Update 6 Beta Available Now

Status
Not open for further replies.
Heads up after updating from Release to Alpha then Beta Getting this error:

  • Provisioning file /provisioning/bfdxnoerq51uuzd/firmware/yealink//YL0000000000.rom requested by XX.9X.17X.1X8 could not be generated
    3CX Template Parser ID: 30040 01/05/2023 10:44:12 AM
  • Provisioning file /provisioning/bthxnoref51uuzd/firmware/yealink//T58W.rom requested by XX.9X.17X.1X8 could not be generated
    3CX Template Parser ID: 30040 01/05/2023 10:44:08 AM


The Phones all work and register but this is in the dashboard logs.

3cx Hosted.
Yealink T58A and T58W Pro. Latest Firmware from 3CX.
 
Heads up after updating from Release to Alpha then Beta Getting this error:

  • Provisioning file /provisioning/bfdxnoerq51uuzd/firmware/yealink//YL0000000000.rom requested by XX.9X.17X.1X8 could not be generated
    3CX Template Parser ID: 30040 01/05/2023 10:44:12 AM
  • Provisioning file /provisioning/bthxnoref51uuzd/firmware/yealink//T58W.rom requested by XX.9X.17X.1X8 could not be generated
    3CX Template Parser ID: 30040 01/05/2023 10:44:08 AM


The Phones all work and register but this is in the dashboard logs.

3cx Hosted.
Yealink T58A and T58W Pro. Latest Firmware from 3CX.

Is « bruteforce » tentative hack/download provisioning file ..
is same for password…

@Nick Galea has something changed with the console restrictions in this build? Just installed the BETA and shortly thereafter, noticed that I have #$#@ trying to login to the console from random IPs. My 3CX instance is locked down to only allow a range of IPs (and these aren't on the allowed list) of IPs that should be even able to get to the console, let alone try to login.
For years prior to this, this has been working fine and we never even saw any attempts due to the console IP 'allowed only' list, and 'Automatic Global 3CX IP Blacklist' always being enabled.

Also noticed that these IP's are NOT being auto added to the 'IP Blacklist' due to too many failed attempts...
GMT is +11 ADST

  • User or password is invalid from 84.239.14.171. (User: 1000, password: 123456)
    3CX Phone System Management Console ID: 30037 02/01/2023 19:52:56
    [*]User or password is invalid from 74.208.16.235. (User: 00000, password: Test123!)
    3CX Phone System Management Console ID: 30037 02/01/2023 18:59:35
    [*]User or password is invalid from 74.208.16.235. (User: 00000, password: Welcome123!)
    3CX Phone System Management Console ID: 30037 02/01/2023 18:59:30
    [*]User or password is invalid from 74.208.16.235. (User: 100, password: Welcome1234!)
    3CX Phone System Management Console ID: 30037 02/01/2023 18:59:21
    [*]User or password is invalid from 74.208.16.235. (User: 110, password: Password123!)
    3CX Phone System Management Console ID: 30037 02/01/2023 18:59:18
    [*]User or password is invalid from 93.125.114.64. (User: 10, password: 3cx@1234)
    3CX Phone System Management Console ID: 30037 02/01/2023 18:58:47
    [*]User or password is invalid from 93.125.114.64. (User: 11, password: 123000)
    3CX Phone System Management Console ID: 30037 02/01/2023 18:58:47
    [*]User or password is invalid from 93.125.114.64. (User: 1000, password: backup1000)
    3CX Phone System Management Console ID: 30037 02/01/2023 18:58:44
    [*]User or password is invalid from 77.68.55.34. (User: 101, password: Passw0rd123!)
    3CX Phone System Management Console ID: 30037 02/01/2023 18:53:16
    [*]User or password is invalid from 77.68.55.34. (User: 100, password: testtest)
    3CX Phone System Management Console ID: 30037 02/01/2023 18:53:13
    [*]User or password is invalid from 77.68.55.34. (User: 000, password: password123!)
    3CX Phone System Management Console ID: 30037 02/01/2023 18:53:05
    [*]User or password is invalid from 77.68.55.34. (User: 000, password: Password1!)
    3CX Phone System Management Console ID: 30037 02/01/2023 18:52:48
    [*]User or password is invalid from 85.215.119.231. (User: 003, password: Test1234!)
    3CX Phone System Management Console ID: 30037 02/01/2023 18:46:31
    [*]User or password is invalid from 85.215.119.231. (User: 301, password: Test1234!)
    3CX Phone System Management Console ID: 30037 02/01/2023 18:46:31
    [*]User or password is invalid from 85.215.119.231. (User: 201, password: Test1234!)
    3CX Phone System Management Console ID: 30037 02/01/2023 18:46:18
    [*]User or password is invalid from 85.215.119.231. (User: 1004, password: Test1234!)
    3CX Phone System Management Console ID: 30037 02/01/2023 18:46:12
    [*]User or password is invalid from 69.169.14.182. (User: 1310, password: 000000)
    3CX Phone System Management Console ID: 30037 02/01/2023 18:32:18
    [*]User or password is invalid from 69.169.14.182. (User: 0000, password: !@0000!@)
    3CX Phone System Management Console ID: 30037 02/01/2023 18:32:17
    [*]User or password is invalid from 69.169.14.182. (User: 000, password: pass@123456)
    3CX Phone System Management Console ID: 30037 02/01/2023 18:32:16
    [*]User or password is invalid from 82.165.71.76. (User: 401, password: Test1234!)
    3CX Phone System Management Console ID: 30037 02/01/2023 17:46:50
    [*]User or password is invalid from 82.165.71.76. (User: 301, password: Test123!)
    3CX Phone System Management Console ID: 30037 02/01/2023 17:46:50
    [*]User or password is invalid from 82.165.71.76. (User: 305, password: Welcome123!)
    3CX Phone System Management Console ID: 30037 02/01/2023 17:46:36
    [*]User or password is invalid from 82.165.71.76. (User: 203, password: Test1234!)
    3CX Phone System Management Console ID: 30037 02/01/2023 17:46:26
    [*]User or password is invalid from 82.165.48.86. (User: 301, password: Start1234!)
    3CX Phone System Management Console ID: 30037 02/01/2023 17:46:11
    [*]User or password is invalid from 82.165.48.86. (User: 502, password: Welcome123!)
    3CX Phone System Management Console ID: 30037 02/01/2023 17:46:02
    [*]User or password is invalid from 82.165.48.86. (User: 301, password: Admin1234!)
    3CX Phone System Management Console ID: 30037 02/01/2023 17:45:47
    [*]User or password is invalid from 82.165.48.86. (User: 301, password: Start123!)
    3CX Phone System Management Console ID: 30037 02/01/2023 17:45:44
    [*]User or password is invalid from 217.160.40.97. (User: 0000, password: Welcome2020!)
    3CX Phone System Management Console ID: 30037 02/01/2023 16:50:51
    [*]User or password is invalid from 217.160.40.97. (User: 2020, password: Welcome123!)
    3CX Phone System Management Console ID: 30037 02/01/2023 16:50:48
    [*]User or password is invalid from 217.160.40.97. (User: 1010, password: Welcome123!)
    3CX Phone System Management Console ID: 30037 02/01/2023 16:50:38
    [*]User or password is invalid from 217.160.40.97. (User: 100, password: Test2020!)
    3CX Phone System Management Console ID: 30037 02/01/2023 16:50:34
    [*]User or password is invalid from 82.165.71.76. (User: 1002, password: Test1234!)
    3CX Phone System Management Console ID: 30037 02/01/2023 16:49:22
    [*]User or password is invalid from 82.165.71.76. (User: 0002, password: Test1234!)
    3CX Phone System Management Console ID: 30037 02/01/2023 16:49:17
    [*]User or password is invalid from 82.165.71.76. (User: 1001, password: Test123!)
    3CX Phone System Management Console ID: 30037 02/01/2023 16:49:06
    [*]User or password is invalid from 82.165.71.76. (User: 1001, password: Welcome123!)
    3CX Phone System Management Console ID: 30037 02/01/2023 16:48:57
    [*]User or password is invalid from 82.165.48.86. (User: 0003, password: Start1234!)
    3CX Phone System Management Console ID: 30037 02/01/2023 16:48:50
    [*]User or password is invalid from 82.165.48.86. (User: 0005, password: Start123!)
    3CX Phone System Management Console ID: 30037 02/01/2023 16:48:50
    [*]User or password is invalid from 84.239.14.171. (User: 0000, password: 123456)
    3CX Phone System Management Console ID: 30037 02/01/2023 16:48:47
    [*]User or password is invalid from 82.165.48.86. (User: 2000, password: Welcome123!)
    3CX Phone System Management Console ID: 30037 02/01/2023 16:48:38
…..



Response from 3CX ..applies for bruteforce get provisioning files

Hi,
Those are webclient bruteforce attempts, we added an event to give these more visibility as previously they would be logged only in the management console logs.
Although this isn't something new there are many scanners/bots out there looking for weak credentials, and it is advisable to stick to random/complex passwords everywhere as it is the case by default.
The Console restrictions option doesn't affect the webclient access but only the management console one.

Such offending IP addresses get eventually in the Global Blacklist once there have been multiple reports from different 3CX Systems, and after your blacklist resyncs (every 2 hours). I checked those and most are already listed on our end.
 
Last edited:
Secure SIP
Was looking through or testing box and noticed that the keys are blank when enabled for Secure SIP. Not sure how this happened never had an issue before. Is there a way to regenerate them without doing removal and reinstall as has been previously posted?
 
Heads up after updating from Release to Alpha then Beta Getting this error:

  • Provisioning file /provisioning/bfdxnoerq51uuzd/firmware/yealink//YL0000000000.rom requested by XX.9X.17X.1X8 could not be generated
    3CX Template Parser ID: 30040 01/05/2023 10:44:12 AM
  • Provisioning file /provisioning/bthxnoref51uuzd/firmware/yealink//T58W.rom requested by XX.9X.17X.1X8 could not be generated
    3CX Template Parser ID: 30040 01/05/2023 10:44:08 AM


The Phones all work and register but this is in the dashboard logs.

3cx Hosted.
Yealink T58A and T58W Pro. Latest Firmware from 3CX.
This is fine as some phones have hard-coded sequence of files they try to get, even those which are not present on the PBX. It's been always like this but now more evident because of the new type of event.
 
Secure SIP
Was looking through or testing box and noticed that the keys are blank when enabled for Secure SIP. Not sure how this happened never had an issue before. Is there a way to regenerate them without doing removal and reinstall as has been previously posted?

to access the PBx… Is it a 3CX supported FQDN or a self-managed FQDN?
 
Our best practice guideline is to start extensions from 200. It leaves us with under 200 to make dummy extensions and avoid users to have nummers in the 1xx range. As we, in Belgium, are using 100, 101, 107, 112, ... as priority nummers.
I hope this might help you.
I never use the 100 range in NZ so that is not what i was getting at. With the new way to add an extension using the Web client it does not give an option to enter the new extension and assignes the first free extension starting at 100. So after I have setup a system if a customer uses the new way to add another extension it ends up in the 100 range.

3CX - I realise this is a beta release, so just asking if this will be tweaked before it goes live?

There is some great stuff in the new release that I'm looking forward to being able to setup for my customers. I just don't want them to then mess up the extension ranges if they use the web client to put in a new extension. If it stays how it is in the beta I will have to show them how to do it from the manager client (which is what I do currently so not a big deal) so they can get the extension number entered into the correct range, but it would be nice to not have customers going into the admin portal for this :-)

Thanks :-)
 
The first, I admit to having been surprised to see password attempts in clear text but, after reflection, it is administrators who have access to this page, therefore, it is much more beneficial to see the attempts (passwords ) , that the negative effect it can bring.
If the user uses good password practices, he should not have the same password in several applications. And the fact that the incorrect password attempt is displayed, this does not leak any information because the password is precisely incorrect..


Personally, I like this new feature, it's easy to see and allows you to quickly see the different attempts ( BruteForce ). I'm mostly surprised at how ingenious bruteforce is made.. I understand that attempts are based on a custom dictionary depending on the type of application application to "break through".. here 3CX

I hope not to leak real passwords!! If so, it's time to change the passwords!! eh eh !







.
@Jakob Tang @G.BOURGEOIS

I thought the same thing when i first saw it as generally adding a password to a database with plain text is a big no no.

But its only an incorrect password attempt, so doesn't have anything to do with real password or users. Plus if it was a big issue to the admin you can have it purge them earlier.

What would be great is access to the global IP list via the API. This way you could then use this list to block at the firewall level.
 
I recommend backing up your current certificates.. before process…

Step 1 : Locate the certificate folder (default) and backup on your computer ..
  • Windows: C:\Program Files\3CX Phone System\Bin\nginx\conf\instance1
  • Linux: /var/lib/3cxpbx/Bin/nginx/conf/Instance1

Step 2 : after, trying this solution share by "vtech" user ;

** BEFORE , please read @YiannisH_3CX disclaimer , Who is written under the procedure share by Vtech **

https://www.3cx.com/community/threads/lets-encrypt-cert-not-renewing.57717/post-241747



00EE9EC2-68F0-42FC-A3BE-24122F68A10B.jpeg


If you are having issues with renewing the certificate as mentioned by YiannisH_3CX, you will need the files backed up in step 1 to restore the old certificates….
 
  • Like
Reactions: Evolute IT
I recommend backing up your current certificates.. before process…

Step 1 : Locate the certificate folder (default) and backup on your computer ..
  • Windows: C:\Program Files\3CX Phone System\Bin\nginx\conf\instance1
  • Linux: /var/lib/3cxpbx/Bin/nginx/conf/Instance1

Step 2 : after, trying this solution share by "vtech" user ;

** BEFORE , please read @YiannisH_3CX disclaimer , Who is written under the procedure share by Vtech **

https://www.3cx.com/community/threads/lets-encrypt-cert-not-renewing.57717/post-241747



View attachment 33440


If you are having issues with renewing the certificate as mentioned by YiannisH_3CX, you will need the files backed up in step 1 to restore the old certificates….
My 3cx web certificate is working just fine the problem is that secure sip page in admin is blank when enabled. Was hoping there was a way to repair that part without extraordinary measures.
 
My 3cx web certificate is working just fine the problem is that secure sip page in admin is blank when enabled. Was hoping there was a way to repair that part without extraordinary measures.




It's the same certificates for SIP TLS and Web Browser (I may be wrong).

So by performing this procedure, based on my logic, it will force the PBX to rewrite the certificate for SIP TLS.

The best in my opinion is to let the 3CX tool do the work, otherwise it is possible to manually copy the web certificates, in the folder where the SIP TLS certificates are stored, but I would try the procedure above , for an "automatic" resolution.


It's not a big surgery, if you follow the instructions, you can do it in less than 2min.
 
  • Like
Reactions: Evolute IT
My 3cx web certificate is working just fine the problem is that secure sip page in admin is blank when enabled. Was hoping there was a way to repair that part without extraordinary measures.

If you insist, you can go see the folder
/var/lib/3cxpbx/Instance1/Bin/Cert/
This is the folder where the SIP TLS certificates are stored.
I'm not convinced that 3CX suggests making manual changes FOR a 3CX managed FQDN.
 
  • Like
Reactions: Evolute IT
If you insist, you can go see the folder
/var/lib/3cxpbx/Instance1/Bin/Cert/
This is the folder where the SIP TLS certificates are stored.
I'm not convinced that 3CX suggests making manual changes FOR a 3CX managed FQDN.
Was just trying to gather all the information first based on other post I had read, thanks for the clarification. The /usr/lib/3cxpbx/PbxConfigTool -renew-certificates, service nginx restart worked.
 
Last edited:
  • Like
Reactions: Evolute IT
Was just trying to gather all the information first based on other post I had read, thanks for the clarification. The /usr/lib/3cxpbx/PbxConfigTool -renew-certificates, service nginx restart worked.
I was mistaken it did not work the certificate renewed without error, but Secure SIP is still blank. Your logic made sense but there must be some other linkage....
 
I was mistaken it did not work the certificate renewed without error, but Secure SIP is still blank. Your logic made sense but there must be some other linkage....


I therefore recommend that you share your problem in the appropriate category.
https://www.3cx.com/community/forums/pbx-on-premise/

This will allow more people to see the problem and help you solve it.
I have some ideas, I will respond to your new post in the right category.
 
  • Like
Reactions: Evolute IT
As this is a beta did not think the general forum was the appropriate place, so we'll wait for final before addressing further if there are no more responses here.
Thanks again for all your assistance...
 
As this is a beta did not think the general forum was the appropriate place, so we'll wait for final before addressing further if there are no more responses here.
Thanks again for all your assistance...
Actually, please open a thread as it may be flagged by the team.

We also noticed this issue with a few systems recently so there may be something there.
 
is the recommendation still to not deploy to prod?
 
Status
Not open for further replies.

Forum statistics

Threads
111,973
Messages
590,079
Members
164,898
Latest member
grahamaskew