← All cheat sheets

OHWURM

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

ohwurm is a lightweight RTP (Real-time Transport Protocol) fuzzer
designed to test VoIP infrastructure. It sends malformed RTP packets
to discover vulnerabilities in VoIP phones, PBX systems, and media
gateways.

BASIC USAGE#

ohwurm -t <target> -p <port>     # Fuzz RTP on target

OPTIONS#

ohwurm -t <target>               # Target IP address
ohwurm -p <port>                 # Target RTP port
ohwurm -m <mode>                 # Fuzzing mode
ohwurm -i <interface>            # Network interface
ohwurm -c <count>                # Number of packets to send

FUZZING MODES#

# Mode 1: Random RTP header values
# Mode 2: Oversized payloads
# Mode 3: Malformed SSRC values
# Mode 4: Invalid payload types
# Mode 5: Sequence number manipulation

EXAMPLES#

# Basic RTP fuzzing
ohwurm -t 192.168.1.100 -p 8000

# Fuzz with specific mode
ohwurm -t 192.168.1.100 -p 8000 -m 1

# Send limited number of packets
ohwurm -t 192.168.1.100 -p 8000 -c 1000

# Fuzz on specific interface
ohwurm -t 192.168.1.100 -p 8000 -i eth0

FINDING RTP PORTS#

# RTP typically uses dynamic ports (1024-65535)
# Usually even-numbered ports (RTCP on next odd port)

# Find RTP ports with nmap:
nmap -sU -p 1024-65535 --open <target>

# SIP phones commonly use:
# 8000-8100 (RTP media ports)
# 10000-20000 (Asterisk default range)

VOIP ATTACK WORKFLOW#

# 1. Discover VoIP devices (SIP scanning)
# 2. Identify RTP ports (from SIP signaling or scanning)
# 3. Run ohwurm to fuzz RTP stack
# 4. Monitor target for crashes/anomalies
# 5. Analyze results

NOTES#

- Targets RTP protocol specifically
- Can crash VoIP phones and PBX systems
- Use in controlled lab environments
- Requires knowledge of target RTP ports
- Pair with SIPVicious for SIP layer testing
- Monitor target device during fuzzing
- Useful for VoIP security assessments