Too many failed authentication

Status
Not open for further replies.

atmomin

Bronze Partner
Advanced Certified
Joined
Nov 5, 2019
Messages
24
Reaction score
3
One of my PBX has been target of hacking attempts for last about 1.5 months.. Every day I get 4-5 IPs blacklisted and still the hackers haven't run out of IPs.

Apparently, they have access to some kind of botnet and are using different user agent, I have noticed at least 9 different user agents as in 3 screenshots.

I had increased lock out period to 15 days, now I increased to 40 days, but the Advanced persistent threat still persists.

Is there a way to get the credentials that hackers are trying? to understand how close they are from figuring out actual credentials.

Is there any other measures I should take to ward off this APT?
 

Attachments

  • blacklist-ip3.jpg
    blacklist-ip3.jpg
    47.2 KB · Views: 30
  • blacklist-ip2.jpg
    blacklist-ip2.jpg
    47 KB · Views: 29
  • blacklist-ip1.jpg
    blacklist-ip1.jpg
    46.5 KB · Views: 26
Usually the Activity Log will show what extension numbers they are trying to register with. I have found that the IPs will generally increase by one digit, so after a pattern begins to emerge, I block an entire subnet rather than wait for them to up the IP number, and try again.
 
Unfortunately, they are using wide variety of IPs that can not be accomodated under any subnet. Starting with 1 digit first octet to 3 digit, I couldn't think of any way to apply any restriction. And they are not changing IP by few numbers or so. Thanks for the idea though.
 
Yes, I have been using the global blacklist feature for over a year now on all my PBX.
 
Do you have the PBX hosted on prem or cloud?
How are the extensions configured to connect?
 
On Google cloud. STUN and phone app.
 
On Google cloud. STUN and phone app.
Ok. I thought if you were local/on prem, you could set your edge firewall to only allow SIP traffic from your provider. But being hosted, and using STUN makes that difficult to manage.

I don't use Google Cloud hosting, but they might have a virtual firewall option you could explore.
 
honestly, you are fine, just an annoying amount of notifications, the emails are commonly misconstrued by users.

The E-Mail means the security system is doing its job.

Think of it like this, you know there are bad guys outside on the open internet, the emails are them knocking on the door and getting blocked, if you ever stop getting those notifications, that is when you need to worry, lol. They will always be trying to get into things, when you stop hearing them knocking, it can often mean they found a way in.
 
  • Like
Reactions: NicholasP_3CX
If you see them getting blacklisted then you know they were blocked for sure.

The Global Blacklist also helps and stops many more without you being notified.

This is fairly common phenomenon and should not be cause for alarm if you use secure passwords (as auto-generated by your PBX).

You can also of course limit your SIP port using the firewall so that it will only talk to the provider's range and to certain other IPs (for remote STUN phones)
 
Thank you for replies.
Now I have over 200 IPs blocked and still the hackers haven't run out of IPs, I see new IP everytime. I still get 3-4-5 blacklists everyday. I get most emails at night, you know why.

Do you guys think I should wait until I get a spike in phone bill and then see which extension they have managed to hack into.

I think it's a better solution to put username in the email, so we know how close hackers are from figuring out the right one. I get many locked out emails from my Wordpress site admin logins, I barely worry about it. because it tells me what username is locked out and it's always wrong, so I have nothing to worry.

If the username is incorrect, I don't care if I get a million emails. But in this case, I have no idea what credentials they are using and how close the hackers are to the correct credential.

I hope this makes sense to others. I don't think it should be that hard to change email format for added peace of mind for admins around the world.
 
If the username is incorrect, I don't care if I get a million emails. But in this case, I have no idea what credentials they are using and how close the hackers are to the correct credential.

If your using 3CX and have allowed it to generate the extension usernames and passwords itself based on its own password policy settings, then it is 99.99% impossible for a hacker to guess the username as they are scrambled alphanumerics, not actual words. Have you even looked at them?

This is a non issue unless you have gone and imported the usernames or changed them yourself to ones you've chosen. So which is the case?
 
Status
Not open for further replies.

Forum statistics

Threads
111,954
Messages
589,924
Members
164,852
Latest member
priya