Prevent Rogue Extension Registration?

Status
Not open for further replies.

BusySignal

SOHO User
Joined
Feb 25, 2022
Messages
7
Reaction score
1
Approximately 1 year ago, I posted this on this forum...

I have a plain vanilla on-prem 3CX PBX. My SIP trunk provider gave me an ESG device. One port is assigned an IP address that's on my local LAN, for my PBX to connect to, and another port connects to the SIP trunk provider.

The other day I suddenly have a number of people in my office complaining that they can't make or receive calls with the outside world. After some quick troubleshooting, I discover that the IP address for the SIP trunk ESG device has been blacklisted. I removed the IP from the blacklist, and inbound and outbound calling was immediately restored.

I reviewed the activity log, and discovered that there were numerous attempts to register a non-existent extension on my system. After some number of failed attempts, the phone system must automatically blacklist the IP where these rogue registration attempts are coming from. I noted the originating SIP telephone number, did some Internet searching, and found that the number is associated with nuisance telemarketing and robocalling. This suddenly started to make sense to me. The bad people that are doing the robocalls somehow get an extension on my phone system, and then start making a huge, huge number of calls, that look like they’re coming from my company. We eventually get a reputation for being an unwanted telemarketer/robocaller, and PSTN service providers start blocking our outbound calls. We’re left with trying to restore our reputation, and getting our number unblocked, while the bad people simply delete their extension from our system, and move on to victimize some other unsuspecting company to make their robocalls.

My question is, how do I prevent these extension registration attempts that originate from the SIP trunk provider's IP address? I only have phones inside the building, and don't need to support any external extensions, so I would think that there would be an easy way for me to do this, but I can't really find anything in the documentation, or this forum, that definitively answers this question.

I'm hoping there's a 3CX expert out here that can point me in the right direction. Thanks.

My SIP provider insisted that this was not their problem and abruptly closed my support ticket. I didn't find a solution to this problem, but there were no more attacks, so life went on as usual... until today. The bad people are back again with their rogue extension registration attempts, and the IP address to my SIP provider was blacklisted again. No calls could come in or go out until I removed the blacklisted IP.

I opened another support ticket with my SIP provider, hoping for a different outcome, being a year later, but alas, the response was exactly the same. It's not their problem.

With the provides ESG device, everything from the outside world is NAT'ed, so all traffic looks like it's coming from the internal LAN IP of the ESG device. I have no way to differentiate good traffic from bad traffic.

Is there a way to configure the PBX NOT to accept extension registrations from a specific internal IP address? If I could do that, there would be no more rogue extension registrations allowed from that ESG device, that IP address won't ever be blacklisted, and then my company won't lose inbound and outbound calling capability.

Is there a way to differentiate an inbound telephone call from an extension registration? Or do they both use the same port 5060 to establish a connection?

Sorry, I am not a SIP expert, but I'm hoping there are people on this forum that are. Thanks.
 
Hi @BusySignal

SIP traffic uses the same port for both calls and registration. You can only have one SIP port on your PBX so you cannot block registrations and allow calls. And there is no easy solution for your problem I am afraid.
These types of "attack" unfortunately are now common and so you need to follow best security practices and allow the PBX to do it's job. The fact that is blacklisting the IP means that the security thresholds are working.

We have a series or articles that highlight the best practices and what you can do to prevent being hacked.

If I were you I would first look into switching providers and find one that does not NAT all traffic to a local IP in my network and consider reinstalling the PBX with a non default SIP port. Most attacks target port 5060 which is the default SIP port for most SIP capable devices. Changing the port to something else keeps most attackers off. You still need to ensure that you are using strong passwords and auth IDs and there are no leaked credentials but it sure helps.
 
Hi @YiannisH_3CX

I have less than a year left on my service contract with my SIP provider. I will have to investigate what competitors are offering for SIP telephone service, and explore using a port other than 5060.

I haven't weakened any of the security in my 3CX install. There are the auto-generated long strings of letters and numbers for passwords. The attacks from bad guys are just a fact of life.

For now, I'll just have to keep an eye out for an email that tells me an IP address has been blacklisted, and that will reduce the length of time the SIP phone service is not working.

Thank you for your insight and expertise in helping me with this matter.
 
  • Like
Reactions: YiannisH_3CX
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet