Solved multiple unknown IP address at Activity Log

Status
Not open for further replies.

tspjoker

SOHO User
Basic Certified
Joined
Jun 14, 2022
Messages
44
Reaction score
1
09/10/2022 6:54:09 AM - Blacklisted (Too many failed auth) IP = 180.222.151.33; Failed auth: 2; unauth: 3; auth: 2; 407: 0; ua: 3CX Phone System

even i followed the 3cx guide line and re installed the sever still got this millions message ; Reason: Credentials don't match, check that authorization-ID and password match the ones in extension settings; Reason: Credentials don't match, check that authorization-ID and password match the ones in extension settings; Reason: Credentials don't match, check that authorization-ID and password match the ones in extension settings; Reason: Credentials don't match, check that authorization-ID and password match the ones in extension settings x1000

idk how? i am not hosting 3cx as locally and it's on 3cx itself hosted for the server so is anyone getting this stupid unknown attacker???
 
Until a hackers IP is blocked (by you, or 3CX), you will get messages, if they continue to attempt an extension registration, from the same IP.
 
but does the blacklist work properly? they came back with different IP addresses and stuff so idk 3cx does have proper security for cloud server or not?
 
Here is an explanation of how it works. Of course, any "new" IP that hacks originate, probably won't be blocked until they hit the threshold, that is set, so you might want to review your settings. Many hacks target your IP directly, which would be blocked because the attempt isn't using the FQDN. The logs are annoying, but, as long as you don't have any easy to guess passwords, you should be good.

https://www.3cx.com/blog/voip-howto/global-ip-blacklist/
 
Last edited:
  • Like
Reactions: YiannisH_3CX
Here is an explanation of how it works. Of course, any "new" IP that hacks originate, probably won't be blocked until they hit the threshold, that is set, so you might want to review your settings. Many hacks target your IP directly, which would be blocked because the attempt isn't using the FQDN. The logs are annoying, but, as long as you don't have any easy to guess passwords, you should be good.

https://www.3cx.com/blog/voip-howto/global-ip-blacklist/
so do you also getting same log as well?? is this common thing hosted 3cx??
 
I have had from 2 to 20 emails a day showing hack attempts. Many times the originating IP just increments, so i manually change the subnet mask to block a wider range of IP, for a long period of time.

Having a VoIP PBX, means you are going to be scanned (Usually port 5060) as people try to get access. Unless you block that port, change it (which might help, others have tried), or limit access to your provider, and perhaps a select list of IPs using a firewall, you will in all likely hood continue to get hack attempts.

Keep in mind that 3CX is not a firewall. If you want better protection, and more control, you might consider installing one.
 
Last edited:
  • Like
Reactions: tspjoker
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet