Too many attacks on 3CX-hosted PBX

Status
Not open for further replies.

Dominique_CH

SMB User
Advanced Certified
Joined
Mar 20, 2020
Messages
84
Reaction score
15
We have a 3CX-hosted PBX for testing purposes and fact is that it is being too widely attacked. Although these attacks' IPs end up blacklisted after 5 unsuccessful attempts, we just wonder why so many attacks happen in the first place. Our IP blacklist currently counts approx. 150 entries after 1 month.
Does anyone else experience this type of problem? Any solution or counter-measure possible?
 
Hi @Dominique_CH,

This matter is less related to a hosted instance or a self-operated system exposed to the internet. 3CX has strong build in measures that are enabled in hosted by default to protect you:

1) Users have by default strong passwords (don't make them weak!)
2) Enabled 'Automatic Global 3CX IP Blacklist'
3) Further reduce failed authentication attempts to block an IP address.
  • Login to your Management Console and select Security from the left menu.
  • Select Anti-Hacking
  • Change the value to whatever suits best for you. (Default is 25)

1645085654267.png

Additionally, make sure that each of your extensions has the following option ticked unless having STUN phones (not supported in 3CX hosted).

1645086087205.png


Please be noted that if scan hacking attempts continue, they will be unsuccessful when the above recommendations are followed.
 

Attachments

  • 1645085635200.png
    1645085635200.png
    9 KB · Views: 31
Last edited by a moderator:
Hi,
These recommendations are implemented already, and unsuccessful attempts are blacklisted after 5 attempts. The numbers used as userIDs aren't even present on the system. The lockout time is even set to one year.
I'm wondering why the number of attacks is so high (2-6 a day) and whether we're the only ones experiencing such attacks on 3CX-hosted system.

We have several customers w/ on-premises systems getting no IPs blacklisted at all, probably because we systematically change the default SIP-port from 5060 to something else.
 
@Dominique_CH I can fully understand what you are saying.
Using custom ports on SIP yes it can kind of reduce the requests but can't ensure also that these will be eliminated totally.
By the time a port is open to the internet the only way to make this not reachable, is to setup a firewall in front with allowed source ip addresses only.
Other than that, if the port is open and anytime registration attempts can happen from anywhere.
PBX has the ability to prevent these kind of attempts due to the advanced security features that work on the background. When an ip has been blacklisted then all requests from the ip are totally ignored from the PBX in order this to not consume resources of the PBX.
We can for sure assure you that 2-6 blacklisted ip addresses per day is not a big number of attempts, its just a random attempt.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,083
Members
164,901
Latest member
Silent_Guru