SIPVicious tools roadmap
Check my current "to do" list here.
Labels: security tools, sipvicious, sipvicious tools
Labels: security tools, sipvicious, sipvicious tools
Labels: password policies, security tools, sipvicious, svcrack
The most obvious and damaging problem is toll fraud. Traditionally phone phreaks enjoyed free calls by abusing security flaws within the phone company's system as well as private companies' PABXs. By gaining access to an extension line which can make international calls, an attacker will be able to run large bills on the victim's account. On the other hand, the social engineering aspect should not be under estimated. Social engineering can be a very effective and reliable method that allows hackers to pull off some of the most interesting (sometimes amusing) attacks ever. From ordering free pizza as someone else, to hijacking the help desk's number and then asking for user's passwords, such attacks rely on human nature and can probably never be totally prevented.The purpose of svcrack is very straightforward.This tool will launch a password guessing attack extensions on the SIP registrar. Attackers will be after your SIP passwords because such knowledge allows them to:
- Get free long distance calls
- Hijack and spoof phone calls
- Eat your spaghetti
Labels: pbx, replay, security tools, sip security, sipvicious tools, site news, svcrack
Svmap is a network scanner for SIP. Similar to nmap - it will scan for devices on ports specified by passing the right command line options. Once svmap finds a device that supports SIP, it will extract information from the response and identify the type of device. Anyone running this tool will typically end up with a list of IP addresses of SIP devices and the names for those devices.
Labels: analysis, security tools, sipvicious, svmap, voip security paper analysis encryption zrtp mikey sdes sip
Labels: security tools, sip security, sipvicious, sipvicious tools, svcrack, svmap, svwar
./svmap.py -m INVITE 192.168.1.4 -p5061Where 192.168.1.4 is the IP of the SIP phone and 5061 is the SIP port of the phone. For a ghost call effect, if you have a network with all SIP phones listening on port 5060, you can just run the following to get them to ring at the same time:
./svmap.py -m INVITE 192.168.1.1/24
Labels: grandstream, open source, security tools, sip security, sjphone, spam, spit, voip spam, vulnerability, x-lite
Labels: blog, security tools, sip security, sipvicious tools, site news
Labels: analysis, encryption, mikey, paper, sdes, security paper, security tools, sip, voip, voip security paper analysis encryption zrtp mikey sdes sip, white paper, zrtp
Labels: exploit, grandstream, hardphone, security tools, sip, vulnerability