Skip to content

Weak Passwords Module Documentation

8 min readUpdated: Sep 26, 2026
View as Markdown
  1. Navigation & Access
  2. Screenshots & Visual Interface
  3. Module Overview (Technical)
  4. Module Overview (Commercial / Business)
  5. Module Overview (End User / Administrator)
  6. Weakness Detection Rules & Algorithm
  7. SIP Device Credential Auditing Reference
  8. Vulnerability Remediation Workflow
  9. Common Scenarios & Attack Vectors
  10. Model Context Protocol (MCP) AI Integration
  11. Troubleshooting Tips
  12. Database Schema
  13. Glossary

To access the Weak Passwords security scanner:

  1. Log in to the Ring2All Web Portal (https://<domain-or-ip>/login).
  2. In the left navigation sidebar, expand PBX Engine.
  3. Under PBX Tools, click Weak Passwords (/pbx/tools/weak-password).
  4. Review the detected vulnerable extensions and click the Refresh button on the toolbar to re-run the security scan.

Security dashboard table listing all SIP extensions with compromised, trivial, or predictable passwords, detailing extension number, extension name, resource type, and weakness classification. Weak Passwords Security Scan View


The Weak Passwords module is an automated credential auditing and vulnerability detection tool designed specifically to protect PBX environments from International Revenue Sharing Fraud (IRSF), SIP brute-force cracking, and unauthorized SIP device registrations.

  • Scanning Engine: Executed by Fastify service (GET /api/telephony/weak-passwords?domainId=:id), inspecting all provisioned SIP devices (sip_devices) belonging to the tenant domain.
  • Entropy & Pattern Analysis: Evaluates raw device passwords using the zxcvbn realistic password strength estimator alongside targeted telecom heuristic rules:
    1. Extension Matching: Checks if password === extension (e.g. extension 2002 with password 2002).
    2. Trivial Sequences: Detects ascending or descending sequences (1234, 123456, 987654).
    3. Dictionary & Default Keys: Checks against a dictionary of common PBX defaults (password, admin, welcome, 0000).
    4. Length Threshold: Flags any device password with fewer than 8 characters.
  • Zero-Storage Auditing: Weakness evaluation is performed in-memory during scan execution; plaintext passwords are never transmitted across non-admin channels or written into unencrypted audit logs.
┌─────────────────────────────────────────────────────────────────┐
│ Weak Password Detection Pipeline │
├─────────────────────────────────────────────────────────────────┤
│ │
│ Fastify Telephony Service │
│ ┌──────────────────────────────────────────────────────────┐ │
│ │ 1. Fetch sip_devices joined with sip_extensions │ │
│ │ filtered by domain_id │ │
│ └─────────────────────────────┬────────────────────────────┘ │
│ │ │
│ ▼ │
│ ┌──────────────────────────────────────────────────────────┐ │
│ │ 2. Heuristic & Entropy Analysis Engine: │ │
│ │ ├─ Rule 1: Password == Extension? │ │
│ │ ├─ Rule 2: Trivial pattern (123456, aaaaa)? │ │
│ │ ├─ Rule 3: Common dictionary / vendor default? │ │
│ │ └─ Rule 4: zxcvbn entropy score < 2? │ │
│ └─────────────────────────────┬────────────────────────────┘ │
│ │ │
│ ▼ │
│ ┌──────────────────────────────────────────────────────────┐ │
│ │ 3. WeakPasswordReport Array Generated │ │
│ │ Rendered in WeakPasswordsPage.tsx DataGrid │ │
│ └──────────────────────────────────────────────────────────┘ │
└─────────────────────────────────────────────────────────────────┘

2. Module Overview (Commercial / Business)

Section titled “2. Module Overview (Commercial / Business)”
  • Prevention of International Toll Fraud (IRSF): Automated internet bots constantly scan SIP ports (5060, 5080) searching for extensions with weak passwords. Once compromised, hackers bridge hundreds of concurrent calls to premium-rate international numbers ($10 - $50/minute), resulting in catastrophic overnight telecom bills.
  • Compliance & Cyber Insurance Eligibility: Many cyber liability policies and security certifications (SOC 2, ISO 27001, PCI-DSS) require regular automated credential audits across telephony systems.
  • Brand Protection: Prevents hijacked business numbers from being used as caller IDs in illegal robo-calling and phishing schemes.

3. Module Overview (End User / Administrator)

Section titled “3. Module Overview (End User / Administrator)”
  • Review flagged extensions in a clean, categorized table.
  • Direct drill-down to remediate vulnerable credentials by clicking on the extension.
  • Regular one-click audits during monthly maintenance schedules.

Weakness Rule Trigger Criteria Risk Level Example
Matches Extension Password identical to extension digits. 🚨 Critical Extension 2002 with secret 2002.
Trivial Sequence Ascending/descending numerical runs. 🚨 Critical Password 123456 or 654321.
Common Default Common word from telecom dictionary. ⚠️ High Password password123, admin, telephony.
Insufficient Length Password length shorter than 8 characters. ⚠️ High Password abc12.
Low Entropy Predictable pattern detected by zxcvbn. 🟡 Medium Password Spring2026!.

5. SIP Device Credential Auditing Reference

Section titled “5. SIP Device Credential Auditing Reference”

The Weak Passwords table displays the following columns:

Column Name Description Example
Extension Numeric extension identifier in the PBX. 2002
Extension Name Descriptive label or employee name. Tech Support Desk 2
Type Classification of audited entity. SIP Device Password
Weakness Specific detected vulnerability rule. Matches Extension Number
Resource Device username in SIP authentication. 2002

When vulnerable extensions are identified:

  1. Note the flagged extension number (e.g. 2002).
  2. Navigate to PBX Engine → Extensions (/pbx/extensions).
  3. Click on the extension to open the configuration form.
  4. Navigate to the SIP Devices tab.
  5. In the device password field, click the Generate Strong Secret icon to assign a cryptographically random 16-character alphanumeric password (e.g., WfZNdHMNn8vFyJH).
  6. Click Save Changes.
  7. Return to PBX Tools → Weak Passwords and click Refresh. The extension will immediately disappear from the report.

Scenario 1: Provisioning Trivial Passwords for Quick Testing

Section titled “Scenario 1: Provisioning Trivial Passwords for Quick Testing”
  • During initial PBX setup, a technician provisions extension 2003 with password password123 for quick softphone testing.
  • The device remains active in production.
  • The Weak Passwords module detects password123 on the next scan, preventing an attacker from finding the credential through SIP dictionary attacks.
  • Legacy IP deskphones provisioned using extension-matching credentials (2002 / 2002).
  • The security scanner exposes all matching devices so the team can re-provision devices with unique randomized secrets.

8. Model Context Protocol (MCP) AI Integration

Section titled “8. Model Context Protocol (MCP) AI Integration”

The Ring2All Platform Copilot integrates with the Credential Security Audit engine via the Model Context Protocol (MCP) to provide proactive brute-force vulnerability discovery and automated SIP security posture scoring.

Tool Name Operation Primary Parameters Description
check_weak_passwords Security Vulnerability Audit (none) Audits all SIP extensions in the active tenant domain against entropy checks, default dictionary lists, and sequential passwords.
list_weak_credentials At-Risk Extension Directory (none) Returns a structured list of extensions with compromised or predictable passwords, detailing severity and reason.
  • Zero-Cleartext Exposure: The AI Copilot NEVER outputs the raw plain-text password to conversational interfaces or logs. Only the extension number, username, entropy score, and reason (e.g., MATCHES_EXTENSION, TRIVIAL_DICTIONARY) are reported.
  • Tenant Isolation: Only extensions belonging to the authenticated tenant domain are audited. Cross-tenant credential inspection is prevented at the database boundary.
  • Auditing: Every password scan initiated via Copilot creates an entry in ss_admin.audit_logs.

1. Running a Weak Password Scan (check_weak_passwords)

Section titled “1. Running a Weak Password Scan (check_weak_passwords)”
{}

Response:

{
"success": true,
"data": {
"totalAudited": 32,
"vulnerabilitiesFound": 2,
"weakExtensions": [
{
"extension": "2002",
"name": "Warehouse Desk",
"username": "2002",
"severity": "CRITICAL",
"reason": "Password matches extension number exactly"
},
{
"extension": "2005",
"name": "Temporary Test Agent",
"username": "2005",
"severity": "HIGH",
"reason": "Common dictionary password (weak entropy)"
}
]
}
}
  • “Scan all extensions in this tenant for weak or default passwords.”
  • “Are there any SIP accounts with passwords identical to their extension numbers?”
  • “Provide a list of at-risk credentials that could be vulnerable to SIP dictionary attacks.”

Symptom Probable Cause Corrective Action
Report is empty after scan All SIP devices have strong passwords Expected behavior when all extensions meet security entropy standards.
Remediated extension still appears Cached browser report Click the Refresh button on the toolbar to re-trigger an active scan.
Scan fails with “Domain not found” Domain context missing Select an active domain in the top-bar domain switcher.

The scanner audits credentials stored in sip_devices joined with sip_extensions in ss_telephony:

SELECT
se.extension,
se.name AS extension_name,
sd.username,
sd.password
FROM public.sip_devices sd
INNER JOIN public.sip_extensions se ON se.id = sd.extension_id
WHERE sd.domain_id = :domain_id;

  • IRSF: International Revenue Sharing Fraud — monetization of stolen telecom minutes via unauthorized calls to premium-rate numbers.
  • Entropy: Measure of randomness and unpredictability in a cryptographic secret.
  • zxcvbn: Industry-standard realistic password strength estimator developed by Dropbox.
  • SIP Device: Hardware IP phone, softphone app, or ATA registered to an extension.