Lot of hack attempt

Status
Not open for further replies.
Today 24/10 it seems one of my pbx is bombarded and very strange blacklisted ips in the morning are again blacklisted at night, if they are blacklisted and global blacklist is enabled how this is possible?
12876

Am i alone to have this behavior? Do you take care if you have like me , same IPs blacklisted more than once on your PBX?
 
Last edited:
What is your Blacklist duration set to? I always set my instances to 31536000sec (1 Year).
 
  • Like
Reactions: NickD_3CX
12877

this setting is equal to 3.17 years
12882

nothing is released before 2022
12878

12879
 
Last edited:
From this night
User-Agent: 3CXPhoneSystem (most seen)
User-Agent: Avaya (2 or 3 time)
User-Agent: Linksys-SPA942 (2 time)
I think 3cx should revoke the license to any of the systems that are involved with hack attempts, lucky for us we can block access from our router, most blocked to date "Amazon and DigitalOcean"
 
I think 3cx should revoke the license to any of the systems that are involved with hack attempts, lucky for us we can block access from our router, most blocked to date "Amazon and DigitalOcean"
The problem is that most of the times, the User-Agent values are deceiving, so when you see "3CXPhoneSystem", it isn't really a 3CX system on the other end...
 
  • Like
Reactions: Evolute IT
We see them only from Digital Ocean, I've blacklisted now all their IP ranges (which you easily get with the following command:
whois -h whois.radb.net -- '-i origin AS14601' | grep ^route
 
My question stay un anserwered, why same IP blacklisted on morning stay able to be blacklisted at night,

Are the blacklisted IPs locally on PBXs always registered to global blacklist or may be not?
 
Status
Not open for further replies.

Forum statistics

Threads
111,856
Messages
589,404
Members
164,693
Latest member
FLCC