OAT is an Open Source Microsoft OCS Assessment Tool designed to check the password strength of Lync and Microsoft Office Communication Server users. After a password is compromised, OAT demonstrates potential UC attacks that can be performed by legitimate users if proper security controls are not in place. We first wrote about OAT when it […]
voip
VoIP Hopper 2.01 Released – IP Phone VLAN Hopping Tool
VoIP Hopper is a GPLv3 licensed security tool, written in C, that rapidly runs a VLAN Hop into the Voice VLAN on specific ethernet switches. VoIP Hopper does this by mimicking the behavior of an IP Phone, in Cisco, Avaya, and Nortel environments. This requires two important steps in order for the tool to traverse […]
SIPVicious SIP Scanner – VoIP Hacking Security Auditing Tool
SIPVicious SIP Scanner is a suite of tools that can be used to audit SIP based VoIP systems. Why the name? Because the tools are not exactly the nicest thing on earth next to a SIP device. Features for SIP Hacking with SIPVicious It currently consists of five tools: svmap – This is a sip […]
OAT (OCS Assessment Tool) – Office Communication Server Security Assessment Tool
OAT is an Open Source Security tool designed to check the password strength of Microsoft Office Communication Server users. After a password is compromised, OAT demonstrates potential UC attacks that can be performed by legitimate users if proper security controls are not in place. Features Online Dictionary Attack Presence Stealing Contact List Stealing Single User […]
Scammers Using Asterisk VoIP Systems to Make Calls
[ad] It seems like ‘vishing‘ (basically Phishing – but utilising VoIP call services) as it’s known is getting bigger, especially since the scammers have been using a flaw in Asterisk systems that allows them to hijack the VoIP exchange. Older versions of Asterisk do have quite a number of serious flaws and it looks like […]
ohrwurm – RTP Fuzzing Tool (SIP Phones)
ohrwurm is a small and simple RTP fuzzer, it has been tested it on a small number of SIP phones, none of them withstood the fuzzing. Features: reads SIP messages to get information of the RTP port numbers reading SIP can be omitted by providing the RTP port numbers, so that any RTP traffic can […]
‘Untraceable’ Phone Frauders Vishing for Credit Cards
[ad] Vishing, now there’s a new term for you. Basically its Phishing – but utilising VoIP call services, which makes it very easy to spoof the Caller ID. Even though Caller ID Spoofing was Made Illegal in the USA – people will still continue to do it, remember the FCC said it’s still easy to […]
Sipflanker – Locate SIP (VoIP) Device Web Interfaces
[ad] SIP devices are getting to be very common now, especially with open source bundled OS offerings like Trixbox making it easy to setup your own digital or IP-PBX. Along with the frequent installations, many (if not most) VoIP devices have available a Web GUI for their configuration, management, and report generation. These Web GUIs […]
VoIP Hopper – VLAN Hopping Tool
[ad] VoIP Hopper is a GPLv3 licensed security tool, written in C, that rapidly runs a VLAN Hop into the Voice VLAN on specific Ethernet switches. VoIP Hopper does this by mimicking the behavior of an IP Phone, in both Cisco and Avaya IP Phone environments. In Cisco IP Phone networks, it first dissects either […]
VoIP Security Testing Tools List from VoIPSA
[ad] The VoIP Security Alliance (VOIPSA) is pleased to announce the public release of its VoIP security tool list. Check it out at: http://www.voipsa.org/Resources/tools.php This VoIP Security Tool List provides categories, descriptions and links to current free and commercial VoIP security tools. This list was developed to address the current void of VoIP security testing […]

