OHWURM
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
ohwurm is a lightweight RTP (Real-time Transport Protocol) fuzzer designed to test VoIP infrastructure. It sends malformed RTP packets to discover vulnerabilities in VoIP phones, PBX systems, and media gateways.
BASIC USAGE#
ohwurm -t <target> -p <port> # Fuzz RTP on target
OPTIONS#
ohwurm -t <target> # Target IP address ohwurm -p <port> # Target RTP port ohwurm -m <mode> # Fuzzing mode ohwurm -i <interface> # Network interface ohwurm -c <count> # Number of packets to send
FUZZING MODES#
# Mode 1: Random RTP header values # Mode 2: Oversized payloads # Mode 3: Malformed SSRC values # Mode 4: Invalid payload types # Mode 5: Sequence number manipulation
EXAMPLES#
# Basic RTP fuzzing ohwurm -t 192.168.1.100 -p 8000 # Fuzz with specific mode ohwurm -t 192.168.1.100 -p 8000 -m 1 # Send limited number of packets ohwurm -t 192.168.1.100 -p 8000 -c 1000 # Fuzz on specific interface ohwurm -t 192.168.1.100 -p 8000 -i eth0
FINDING RTP PORTS#
# RTP typically uses dynamic ports (1024-65535) # Usually even-numbered ports (RTCP on next odd port) # Find RTP ports with nmap: nmap -sU -p 1024-65535 --open <target> # SIP phones commonly use: # 8000-8100 (RTP media ports) # 10000-20000 (Asterisk default range)
VOIP ATTACK WORKFLOW#
# 1. Discover VoIP devices (SIP scanning) # 2. Identify RTP ports (from SIP signaling or scanning) # 3. Run ohwurm to fuzz RTP stack # 4. Monitor target for crashes/anomalies # 5. Analyze results
NOTES#
- Targets RTP protocol specifically - Can crash VoIP phones and PBX systems - Use in controlled lab environments - Requires knowledge of target RTP ports - Pair with SIPVicious for SIP layer testing - Monitor target device during fuzzing - Useful for VoIP security assessments