Our 3cx was hacked - Very Important

Status
Not open for further replies.

fernandoml

Joined
Feb 20, 2010
Messages
2
Reaction score
0
Dear Sirs,

Someone logged in our 3cx and used the extension *888 (FAX) to call International numbers. Our Firewall had a permission to route ports to our server (virtualid). However I do not believe in our configuration this extension could be used for international calls. The anti-hacking system did not worked as well as the outbound rule that should be used only from the specific group of extensions.

I changed the password, removed the VirtualID on Firewall. Then I would like to know if there is another thing that I can do?

Regards,
 
By the way. There were more then 150 calls... to Palestina, Africa.. and countries like this.
 
If you don't normally place calls to certain countries then those can be blocked in the 3CX settings. Outbound rules can further refine this. You can also introduce a (more complex) prefix that would be required when dialling internationally.

Some VoIP providers allow you to restrict calls (set a limit) to numbers below a certain cost-per-minute. You might want to check to see if your provider offers this service.
 
Restrict (in your firewall) port 5060 to the SIP trunk provider's IP range (ask them for the list). Force any external user to use the 3CX tunnel if on Dynamic IP addresses and whitelist those that are on static IPs. Issue resolved.
 
... and this just came to mind... 3CX would have locked out the IP for too many failed logins (and if you have e-mail notifications on you would have known). I find it hard to believe that they just guessed the password... Look at your security settings while you are at it.
 
Status
Not open for further replies.

Members Online Now

No members online now.

Forum statistics

Threads
111,835
Messages
589,289
Members
164,665
Latest member
dominik.pepel