- Joined
- Oct 4, 2023
- Messages
- 61
- Reaction score
- 16
Some advise appreciated.
A few months ago, I was reviewing the windows event viewer when I noticed a number of entries where it looked like someone had been trying to access the 3cx management console who was not authoirsed.
At the time, I was advised to go to Advanced, Console restrictions and change the setting to "Allow access from Specific IP Address". Which I did, it was previously set to "Allow access from everywhere" and thought nothing of it.
However, another review of the windows event log is continuing to show these events.
I am not going to include the entire entry by the one that made me wonder if this setting actually works is:
"LoginException: User or password is invalid from (xxx.xxx.xxx.xx)" Obviously I have masked the IP address, but is says user or password invalid as though someone is able to try login from outside the authoirsed list of white list IPs
Does anyone know what is going on, I do not want a brute force attack to successfully access my system?
A few months ago, I was reviewing the windows event viewer when I noticed a number of entries where it looked like someone had been trying to access the 3cx management console who was not authoirsed.
At the time, I was advised to go to Advanced, Console restrictions and change the setting to "Allow access from Specific IP Address". Which I did, it was previously set to "Allow access from everywhere" and thought nothing of it.
However, another review of the windows event log is continuing to show these events.
I am not going to include the entire entry by the one that made me wonder if this setting actually works is:
"LoginException: User or password is invalid from (xxx.xxx.xxx.xx)" Obviously I have masked the IP address, but is says user or password invalid as though someone is able to try login from outside the authoirsed list of white list IPs
Does anyone know what is going on, I do not want a brute force attack to successfully access my system?
