aholmes-think
Platinum Partner
- Joined
- Aug 10, 2017
- Messages
- 33
- Reaction score
- 19
If anyone needs a way to push this update to all of their self hosted 3CXs in a few clicks, shoot me a PM.
<field name="RequireAuthFor">4</field>
It sounds like if you use authentication to register your SIP trunks, you are not vulnerable. If you don't send credentials to register, you need to patch.I'm assuming fqdn authentication is the same thing correct? can we get more info on what the attack involves? was there a hardening configuration we could apply before this update to prevent this attack surface?
Terrible is a bit harsh, its not that much different.. the new lick of paint looks very nice - stick it in dark mode and its easier on the eyes.The new PWA app with the latest update needs a lot of work. It looks terrible, the older version was much better.
I really love the new design and the notification tab but I feel it a bit "over-sized" compare to the old one.You mean the new update 9 interface? You don't like the look or you have specific issues with different pages in terms of sizing or incompatibility?

You are right, I was about to add my opinion as well, so you did the right thing by reminding.Please dont get me wrong, but the topic is "Security Alert for Systems with IP Based SIP Trunks"
Maybe webclient design discussions are a bit wrong at this place.
Is there something else except dark mode (for EVERYTHING)???Terrible is a bit harsh, its not that much different.. the new lick of paint looks very nice - stick it in dark mode and its easier on the eyes.
We do have it in several security related guides, but it's difficult to offer as a blanket advice - there are many SIP providers that have IP address pools that can change somewhat dynamically, breaking communications if the PBX admins are not getting advanced notice - yes, your point is valid, just difficult to put out as core setup guidance.In the 3CX users' guides it should really recommend allowing the SIP ports to your provider IPs only.
I guess would also create a support issue, if people dont do it rightWe do have it in several security related guides, but it's difficult to offer as a blanket advice - there are many SIP providers that have IP address pools that can change somewhat dynamically, breaking communications if the PBX admins are not getting advanced notice - yes, your point is valid, just difficult to put out as core setup guidance.
Details The IP 77.239.128.11 has been blacklisted for 201 sec. Reason: requests rate is too high!Well you should whitelist it, but if proper communication/registration was taking place it should not really be getting throttled.Details The IP 77.239.128.11 has been blacklisted for 201 sec. Reason: requests rate is too high!
is this part of what the update does? like some throttle on requests on the trunk ip address?
The ip is the provider ip address, never happened before.
If I allow the ip address in the ip blacklist this shouldn't happen anymore, correct?
can you explain a bit more in depth what this is about? Before the blacklist took place I have 6 INVITES from sip:nonexistingDID@trunkip, then the blacklist kicked inWell you should whitelist it, but if proper communication/registration was taking place it should not really be getting throttled.
WebRTC needs them, though.In the 3CX users' guides it should really recommend allowing the SIP ports to your provider IPs only.
Founded in 2005, when VoIP was an emerging technology, 3CX has gone on to establish itself as a global leader in business communications.