andrewgroup Posted March 9, 2009 Report Posted March 9, 2009 Today we had a client PBX with park orbits and low or easy SIP passwords get remote registrations from a Canadian IP address and the clients PBX was making outbound BANK CARD scam calls.... Caught it early but the lessons are clear and a few best practices are coming from the experience and perhaps a feature request... Lesson 1. Complex Passwords are a must - No longer can we make it easy for the users Lesson 2. Park Orbits will not enherit a default dial plan Lesson 3. enable more logging an email notifications on extensions Possible Feature requests - (optional allowable IP Address ranges on an ext Basis for phones to register from. Cheers, and learn from the experienced. Quote
Vodia PBX Posted March 10, 2009 Report Posted March 10, 2009 Today we had a client PBX with park orbits and low or easy SIP passwords get remote registrations from a Canadian IP address and the clients PBX was making outbound BANK CARD scam calls.... Caught it early but the lessons are clear and a few best practices are coming from the experience and perhaps a feature request... Lesson 1. Complex Passwords are a must - No longer can we make it easy for the users Lesson 2. Park Orbits will not enherit a default dial plan Lesson 3. enable more logging an email notifications on extensions Possible Feature requests - (optional allowable IP Address ranges on an ext Basis for phones to register from. Cheers, and learn from the experienced. Totally agree. We introduced the script that checks password for their "randomness". Unfortunately, due to a request from the sales front, we were asked to disable it in the default installation, so that a password like "secret" is accepted as a password (like "", the empty string). Quote
hosted Posted April 8, 2009 Report Posted April 8, 2009 Yea i had this happed here in utah also customer created some extensions with blank passwords. fortunalty our sip switch sets budgets for each domain so they were cut off fairly fast. i have however seen pbxnsip defend itself from constant registration attempts.. Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.