Spam calls (or hack attempts?)

Status
Not open for further replies.

[email protected]

Customer
Joined
Jul 30, 2010
Messages
19
Reaction score
0
Since the 14th, I have received over 150 calls (and 15 second voice mail messages) that are coming through the system that are obviously not valid phone numbers. I have blocked all the different numbers, and eventually they stop, but it starts usually at 5:30 or so and goes on until 10 or so. However, they keep changing what the numbers are and I have to keep adding to the blacklist. When I looked at the activity log, then I see messages saying "ACK not received from sip:[email protected] (our main internet address). So I'm guessing these are SIP calls coming from the outside world? How can I block these, as they are going directly to my extension number.

I did answer one of the calls just to see what it might be, but I heard nothing for 20 seconds and then hung up.
 
Do you have SIP open to the internet, or just to your carrier?
Are all the phones local, or some DirectSIP?
 
Do you have SIP open to the internet, or just to your carrier?
Are all the phones local, or some DirectSIP?
Yes, I believe it is open to the internet - we have users outside the building (especially now).
Most phones are local, but the ones on the outside are using the tunnel.
 
If you are just using the 3CX Client for external users, I would recommend restricting your SIP and Media ports to just your provider.
 
As mentioned, sort your firewall out. Restrict SIP port from your SIP provider (Run firewall check prior to lockdown so it passes).

I'd also look to move off Server 2008 and upgrade 3CX to the latest version.
 
  • Like
Reactions: JohnS_3CX
I would check the logs to see where the invite comes from, if it is not from your provider's IP then someone is "ringing" your main PBX SIP port which the PBX should normally reject as it will not match the source of the call with a trunk it knows. So which Source IP is sending the calls in and who does it belong to?

I would also strongly advise to upgrade to V16 as soon as possible because 15.5 has reached and of life and does not receive updates/patches. The OS will also need to be upgraded.
 
  • Like
Reactions: craigreilly
I would check the logs to see where the invite comes from, if it is not from your provider's IP then someone is "ringing" your main PBX SIP port which the PBX should normally reject as it will not match the source of the call with a trunk it knows. So which Source IP is sending the calls in and who does it belong to?

I would also strongly advise to upgrade to V16 as soon as possible because 15.5 has reached and of life and does not receive updates/patches. The OS will also need to be upgraded.


Do I need to change the logging level then? This is what the log currently shows for a call that made it through: Call to T:Extn:1550@[Dev:sip:[email protected]:55052;rinstance=0-21127a77fe57461db062069082e8e0a2;ob] from L:771.1[Line:10001<<15963214789] failed, cause: Cause: 486 Busy Here/INVITE from 10.0.0.91:55052

Otherwise, I see some lines like this, which is what made me think it was not coming through our phone service trunk: ACK is not received from sip:[email protected]
 
How can I block these, as they are going directly to my extension number.
How do these go direct to your phone? Are the calling your extension number (only) each time? Is the source always the same IP? What type of set are you using? There have been issues, with some makes, that allow direct SIP calls to the set, unless an option is set to prevent this.
 
Last edited:
Under network settings then FQDN do you have the option for Settings for Direct SIP Calls Allowed?
 
Under network settings then FQDN do you have the option for Settings for Direct SIP Calls Allowed?
No, the option is not checked.
 
How do these go direct to your phone? Are the calling your extension number (only) each time? Is the source always the same IP? What type of set are you using? There have been issues, with some makes, that allow direct SIP calls to the set, unless an option is set to prevent this.
Based on the log info I am seeing, I believe so. THe log says call to t:extn:1550. As to the set, i'm using the 3cx windows client..
 
...and do the calls originate from the same IP each time?

Hackers usually try to place calls back out of the PBX, not to an extension.
 
Status
Not open for further replies.

Forum statistics

Threads
111,944
Messages
589,864
Members
164,835
Latest member
Firefox Technologies