Security Question

Status
Not open for further replies.

khaskin

Customer
Joined
Jun 17, 2015
Messages
3
Reaction score
0
Our 3CX system was hacked and someone made calls to Samoa and other international numbers. They went into one extension and made the calls. I have the report for our 3CX system with the extension. One line of the report states: user (6706) replaced by 011237667086432

Does this mean they hacked the registered extension? Our Voicemail system will not allow calls to go out so if they used the PIN to access the options on this extension, they would not have been able to call through VM. We are using v16. Any suggestions on some security measures I'm missing?

Before we moved to 16, we had the Disallow use of extension outside Lan checked. It looks like all extensions now have this unchecked.
  • Disallow use of extension outside the LAN – blocks any registrations from outside of the network for 3CX apps and IP phones.
We have a few people using the 3CX app. This particular extension hacked uses the app.

Any recommendations would be most welcome.

Thank you everyone,
Kim Haskin
Denton Bible Church
 
So, from what you can tell, a 3CX extension placed this/these calls? If that is the case then they would have to know the password. If this was set to something easy to guess, then it may have been a matter of trying different extension /password combinations. Usually that is not something that is an easy hack. If your password is a random number/letter combination, then it may mean that someone with inside knowledge of your system actually placed the call.

The Activity Log should show from what IP the call(s) originated. That IP can be Blacklisted.

You can block all international calls to certain destinations if no one ever calls there.

You can change your outbound rules to require a "non-standard" prefix, known only to a few, to place international calls.

Be certain that all extension passwords are secure, not east to guess

How many people have access to manage 3CX at your site? You may want to consider changing that password as well.

Run a virus scan of the PC/server running 3CX, if possible, there might be a Trojan collecting keystrokes, or giving remote access.
 
Well the fact that the disallow use of extension outside of the lan is unchecked for all the extensions leads me to believe the admin credentials (or a user with system admin rights) were compromised and SIP credentials were gained that way. Then someone just authenticated against your system as a valid extension and made those calls. I'd start by regenerating all extensions and changing the admin password.
 
Thank you so much. Yes, I think the extension password was weak allowing them to gain access. I'm trying to find that activity log from that date.

I'm currently showing in my activity log a consistent IP address trying to authenticate assigned to an extension that does not exist on my system. I'm looking into how to find and delete that extension. I have blacklisted that IP. We are reviewing our International needs.

Only myself and our Managed IT group have access to the 3CX console. I can change that password. Our PC/Server has been reviewed and scrutinized for any Trojan or malicious agent.

Thank you for your insight!
Kim
 
I would agree with the above points, it seems someone has compromised the system/network as opposed to using something like a scanner (for the most part 3CX will block commonly known scanner user-agents as standard anyway - sipviscous, pplsip etc).

Inspecting the local server with something like malwarebytes and/or Microsoft safety scanner (2 free options) if using Windows is a good idea, https://docs.microsoft.com/en-us/wi...otection/intelligence/safety-scanner-download first.

I would also regenerate (as already advised) all passwords and credentials, also check that your system admin email has not been changed since you can opt for "forgot" password on the management console and have the password sent to this specified address, I would also go a step further and only allow access to specific IP addresses: https://www.3cx.com/community/threa...llow-access-from-specific-ip-addresses.69348/

You can limit the PBX to only allow calls to certain countries and manipulate the outbound rules to only allow (for example) certain call lengths and blocking of premium rate numbers, however if your hacker had the ability to change the "disallow use of extension outside of the LAN" setting they would of most likely had the ability to change these settings too.

I think also a call to your provider would be a good step, explain the situation. I have known of some providers being able to offer some form of a rebate (dependent on circumstance and provider) since they may not wish to be seen as profiting from malicious activities (its worth a shot). Whilst on the call try and find out what options they offer for limiting calls by Geo location and limits/caps outside of normal working hours - if they don't I would recommend moving to a provider who does - I can give recommendations.

Whist on the subject of security (although it may depend on how the system was breached) also check the firewall in front of 3CX (I hope it is not public facing) and ensure that there are no rules open to "any" specifically for the likes of HTTPS or SIP 5060.
 
Last edited:
Status
Not open for further replies.

Forum statistics

Threads
111,954
Messages
589,921
Members
164,852
Latest member
priya