업데이트로 돌아가기
New releaseSep 15, 2026

sippts v4.2.1

SIP 기반 VoIP 시스템 감사용 도구 세트

공유
logo

Sippts란 무엇인가?

Sippts는 SIP 프로토콜을 사용하는 VoIP 서버와 장치를 감사하기 위한 도구 모음입니다. Sippts는 Python으로 프로그래밍되었으며, SIP 프로토콜을 사용하는 VoIP 서버의 보안을 점검할 수 있게 해줍니다.

무료인가요?

네. 자유롭게 사용, 수정 및 배포할 수 있습니다. 수정하는 경우 이 사이트에 대한 참조를 포함해 주세요.

sippts를 불법적인 목적으로 사용할 수 있나요?

이 도구의 목적은 자신의 시스템을 감사하거나 명시적인 승인을 받은 시스템에 대해 침투 테스트를 수행하는 것입니다. 이 도구의 오용에 대해 저는 책임지지 않습니다.

사용법

도움말 표시:``` sippts -h usage: sippts [-h] [-up] {video,astami,scan,exten,rcrack,send,wssend,enumerate,leak,ping,invite,dump,dcrack,flood,sniff,spoof,pcapdump,rtpbleed,rtcpbleed,rtpbleedflood,rtpbleedinject} ...

⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣀⣀⣀⣀⣤⣤⣤⣤⣤⣤⣤⣤⣤⣤⣄⣀⣀⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣀⣤⠤⠶⠒⠛⠉⠉⠉⠉⠀⠀⢀⣀⣀⣀⣤⣤⣤⣤⣤⣤⣤⣤⣬⣍⣙⣳⣄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣀⣤⠴⠒⠋⠉⠀⠀⠀⢀⣀⣠⡤⠴⠖⠚⠛⠉⠉⠉⠀⣠⡶⠖⠲⣄⠀⠀⠀⠀⠀⠀⠀⠈⠉⢷⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⢀⣀⡤⠖⠋⠁⠀⠀⠀⣀⣤⠴⠖⣛⣉⣁⠀⠀⠀⠀⠀⠀⠀⣀⣀⣠⡇⢹⡄⠀⠸⡆⠀⠀⠀⠀⠀⠀⠀⠀⠈⢿⡄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⣀⡤⠞⠋⠀⠀⠀⢀⣠⠴⠚⠋⠁⠀⠀⡿⡏⠀⠈⣧⣤⠴⠖⠚⠛⠉⠉⠳⢄⡀⠀⣧⠀⠀⢷⠀⠀⠀⠀⠀⠀⠀⠀⠀⠘⣷⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⢠⡞⠧⣄⠀⢀⣠⠴⠚⠉⠀⠀⠀⠀⠀⢀⣴⠇⢹⠀⠀⢸⡆⠀⠀⠀⠀⠀⠀⠀⠀⠉⣲⣿⣀⣠⣼⣦⣤⣀⣀⣀⡀⠀⢀⣀⣠⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⢀⡿⠀⠀⠈⣿⠉⠀⠀⠀⠀⠀⠀⠙⢄⣰⠏⠀⠀⠘⡇⠀⠀⣇⢀⣀⡤⠤⠖⠒⠛⠉⠉⠉⣁⣀⠀⠀⠀⠉⠙⠛⢿⣿⡛⠛⠛⢻⡟⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⣸⣧⣄⠀⠀⡇⠀⠀⠀⠀⠀⠀⠀⠀⢈⣿⡄⠀⠀⠀⣷⠴⠚⠋⠉⠀⠀⢀⣠⣴⡖⠛⠉⠿⢻⣿⣉⡉⠙⠓⢲⠦⢤⣈⠙⢶⣶⠋⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⢠⣏⠙⢦⣹⣼⠀⠀⠀⠀⠀⠀⢀⣴⣾⠟⠁⢀⡏⢀⡞⠀⠀⠀⠀⠀⣰⣯⡟⡀⠀⣼⡏⢘⡢⢠⣷⣾⡿⠿⠿⣷⣤⣞⠀⠙⢦⡀⠀⠙⢿⣷⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⣰⡟⠿⡍⢷⢀⡇⠀⠀⠀⠀⠀⠀⠀⣠⣾⠏⣧⠀⢀⡞⠁⠀⠀⠀⠀⢠⡴⠋⠛⠻⣧⣤⡶⢿⡹⡟⠛⢯⣉⣿⢾⣧⣄⡈⠙⠲⢝⣷⣄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⢠⣏⠙⢦⣹⣼⠀⠀⠀⠀⠀⠀⢀⣴⣾⠟⠁⢀⡏⢀⡞⠀⠀⠀⠀⠀⣰⣯⡟⡀⠀⣼⡏⢘⡢⢠⣷⣾⡿⠿⠿⣷⣤⣞⠀⠙⢦⡀⠀⠙⢿⣷⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ SIPPTS version 4.1.2 (updated) ⣿⣍⡓⣄⣿⣧⣤⣤⣤⣶⣶⠿⠟⠋⠀⠀⣠⣎⣠⠎⠘⢄⠀⠀⠀⢀⡏⠛⠙⠋⢸⠋⠧⠤⠗⣾⢻⠁⠀⠀⠀⠀⠈⠻⡳⡀⠀⠙⢦⠀⣠⡹⡟⣦⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀ CVE version 0.1 (updated) ⣷⣤⣙⢾⣿⣭⡉⠉⠉⠁⠀⠀⣀⣠⠴⠚⠉⠉⠀⠀⠀⠈⠳⡀⠀⠘⣧⣤⢀⠀⢸⡶⣏⠙⣦⠹⡜⢦⡀⠀⠀⠀⠀⢀⡇⣿⣶⣶⣾⣿⣥⡇⠹⡌⠻⣄⠀⠀⠀⠀⠀⠀⠀⠀ https://github.com/Pepelux/sippts ⣿⠤⢬⣿⣇⠈⢹⡟⠛⠛⠛⠉⠉⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠙⢆⠀⢻⡹⡎⠃⠀⠳⡄⣽⠛⠦⠉⠲⣍⣓⣒⢒⣒⣉⡴⠋⣟⠙⢲⣿⠘⠃⠀⣷⠀⠙⢧⡀⠀⠀⠀⠀⠀⠀by Pepelux - https://twitter.com/pepeluxx ⣿⠶⠒⠺⣿⡀⢸⡇⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⢣⡀⠳⡄⢀⡀⠀⠙⠮⣗⠚⢠⡖⠲⣌⣉⡭⣍⡡⣞⠓⣾⠉⣽⠃⢠⡄⣼⣿⠀⠀⠈⠳⡄⠀⠀⠀⠀⠀ ⠸⡟⠉⣉⣻⣧⣼⠿⣦⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠙⣄⠙⢮⡿⢿⡃⠀⠈⠑⠶⢽⣒⣃⣘⣲⣤⣗⣈⣹⠵⠛⠁⠀⠀⡴⣻⠃⠀⠀⠀⠀⠹⣆⠀⠀⠀⠀ ⠀⠹⣯⣁⣠⠼⠿⣿⡲⠿⠷⣤⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⢦⠀⠙⠳⣄⡀⠀⣄⣶⣄⠀⠉⠉⠉⣉⡉⠉⠀⠀⠘⣶⣴⣦⠞⠁⠀⠀⠀⠀⠀⠀⠘⣧⠀⠀⠀ ⠀⠀⠘⣧⡤⠖⢋⣩⠿⣶⣤⣈⣙⣷⣤⣀⣠⣤⣄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⢳⡀⠀⠀⠉⠓⠶⢽⣼⣆⡀⠀⠀⢿⣿⣶⣀⣀⡬⠷⠚⠁⣀⣀⣀⠀⢰⣿⠿⡇⠀⠘⣧⠀⠀ ⠀⠀⠀⠀⠙⠾⣏⣤⠞⢁⡞⠉⣿⠋⣹⠉⢹⠀⣿⡄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠹⡄⠀⠀⠀⠀⠀⠀⠉⠉⠉⠉⠉⠉⠉⠉⠀⣤⣤⣄⠀⣿⠙⢻⠆⠀⠓⢒⣁⡤⠴⠺⡆⠀ ⠀⠀⠀⠀⠀⠀⠀⠙⠒⠻⠤⣴⣇⣀⣿⣀⣾⡤⠿⢷⣄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠘⣆⠀⠀⠀⠀⠀⣀⣀⡀⠀⢸⠿⢷⡄⠀⣿⣀⡿⠀⢈⣉⡭⠴⠒⠋⠉⠀⠀⠀⠀⢻⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠉⠻⣦⣀⠀⠀⠀⠀⠀⠀⠀⠀⠈⢆⠀⠀⠀⠰⣟⠛⡇⠀⠘⠧⠞⢁⣀⡤⠴⠒⠋⠉⠀⠀⠀⠀⠀⠀⠀⠀⣀⣠⣼⠃ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠙⠳⣦⣀⠀⠀⠀⠀⠀⠀⠈⢧⠀⠀⠀⠉⢋⣁⡤⠴⠚⠋⠉⠀⠀⠀⠀⠀⠀⠀⢀⣀⣠⣴⠶⠚⠛⠉⢉⣽⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⠙⠷⣤⡀⠀⠀⠀⠀⠘⡆⠴⠒⠋⠉⠀⠀ ⢀⣀⣤⠴⠖⠛⠉⠉⠉⠉⠙⠛⠋⠉⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⢛⠷⠦⠀⠀⠀⣿⠀⠀ ⠀⠀⠀⢠⠴⡖⠛⠉⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⠙⠷⣤⡀⠀⠘⡆⠴⠒⠋⠉⣤⠴⠖⠛⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⢛⢠⠴⡖⠛⠉⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀

-= SIPPTS is a set of tools for auditing VoIP systems based on the SIP protocol =-

Commands: {video,astami,scan,exten,rcrack,send,wssend,enumerate,leak,ping,invite,dump,dcrack,flood,sniff,spoof,pcapdump,rtpbleed,rtcpbleed,rtpbleedflood,rtpbleedinject} video Animated help astami Asterisk AMI pentest scan Fast SIP scanner exten Search SIP extensions of a PBX rcrack Remote password cracker send Send a customized message wssend Send a customized message over WS enumerate Enumerate methods of a SIP server leak Exploit SIP Digest Leak vulnerability ping SIP ping invite Try to make calls through a PBX dump Dump SIP digest authentications from a PCAP file dcrack SIP digest authentication cracking flood Flood a SIP server sniff SIP network sniffing spoof ARP Spoofing tool pcapdump Extract data from a PCAP file rtpbleed Detect RTPBleed vulnerability (send RTP streams) rtcpbleed Detect RTPBleed vulnerability (send RTCP streams) rtpbleedflood Exploit RTPBleed vulnerability (flood RTP) rtpbleedinject Exploit RTPBleed vulnerability (inject WAV file)

Options: -h, --help show this help message and exit -up Update scripts

Command help: sippts -h

scan 명령어에 대한 도움말을 표시합니다:```
sippts scan -h
usage: sippts scan [-i IP|HOST] [-f FILE] [-r REMOTE_PORT] [-p PROTOCOL]
                   [-proxy IP:PORT] [-m METHOD] [-d DOMAIN]
                   [-cd CONTACT_DOMAIN] [-fn FROM_NAME] [-fu FROM_USER]
                   [-fd FROM_DOMAIN] [-tn TO_NAME] [-tu TO_USER]
                   [-td TO_DOMAIN] [-ua USER_AGENT] [-ppi PPI] [-pai PAI] [-v]
                   [-vv] [-nocolor] [-o FILE] [-oi FILE] [-ot FILE] [-oj FILE]
                   [-ocsv FILE] [-cve] [-th THREADS] [-t TIMEOUT] [-ping]
                   [-fp] [-random] [-local-ip IP] [-h]


  ___ ___ ___ ___ _____ ___                    
 / __|_ _| _ \ _ \_   _/ __|  ___ __ __ _ _ _  
 \__ \| ||  _/  _/ | | \__ \ (_-</ _/ _` | ' \ 
 |___/___|_| |_|   |_| |___/ /__/\__\__,_|_||_|
            
  Module scan is a fast SIP scanner using multithread that can check several IPs and port ranges. It works with UDP, TCP and TLS protocols.

Target:
  -i IP|HOST            Host/IP address/network (ex: mysipserver.com | 192.168.0.10 | 192.168.0.0/24)
  -f FILE               File with several IPs or network ranges
  -r REMOTE_PORT        Ports to scan. Ex: 5060 | 5070,5080 | 5060-5080 | 5060,5062,5070-5080 | ALL for 1-65535 (default: 5060)
  -p, --protocol PROTOCOL
                        Protocol: udp|tcp|tls|all (default: udp)
  -proxy IP:PORT        Use an outbound proxy (ex: 192.168.1.1 or 192.168.1.1:5070)

Headers:
  -m METHOD             SIP method: options, invite, register (default: options)
  -d, --domain DOMAIN   SIP Domain or IP address. Ex: my.sipserver.com (default: target IP address)
  -cd CONTACT_DOMAIN    Domain or IP address for Contact header. Ex: 10.0.1.2
  -fn FROM_NAME         From Name. Ex: Bob
  -fu FROM_USER         From User (default: 100)
  -fd FROM_DOMAIN       From Domain. Ex: 10.0.0.1
  -tn TO_NAME           To Name. Ex: Alice
  -tu TO_USER           To User (default: 100)
  -td TO_DOMAIN         To Domain. Ex: 10.0.0.1
  -ua USER_AGENT        User-Agent header (default: pplsip)
  -ppi PPI              P-Preferred-Identity
  -pai PAI              P-Asserted-Identity

Log:
  -v                    Increase verbosity
  -vv                   Increase more verbosity
  -nocolor              Show result without colors
  -o FILE               Save data into a log file
  -oi FILE              Save IPs into a log file
  -ot FILE              Save found hosts as ip:port/proto, ready for -f of exten, rcrack and leak
  -oj FILE              Save results into a JSON file
  -ocsv FILE            Save results into a CSV file
  -cve                  Show possible CVEs

Other options:
  -th THREADS           Number of threads (default: 200)
  -t, --timeout TIMEOUT
                        Sockets timeout (default: 5)
  -ping                 Ping host before scan
  -fp                   Try to fingerprinting
  -random               Randomize target hosts
  -local-ip IP          Set local IP address (by default try to get it)
  -h, --help            Show this help

Usage examples:
  Searching for SIP services and devices with default ports (5060/udp) on the local network
     sippts scan -i 192.168.0.0/24
  Extend the port range from 5060 to 5080 and look for UDP, TCP and TLS services
     sippts scan -i 192.168.0.0/24 -r 5060-5080 -p all
  Load several target IP addresses from a file
     sippts scan -f targets.txt
  Random scanning for non-sequential scanning of IP ranges
     sippts scan -f targets.txt -random
  Disguise the tool behind another User-Agent
     sippts scan -i 192.168.0.0/24 -ua Grandstream
  Scan all ports and protocols of an address range using 500 threads (slow)
     sippts scan -f targets.txt -r all -p all -th 500 -ua Grandstream
  Typical scanning for large ranges
     sippts scan -f targets.txt -r 5060-5080 -p all -th 500 -ua Grandstream -v -fp -o output.txt
  Save the hosts found as ip:port/proto, to chain with exten, rcrack or leak
     sippts scan -i 192.168.0.0/24 -r 5060-5080 -p all -ot targets.txt
     sippts exten -f targets.txt -e 100-200 -oe extens.txt
     sippts rcrack -f targets.txt -ef extens.txt -w wordlist.txt
  Save the results as JSON or CSV, to process them with another tool
     sippts scan -i 192.168.0.0/24 -oj result.json -ocsv result.csv

스크립트 업데이트:``` sippts -up

# SIP 프로토콜 침투 테스트를 위한 도구 모음 #

이 도구의 사용 방법에 대한 도움말은 https://sippts.seguridadvoip.com 에서 확인할 수 있으며, Github 위키 페이지에서도 확인할 수 있습니다:

Sippts는 SIP 프로토콜을 사용하는 VoIP 서버 및 장치를 감사하기 위한 도구 모음입니다. Sippts는 Python으로 프로그래밍되었으며 다음 명령 또는 모듈로 구성됩니다:
  * _**scan**_ 은 SIP 서비스를 위한 빠른 멀티스레드 스캐너입니다. 여러 IP 주소와 포트 범위를 확인할 수 있으며, UDP, TCP 및 TLS를 통해 작동합니다. [scan 명령에 대해 더 읽으려면 여기를 클릭하세요](https://github.com/Pepelux/sippts/wiki/Command-scan)

  * _**exten**_ 은 SIP 서버의 내선 번호를 식별합니다. 또한 해당 내선 번호에 인증이 필요한지 여부를 알려줍니다. 여러 IP 주소를 확인할 수 있으며, -f를 사용하면 파일에서 대상을 읽습니다. [exten 명령에 대해 더 읽으려면 여기를 클릭하세요](https://github.com/Pepelux/sippts/wiki/Command-exten)

  * _**rcrack**_ 은 원격 비밀번호 크래커입니다. 여러 IP 주소의 여러 사용자에 대해 비밀번호를 테스트할 수 있으며, -f를 사용하면 파일에서 대상을 읽습니다. [rcrack 명령에 대해 더 읽으려면 여기를 클릭하세요](https://github.com/Pepelux/sippts/wiki/Command-rcrack)

  * _**invite**_ 는 서버가 인증 없이 통화를 허용하는지 확인합니다. SIP 서버의 구성이 잘못된 경우 외부 번호로 통화를 허용합니다. 또한 통화를 두 번째 외부 번호로 전환할 수 있습니다. [invite 명령에 대해 더 읽으려면 여기를 클릭하세요](https://github.com/Pepelux/sippts/wiki/Command-invite)

  * _**leak**_ 은 Sandro Gauci가 발견한 SIP Digest Leak 취약점을 악용하며, 이는 많은 수의 하드웨어 및 소프트웨어 장치에 영향을 미칩니다. [leak 명령에 대해 더 읽으려면 여기를 클릭하세요](https://github.com/Pepelux/sippts/wiki/Command-leak)

  * _**flood**_ 는 대상에 무제한 메시지를 보냅니다. [flood 명령에 대해 더 읽으려면 여기를 클릭하세요](https://github.com/Pepelux/sippts/wiki/Command-flood)

  * _**send**_ 는 사용자 정의된 SIP 메시지를 보내고 응답을 분석합니다. [send 명령에 대해 더 읽으려면 여기를 클릭하세요](https://github.com/Pepelux/sippts/wiki/Command-send)

  * _**wssend**_ 는 WebSockets를 통해 사용자 정의된 SIP 메시지를 보내고 응답을 분석합니다. [wssend 명령에 대해 더 읽으려면 여기를 클릭하세요](https://github.com/Pepelux/sippts/wiki/Command-wssend)

  * _**enumerate**_ 는 SIP 서비스 또는 서버의 사용 가능한 메서드를 열거합니다. [enumerate 명령에 대해 더 읽으려면 여기를 클릭하세요](https://github.com/Pepelux/sippts/wiki/Command-enumerate)

  * _**dump**_ 는 PCAP 파일에서 SIP Digest 인증을 추출합니다. [dump 명령에 대해 더 읽으려면 여기를 클릭하세요](https://github.com/Pepelux/sippts/wiki/Command-dump)

  * _**dcrack**_ 은 SIP 프로토콜의 digest 인증을 크랙합니다. [dcrack 명령에 대해 더 읽으려면 여기를 클릭하세요](https://github.com/Pepelux/sippts/wiki/Command-dcrack)

  * _**pcapdump**_ 는 PCAP 파일에서 SIP 및 RTP 데이터를 추출하며, 오디오 스트림을 WAV 파일로 저장할 수 있습니다. [pcapdump 명령에 대해 더 읽으려면 여기를 클릭하세요](https://github.com/Pepelux/sippts/wiki/Command-pcapdump)

  * _**ping**_ 은 서버 또는 장치가 살아 있는지 확인하기 위해 SIP ping을 보냅니다. [ping 명령에 대해 더 읽으려면 여기를 클릭하세요](https://github.com/Pepelux/sippts/wiki/Command-ping)

  * _**astami**_ 는 Asterisk Manager Interface (AMI)를 스캔하고 감사하며, 자격 증명이 작동하는 곳에서 명령을 실행할 수 있습니다. [astami 명령에 대해 더 읽으려면 여기를 클릭하세요](https://github.com/Pepelux/sippts/wiki/Command-astami)

  * _**sniff**_ 는 SIP 트래픽을 실시간으로 캡처하고 메시지, 장치 및 확인된 digest 인증을 표시합니다. [sniff 명령에 대해 더 읽으려면 여기를 클릭하세요](https://github.com/Pepelux/sippts/wiki/Command-sniff)

  * _**spoof**_ 는 ARP 스푸핑 도구로, 두 장치 사이에 자신을 위치시키고 트래픽을 캡처합니다. [spoof 명령에 대해 더 읽으려면 여기를 클릭하세요](https://github.com/Pepelux/sippts/wiki/Command-spoof)

  * _**video**_ 는 일반적인 워크플로우의 애니메이션 데모를 재생합니다: scan에서 exten으로, exten에서 rcrack으로, dump에서 dcrack으로, leak에서 dcrack으로, 그리고 spoof에서 sniff로.

  * _**rtpbleed**_ 는 RTP 포트로 데이터를 전송하여 RTP Bleed 취약점을 악용합니다. [rtpbleed 명령에 대해 더 읽으려면 여기를 클릭하세요](https://github.com/Pepelux/sippts/wiki/Command-rtpbleed)

  * _**rtcpbleed**_ 는 RTCP 포트로 데이터를 전송하여 RTP bleed 취약점을 악용합니다. [rtcpbleed 명령에 대해 더 읽으려면 여기를 클릭하세요](https://github.com/Pepelux/sippts/wiki/Command-rtcpbleed)

  * _**rtpbleedflood**_ 는 활성 다이얼로그로 RTP 포트를 플러딩하여 RTP Bleed 취약점을 악용합니다. [rtpbleedflood 명령에 대해 더 읽으려면 여기를 클릭하세요](https://github.com/Pepelux/sippts/wiki/Command-rtpbleedflood)

  * _**rtpbleedinject**_ 는 RTP 트래픽을 주입하여 RTP Bleed 취약점을 악용합니다. [rtpbleedinject 명령에 대해 더 읽으려면 여기를 클릭하세요](https://github.com/Pepelux/sippts/wiki/Command-rtpbleedinject)

## TLS 인증서 ##

sippts는 TLS를 지원하며, 지금까지는 인증서를 버렸습니다. `-tlsinfo` 를 사용하면 `scan` 모듈이 서버가 제시하는 내용을 읽습니다:```
sippts scan -i 192.168.0.1 -r 5061 -p tls -tlsinfo

추가 연결 비용이 들지 않습니다. 핸드셰이크는 어차피 일어나기 때문입니다. 일반적인 표 뒤에 두 개의 표가 따라옵니다. 하나는 인증서가 말하는 내용(TLS 버전, 암호, 키, 만료, 그리고 -v를 사용하면 subject, issuer, SAN 및 SHA-256)이고, 다른 하나는 그것에 대해 보고할 가치가 있는 사항 — 만료됨, 자체 서명, 2048비트 미만의 키, SHA-1 또는 MD5 서명, 일치하지 않는 이름, 오래된 TLS 버전 또는 약한 암호입니다.

VoIP에서 가장 중요한 것은 CERT_DEFAULT_VENDOR입니다. PBX나 전화기의 공장 인증서로, 그 개인 키가 펌웨어 이미지 안에 함께 배포됩니다. 그 이미지를 다운로드하는 사람은 누구나 SIP-TLS의 중간에 앉을 수 있습니다.

-tlsversions를 사용하면 TLS 1.0, 1.1, 1.2, 1.3을 한 번에 하나씩 시도하기도 하는데, 이는 버전당 한 번의 핸드셰이크 비용이 들며 호스트와 포트당 한 번 수행됩니다:``` sippts scan -i 192.168.0.1 -r 5061 -p tls -tlsversions

각 버전은 `accepted`, `refused` 또는 `untested`로 반환됩니다. 마지막 것은 *이* OpenSSL이 해당 버전을 제공할 수 없음을 의미하며, 이는 서버에서 해당 버전이 꺼져 있는 것과는 다르고, 그 차이는 결과가 보고서에 들어갈 때 중요합니다.

도구가 숨기지 않고 출력하는 두 가지 정직한 한계:

  * **SSLv2와 SSLv3는 테스트할 수 없습니다.** OpenSSL 3는 이들을 포함하지 않고 빌드되므로, sippts는 이들을 제공할 수 없습니다. 이들은 `untested`로 보고되며, 결코 `disabled`로 보고되지 않습니다.

  * 내부 SIP 트렁크의 자체 서명 인증서는 그 자체로는 발견 사항이 아닙니다. 맥락 속에서 판단하십시오.

메인 테이블, `-o`의 파일, `-ocsv`의 CSV는 변경되지 않습니다. `-oj`의 JSON은 `tls`와 `tls_findings`를 얻습니다.

## 통화 하이재킹 ##

`Replaces` (RFC 3891)는 이미 연결된 통화를 Call-ID와 두 개의 태그로 가리킵니다. `sippts dump`와 `sippts sniff`가 캡처에서 이 세 가지 값을 얻어내는 수단이며, 거기서부터:```
sippts send -i 192.168.0.1 -m REFER -refer-to 200 -replaces "CALLID;to-tag=X;from-tag=Y"
sippts send -i 192.168.0.1 -m INVITE -replaces "CALLID;to-tag=X;from-tag=Y"

REFER에서는 전환(attended transfer)이고, INVITE에서는 통화를 넘겨받는다. sippts invite-replaces도 받는데, 이는 -t가 이미 보내는 REFER에 추가하기 위한 것으로, 방금 설정한 통화 내부에서 전환이 일어나게 한다.

서버가 지원한다고 말하는 것

enumerate는 14개의 SIP 메서드를 하나씩 시도하고 응답으로 그것들을 구별하지만, 서버는 또한 Allow, Supported, Allow-Events 헤더에서 무엇을 받아들이는지 밝힌다. 이것들도 읽어서 두 번째 표에 출력하며, 여기서 살펴볼 만한 두 가지 모순도 지적한다: Allow에 광고되었지만 405로 응답하는 메서드, 그리고 광고되지 않았는데도 잘 응답하는 메서드. Allow-Eventsdialog, message-summary, presence를 구독할 수 있는지 알려주는 헤더이며, send -m subscribe가 다음으로 향하는 곳이다.``` sippts enumerate -i 192.168.0.1

첫 번째 테이블은 원래 가지고 있던 형태를 그대로 유지하며, `-ocsv`의 CSV도 마찬가지입니다. 새로운 데이터는 `-oj`의 JSON에만 `capabilities` 아래에 추가됩니다.

## 알려진 취약점 ##

`-cve`를 사용하면 `scan` 모듈은 핑거프린팅한 내용을 패키지 내부에 포함되어 함께 다니는 알려진 취약점 목록(`src/sippts/data/cve.csv`)과 비교합니다. 이 목록은 [NIST의 NVD](https://nvd.nist.gov)를 기반으로 구축된 54개 벤더의 약 1400개 CVE를 담고 있으며, 버전 범위는 각 CVE의 CPE에서 가져옵니다:```bash
sippts scan -i 192.168.0.0/24 -fp -cve

버전이 실제로 영향을 받는 범위 안에 들어가는 결과가 먼저 나열된다. 나머지는 단지 가능성 있는 항목으로 그 뒤에 표시되는데, 스캐너에서는 존재하지만 보고되지 않은 CVE가 과도하게 보고된 CVE보다 더 나쁘기 때문이다. 범위가 없는 행은 해당 장치의 모든 버전이 영향을 받는다는 의미이다.

알아둘 만한 두 가지 한계가 있다. 탐지는 User-Agent에 의존하므로, 이를 숨기는 서버는 어떤 것과도 대조하여 확인할 수 없다. 그리고 일부 제품은 문자로 버전이 매겨지는데(Asterisk Business Edition의 A, B, C 또는 beta_5), 이는 어떤 숫자 비교로도 정렬할 수 없다. 이런 것들은 텍스트로만 일치되며, 항상 확인된 것이 아니라 가능성 있는 항목으로 나온다.

목록을 업데이트하려면:```bash sippts -up

which downloads it from github along with the rest of the modules.

### Severity ###

Each CVE carries its CVSS, coloured by severity: purple for critical, red for
high, yellow for medium and cyan for low. The worst ones are listed first.

The NVD does not have CVSS v3 for every CVE: roughly a third of the list is
older than 2016 and only has v2, and for Asterisk it is most of them. When
only v2 exists it is used and **marked with `v2`**, because the two scales are
not equivalent and v2 has no CRITICAL level: CVE-2017-16563 is 6.0 MEDIUM in
v2 and 8.0 HIGH in v3.

A sippts older than 4.2.1 cannot read this column. Update with `sippts -up`.

### Rebuilding the list (maintainers) ###

`tools/cve_update.py` rebuilds `cve.csv` from the NVD. It is not something the
user of sippts runs: the idea is to regenerate it, look at the diff, commit it,
and let everybody else get it with `sippts -up`. That keeps the API key and the
rate limits of the NVD out of the middle of an audit.```bash
./tools/cve_update.py --dry-run          # what would change, writing nothing
./tools/cve_update.py                    # rebuild it
./tools/cve_update.py --vendor yealink   # only one vendor
NVD_API_KEY=xxxx ./tools/cve_update.py   # ten times faster

API 키가 없으면 NVD는 30초마다 5회의 요청을 허용하며, 전체 실행에는 약 15분이 걸립니다. API 키는 nvd.nist.gov에서 무료로 발급받을 수 있습니다.

스크립트 상단의 두 목록이 무엇을 검색할지 제어합니다. VENDORS에는 벤더가 들어가며, 각 항목은 전체 벤더, 제품 목록, 또는 태그로 필터링된 형태일 수 있습니다. TAGS_VOIP에는 태그(voip, sip, ip_phone, ata, pbx, ip_office, mivoice...)가 들어갑니다. 이 필터는 라우터와 방화벽도 만드는 벤더에게 중요합니다. 예를 들어 NVD에 Zyxel 전체를 요청하면 sippts가 SIP를 통해 절대 보지 못할 3223개의 WiFi 및 DSL 장비 행이 반환됩니다.

운영 체제

Sippts는 다음에서 테스트되었습니다:

  • Linux
  • MacOS

요구 사항

  • Python 3
  • requirements.txt에 나열된 의존성으로, pip에 의해 자동으로 설치됩니다
  • sniff, dump 및 pcapdump의 경우: tshark (Wireshark의 일부)
  • pcapdump로 오디오를 추출하는 경우: sox 및 ffmpeg

설치

git을 통한 설치: ```bash git clone https://github.com/Pepelux/sippts.git

```bash
cd sippts
pip3 install .

카테고리