- Joined
- Mar 31, 2023
- Messages
- 27
- Reaction score
- 3
For the past few days, I've had email alerts about attempted calls to blocked countries (we lock down certain countires I know my users will never call).
On investigation, it seems someone has logged in to an extension and made about 100 calls over an 8 hour period overnight. Some have got throgh to countries we do call. I've changed the password on the account that was used, but on the second night, a different account was used. Our users use Office365 to login to 3CX and we leave the default 3cx password as is. I'm hoping I don't have to go thorugh all my extensions and change this if the default is not complex enough!! One of the accounts was a temp test account and I know the password was "Password12345!". We've now obviously reset all our test account passwords and wont be so lazy in future!!
Diagnosing how this happened seems to be really hard! I've searched throgh all the log files and finally found their IP address in the 3CX-tunnel log. We're on prem so I've blocked the network range on our firewall. IP whois said it was a home broadband pool of addresses. Second day, the IP range comes from different country and different ISP - again home broadband pool from a known ISP so I don't think NordVPN or the like are in use here.
I'm assuming they have just logged in to the 3CX web client and made calls as the logs say they calls were made from 127.0.0.1.
Anyone got any ideas what else I can do? The anti-hacking settings are all on the default. Nothing triggered the IP blacklist and failed auth protection is set to 2 attempts. Does 3CX log failed password attemtps? Just seems crazy I've got to sit here and wait for their next move!!! So frustrating I can't turn off non O365 logins which require 2FA.
We're on v18 debian update 9.
On investigation, it seems someone has logged in to an extension and made about 100 calls over an 8 hour period overnight. Some have got throgh to countries we do call. I've changed the password on the account that was used, but on the second night, a different account was used. Our users use Office365 to login to 3CX and we leave the default 3cx password as is. I'm hoping I don't have to go thorugh all my extensions and change this if the default is not complex enough!! One of the accounts was a temp test account and I know the password was "Password12345!". We've now obviously reset all our test account passwords and wont be so lazy in future!!
Diagnosing how this happened seems to be really hard! I've searched throgh all the log files and finally found their IP address in the 3CX-tunnel log. We're on prem so I've blocked the network range on our firewall. IP whois said it was a home broadband pool of addresses. Second day, the IP range comes from different country and different ISP - again home broadband pool from a known ISP so I don't think NordVPN or the like are in use here.
I'm assuming they have just logged in to the 3CX web client and made calls as the logs say they calls were made from 127.0.0.1.
Anyone got any ideas what else I can do? The anti-hacking settings are all on the default. Nothing triggered the IP blacklist and failed auth protection is set to 2 attempts. Does 3CX log failed password attemtps? Just seems crazy I've got to sit here and wait for their next move!!! So frustrating I can't turn off non O365 logins which require 2FA.
We're on v18 debian update 9.