Security problem in Xorcom XE2000 running Elastix

Joined
Apr 9, 2013
Messages
1
Points
0
Hi guys.

Almost a month ago, I installed a Xorcom XE2000 (www.xorcom.com) unit with 1 E1 port and 8 analog trunks.

Everything was working fine. Firewall is up and connections to the unit are restricted to specific IPs.

We activated the IVR option for a holliday message (Holly Week) and then, some calls appears in the CDR as 's destination' with no source address. The calls was made through analog trunks with destination to Africa (our telephone provider give us a report for this calls)

Question. Is it possible to call the IVR and get access to a different trunk to make a call ?? I never seen this before.

Best regards.
 
Joined
May 11, 2008
Messages
22
Points
0
Hi mario.rocha,
FreePBX dialing plan doesn't allow calls between trunks. It means that if the intruder got to your IVR via a trunk then the call could be routed to an extension, a queue etc. But sometimes the call can be eventually routed to another trunk. For example, when there is a FollowMe to an external number defined.
In other words, you have to review your dialing plan and check the Asterisk log in order to understand what happened with the calls.
Best regards
 
Joined
May 11, 2008
Messages
22
Points
0
Also, I recommend you to change the passwords and check the fail2ban settings. Meantime you don't know the way how the calls were stolen...
 

Members online

No members online now.

Latest posts

Forum statistics

Threads
31,000
Messages
131,118
Members
17,716
Latest member
Orbit114
Top