Spoofed IP's / Port 5060

Status
Not open for further replies.

DrainBamaged

Forum User
Advanced Certified
Joined
Feb 21, 2019
Messages
168
Reaction score
41
Good Day,

We have a branch office who is experiencing a concentrated and prolonged hack attempt by someone using spoofed IP's on port 5060. They are attempting to register a phone with thousands of attempts that has lasted two weeks now. Some notes:

- Remote users use softphones through the port 5090 tunnel.
- "Disallow use of extension outside the LAN (Remote extensions using Direct SIP or STUN will be blocked)" is turned on for all extensions.
- Each extension has a randomly generated user name and password that are quite complex.
- The hacker was recycling IP's when they became unblocked, so I extended the time they were blocked on the server dramatically.

Basically, it's impossible for them to log on, but the attempts are clogging my server with blocked IP's (currently 420+) and while remote, it is possible they can use an IP of one of our remote workers and block them.

My question is, if we are using port 5090 for the softphone tunnel, can I turn off port 5060 on the firewall and stop these attempts at the firewall so they never make it to the server? The SIP has an independent internal connection so no issues there.

Thanks.
 
Good Day,

We have a branch office who is experiencing a concentrated and prolonged hack attempt by someone using spoofed IP's on port 5060. They are attempting to register a phone with thousands of attempts that has lasted two weeks now. Some notes:

- Remote users use softphones through the port 5090 tunnel.
- "Disallow use of extension outside the LAN (Remote extensions using Direct SIP or STUN will be blocked)" is turned on for all extensions.
- Each extension has a randomly generated user name and password that are quite complex.
- The hacker was recycling IP's when they became unblocked, so I extended the time they were blocked on the server dramatically.

Basically, it's impossible for them to log on, but the attempts are clogging my server with blocked IP's (currently 420+) and while remote, it is possible they can use an IP of one of our remote workers and block them.

My question is, if we are using port 5090 for the softphone tunnel, can I turn off port 5060 on the firewall and stop these attempts at the firewall so they never make it to the server? The SIP has an independent internal connection so no issues there.

Thanks.
Yes you can block 5060 if you don't have any STUN phones and no outside providers.

However, put a screenshot of your Security > Anti-Hacking page. We usually dial those to limit the amount of attacks we get.
 
In your case then most likely you will be just fine. Externally 5060 will be used:

- by internet SIP providers
- also by STUN phones
- any app that doesn't use tunnel (deprecated)
- remote bridges that don't use tunnel

Monitor the system for a while after you block it and you should be fine.
 
Hi Frederick,

By policy, I can't post internal information. I have adjusted those values to lower thresholds to combat the logins

Good news on the 5060
 
Hi Frederick,

By policy, I can't post internal information. I have adjusted those values to lower thresholds to combat the logins

Good news on the 5060
"Internal information"? You mean settings. Anyway, make sure the flood is set to 100, this will help a lot.
 
I picked ten IP's at random and you may be able to detect a subtle pattern emerging.

US (Virginia)
US (California)
US (Montana)
US (Kentucky)
US (California)
US (Oregon)
US (Kentucky)
US (Missouri)
US (Oregon)
US (Louisiana)

Looks like a firewall country filter is all I need to do.
 
Update: I applied a US 5060 rule and blocked 6,600+ login attempts overnight. Still had a dozen or so bans coming from UK and Canada IP's. Will remove the US filter and just leave the 5060 block in place to cover all traffic globally.
These attempts are coming from a VPN network. I can't identify which one or I'd report it. 6,600 login attempts in eight hours across a dozen IP's is definitely deliberate and criminal.

As an FYI to others, the telephone they are trying to register is: PolycomVVX-VVX_401-UA5.4.1.18405
 
  • Like
Reactions: JohnS_3CX
Make sure that if you are using a SIP Trunk to allow that through the firewall on 5060 (or 5061 as appropriate)
 
Make sure that if you are using a SIP Trunk to allow that through the firewall on 5060 (or 5061 as appropriate)
The last line of the OP will address your concerns.
 
Great information about the port. However, the actual process involved in attempting this fix is a bit turbid.
A) Can this be done on a 3CX hosted sever as well?
B) are the config changes limited to the Management console?
C) must the SIP provider be informed or must config changes occur at the SIP provider as well?

I'm Really curious to test this out, but to I am reluctant to muck up the install to learn.

Any suggestions? or clarifications? Your insight is a appreciated in figuring out the mechaics of this this fix.

Thanks,
 
Between your 3CX server and the internet you likely have a device doing some sort of firewalling or at least NAT.

This device is allowing traffic to pass to the 3CX server.

The advise above is to lock down / restrict what traffic is allowed to pass.

If your server is hosted by 3CX this is not applicable to you. If your server directly connects to the internet (The server's IP is not in RFC1918 space) this is also not applicable to you.

The changes affect 3CX as a whole - not specific to management.

The SIP provider needs to be allowed to talk to 3CX - so you should check with them as to what IPs they need allowed. They don't need to change anything on their end.
 
Status
Not open for further replies.

Forum statistics

Threads
111,976
Messages
590,088
Members
164,904
Latest member
gdstratton