- Joined
- Oct 24, 2018
- Messages
- 367
- Reaction score
- 40
While doing our security audits on all our pbx's I came across one that had a bunch of IP's added to it's allowed list under the ip block list. This particular PBX does have an additional admin besides us and I'm thinking the account got compromised. I've changed her password as a precaution. Some of my PBX's are open to the world (for the moment) and I'm guessing this was at the beginning phase of about to be used for something bad. I don't see any added extensions though and the call logs/rules aren't changed allowing anyone to call outside the US.
Anybody have any input on this?
Thanks.
Anybody have any input on this?
Thanks.
