False positive Unusual outgoing traffic from 3CX

Status
Not open for further replies.

Yannik

Free User
Joined
Oct 20, 2018
Messages
5
Reaction score
0
@Yannik based on the attached screenshot the " lencr.org " is Lets Encrypt for the certificate of the PBX, please check here :

https://letsencrypt.org/docs/lencr.org/

The rest are PUSH messages.

If you have any further questions, please let us know.
 
  • Like
Reactions: Charles_3CX
Unfortunately, this is not a satisfying resolution. Please escalate this issue.

I can provide the following additional information:
Lets encrypt is not configured on the PBX, so there should not be any outgoing traffic to that domain.

According to my research the traffic to 92.123.213.105 are push messages for the firefox browser - which makes no sense, since firefox is obviously not installed on the PBX.

Since this could also be used for exfiltration of data, this should be investigated further.
 
@Yannik as I can see the FQDN of your PBX is " xxxxxx.my3cx.de " which is a 3cx one.
Now, open your Management Console, click on the View Site Information on the top left corner and then click on " Connection is Secure " . Then click on the " Certificate is Valid " and you will see that the Organization is Let's Encrypt.

" updates.push.services.mozilla.com " is a push notification server for users that are using Mozilla as their browser.
If you have users on Firefox with the web client, please check here :
https://mozilla-push-service.readth...Service is the,the autopush HTTP API document.
This can also be related to your Windows machine where the PBX is installed on.
 
Hello Nikos, it is a different PBX, not the one associated with this account.

Can you please confirm that 3cx is using the mozilla push service? Is it using something else for chrome?

It would be good if these requirements would be added to the Firewall page I have linked in the OP.
 
@Yannik PM me with the License key of the PBX that has this behavior and does not have a 3CX FQDN.
 
I have found the reasons for the requests to r3.o.lencr.org:
3cx has OCSP stapling enabled in /var/lib/3cxpbx/Bin/nginx/conf/nginx.conf.
("ssl_stapling on")
Therefore nginx tries to get OCSP information from the OCSP URI, which, in this case, indeed was a letsencrypt certificate.

Please add this requirement to the firewall configuration guide.

Regarding the mozilla push thing:
Can you please confirm that 3cx is using the mozilla push service? Is it using something else for chrome?
 
@Yannik as per our OM as proven yes this is a custom certificate on the PBX which is Lets Encrypt.
Indeed as you mentioned the requests are valid and you can also check them here: https://crt.sh/

For the firewall configuration, all the references are for 3cx which includes also requests from the PBX for renewal of a 3cx cert.
Since this is a custom certificate and not a 3CX one, we will check this with the relevant department.

For the PUSH, yes this is also normal as we use background technology in order push to work.
Since this is a false positive, we will mark this thread accordingly.
Thank you for your query!
 
Status
Not open for further replies.

Forum statistics

Threads
111,819
Messages
589,168
Members
164,642
Latest member
davids86