SIPcrack – SIP Login Dumper & Hash/Password Cracker

The New Acunetix V12 Engine


SIPcrack is a suite for sniffing and cracking the digest authentication used in the SIP protocol.

The tools offer support for pcap files, wordlists and many more to extract all needed information and bruteforce the passwords for the sniffed accounts.

If you don’t have OpenSSL installed or encounter any building problems try ‘make no-openssl’ to build with integrated MD5 function (which is slower than the OpenSSL implementation).

Usage

Use sipdump to dump SIP digest authentications to a file. If a login is found, the sniffed login is written to the dump file. See ‘sipdump -h’ for options.

Use sipcrack to bruteforce the user password using the dump file generated by sipdump. If a password is found, the sniffed login in the dump file is updated See ‘sipcrack -h’ for options.

You can download SIPcrack here:

SIPcrack-0.3pre.tar.gz

Or read more here.

Posted in: Hacking Tools, Networking Hacking, Password Cracking

, , , ,


Latest Posts:


Malcom - Malware Communication Analyzer Malcom – Malware Communication Analyzer
Malcom is a Malware Communication Analyzer designed to analyze a system's network communication using graphical representations of network traffic.
WepAttack - WLAN 802.11 WEP Key Hacking Tool WepAttack – WLAN 802.11 WEP Key Hacking Tool
WepAttack is a WLAN open source Linux WEP key hacking tool for breaking 802.11 WEP keys using a wordlist based dictionary attack.
Eraser - Windows Secure Erase Hard Drive Wiper Eraser – Windows Secure Erase Hard Drive Wiper
Eraser is a hard drive wiper for Windows which allows you to run a secure erase and completely remove sensitive data from your hard drive by overwriting it several times with carefully selected patterns.
Insecure software versions are a problem Web Security Stats Show XSS & Outdated Software Are Major Problems
Netsparker just published some anonymized Web Security Stats about the security vulnerabilities their online solution identified on their users’ web applications and web services during the last 3 years.
CTFR - Abuse Certificate Transparency Logs For HTTPS Subdomains CTFR – Abuse Certificate Transparency Logs For HTTPS Subdomains
CTFR is a Python-based tool to Abuse Certificate Transparency Logs to get subdomains from a HTTPS website in a few seconds.
testssl.sh - Test SSL Security Including Ciphers, Protocols & Detect Flaws testssl.sh – Test SSL Security Including Ciphers, Protocols & Detect Flaws
testssl.sh is a free command line tool to test SSL security, it checks a server's service on any port for the support of TLS/SSL ciphers, protocols as well as recent cryptographic flaws and more.


11 Responses to SIPcrack – SIP Login Dumper & Hash/Password Cracker

  1. JD August 1, 2008 at 4:51 pm #

    Just thought I’d add– if you don’t feel like compiling it, it’s available in the Debian (lenny) and Ubuntu (intrepid) repositories. I don’t know if I expected seeing a package like sipcrack in the Ubuntu repositories, but their site had said that there was a “massive merge from Debian” for the intrepid release. Intrepid is avalible in it’s alpha stage now…

  2. Morgan Storey August 2, 2008 at 12:33 pm #

    Another one to add to OpenWrt, then plug it in and let it hack a voip network.

  3. gul August 4, 2008 at 7:32 am #

    I really have to repair my box. The more I get here, the more I saw funny stuff to had for network sniffing :)

  4. splink August 4, 2008 at 8:53 pm #

    Awesome tool! I hope darknet posts more interesting pen-test tools in the future.

  5. Brill August 5, 2008 at 4:19 pm #

    Don’t miss having a look at USAGE_EXAMPLES file, You can use SIPcrack with the “olds” Tcpdump and John the ripper!!

  6. Sieyapdji August 8, 2008 at 8:28 am #

    Hi,

    i want to ask if SipCrack is more powerful than CAin & Abel On SiP Password cracking. I regularly use Cain to crack my Sip password

    Thank…

  7. lyz August 12, 2008 at 4:05 pm #

    Can’t wait to play with this one. :P

    Btw, if you want to check out the latest security tools, there’s this section called Tools Watch. security-database.com. This is really useful if you want to do pentests. I got this from the seminar I have attended last week. (Hackacon)

  8. Brill August 12, 2008 at 10:30 pm #

    @Sieyapdji,
    I’ve just made some quick and very basic tests but it seems that SipCrack its only based on brute force attacks so I would say that Cain & Abel seems to be more powerful on that.
    But you should keep in mind what I mentioned before… you can have some “advance usage” in which you can combine the other tools like John the ripper, or store some dump files for testing purposes, etc.

    SIPCrack is a suite of different tools we can not ask the perfection for all of them.

  9. Brill August 14, 2008 at 9:16 am #

    @lyz
    I’ve just looked into http://www.security-database.com/toolswatch/ .. and it seems very interesting.. Thanks for the tip!!

  10. lyz August 14, 2008 at 11:18 am #

    @brill

    No problem pal. Thanks too for sharing us tons of links.

  11. Navin August 14, 2008 at 4:31 pm #

    I’d definitely say Cain and Abel is the best SiP cracking tool….Its a classic, with its own fan following!!