Security problem, incoming call not from Centurylink

Status
Not open for further replies.

rmeicher

SOHO User
Joined
Nov 27, 2019
Messages
11
Reaction score
0
Get about 15 incoming calls a day with Caller ID: Conduent (8012336360) that rings into the 'All Phones' ring group. The only incoming lines are 6 Centurylink Analogs into 2 Patton 4114 devices. But when I run a Centurylink call report, no 801 number is listed and the call in times don't match the 3CX call logs either. So I don't think its coming in from the analogs.
Besides all Centurlink incoming are routed to the receptionist ex. 200.

How are these calls coming in and how do they get to my 'All Phones' ring group?
Some of the users are using the 3CX phone app, could one of the cell phones be compromised, calling ex 803 the 'All Phones' RG?

Running 3CX Windows, v16.0.5.612.
 
What ports do you have open to the PBX at the firewall? What type of firewall?
 
Its a Fortinet 60E firewall and I only have the following inbound ports open:
5001 TCP
5060 TCP & UDP
5090 TCP & UDP
9000-10999 UDP.
 
Correction. 5060-5061 TCP & UDP.
 
If you are not using a SIP provider, and have no remote phones using STUN or using the web client, you could close ports 5060 and 5061. The 3CX app will still work since it's using 5090.

Do you have Direct SIP Calls enabled?
Settings>Network Settings>FQDN> "Allow calls from/to external SIP URIs" should be unchecked.
 
If the calls are going to ring group, and not a direct SIP call, to one set, then there should be a log of the call(s) in the 3CX Activity Log. This should show the originating IP(s), which would allow you to block/ blacklist.
 
No SIP provider. Haven't yet but was planning on setting up a remote phone using STUN. So I just closed 5060 & 5061 ports. I also now allow 5001 only from two known IP addresses for web console management. No one using the Windows web client remotely.

Is there a way to see which users are using the Android or IOS client?
 
The first thing I did when I discovered the problem is I blacklisted the number in settings - blacklisted numbers, which didn't work. But I just noticed that I put it in as 801-233-6360, maybe it has to be entered with no dashes? They probably will change the caller ID number anyway. Oh, and no direct sip calls are enabled (box unchecked).

I will check the activity logs.
 
If they are reaching a ring group, then, as I said, there should be an Activity log, which will give more information than the Call Log.
 
Standard version, activity logs only go back to 5pm yesterday
 
Calls from 801-233-6360 are still coming in, so it must be through the only ports still open 5060-5061 TCP & UDP.

Call log shows: 06/15/2020 4:46:00 PM CONDUENT:Conduent (8012336360) PBX Not Answered
Activity log just shows: 06/15/2020 4:46:00 PM - [Flow] Call(C:473): caller's number '8012336360' is in blacklist

Is there another log file in Activity Log 'Global' or 'Instance' that would give me more information?
 
The activity log shown no originating IP/ provider information , in other words a full Invite message? You can set the Activity Log to Verbose.
 
OK its set to Verbose. I'm thinking a hacker has connected to one of the extensions with a client which is scarry. I guess I could initiate a 'Regenerate' on all extensions. The only users that would have to do anything are the ones using the client right (reconnect their phones)?
 
Status
Not open for further replies.

Forum statistics

Threads
111,953
Messages
589,910
Members
164,845
Latest member
tdzski5