Voice Over IP (VoIP)

VoIP systems, particularly Cisco Unified Communications Manager (CUCM), are commonly found in enterprise environments and can provide initial access vectors, username enumeration, and potential credential harvesting opportunities.

Resources

Discovery

SIP Service Discovery

Identify SIP services on the network:

# Nmap SIP enumeration
nmap -sU -p 5060 10.10.10.0/24 --script=sip-methods

# SIP banner grab
nmap -sV -p 5060,5061 10.10.10.123

VoIP Protocol Identification

SIPVicious Tools

SIPVicious is a suite of tools for auditing SIP-based VoIP systems.

Installation

Extension Enumeration

Enumerate valid SIP extensions:

SIP Authentication Cracking

Crack SIP authentication credentials:

Cisco IP Phone Exploitation

iCULeak.py - Credential Theft

GitHub: https://github.com/llt4l/iCULeak.pyarrow-up-right

Exploit misconfigured Cisco IP phones to obtain domain credentials. Physical access to a Cisco IP phone can provide initial AD access during a pentest.

Source Tweet: https://twitter.com/snovvcrash/status/1555542379272323072?s=20&t=d1esgQD98FboqHYBB2bS9warrow-up-right

CUCM Username Enumeration

Unauthenticated username dumping via CUCM:

Configuration File Extraction

Cisco IP phones often expose configuration files:

Call Interception

RTP Stream Capture

Capture and decode VoIP audio streams:

VoIP Wiretapping

Common Attack Vectors

Default Credentials

Common default credentials for VoIP systems:

  • Cisco CUCM: admin:admin, administrator:admin

  • Avaya: admin:admin, Administrator:AvayaPassword

  • Asterisk: admin:admin, root:password

  • 3CX: admin:admin

SIP Registration Hijacking

Register as a legitimate extension to make/receive calls:

Last updated