GO HERE Hack made calls to kosovo, how to block

ghurty

Senior Member
Joined
Jan 13, 2009
Messages
852
Reaction score
4
One of our boxes got hacked and we had many calls made to kosovo on it.
Our setup is as follows:
Local extensions
One remote pbx in a flash server via SIP
remote extensions using VPN

How can I lock down the box so only the approporaite extensions can make the calls. The extension that the calls were coming from actually for some reason did not have a secret. i have since deleted that extension, but I want to lock the system down more.

PIAF 2.0.6.2
Freepbx 2.10.0.2
asterisk 1.8.13

THank You
 
Or setup iptables to only allow the addresses that you need to access the PIAF system. Especially on port 5060 and the web interface on 80 and 443.
 
and set some dialplan rules ? so only local and within your country calls can be made?
 
Trouble is if someone can hack into your management web interface then you could easily setup new extensions (without secrets even!) so exploit your system over and over again.
 
Security 101: If your system has been hacked, start over! Change all of your provider passwords, too. Trying to repair a system when you have no idea what the bad guys were able to do is CRAZY!
 
"one of our boxes got hacked"... doesn't really say HOW it was hacked... they root the system or merely guessed your maint passwd? or just used some funky extension brute force-like that didn't have a 'secret'?
but Ward is right... if you got hacked.. change it all..
 

Members online

No members online now.

Forum statistics

Threads
26,687
Messages
174,411
Members
20,257
Latest member
Dempan
Get 3CX - Absolutely Free!

Link up your team and customers Phone System Live Chat Video Conferencing

Hosted or Self-managed. Up to 10 users free forever. No credit card. Try risk free.

3CX
A 3CX Account with that email already exists. You will be redirected to the Customer Portal to sign in or reset your password if you've forgotten it.
Back
Top