgre, flipped the bit on the Console Restrictions enable setting and restarted his services. His server does not appear to be respecting the entries, perhaps a bug, or something is wrong otherwise in his system but yea.... I got it back open doing what i mentioned above.

On my test system i actually added my own IP to console restrictions using a /16 as a test, and it also blocked me after about 5 minutes suddenly and i had to perform the same fix to get back into it. It respected the IP for a few minutes, but them blocked me suddenly without provocation. I suspect there may be a bug hiding in the Console Restrictions system in the latest build, both his server and my test server are Linux 16.0.4.493

A very perplexing situation.... BTW, my test system is clean, no addons, mods, funny business, its just a linux build with a demo trunk, 2 phones, and a ring group, as dumb as it gets and it had the same incident happen.
 
A third server has now also demonstrated the same behavior....
 
Unless I'm misunderstanding the configuration it would seem everything is working as expected. I interpret IP's under console restriction to be the only IPs allowed to access the console, but still subject to blacklisting.
 
so there were no failed login attempts btw, i added my own ip to the console restrictions and enabled it on a clean server and all was well for about 5 mins, after 5 mins, suddenly i was auto-logged out while browsing the admin panel, and when i tried to relogin, on the very first attempt i got the message i was locked out for too many attempts. Restarting services via shell without making any changes yielded no help. but after editing the DB to disable console restrictions, flipping the 1 to a 0, and restarting services again, that got me back in.
 
@BrenttG

Did your IP show up under the blacklist?
 
Negatory, i checked even in the DB
 
Hmm.. then that does definitely sound like a bug.
 
@BrenttG can you open a case for investigation with 3CX?
 
@BrenttG can you open a case for investigation with 3CX?

Im quite busy today but i urge @rado53 to do so as his systems were the ones rendered in-operable by this until i fixed them for him.

Technical Notes:
IPs added to the Console Restrictions were not being respected, but were visibly set in the Console of 2 seperate systems.
On at least one system, the blacklist page listed one IP(allow) as having been added by console restrictions, but that IP curiously was absent from the Console Restrictions page, yet on the blacklist page i was prevented from editting or deleting that entry, as if the two lists became out of sync.
I reproduced the issue on a third non-production system.

I noticed interestingly, that while the blacklist which resides in the postgre database always contains a copy of the ips from console restrictions, there is an additional array in the parameters which designates the console restrictions ips in a format that is or resembles JSON, perhaps they get out of sync somehow.
 
Last edited:
Status
Not open for further replies.

Forum statistics

Threads
111,935
Messages
589,823
Members
164,816
Latest member
natedog