返回更新列表
新发布Sep 15, 2026

sippts v4.2.1

用于审计基于 SIP 的 VoIP 系统的工具集

分享
logo

什么是 Sippts?

Sippts 是一套用于审计使用 SIP 协议的 VoIP 服务器和设备的工具。Sippts 使用 Python 编写,它允许我们使用 SIP 协议检查 VoIP 服务器的安全性。

它是免费的吗?

是的。你可以自由使用、修改和分发它。如果你修改了它,请包含对本网站的引用。

sippts 可以用于非法目的吗?

本工具的目的是审计你自己的系统,或对已获得明确授权的系统进行渗透测试。我不对本工具的滥用负责。

用法

显示帮助:``` sippts -h usage: sippts [-h] [-up] {video,astami,scan,exten,rcrack,send,wssend,enumerate,leak,ping,invite,dump,dcrack,flood,sniff,spoof,pcapdump,rtpbleed,rtcpbleed,rtpbleedflood,rtpbleedinject} ...

⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣀⣀⣀⣀⣤⣤⣤⣤⣤⣤⣤⣤⣤⣤⣄⣀⣀⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣀⣤⠤⠶⠒⠛⠉⠉⠉⠉⠀⠀⢀⣀⣀⣀⣤⣤⣤⣤⣤⣤⣤⣤⣬⣍⣙⣳⣄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣀⣤⠴⠒⠋⠉⠀⠀⠀⢀⣀⣠⡤⠴⠖⠚⠛⠉⠉⠉⠀⣠⡶⠖⠲⣄⠀⠀⠀⠀⠀⠀⠀⠈⠉⢷⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⢀⣀⡤⠖⠋⠁⠀⠀⠀⣀⣤⠴⠖⣛⣉⣁⠀⠀⠀⠀⠀⠀⠀⣀⣀⣠⡇⢹⡄⠀⠸⡆⠀⠀⠀⠀⠀⠀⠀⠀⠈⢿⡄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⣀⡤⠞⠋⠀⠀⠀⢀⣠⠴⠚⠋⠁⠀⠀⡿⡏⠀⠈⣧⣤⠴⠖⠚⠛⠉⠉⠳⢄⡀⠀⣧⠀⠀⢷⠀⠀⠀⠀⠀⠀⠀⠀⠀⠘⣷⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⢠⡞⠧⣄⠀⢀⣠⠴⠚⠉⠀⠀⠀⠀⠀⢀⣴⠇⢹⠀⠀⢸⡆⠀⠀⠀⠀⠀⠀⠀⠀⠉⣲⣿⣀⣠⣼⣦⣤⣀⣀⣀⡀⠀⢀⣀⣠⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⢀⡿⠀⠀⠈⣿⠉⠀⠀⠀⠀⠀⠀⠙⢄⣰⠏⠀⠀⠘⡇⠀⠀⣇⢀⣀⡤⠤⠖⠒⠛⠉⠉⠉⣁⣀⠀⠀⠀⠉⠙⠛⢿⣿⡛⠛⠛⢻⡟⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⣸⣧⣄⠀⠀⡇⠀⠀⠀⠀⠀⠀⠀⠀⢈⣿⡄⠀⠀⠀⣷⠴⠚⠋⠉⠀⠀⢀⣠⣴⡖⠛⠉⠿⢻⣿⣉⡉⠙⠓⢲⠦⢤⣈⠙⢶⣶⠋⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⢠⣏⠙⢦⣹⣼⠀⠀⠀⠀⠀⠀⢀⣴⣾⠟⠁⢀⡏⢀⡞⠀⠀⠀⠀⠀⣰⣯⡟⡀⠀⣼⡏⢘⡢⢠⣷⣾⡿⠿⠿⣷⣤⣞⠀⠙⢦⡀⠀⠙⢿⣷⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⣰⡟⠿⡍⢷⢀⡇⠀⠀⠀⠀⠀⠀⠀⣠⣾⠏⣧⠀⢀⡞⠁⠀⠀⠀⠀⢠⡴⠋⠛⠻⣧⣤⡶⢿⡹⡟⠛⢯⣉⣿⢾⣧⣄⡈⠙⠲⢝⣷⣄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⢠⣏⠙⢦⣹⣼⠀⠀⠀⠀⠀⠀⢀⣴⣾⠟⠁⢀⡏⢀⡞⠀⠀⠀⠀⠀⣰⣯⡟⡀⠀⣼⡏⢘⡢⢠⣷⣾⡿⠿⠿⣷⣤⣞⠀⠙⢦⡀⠀⠙⢿⣷⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ SIPPTS version 4.1.2 (updated) ⣿⣍⡓⣄⣿⣧⣤⣤⣤⣶⣶⠿⠟⠋⠀⠀⣠⣎⣠⠎⠘⢄⠀⠀⠀⢀⡏⠛⠙⠋⢸⠋⠧⠤⠗⣾⢻⠁⠀⠀⠀⠀⠈⠻⡳⡀⠀⠙⢦⠀⣠⡹⡟⣦⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀ CVE version 0.1 (updated) ⣷⣤⣙⢾⣿⣭⡉⠉⠉⠁⠀⠀⣀⣠⠴⠚⠉⠉⠀⠀⠀⠈⠳⡀⠀⠘⣧⣤⢀⠀⢸⡶⣏⠙⣦⠹⡜⢦⡀⠀⠀⠀⠀⢀⡇⣿⣶⣶⣾⣿⣥⡇⠹⡌⠻⣄⠀⠀⠀⠀⠀⠀⠀⠀ https://github.com/Pepelux/sippts ⣿⠤⢬⣿⣇⠈⢹⡟⠛⠛⠛⠉⠉⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠙⢆⠀⢻⡹⡎⠃⠀⠳⡄⣽⠛⠦⠉⠲⣍⣓⣒⢒⣒⣉⡴⠋⣟⠙⢲⣿⠘⠃⠀⣷⠀⠙⢧⡀⠀⠀⠀⠀⠀⠀by Pepelux - https://twitter.com/pepeluxx ⣿⠶⠒⠺⣿⡀⢸⡇⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⢣⡀⠳⡄⢀⡀⠀⠙⠮⣗⠚⢠⡖⠲⣌⣉⡭⣍⡡⣞⠓⣾⠉⣽⠃⢠⡄⣼⣿⠀⠀⠈⠳⡄⠀⠀⠀⠀⠀ ⠸⡟⠉⣉⣻⣧⣼⠿⣦⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠙⣄⠙⢮⡿⢿⡃⠀⠈⠑⠶⢽⣒⣃⣘⣲⣤⣗⣈⣹⠵⠛⠁⠀⠀⡴⣻⠃⠀⠀⠀⠀⠹⣆⠀⠀⠀⠀ ⠀⠹⣯⣁⣠⠼⠿⣿⡲⠿⠷⣤⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⢦⠀⠙⠳⣄⡀⠀⣄⣶⣄⠀⠉⠉⠉⣉⡉⠉⠀⠀⠘⣶⣴⣦⠞⠁⠀⠀⠀⠀⠀⠀⠘⣧⠀⠀⠀ ⠀⠀⠘⣧⡤⠖⢋⣩⠿⣶⣤⣈⣙⣷⣤⣀⣠⣤⣄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⢳⡀⠀⠀⠉⠓⠶⢽⣼⣆⡀⠀⠀⢿⣿⣶⣀⣀⡬⠷⠚⠁⣀⣀⣀⠀⢰⣿⠿⡇⠀⠘⣧⠀⠀ ⠀⠀⠀⠀⠙⠾⣏⣤⠞⢁⡞⠉⣿⠋⣹⠉⢹⠀⣿⡄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠹⡄⠀⠀⠀⠀⠀⠀⠉⠉⠉⠉⠉⠉⠉⠉⠀⣤⣤⣄⠀⣿⠙⢻⠆⠀⠓⢒⣁⡤⠴⠺⡆⠀ ⠀⠀⠀⠀⠀⠀⠀⠙⠒⠻⠤⣴⣇⣀⣿⣀⣾⡤⠿⢷⣄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠘⣆⠀⠀⠀⠀⠀⣀⣀⡀⠀⢸⠿⢷⡄⠀⣿⣀⡿⠀⢈⣉⡭⠴⠒⠋⠉⠀⠀⠀⠀⢻⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠉⠻⣦⣀⠀⠀⠀⠀⠀⠀⠀⠀⠈⢆⠀⠀⠀⠰⣟⠛⡇⠀⠘⠧⠞⢁⣀⡤⠴⠒⠋⠉⠀⠀⠀⠀⠀⠀⠀⠀⣀⣠⣼⠃ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠙⠳⣦⣀⠀⠀⠀⠀⠀⠀⠈⢧⠀⠀⠀⠉⢋⣁⡤⠴⠚⠋⠉⠀⠀⠀⠀⠀⠀⠀⢀⣀⣠⣴⠶⠚⠛⠉⢉⣽⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⠙⠷⣤⡀⠀⠀⠀⠀⠘⡆⠴⠒⠋⠉⠀⠀ ⢀⣀⣤⠴⠖⠛⠉⠉⠉⠉⠙⠛⠋⠉⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⢛⠷⠦⠀⠀⠀⣿⠀⠀ ⠀⠀⠀⢠⠴⡖⠛⠉⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⠙⠷⣤⡀⠀⠘⡆⠴⠒⠋⠉⣤⠴⠖⠛⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⢛⢠⠴⡖⠛⠉⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀

-= SIPPTS is a set of tools for auditing VoIP systems based on the SIP protocol =-

Commands: {video,astami,scan,exten,rcrack,send,wssend,enumerate,leak,ping,invite,dump,dcrack,flood,sniff,spoof,pcapdump,rtpbleed,rtcpbleed,rtpbleedflood,rtpbleedinject} video Animated help astami Asterisk AMI pentest scan Fast SIP scanner exten Search SIP extensions of a PBX rcrack Remote password cracker send Send a customized message wssend Send a customized message over WS enumerate Enumerate methods of a SIP server leak Exploit SIP Digest Leak vulnerability ping SIP ping invite Try to make calls through a PBX dump Dump SIP digest authentications from a PCAP file dcrack SIP digest authentication cracking flood Flood a SIP server sniff SIP network sniffing spoof ARP Spoofing tool pcapdump Extract data from a PCAP file rtpbleed Detect RTPBleed vulnerability (send RTP streams) rtcpbleed Detect RTPBleed vulnerability (send RTCP streams) rtpbleedflood Exploit RTPBleed vulnerability (flood RTP) rtpbleedinject Exploit RTPBleed vulnerability (inject WAV file)

Options: -h, --help show this help message and exit -up Update scripts

Command help: sippts -h

显示命令 scan 的帮助信息:```
sippts scan -h
usage: sippts scan [-i IP|HOST] [-f FILE] [-r REMOTE_PORT] [-p PROTOCOL]
                   [-proxy IP:PORT] [-m METHOD] [-d DOMAIN]
                   [-cd CONTACT_DOMAIN] [-fn FROM_NAME] [-fu FROM_USER]
                   [-fd FROM_DOMAIN] [-tn TO_NAME] [-tu TO_USER]
                   [-td TO_DOMAIN] [-ua USER_AGENT] [-ppi PPI] [-pai PAI] [-v]
                   [-vv] [-nocolor] [-o FILE] [-oi FILE] [-ot FILE] [-oj FILE]
                   [-ocsv FILE] [-cve] [-th THREADS] [-t TIMEOUT] [-ping]
                   [-fp] [-random] [-local-ip IP] [-h]


  ___ ___ ___ ___ _____ ___                    
 / __|_ _| _ \ _ \_   _/ __|  ___ __ __ _ _ _  
 \__ \| ||  _/  _/ | | \__ \ (_-</ _/ _` | ' \ 
 |___/___|_| |_|   |_| |___/ /__/\__\__,_|_||_|
            
  Module scan is a fast SIP scanner using multithread that can check several IPs and port ranges. It works with UDP, TCP and TLS protocols.

Target:
  -i IP|HOST            Host/IP address/network (ex: mysipserver.com | 192.168.0.10 | 192.168.0.0/24)
  -f FILE               File with several IPs or network ranges
  -r REMOTE_PORT        Ports to scan. Ex: 5060 | 5070,5080 | 5060-5080 | 5060,5062,5070-5080 | ALL for 1-65535 (default: 5060)
  -p, --protocol PROTOCOL
                        Protocol: udp|tcp|tls|all (default: udp)
  -proxy IP:PORT        Use an outbound proxy (ex: 192.168.1.1 or 192.168.1.1:5070)

Headers:
  -m METHOD             SIP method: options, invite, register (default: options)
  -d, --domain DOMAIN   SIP Domain or IP address. Ex: my.sipserver.com (default: target IP address)
  -cd CONTACT_DOMAIN    Domain or IP address for Contact header. Ex: 10.0.1.2
  -fn FROM_NAME         From Name. Ex: Bob
  -fu FROM_USER         From User (default: 100)
  -fd FROM_DOMAIN       From Domain. Ex: 10.0.0.1
  -tn TO_NAME           To Name. Ex: Alice
  -tu TO_USER           To User (default: 100)
  -td TO_DOMAIN         To Domain. Ex: 10.0.0.1
  -ua USER_AGENT        User-Agent header (default: pplsip)
  -ppi PPI              P-Preferred-Identity
  -pai PAI              P-Asserted-Identity

Log:
  -v                    Increase verbosity
  -vv                   Increase more verbosity
  -nocolor              Show result without colors
  -o FILE               Save data into a log file
  -oi FILE              Save IPs into a log file
  -ot FILE              Save found hosts as ip:port/proto, ready for -f of exten, rcrack and leak
  -oj FILE              Save results into a JSON file
  -ocsv FILE            Save results into a CSV file
  -cve                  Show possible CVEs

Other options:
  -th THREADS           Number of threads (default: 200)
  -t, --timeout TIMEOUT
                        Sockets timeout (default: 5)
  -ping                 Ping host before scan
  -fp                   Try to fingerprinting
  -random               Randomize target hosts
  -local-ip IP          Set local IP address (by default try to get it)
  -h, --help            Show this help

Usage examples:
  Searching for SIP services and devices with default ports (5060/udp) on the local network
     sippts scan -i 192.168.0.0/24
  Extend the port range from 5060 to 5080 and look for UDP, TCP and TLS services
     sippts scan -i 192.168.0.0/24 -r 5060-5080 -p all
  Load several target IP addresses from a file
     sippts scan -f targets.txt
  Random scanning for non-sequential scanning of IP ranges
     sippts scan -f targets.txt -random
  Disguise the tool behind another User-Agent
     sippts scan -i 192.168.0.0/24 -ua Grandstream
  Scan all ports and protocols of an address range using 500 threads (slow)
     sippts scan -f targets.txt -r all -p all -th 500 -ua Grandstream
  Typical scanning for large ranges
     sippts scan -f targets.txt -r 5060-5080 -p all -th 500 -ua Grandstream -v -fp -o output.txt
  Save the hosts found as ip:port/proto, to chain with exten, rcrack or leak
     sippts scan -i 192.168.0.0/24 -r 5060-5080 -p all -ot targets.txt
     sippts exten -f targets.txt -e 100-200 -oe extens.txt
     sippts rcrack -f targets.txt -ef extens.txt -w wordlist.txt
  Save the results as JSON or CSV, to process them with another tool
     sippts scan -i 192.168.0.0/24 -oj result.json -ocsv result.csv

更新脚本:``` sippts -up

# 用于 SIP 协议渗透测试的工具集 #

你可以在 https://sippts.seguridadvoip.com 以及 Github wiki 页面上获取有关如何使用此工具的帮助:

Sippts 是一组用于使用 SIP 协议审计 VoIP 服务器和设备的工具。Sippts 使用 Python 编写,由以下命令或模块组成:
  * _**scan**_ 是一个用于 SIP 服务的快速多线程扫描器。它可以检查多个 IP 地址和端口范围,并支持 UDP、TCP 和 TLS。[点击此处阅读有关 scan 命令的更多信息](https://github.com/Pepelux/sippts/wiki/Command-scan)

  * _**exten**_ 用于识别 SIP 服务器上的分机。它还会告诉你该分机是否需要身份验证。它可以检查多个 IP 地址,并且使用 -f 时可以从文件中读取目标。[点击此处阅读有关 exten 命令的更多信息](https://github.com/Pepelux/sippts/wiki/Command-exten)

  * _**rcrack**_ 是一个远程密码破解器。它可以测试多个 IP 地址上多个用户的密码,并且使用 -f 时可以从文件中读取目标。[点击此处阅读有关 rcrack 命令的更多信息](https://github.com/Pepelux/sippts/wiki/Command-rcrack)

  * _**invite**_ 用于检查服务器是否允许我们在未经身份验证的情况下拨打电话。如果 SIP 服务器配置不当,它将允许我们拨打外部号码。它还可以将呼叫转接到第二个外部号码。[点击此处阅读有关 invite 命令的更多信息](https://github.com/Pepelux/sippts/wiki/Command-invite)

  * _**leak**_ 利用 Sandro Gauci 发现的 SIP Digest Leak 漏洞,该漏洞影响大量硬件和软件设备。[点击此处阅读有关 leak 命令的更多信息](https://github.com/Pepelux/sippts/wiki/Command-leak)

  * _**flood**_ 向目标发送无限量的消息。[点击此处阅读有关 flood 命令的更多信息](https://github.com/Pepelux/sippts/wiki/Command-flood)

  * _**send**_ 发送自定义 SIP 消息并分析响应。[点击此处阅读有关 send 命令的更多信息](https://github.com/Pepelux/sippts/wiki/Command-send)

  * _**wssend**_ 通过 WebSockets 发送自定义 SIP 消息并分析响应。[点击此处阅读有关 wssend 命令的更多信息](https://github.com/Pepelux/sippts/wiki/Command-wssend)

  * _**enumerate**_ 枚举 SIP 服务或服务器可用的方法。[点击此处阅读有关 enumerate 命令的更多信息](https://github.com/Pepelux/sippts/wiki/Command-enumerate)

  * _**dump**_ 从 PCAP 文件中提取 SIP Digest 身份验证信息。[点击此处阅读有关 dump 命令的更多信息](https://github.com/Pepelux/sippts/wiki/Command-dump)

  * _**dcrack**_ 破解 SIP 协议的 digest 身份验证。[点击此处阅读有关 dcrack 命令的更多信息](https://github.com/Pepelux/sippts/wiki/Command-dcrack)

  * _**pcapdump**_ 从 PCAP 文件中提取 SIP 和 RTP 数据,并可以将音频流保存为 WAV 文件。[点击此处阅读有关 pcapdump 命令的更多信息](https://github.com/Pepelux/sippts/wiki/Command-pcapdump)

  * _**ping**_ 发送 SIP ping 以检查服务器或设备是否存活。[点击此处阅读有关 ping 命令的更多信息](https://github.com/Pepelux/sippts/wiki/Command-ping)

  * _**astami**_ 扫描和审计 Asterisk Manager Interface (AMI),并可以在凭据有效的目标上运行命令。[点击此处阅读有关 astami 命令的更多信息](https://github.com/Pepelux/sippts/wiki/Command-astami)

  * _**sniff**_ 实时捕获 SIP 流量,并显示其看到的消息、设备和 digest 身份验证信息。[点击此处阅读有关 sniff 命令的更多信息](https://github.com/Pepelux/sippts/wiki/Command-sniff)

  * _**spoof**_ 是一个 ARP 欺骗工具,用于将自己置于两个设备之间并捕获它们的流量。[点击此处阅读有关 spoof 命令的更多信息](https://github.com/Pepelux/sippts/wiki/Command-spoof)

  * _**video**_ 播放常见工作流程的动画演示:scan 到 exten 到 rcrack、dump 到 dcrack、leak 到 dcrack,以及 spoof 到 sniff。

  * _**rtpbleed**_ 用于利用 RTP Bleed 漏洞,向 RTP 端口发送数据。[点击此处阅读有关 rtpbleed 命令的更多信息](https://github.com/Pepelux/sippts/wiki/Command-rtpbleed)

  * _**rtcpbleed**_ 用于利用 RTP bleed 漏洞,向 RTCP 端口发送数据。[点击此处阅读有关 rtcpbleed 命令的更多信息](https://github.com/Pepelux/sippts/wiki/Command-rtcpbleed)

  * _**rtpbleedflood**_ 用于利用 RTP Bleed 漏洞,通过活动对话对 RTP 端口进行洪泛。[点击此处阅读有关 rtpbleedflood 命令的更多信息](https://github.com/Pepelux/sippts/wiki/Command-rtpbleedflood)

  * _**rtpbleedinject**_ 用于利用 RTP Bleed 漏洞注入 RTP 流量。[点击此处阅读有关 rtpbleedinject 命令的更多信息](https://github.com/Pepelux/sippts/wiki/Command-rtpbleedinject)

## TLS 证书 ##

sippts 支持 TLS,但到目前为止它会丢弃证书。使用
`-tlsinfo` 时,`scan` 模块会读取服务器所呈现的内容:```
sippts scan -i 192.168.0.1 -r 5061 -p tls -tlsinfo

它不需要额外的连接,因为握手本来就会发生。在通常的表格之后还有两个表:证书本身说明了什么(TLS 版本、密码套件、密钥、有效期,使用 -v 时还包括主题、颁发者、SAN 和 SHA-256),以及关于它有哪些值得报告的问题——已过期、自签名、密钥长度低于 2048 位、SHA-1 或 MD5 签名、名称不匹配、过旧的 TLS 版本或弱密码套件。

在 VoIP 中最重要的是 CERT_DEFAULT_VENDOR:PBX 或电话的出厂证书,其私钥随固件镜像一同分发。任何下载了该镜像的人都可以对 SIP-TLS 进行中间人攻击。

使用 -tlsversions 时,它还会逐一尝试 TLS 1.0、1.1、1.2 和 1.3,每个版本消耗一次握手,并且对每个主机和端口只执行一次:``` sippts scan -i 192.168.0.1 -r 5061 -p tls -tlsversions

每个版本返回 `accepted`、`refused` 或 `untested`。最后一种表示*此* OpenSSL 无法提供该版本,这与服务器已将其关闭并不相同,当结果写入报告时,这一区别至关重要。

工具会打印出两个诚实的限制,而非将其隐藏:

  * **SSLv2 和 SSLv3 无法测试。** OpenSSL 3 在构建时未包含它们,因此 sippts 无法提供。它们被报告为 `untested`,绝不会是 `disabled`。

  * 内部 SIP 中继上的自签名证书本身并不构成发现项。应结合上下文进行判断。

主表格、`-o` 的文件以及 `-ocsv` 的 CSV 不会改变。`-oj` 的 JSON 增加了 `tls` 和 `tls_findings`。

## 呼叫劫持 ##

`Replaces`(RFC 3891)通过 Call-ID 及其两个标签指向一个已接通的呼叫。`sippts dump` 和 `sippts sniff` 正是从抓包中获取这三个值的手段;接下来:```
sippts send -i 192.168.0.1 -m REFER -refer-to 200 -replaces "CALLID;to-tag=X;from-tag=Y"
sippts send -i 192.168.0.1 -m INVITE -replaces "CALLID;to-tag=X;from-tag=Y"

在 REFER 上,这是一次有人值守的转接;在 INVITE 上,它会接管通话。sippts invite 还接受 -replaces,将其添加到 -t 已经发送的 REFER 中,因此转接发生在它刚刚建立的通话内部。

服务器声称支持什么

enumerate 逐一尝试 14 种 SIP 方法,并通过应答来区分它们,但服务器也会在 AllowSupportedAllow-Events 头中声明它接受什么。这些头也会被读取并打印在第二个表格中,该表格还会指出两个值得关注的矛盾:一个在 Allow 中声明但随后应答 405 的方法,以及一个应答正常却完全没有被声明的方法。Allow-Events 是说明是否可以订阅 dialogmessage-summarypresence 的那个头,而 send -m subscribe 接下来正是针对这一点。``` sippts enumerate -i 192.168.0.1

第一个表保持它一贯的形状,`-ocsv` 的 CSV 也是如此。新数据仅添加到 `-oj` 的 JSON 中,位于 `capabilities` 下。

## 已知漏洞 ##

使用 `-cve` 时,`scan` 模块会将指纹识别结果与随包分发的已知漏洞列表(`src/sippts/data/cve.csv`)进行比对。该列表包含来自 54 个供应商的约 1400 个 CVE,基于 [NIST 的 NVD](https://nvd.nist.gov) 构建,版本范围来自每个 CVE 的 CPE:```bash
sippts scan -i 192.168.0.0/24 -fp -cve

版本确实落在受影响范围内的结果会列在最前面。 其余结果作为“可能受影响”显示在其后,因为在扫描器中,一个存在却未被报告的 CVE 比一个被过度报告的 CVE 更糟糕。某一行没有范围意味着该设备的所有版本都受影响。

有两点限制值得了解。检测依赖于 User-Agent,因此隐藏了它的服务器 无法与任何内容进行比对。另外,有些产品使用字母进行版本标识(Asterisk Business Edition 的 A、B 和 C,或者 beta_5),任何数值比较都无法对其排序:这些仅按文本匹配, 并且始终显示为可能受影响,而非已确认。

要更新列表:```bash sippts -up

它会从 github 下载该模块以及其余模块。

### 严重性 ###

每个 CVE 都带有其 CVSS 评分,并按严重性着色:紫色表示严重,红色表示
高危,黄色表示中危,青色表示低危。最严重的列在最前面。

NVD 并非对每个 CVE 都有 CVSS v3:列表中大约三分之一早于 2016 年,
只有 v2,而对于 Asterisk 来说,大多数都是如此。当只有 v2 存在时,就使用它
并**标记为 `v2`**,因为这两个评分标准并不等价,而且 v2 没有 CRITICAL 级别:
CVE-2017-16563 在 v2 中是 6.0 MEDIUM,在 v3 中是 8.0 HIGH。

早于 4.2.1 的 sippts 无法读取此列。请使用 `sippts -up` 更新。

### 重建列表(维护者) ###

`tools/cve_update.py` 会从 NVD 重建 `cve.csv`。这不是 sippts
用户会运行的东西:其思路是重新生成它,查看差异,提交它,
然后让其他人通过 `sippts -up` 获取它。这样可以将 NVD 的 API 密钥和
速率限制排除在审计过程之外。```bash
./tools/cve_update.py --dry-run          # what would change, writing nothing
./tools/cve_update.py                    # rebuild it
./tools/cve_update.py --vendor yealink   # only one vendor
NVD_API_KEY=xxxx ./tools/cve_update.py   # ten times faster

没有 API 密钥时,NVD 允许每 30 秒 5 次请求,完整运行大约需要十五分钟。API 密钥可在 nvd.nist.gov 免费获取。

脚本顶部的两个列表控制查找的内容。VENDORS 保存厂商,每个条目可以是整个厂商、产品列表,或按标签过滤。TAGS_VOIP 保存标签(voipsipip_phoneatapbxip_officemivoice……)。对于同时生产路由器和防火墙的厂商,过滤很重要:向 NVD 查询整个 Zyxel 会返回 3223 行 WiFi 和 DSL 设备,而 sippts 永远不会通过 SIP 看到这些设备。

操作系统

Sippts 已在以下系统上测试:

  • Linux
  • MacOS

要求

  • Python 3
  • requirements.txt 中列出的依赖项,由 pip 自动安装
  • 对于 sniff、dump 和 pcapdump:tshark(Wireshark 的一部分)
  • 对于使用 pcapdump 提取音频:sox 和 ffmpeg

安装

通过 git 安装: ```bash git clone https://github.com/Pepelux/sippts.git

```bash
cd sippts
pip3 install .

分类