Wednesday
Apr152009
VOIPPACK for April adds Asterisk scanning, leaking phones and Troopers09
Wednesday, April 15, 2009 at 3:18PM
Announcing the VOIPPACK April edition supporting IAX2 and can now scan Asterisk servers. Because the feedback for sipautohack was great, we included a similar tool for the Asterisk protocol called iax2autohack in the April edition of VOIPPACK. The following are the new tools avialable in this update:
The following demo shows iax2autohack in action:
[vimeo http://vimeo.com/4162693]
For more information about VOIPPACK and our other offerings check out the products page.
Additionally we confirmed a few phones that are vulnerable to the SIP Digest Leak vulnerability (tools included in VOIPPACK) for the Cisco 7940, Grandstream, Fritzbox and more, thanks to Sjur and another unnamed entity ;-) Will be working on further research and releasing a paper after Troopers09 where Wendel G Henrique and I will be presenting our Web Application Firewall research and releasing new tools.
Watch twitter if you're interested in what's happening ;-)
- iax2enumerate which like sipenumerate, tries to guess extensions present on the Asterisk box, and will inform you if the extension has any password set or not
- iax2cracker which given a known extension on the Asterisk box, will attempt to recover the password through an online bruteforce attack
- iax2autohack which finds out any Asterisk servers on the network, enumerates the extensions and launches a password cracking attack on each extension
The following demo shows iax2autohack in action:
[vimeo http://vimeo.com/4162693]
For more information about VOIPPACK and our other offerings check out the products page.
Additionally we confirmed a few phones that are vulnerable to the SIP Digest Leak vulnerability (tools included in VOIPPACK) for the Cisco 7940, Grandstream, Fritzbox and more, thanks to Sjur and another unnamed entity ;-) Will be working on further research and releasing a paper after Troopers09 where Wendel G Henrique and I will be presenting our Web Application Firewall research and releasing new tools.
Watch twitter if you're interested in what's happening ;-)
tagged
asterisk security,
canvas,
iax2 security,
iax2autohack,
sipautohack,
voip security,
voippack in
Site news
asterisk security,
canvas,
iax2 security,
iax2autohack,
sipautohack,
voip security,
voippack in
Site news