User agent empty in blacklist email

Status
Not open for further replies.

davide.bonavita

Premier Customer
Joined
Apr 17, 2020
Messages
136
Reaction score
29
Hello all!
V. 16.0.619 Enterprise here
It sometime happens that an agent types in the wrong password. His IP is blacklisted and I receive an email, as expected.

The only minor issue is that the user agent field is empty, so I cannot know who typed the wrong password, and I just need to wait for someone to send me a message:

IP XXXXXXX has been blacklisted on PBX XXXXXXXX
Affected Module: 3CX Clients / Softphones
User agent:

The IP XXXXXXXX has been blacklisted for 604800 seconds. (Expires at: 2020-07-22 16:03:53).
Reason: 3CX Clients / Softphones blocked - 3CX API Component This IP Address has made numerous attempts to authenticate with 3CX with invalid authentication details. Therefore a blacklist rule has been created denying this IP to continue sending requests.


Infact I don't see the variable %%USERAGENT%% in the following list, but %%SOURCE%% is missing as well even if it's correctly showing the affected module:

https://www.3cx.com/docs/variables-email-templates/#h.ox4cqw3rp922
 
As no info is given then , You just need to learn everybody's IP address :p ;)

I don't know what you can do but if IP is from your LAN , then no risk to release even you don't know who exactly it is.
 
our 3CX is on cloud, so I can just read their IP public address, everybody is working from home :) Since they're all around the world, I can make a guess based on the Geo-IP infos :D
 
That's obviously different with a Cloud pbx , No idea what you can improve to know who's blacklisted.
 
Actually I think there has been a misunderstanding, sorry :D. For "User agent" I meant the extension number of the agent (e.g. 1003), but it is in fact the software that the agent uses for the connection (e.g. PolycomVVX-VVX_300-U).
So my original question becomes: "is there a variable that stores the extension number so that I can use it in the email template?"
 
Hi Davide,

The email will report the IP address but not the extension, so basically it's not the extension that gets banned - it's the IP that entered the wrong login info that will get banned.

So in answer to your original question, the "who" is an IP address, not a user/extension and the email already contains the IP :)
 
Thank you John! It would be nice to know the details about the login info behind the blacklisted IP, tho :) It would make it easier for the admin contacting the person trying to use the wrong/old password and make them aware of that
 
Unfortunately there is no direct way that I'm aware of for doing that. It just know that invalid credentials were used, but will not keep track of what the user typed.

To the system, a random attacker VS a legit user miss-typing their password will look the same:

"Some IP is trying to log in on my server with wrong credentials, so I'm going to ban that IP from potentially attacking me"

1594886414196.png 1594886444550.png
 
Status
Not open for further replies.

Forum statistics

Threads
111,954
Messages
589,921
Members
164,851
Latest member
DrunkeMeister