- Joined
- Sep 24, 2018
- Messages
- 1
- Reaction score
- 0
We have at least 2 Clients where their Web Logins have been compromised by the same group (looks to be a Spam Call Centre)
they were able to login to the web client and call numbers in Sri Lanka
at one Client they logged into 4 separate Extensions and at the other client only 1 Extension
These are the IPs - 185.165.243.144, 185.253.118.71, 146.70.104.27, 169.197.85.171
We Know the passwords are random generated of at least 8 Char
is there a way to see failed Web Client Logins?
we are using the default Anti-Hacking Rules 5 attempts and blocked for 24 Hrs
we are also using the Automatic Global IP Block
These Clients don't use the Web Clients at all and use Physical Phones
Both Clients use Latest updated 3cx running in Azure on 3cx's Marketplace Image
we have implemented a Firewall Rule to block access to the web page from outside our country
and discussing Turning MFA on for to the Clients (MFA is on Admin Extensions)
they were able to login to the web client and call numbers in Sri Lanka
at one Client they logged into 4 separate Extensions and at the other client only 1 Extension
These are the IPs - 185.165.243.144, 185.253.118.71, 146.70.104.27, 169.197.85.171
We Know the passwords are random generated of at least 8 Char
is there a way to see failed Web Client Logins?
we are using the default Anti-Hacking Rules 5 attempts and blocked for 24 Hrs
we are also using the Automatic Global IP Block
These Clients don't use the Web Clients at all and use Physical Phones
Both Clients use Latest updated 3cx running in Azure on 3cx's Marketplace Image
we have implemented a Firewall Rule to block access to the web page from outside our country
and discussing Turning MFA on for to the Clients (MFA is on Admin Extensions)