Poor Welcome Email Security

Status
Not open for further replies.

COIT

Silver Partner
Joined
Jan 25, 2022
Messages
15
Reaction score
4
I'm very concerned about the very lax security of the welcome email, sending plain text passwords in an email is a complete no no these days.

Is there a way to prevent welcome emails being sent upon user request (e.g. via the mobile app)?

I know I can edit the email template and remove any passwords and qr codes from the email body but I can't find a way to prevent it sending the provisioning file attachment. The attachment has the tunnel password, extension id and extension password right there in plain text, it's even handily marked up for any attacker (in xml) so they know which password should be entered where :eek:
 
Removing the attachment is not possible I'm afraid so only thing I can recommend now is maybe having a quick look through our Ideas Section to see if anyone recommended anything similar and upvote that post to help push it up the list. I found one that's somewhat related so you might want to give it a quick look: https://www.3cx.com/community/threads/improved-security-web-client-desktop-app.112898/


In the meantime, if you're using a custom SMTP you could perhaps see it has any filtering capabilities or even check your mail server instead.
 
Removing the attachment is not possible I'm afraid so only thing I can recommend now is maybe having a quick look through our Ideas Section to see if anyone recommended anything similar and upvote that post to help push it up the list. I found one that's somewhat related so you might want to give it a quick look: https://www.3cx.com/community/threads/improved-security-web-client-desktop-app.112898/


In the meantime, if you're using a custom SMTP you could perhaps see it has any filtering capabilities or even check your mail server instead.
Funnily enough, I upvoted that very thread earlier.

It's a problem I'm having to deal with right now hence my post.

I'm sure this isn't the first time this issue has been highlighted and it's such a glaring security hole (IMO), that I feel it should be addressed without having to upvote forum ideas.

More generally, 3CX login security really isn't up to expected/accepted modern standards. 365 SSO integration has been a step forward as it allows mfa via 365 but it's not enforceable so again, not great.

We were hoping to prevent users ever knowing their own 3CX credentials but as we can't stop the welcome email being requested with the provisioning file attached, we can't do it. As soon as a user knows their password, they can set it to 'pa55word' if they want and there is no enforceable mfa. Further, if the credential data is leaked, anyone can log into the extension and start using it as and ATM.
 
  • Like
Reactions: VSC
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,083
Members
164,900
Latest member
Silent_Guru