Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chriss Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

8.0 ip office hacked!! 2

Status
Not open for further replies.

Jonjr88

Vendor
Joined
Jun 5, 2011
Messages
191
Location
US
The past few night my system has been getting hacked or something odd is going on. First time over 1000 SIP extensions and users were added, that happened a couple times now this time over 2000 SIP extns and users were added and all of my user rights were deleted and my manager folder with backups was cleaned out!!! I was told they were able to get through VMPro. Any help would be great. I do use SIP trunks and all passwords and usernames are changed and i ordered an SBC but i am not 100% convinced they are getting in through the WAN.

Thanks
 
They cannot get in through VM Pro, you need to configure VM Pro specifically to allow outside access and then it's only to make calls not anything like this. They will be coming in through your WAN, what do you get if you out the external address your system comes from into Manager/Monitor? In the meantime turn off auto extn create on that interface :-)

 
That should be.... put the external address in Manager/Monitor not "out" :-)

 
if i put the external address in manager i can login to it and make changes
 
Then you did not change the standard credentials.
I bet you have auto create extension turned on and i guess a lot of calls has been made to expensive numbers.
Change the login credentials right now and disable auto create extension for all type of extensions.


BAZINGA!

I'm not insane, my mother had me tested!

 
i changed login credentials so a completely different username and password and disabled all other accounts and auto create extn is off
 
and no expensive numbers plus international is locked there is a separate code on the trunks to get out
 
Why is the system on an external address? This isn't required for SIP or Remote extns :-)

 
And don't forget to remove routings you don't need, like 0.0.0.0/wan/static IP.
The narrower, the better.
Get a decent firewall if you need to keep it online.

Kind regards

Gunnar
__________________________________________________________________
Hippos have bad eyesight, but considering their weight, it’s hardly their problem
 
how else would i set it up without a SBC??
 
Yea i have the 0.0.0.0 route but i thought i needed that for the trunks, should i change the address to the address where the trunks are coming from??
 
We use SIP trunks and we have the system on an internal address without any port forwarding or anything, a good SIP provider will have a SBC themselves and that will take care of your systems NAT. Only thing you may need to do is turn your routers SIP ALG off depending on make/setup :-)

 
So...you have invited everyone on Internet in the front door.. Yes, change It, and if you ran Stun, check the settings there too.

Kind regards

Gunnar
__________________________________________________________________
Hippos have bad eyesight, but considering their weight, it’s hardly their problem
 
ok i will try that amriddle01. thanks
 
Gunnaro i changed the IP route and i can still access from the outside any suggestions?
 
What did you change the IP route to?

-Austin
ACE: Implement IP Office
qrcode.png
 
If you are using the same connection that the system uses it will be coming from the same address range so the system will respond, what if you try from a totally different connection? You really need it on an internal address :-)

 
address to (sip provider)
mask- 0.0.0.0
gateway to - gateway of my external IPs
 
i logged into a customers pc and tried from their manager
 
The mask should be 255.255.255.255 to allow a single address only :-)

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top