Skip to content

Procedures for removing a device

After removing a device — because a customer has left, or an employee at an existing customer has left — perform one of the following on the VoIP device:

  • Factory reset the device. This is the recommended option.
  • If you cannot factory reset, log into the phone and remove the BrightPBX VoIP URL from the device.

Once completed, unplug the device.

It stops unnecessary authorization register requests. Some VoIP devices are aggressive with these requests, effectively performing a DDoS attack against the registrar.

It prevents configuration details leaking. An abandoned device exposes information about our infrastructure and authorization format. Once a bad actor has that, your entire customer base can be infiltrated. VoIP devices use cheap hardware with almost no protection, making them easy targets — and the same applies if a device is exposed to the public internet through a missing firewall, an open port redirect, or a DMZ.

To mitigate these issues, we trace unsecured register attempts in real time and block IPs with too many failed authentications.

Your participation in this is outlined in our Terms of Service.