V16 - Security Question

Status
Not open for further replies.

AWS2P

Silver Partner
Advanced Certified
Joined
Jan 9, 2014
Messages
5,076
Reaction score
1,096
Hello,
since the passage in V16 and activation of the IP escalation of hacking attempts to 3CX, I see synchronized attacks on almost all my machines.

I wonder if this procedure supposed to bring us more security does not provoke the opposite. How is it possible that all machines receive an attack of the same IP ,same time? is it possible that hackers take the source of all existing 3CX machines directly on the collection system set up by 3CX ?

How is it supposed to see an improvement with the activation of this system, because for the moment I do not see anything that gives me the feeling of better protection.
 
Yes it is possible that all your machines get attacked because:
  1. Hackers can easily find and target pbxs. They just find ips which listen to 5060 or other sip ports no matter if they are 3CX or other systems.
  2. Hackers typically scan ip ranges/blocks which means thousands of ips. If you are deploying in Google or OVH etc each instance will get an IP in a specific block. By hackers scanning the whole block it is expected that all machines in it will be reached.
  3. I cannot see how the global blacklist system can actually bring the opposite result, as the blacklist just holds a list of offending IPs, not IPs of 3CX instances.
By the way how do you see the "synchronized" attacks? In the logs? Or the IPs blacklisted?
 
Thanks for answer,

i see attacks by receiving mail notifications from my on premise 3CX windows machines and in the log.

When in V15.5 same computers didn't received simultaneous attacks from same IP, also my question is about what is the supposed benefit expected , for now IMO i see no change, a never ending attack

The only way to stop this is to restrict 5060 to provider IP, but in that case FWC is red because of restriction on one IP
 
For example this 3CX has just 2 days live in V16, 5060 FW rule didn't change from V15.5, but i checked the IP escalation to 3CX

10442

Do you feel safe when this events fill the log, I didn't got this before with same internet provider and just an upgrade from V15.5 to V16 happens?
 
When in V15.5 same computers didn't received simultaneous attacks from same IP, also my question is about what is the supposed benefit expected , for now IMO i see no change, a never ending attack

If 3CX sees the same IP being reported by many 3CX systems then its added in the blacklist. That blacklist is being pushed to all 3CX instances which are part of the global blacklist network which means that they will be protected from that IP even if it didn't attack them yet.

For example this 3CX has just 2 days live in V16, 5060 FW rule didn't change from V15.5, but i checked the IP escalation to 3CX

View attachment 10442

Do you feel safe when this events fill the log, I didn't got this before with same internet provider and just an upgrade from V15.5 to V16 happens?
I see what you mean. Maybe you were getting attacked by those IPs before and for some reason they weren't blocked. So...I would prefer seeing my log full which means that it works rather than being empty and have the false sense of security :) I can't know exactly what the case is, I am just making assumptions. Based on my experience, it is impossible for a system NOT to get any attacks. If something is online, it's going to be probed. It happened to me to take a server online and start getting attacks literally minutes after. Also keep something else in mind: Those IPs (the one you get for your PBX) are being reused/circulated which means they are not totally unknown to the world. They've been online before, are known and most probably been attacked. So once you get the IP which was just released, you will of course get traffic.
 
How do you know what exactly is done by 3CX with these IP added to blacklist? is there documentation about how it works.

Also when something is blacklisted by 3CX how many time it stays in blacklist, for ever ?
Can we remove the IP in local blacklist if they are registred by 3cx global blacklist?

My public IP's are all static but of course they are from provider range so they are not nknown, that's strange on AWS i've less attempt than all on premise.
 
I am not aware of any documentation on this as it is an automated process however I found some info here (close to the end of the article) https://www.3cx.com/blog/voip-howto/call-fraud/ and it is also briefly mentioned in this 3CX training video:

I don't know more details such as for how long the IPs are blacklisted or IP removal process etc.
 
The only way to stop this is to restrict 5060 to provider IP, but in that case FWC is red because of restriction on one IP

This is not true. The FWC will only go red if you run it AFTER restricting 5060. But again, FWC is just a tool, nothing more. Green doesn't guarantee your system will work just like RED doesn't mean it's not working. So pick your poison.
 
Is someone knowing more about what 3cx is doing with global blacklist?

how are kept IPs when blacklisted?
How many time they stay in global blacklist?
How many Ip attemps attack are needed before 3cx has in consideration to add to global list?
How many time after an IP is added to Global blacklist is propagated all the 3CX over the world?
Is it necessary to keep the IP in local 3cx blacklist if done in global ?
How to know if IPs are in Global list or not?
 
Last edited:
Nothing more on subject?
 
you may understand that we will not elab on the mechanics on our global blacklist system.

You may keep add and whilst your IPs still by yourself using the add button.
All 3CX Managed IPs are stored in the PBX and you dont see them as such.
 
AWS2P, all of our PBXs have 5060 closed other than our SIP Providers, as previously mentioned if you are hosting in the cloud the IP ranges of these providers are known and are actively targeted.

We have seen a fresh PBX attached within 24 hours. You should probably look into alternate methods of provisioning your remote extensions.
 
you may understand that we will not elab on the mechanics on our global blacklist system.

You may keep add and whilst your IPs still by yourself using the add button.
All 3CX Managed IPs are stored in the PBX and you dont see them as such.

So we just need to stay as idiot we were and have no more answer . My questions are not asking 3CX details but have answer on global actions done by BLS.

if you are hosting in the cloud the IP ranges of these providers are known and are actively targeted.
No most of my 3CX are on premise and strangely the one hosted on AWS is less targeted than others.
 
No most of my 3CX are on premise and strangely the one hosted on AWS is less targeted than others.

This is likely because different providers are known to block the worst offenders upstream, while others do not. Just because you do not see the same attacker beating on system A as is beating on system B, C, and D, does not mean they are not trying to scan it, likely the provider has something upstream that is killing it before it even gets to you. So you never even knew it was there.

We audit our traffic regularly as we have quite the large datacenter environment, and we block large numbers of scanning IPs upstream in our Core Routers, thus all the sudden 3CX does not see them attacking anymore, even though they are still trying to. Likely one provider is very pro-active, and the other is not. Most attackers scan the entire IPv4 range blindly looking for attack-able hosts of a given type. But due to the blocking some carriers do, you dont always see it on hosts on different providers.
 
Status
Not open for further replies.

Members Online Now

Forum statistics

Threads
111,832
Messages
589,283
Members
164,662
Latest member
DejanMDS