Security questions or issues?

Status
Not open for further replies.

Nomads IT

Trial User
Joined
Nov 5, 2019
Messages
9
Reaction score
0
I got a really weird one:

I'm sure you've seen this one before. Someone tries to call a blocked number, and you get a notification:
Call from [ext] to [001116105004196] has been rejected by 3CX as it's listed as a "blocked country"[00111].

Reason: 001116105004196 contains Prefix 00111. Calls to 00111 are not allowed by the system.

(If you google that number, it's some Telemarketer number in pensivania). The first time calls like these racked up a massive bill, before I clamped down on the country codes.

Now I'm getting this from various extensions every so often. I can re-provision the phone, and the next day it happens again. From the same Extension. I can even change the userID to a 30 digit userID, same as the password, next day I get another attempt.
I removed that phone from the LAN, so now it stopped.

But this is now starting on a different extension.
Is there a way to see, from which external IP someone connected an Ext to the PABX? They would have to authenticated in some way before the Ext could attempt to dial. Or am I being too paranoid?
Or am I looking in the wrong place for this?
 
Typically the phones page shows the external IP under the IP column (some clients do not and show 127.0.0.1).
1653351637910.png

Try a re-generate on the extension and have all the passwords change.
If the phone is only used in LAN or via SBC/Apps you can block external access
1653351705024.png
Or if used in LAN and no SBC/Apps
1653351728417.png
 
The 3CX Activity Log (may have to set to Verbose), will show any registration attempt, and the originating IP. Unless you have made the passwords easy to guess, or they have obtained the passwords by some other means, then a random hacker should not be able to place calls using a valid extension.

Some hackers will attempt to send a Direct SIP call, but I have never seen one succeed. In most cases they are sending to your public IP and not your FQDN (because they don't know it).
 
Last edited:
Typically the phones page shows the external IP under the IP column (some clients do not and show 127.0.0.1).
View attachment 30300

Try a re-generate on the extension and have all the passwords change.
If the phone is only used in LAN or via SBC/Apps you can block external access
View attachment 30301
Or if used in LAN and no SBC/Apps
View attachment 30302
Done that before. Regenerated the ID and password, updated the phone, the next day I got the same messages again that said phone tried the same calls.
 
The 3CX Activity Log (may have to set to Verbose), will show any registration attempt, and the originating IP. Unless you have made the passwords easy to guess, or they have obtained the passwords by some other means, then a random hacker should not be able to place calls using a valid extension.

Some hackers will attempt to send a Direct SIP call, but I have never seen one succeed.
That's a good one. I'll give this one a try, fingers crossed it shows something. thank you :)
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,083
Members
164,900
Latest member
Silent_Guru