System attacks on all 3cx systems at the same time

Status
Not open for further replies.

teichhei

Joined
Oct 11, 2009
Messages
28
Reaction score
0
Morning everyone,

For a short while now, maybe a week or so, all PABXs that I receive notifications from are blocking IPs for invalid credentials. Simultaneously. The systems are on different Azure datacenters and the DNS Servers are from various providers, the attackers are mostly from Russia and the US.
Now am I missing something here or is 3cx itself the only common denominator where those people potentially have all PABX URLs in one place? Or did a brand spanking new cool port scanner come out and everyone is trying that now. Was reasonably quiet before, maybe 4 per week.

Latest offenders:
91.233.116.240
74.91.26.18
162.219.24.2
107.181.79.27
 
If they are all in different datacenter locations then that is most strange.

Either way however 3CX is doing it's job but I still would consider bolstering your security.

Look at locking down your firewall and if you don't make or receive calls from Russia or the U.S restrict the under Settings - security - allowed country codes in the PBX.
 
I have seen hits on multiple 3CX installs, from the same IP, within a short time. I don't doubt that they have many bots scanning different ranges of public IPs. Even though I have set 3CX to block an attempt for several days automatically, If I don't block them permanently, I see them come back for another try.

I try to keep on top of adding then to the permanent blacklist, when i get an email notification, and widening in the net (subnet), as/if they change IPs. It does eventually slow down. Even with all of the attempts, I'm not aware that anyone has actually compromised my system.

Just be sure you haven't left any, easy to guess "testing" passwords , on the system.
 
I've now blocked everything as a trial on one system except known provider IP ranges and static IPs for my extensions. That works, but makes the mobile apps a bit hard to use. :)
Country blocking would be really nice on the 3cx side, not just by dialled number but also by zone list so that it doesn't even accept connection attempts from e.g. russia or the US. I know some firewalls do it.
It's still weird that this was not an issue up to beginning of July and now, if it is port scanners then they are extremely effective. It looks like they use DNS names once they've established that. But to be fair, all of them are in Microsoft datacenters.
 
It looks like they use DNS names once they've established that. But to be fair, all of them are in Microsoft datacenters.

I suspect that they just go, sequentially, through IP addresses...much easier. If they get a "hit", they note it, and come back for another go.
 
I've now blocked everything as a trial on one system except known provider IP ranges and static IPs for my extensions. That works, but makes the mobile apps a bit hard to use. :)

Try locking down just 5060 to your sip provider and not 5090/tunnel or your Management port (normally 443/5001). Most attacks are going for the 5060 which isn't used by the mobile phones. 5060 is only needed for the provider and for phones configured as remote stun.
 
Status
Not open for further replies.

Forum statistics

Threads
111,889
Messages
589,571
Members
164,753
Latest member
GemmaC