Got Hacked... Now What?

mahables

New Member
Joined
Feb 3, 2009
Messages
32
Reaction score
0
Ok guys... (hangs head low) I got hacked... looks like someone set up some kind of auto dialer on my system. I deleted the extension it was using. That seemed to prevent any further calls from succeeding. I also closed the public ssh port. I'm pretty sure the whoever is behind this can't do anything more at this point. But the system keeps trying to make calls out over the extension that I deleted. How can I stop this?
 
I would first look in the /var/spool/asterisk/outgoing and delete any call files that may be there.

That should do it.
 
Try Wards security primer
http://nerdvittles.com/?p=580

It's all great info!!! However the item I GREATLY encourage is the pay as you go. With your VOIP provider do NOT use the auto replenishment, always use the pay as you go plan. That way theoretically you can only lose up to what you have deposited, for me it's never more than $15.00
 
I would first look in the /var/spool/asterisk/outgoing and delete any call files that may be there.

That should do it.

I didn't find any call files. I don't really know how they were initiating the calls, but as soon as I closed the sip and rtp ports, the calls stopped.
 
In the freepbx gui, use the permit/deny fields for every extension in your system to lock them to your local LAN or remote extension IP. Also, if it's an option on your firewall and you don't use remote extensions, designate port forwarding only from your ITSP's IP.

I've come to apreciate IAX more and more. If your ITSP supports IAX and you don't need remote SIP extensions, you could drop SIP outside your LAN and close off the SIP & RTP ports. Aside from that, follow Ward's security primer, and make sure fail2ban is enabled and that you use secure passwords.
 

Members online

Forum statistics

Threads
26,688
Messages
174,412
Members
20,259
Latest member
Fadeek86
Get 3CX - Absolutely Free!

Link up your team and customers Phone System Live Chat Video Conferencing

Hosted or Self-managed. Up to 10 users free forever. No credit card. Try risk free.

3CX
A 3CX Account with that email already exists. You will be redirected to the Customer Portal to sign in or reset your password if you've forgotten it.
Back
Top