Update 6 Beta Available Now

Status
Not open for further replies.
Hi,
Those are webclient bruteforce attempts, we added an event to give these more visibility as previously they would be logged only in the management console logs.
Although this isn't something new there are many scanners/bots out there looking for weak credentials, and it is advisable to stick to random/complex passwords everywhere as it is the case by default.
The Console restrictions option doesn't affect the webclient access but only the management console one.

Such offending IP addresses get eventually in the Global Blacklist once there have been multiple reports from different 3CX Systems, and after your blacklist resyncs (every 2 hours). I checked those and most are already listed on our end.
Is there a way to access the block list so we can do it at the firewall/router level?
 
You can only add a router phone via the webclient, not management console.
A guide of sorts can be seen here: https://www.3cx.com/blog/releases/v18-update-6-alpha/
I don't think my entire post was read. "In the desktop client under admin > Users > Ext 111 and I see no reference to SBC but "Routing device" drop down thats blank (Don't see the SBC that is set under admin console)."

I see where it should be but its not working as you'd expect. This site has an SBC server that shows up in the admin console. However, when you look in the "web/desk client" and it does not indicate any SBC is available or configurable and "Routing Device" is blank with nothing in the drop down or ability to add. I would think an SBC is SBC whether its piggy backed on a IP phone or running on a server, so changing the name is confusing, and its missing the one configured and visible from the main admin console.

You can't add a phone to a an existing user that has phones configured already. Currently you'd have to delete them all to get the "Configure a phone" option to appear in the web/desk client.

For the site I'm testing this in, it has a server SBC, 10+ extensions, and no current router phones.The system doesn't detect that a full fledged server SBC is available and when I create a new extension (among existing ones) and when I use the "Configure a Phone" wizard option it tries to force this extensions first phone to be a router phone, normal is greyed out. Hope that clarifies the issue.

@Nick Galea
 
Last edited:
  • Like
Reactions: Evolute IT
I don't think my entire post was read. "In the desktop client under admin > Users > Ext 111 and I see no reference to SBC but "Routing device" drop down thats blank (Don't see the SBC that is set under admin console)."

I see where it should be but its not working as you'd expect. This site has an SBC server that shows up in the admin console. However, when you look in the "web/desk client" and it does not indicate any SBC is available or configurable and "Routing Device" is blank with nothing in the drop down or ability to add. I would think an SBC is SBC whether its piggy backed on a IP phone or running on a server, so changing the name is confusing, and its missing the one configured and visible from the main admin console.

You can't add a phone to a an existing user that has phones configured already. Currently you'd have to delete them all to get the "Configure a phone" option to appear in the web/desk client.

For the site I'm testing this in, it has a server SBC, 10+ extensions, and no current router phones.The system doesn't detect that a full fledged server SBC is available and when I create a new extension (among existing ones) and when I use the "Configure a Phone" wizard option it tries to force this extensions first phone to be a router phone, normal is greyed out. Hope that clarifies the issue.

@Nick Galea
This does clarify what you meant quite a bit.

Router Phone and SBC are not the same in 3CX. SBC can do "anything" but Router phone can only act as a proxy for other phones (and not DECT, FXS, etc).

There are limits in the Web Client Admin about using a SBC just as there are limits in the 3CX Management Console about adding a Router Phone. I suspect as time goes on those limits will be fixed, but that's a guess.

What I've done for now is if using a full SBC then use the MC for now, if you are using a Router Phone use the web client.
 
  • Like
Reactions: Evolute IT
This does clarify what you meant quite a bit.

Router Phone and SBC are not the same in 3CX. SBC can do "anything" but Router phone can only act as a proxy for other phones (and not DECT, FXS, etc).

There are limits in the Web Client Admin about using a SBC just as there are limits in the 3CX Management Console about adding a Router Phone. I suspect as time goes on those limits will be fixed, but that's a guess.

What I've done for now is if using a full SBC then use the MC for now, if you are using a Router Phone use the web client.
Thanks and yes, I know how to make it work. I'm just looking at it from a client experience/usability perspective. It's confusing currently and I'm hoping this feedback gets seen and addressed in future updates/general release from beta.
 
  • Like
Reactions: SteveITS
Thanks and yes, I know how to make it work. I'm just looking at it from a client experience/usability perspective. It's confusing currently and I'm hoping this feedback gets seen and addressed in future updates/general release from beta.
Ah, gotcha. Yes, I too hope for improvements in the 3CX UI, but Nick has said that almost everything is moving to the web client admin and I suspect these improvements will come when that happens.
 
  • Like
Reactions: Evolute IT
Is something still to come regarding IP Phone SBC functionality that was announced in Alpha 6? I'm running Beta 6 and seeing the following:

Looking at a user in the admin console User > Ext 111 > Phone Provisioning for a Yealink T54W. It has 3CX SBC selected as the provisioning method and a server identified via drop down.
In the desktop client under admin > Users > Ext 111 and I see no reference to SBC but "Routing device" drop down thats blank (Don't see the SBC that is set under admin console). I also don't see where I can set a phone as an SBC if I wanted.
Hi! Could you share some more info about your system please?

1. Do you see this SBC listed in the "Admin / "Voice & Chat" section of the desktop client?
2. How has this SBC been added in the first place, using the admin console or the desktop client?
 
Hi! Could you share some more info about your system please?

1. Do you see this SBC listed in the "Admin / "Voice & Chat" section of the desktop client?
2. How has this SBC been added in the first place, using the admin console or the desktop client?
Thanks for looking into this:
1: No it doesn't show up there but the SIP Trunks do, webmeeting bridge isn't in the web/desktop client ether
2: It was added via main admin console originally.
 
i've noticed our flowroute DID rules don't match from the new admin web client vs the OG admin console. three of our DIDs show "end call" in the web console, but on the management console inbound rules they are correct and calls flow as expected.
 

Attachments

  • webclienterror.jpg
    webclienterror.jpg
    72.2 KB · Views: 14
Hi! Could you share some more info about your system please?

1. Do you see this SBC listed in the "Admin / "Voice & Chat" section of the desktop client?
2. How has this SBC been added in the first place, using the admin console or the desktop client?
I found in the Alpha version when i was having a play, i added a SBC via the admin area and then added to a group.

Then in the admin area and you go to add the phones to the 3CX system the SBC was missing from the list to select.

But if i took the SBC out of the group I could then see it and add the phones to the SBC. Then once done i added it back to the group and worked fine.
 
  • Like
Reactions: Evolute IT
Would it be possible in the future to have a Group rule send a call to a CFD app? Also, are there planned updates to the Call Flow Designer to take advantage of getting and setting group statuses? I note that there are DN properties that can be pulled from Parameters. I have a few builds where I've had to create IVRs to let users update forwarding from a handset (for example), due to the end user requirement that they not handle such things from a PC, so I'm interested to see what is happening in the CFD space.
 
Would it be possible in the future to have a Group rule send a call to a CFD app? Also, are there planned updates to the Call Flow Designer to take advantage of getting and setting group statuses? I note that there are DN properties that can be pulled from Parameters. I have a few builds where I've had to create IVRs to let users update forwarding from a handset (for example), due to the end user requirement that they not handle such things from a PC, so I'm interested to see what is happening in the CFD space.


Hi @richiewhite ,
I allow myself to answer this question since I asked the exact same questions yesterday.. to Ernesto, whom you surely know, 3CX staff well involved in the Call Flow "module".

Now that I see your question, I realize that I should have posted my question in the public forum…. to avoid imposing double “work” to 3CX Staff. Sorry @edossantos for the « duplicate work ». . I hope I can be forgiven by sharing your answer, thus saving you from repeating :)


G. BOURGEOIS say ;

Hi Ernesto,
3CX 18 version 6 gives us new features for "Extension groups" .
Are you authorized / can tell me if an update of CallFlow Designer is planned in order to facilitate project design in connection with recent new functionalities.

Aka; Date and time condition based on schedules set up in "extension groups" ;)

This is not a suggestion/idea, it's a question about what you have planned to help me establish future CallFlow Apps project strategies ..
I can see that in the Dn Properties.. we have the destinations according to the 'status' ( BREAKTIME_OPERATOR , CLOSEDTIME_OPERATOR , OPENEDHOURS_OPERATOR ) but not the schedule..


Ernesto answer me ;

« Hello Guillaume,

Happy new year!

We haven't been working on changes to the CFD yet. I understand that all these changes in 3CX would require new components to deal with those features, but nothing has been developed so far. This is something that we will need to discuss internally. … … »



I believe this is entirely justified on the part of 3CX and makes sense considering that 3CX V18.6 is still in beta… I confess to being impatient.. I am so happy with the new 3CX features. They did a great job!

friendly,

Guillaume
 
@richiewhite @gbourgeois You can forward a call to a CFD from a mini IVR Group menu yes. However big routing programmability changes will be coming with our new call manager. The new call manager, a year in the making and now in early stage testing should be available over the next few months and will feature a new routing endpoint / routing API which will make integration easier but also make it easier for us to extend features in the CFD, improve CRM and Office 365 integration as well as general integration.
 
Great that it shows incorrect login attempts, but maybe the password shouldn't be shown in clear text?
 

Attachments

  • pic.png
    pic.png
    8.6 KB · Views: 25
  • Like
Reactions: tronic
@richiewhite @gbourgeois You can forward a call to a CFD from a mini IVR Group menu yes. However big routing programmability changes will be coming with our new call manager. The new call manager, a year in the making and now in early stage testing should be available over the next few months and will feature a new routing endpoint / routing API which will make integration easier but also make it easier for us to extend features in the CFD, improve CRM and Office 365 integration as well as general integration.

Wow !!! A wonderful bright future is planned !
Hooo yes!
Thank you for your generosity in sharing this information.
It's a great gift for the New Year! !

I have the same feeling as a child .. who is told that he will have the right to go and have fun in the park if he is nice. :p

The time waits will definitely be worth it !




May the new year bring you all your wishes ! :D
 
  • Like
Reactions: Evolute IT and N_G
@G.BOURGEOIS Thanks for your enthusiasm! I think the new routing API will not disappoint you - its going to be very powerful. Plus our call manager will be faster and more efficient and handle many more calls :) we will look forward to your feedback :)
 
Great that it shows incorrect login attempts, but maybe the password shouldn't be shown in clear text?

The first, I admit to having been surprised to see password attempts in clear text but, after reflection, it is administrators who have access to this page, therefore, it is much more beneficial to see the attempts (passwords ) , that the negative effect it can bring.
If the user uses good password practices, he should not have the same password in several applications. And the fact that the incorrect password attempt is displayed, this does not leak any information because the password is precisely incorrect..


Personally, I like this new feature, it's easy to see and allows you to quickly see the different attempts ( BruteForce ). I'm mostly surprised at how ingenious bruteforce is made.. I understand that attempts are based on a custom dictionary depending on the type of application application to "break through".. here 3CX

I hope not to leak real passwords!! If so, it's time to change the passwords!! eh eh !

User or password is invalid from 93.125.114.64. (User: 10, password: 3cx@1234)
3CX Phone System Management Console ID: 30037 02/01/2023 18:58:47

User or password is invalid from 69.169.14.182. (User: 0000, password: !@0000!@)
3CX Phone System Management Console ID: 30037 02/01/2023 18:32:17

User or password is invalid from 203.209.212.100. (User: 11, password: 3cx123)
3CX Phone System Management Console ID: 30037 02/01/2023 14:28:05

.
 
Almost every other system out there does not show the password attempted. Regardless of if it's unique for that site or not, showing the attempted password in plain text is a security risk and I would ask that 3CX consider disabling that.

Imagine a situation where I use a password manager and I accidently send the wrong sites credentials to 3CX. Now I have to change that elsewhere and I only do that if I know that 3CX shows those credentials. Since the usual behavior is that a site doesn't show attempted passwords, I don't know to go to the other site and change the password and thus my password remains compromised.

At the very least a notice on the login page would be a good idea - something like: "Warning: Any Passwords Entered here, even incorrect, are logged and visible to the system administrators in plain text".
 
  • Like
Reactions: imperator
The first, I admit to having been surprised to see password attempts in clear text but, after reflection, it is administrators who have access to this page, therefore, it is much more beneficial to see the attempts (passwords ) , that the negative effect it can bring.
If the user uses good password practices, he should not have the same password in several applications. And the fact that the incorrect password attempt is displayed, this does not leak any information because the password is precisely incorrect..


Personally, I like this new feature, it's easy to see and allows you to quickly see the different attempts ( BruteForce ). I'm mostly surprised at how ingenious bruteforce is made.. I understand that attempts are based on a custom dictionary depending on the type of application application to "break through".. here 3CX

I hope not to leak real passwords!! If so, it's time to change the passwords!! eh eh !







.
[/SPOILER]
I can easily follow you, but I'm still not that exicited for seeing passwords in clear text :-)
For brute forces attacks, there's no need to have the password shown. We use the built-in firewall to block this instead.

And you say it yourself - users should have a good password practice, but let's not get into that discussion here xD
But this is also why I hope that they change it, so it only shows username.
 
@G.BOURGEOIS Thanks for your enthusiasm! I think the new routing API will not disappoint you - its going to be very powerful. Plus our call manager will be faster and more efficient and handle many more calls :) we will look forward to your feedback :)
One request: allow busy ring groups members to ring on new call (like the parameter allows), but actually as a checkbox :)
 
….

At the very least a notice on the login page would be a good idea - something like: "Warning: Any Passwords Entered here, even incorrect, are logged and visible to the system administrators in plain text".

I understand your opinion/recommandation..
Maybe a "setting to enable/disable like it is for Audit Log & Chat Logs" ?


And you say it yourself - users should have a good password practice, but let's not get into that discussion here xD
I recognize that I am not perfect myself, in my different practices lol

xD



Have nice day all ! :p
 
  • Like
Reactions: Evolute IT
Status
Not open for further replies.

Forum statistics

Threads
111,973
Messages
590,079
Members
164,898
Latest member
grahamaskew