SIPVicious : Auditing And Protecting Yourself From SIP Registration Attacks.
SIPVicious http://snapvoip.blogspot.com/
SIPVisious is a tool developed to audit your SIP based VoIP IP Telephony system. Basically it is four tools that runs on any system capable of supporting python
SIPVisious via ecg
SIPVisious is a tool developed to audit your SIP based VoIP IP Telephony system. Basically it is four tools that runs on any system capable of supporting python
- svmap - this is a sip scanner. Lists SIP devices found on an IP range
- svwar - identifies active extensions on a PBX
- svcrack - an online password cracker for SIP PBX
- svreport - manages sessions and exports reports to various formats
- svcrash - attempts to stop unauthorized svwar and svcrash scans
- SIP Endpoint registration, always use SIP authentication! and encourage / force users to use proper passwords.
- If you have a Session Border Controller (SBC), you can blacklist devices after they fail a few REGISTER attempts.
- If you’re using non-registering SIP (such as SIP peering for SIP Trunking), limit access by SIP signaling IP addresses using firewall rules / or ACLs to block all connections except from the your peers.
- Find methods to spot SIP devices sending abnormal traffic loads, and alarm your staff and/or block them for a certain period.
SIPVisious via ecg
0 comments:
Post a Comment