Viproy - Pentesting and exploitation tool for VoIP

Viproy - Pentesting and exploitation tool for VoIP

Viproy - Pentesting and exploitation tool for VoIP


Viproy Voip Pen-Test Kit provides penetration test modules for VoIP networks. It supports signaling analysis for SIP and Skinny protocols, IP telephony services and network infrastructure. Viproy 2.0 is published in Blackhat Arsenal USA 2014 with TCP / TLS support for SIP, provider extension support, Cisco CDP spoofer / sniffer, Cisco skinny protocol analyzers, VOSS exploits and network analysis modules. In addition, Viproy provides SIP and Skinny development libraries for custom fuzzing and analysis modules.

Current Version and Updates

Current version: 4.1 (Requires ruby 2.1.X and Metasploit Framework Github Repo)
Pre-installed repo: https://github.com/fozavci/metasploit-framework-with-viproy

Homepage of Project

Talks

Black Hat USA 2016 - VoIP Wars: The Phreakers Awaken

DEF CON 24 - VoIP Wars: The Live Workshop

To be added later

Black Hat Europe 2015 - VoIP Wars: Destroying Jar Jar Lync

DEF CON 23 - The Art of VoIP Hacking Workshop Slide Deck

Black Hat USA 2014 / DEF CON 22 - VoIP Wars: Attack of the Cisco Phones

DEF CON 21 - VoIP Wars: Return of the SIP

Attacking SIP/VoIP Servers Using Viproy


Current test modules

  • SIP Register
  • SIP Invite
  • SIP Message
  • SIP Negotiate
  • SIP Options
  • SIP Subscribe
  • SIP Enumerate
  • SIP Brute Force
  • SIP Trust Hacking
  • SIP UDP Amplification DoS
  • SIP Proxy Bounce
  • Skinny Register
  • Skinny Call
  • Skinny Call Forward
  • CUCDM Call Forwarder
  • CUCDM Speed ​​Dial Manipulator
  • MITM Proxy TCP
  • MITM Proxy UDP
  • Cisco CDP Spoofer
  • Boghe VoIP Client INVITE PoC Exploit (New)
  • Boghe VoIP Client MSRP PoC Exploit (New)
  • SIP Message with INVITE Support (New)
  • Sample SIP SDP Fuzzer (New)
  • MSRP Message Tester with SIP INVITE Support (New)
  • Sample MSRP Message Fuzzer with SIP INVITE Support (New)
  • Sample MSRP Message Header Fuzzer with SIP INVITE Support (New)

Installation

Copy the contents of the "lib" and "modules" folders to the root directory of Metasploit. 
The file Mixins.rb (lib / msf / core / auxiliary / mixins.rb) must contain the following lines 
Requires' msf / core / auxiliary / sip ' 
Requires' msf / core / auxiliary / skinny' 
Require 'msf / core / auxiliary / msrp '

Use of SIP modules

Use of Skinny modules

Use of Voproy auxiliary modules