Receiving lots of registration attacks last few days

Status
Not open for further replies.

mobilowa

Forum User
Joined
Feb 5, 2015
Messages
45
Reaction score
4
I receive lots of registration attacks last few days from various IP ranges and IP addresses getting black listed by 3CX PABX

See the attached screenshots

Lots of registration attacks with in 2 days

Any suggestions please?

upload_2018-7-15_21-44-21.png
 
There's really not a lot you can do about the attempts. Bots will be bots.

Were I you, I would attempt geolocation lookup of the offending IP's and see if you can spot a pattern. My findings are that about 85% of the attacks on my managed PBX's originate in the Netherlands.

It's more an out-of-interest thing than anything else, but you may be able to find that there are certain ISP's that are more lax on their own security, identify their subnets, contact their abuse department and then (if all else fails) preemptively block them (providing you're not expecting any calls from that area of the world).

Also, you can take relative comfort in the fact that your 3CX PBX is doing its job in recognizing the failed attempts and taking the appropriate (block) action.
 
Well firstly the PBX looks like it's doing it's job correctly.

But what I would do is check your firewall over and ensure you have locked it down.

Only open ports up from trusted sources such as your VoIP Provider etc
 
Well firstly the PBX looks like it's doing it's job correctly.

But what I would do is check your firewall over and ensure you have locked it down.

Only open ports up from trusted sources such as your VoIP Provider etc

What about users on Smart phones? If you restrict by IP origin - then those users will not connect with full functionality.
 
I see no mention in this post that they are using Smartphones or remote extensions.
 
I see no mention in this post that they are using Smartphones or remote extensions.

Doesn't matter that they didn't mention if the site uses Smartphones or Remote Extensions. It's useful information for the OP to have. If they just go and lock down their firewall to all these IP's - or allow their VoIP provider only - they'll be back here asking why their smartphones can't connect. These forums are made up of folks from novice to pro - we accommodate all.
 
I don't agree, I know plenty of sites who are purely on premise with local extensions only and SIP trunks.

If you aren't using smartphones - or don't mention using smartphones why recommend to open up extra ports for provisioning and presence and 3CX tunnel if they aren't needed.

Only open up whats mentioned in the requirement.
 
We recommend customers who have a capable router and don't use phones over STUN to open port 5060 only to the SIP provider. This has no impact on smartphone use and blocks most hacking attempts.

Those who use STUN phones, if the remote site has Static IP, it can be opened to that IP as well. Alternatively they can use SBC software or SBC on a Pi or setup VPN between the two sites.

That being said we haven't seen a successful hack of a 3CX system in a few years now. The anti-hacking module in 3CX is fantastic. The fact 3CX prevents/identifies weak passwords (bad practices) helps a lot. The ability to control which countries calls are allowed to also helps block things in case of a successful attack.

We recommend IXICA trunks in Canada (recently 3CX certified) and as an added protection they setup international calling for customers with a "maximum" amount of monthly spending that can be adjusted. This way in the unlikely event of a hack the international calling would be limited in exposure.
 
Many providers also allow you to set a maximum per-minute rate, which allows calls to most landline numbers in commonly called countries, but prevents calls to high value, or mobile numbers. If your provider allows this, you may want to consider using this feature.

Be sure all passwords are secure.
Extend the default IP blacklist time to days, or longer.
Set so that you get am email when an IP is blacklisted, then go in and extend that time to several years.
Keep track of attempts from similar IPs and widen the net (the subnet), to include a wider range as needed.
 
To
Doesn't matter that they didn't mention if the site uses Smartphones or Remote Extensions. It's useful information for the OP to have. If they just go and lock down their firewall to all these IP's - or allow their VoIP provider only - they'll be back here asking why their smartphones can't connect. These forums are made up of folks from novice to pro - we accommodate all.
add further ,
We have couple of IP phones provisioned via STUN, those IP phones have dynamic public IP address, approx lease time of public IP is 10 hours

And mobile users via 3CX tunnels

When it comes to SIP trunk, we only have call centric pay as you go
 
Status
Not open for further replies.

Members Online Now

Forum statistics

Threads
111,832
Messages
589,278
Members
164,662
Latest member
DejanMDS