← All cheat sheets

SIPARMYKNIFE

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

SIPArmyKnife is a SIP (Session Initiation Protocol) fuzzer that
tests VoIP infrastructure by sending malformed SIP messages. It
discovers vulnerabilities in SIP proxies, phones, and PBX systems.

BASIC USAGE#

siparmyknife <target>            # Fuzz SIP target
siparmyknife -p <port> <target>  # Custom port

OPTIONS#

siparmyknife <target>            # Target IP address
siparmyknife -p <port>           # SIP port (default: 5060)
siparmyknife -P <protocol>       # Protocol (UDP/TCP)
siparmyknife -m <method>         # SIP method to fuzz
siparmyknife -l <file>           # Log results to file

SIP METHODS FUZZED#

# INVITE    - Call initiation
# REGISTER  - Registration
# OPTIONS   - Capabilities query
# ACK       - Acknowledgment
# BYE       - Call termination
# CANCEL    - Cancel pending request
# INFO      - Mid-session information
# NOTIFY    - Event notification
# SUBSCRIBE - Event subscription
# MESSAGE   - Instant messaging
# REFER     - Call transfer
# UPDATE    - Session update

FUZZ TARGETS#

# SIP headers fuzzed:
# - From / To / Contact headers
# - Via header
# - Call-ID
# - CSeq
# - Content-Length
# - Max-Forwards
# - Authorization
# - Route / Record-Route
# - Content-Type

# Fuzzing techniques:
# - Buffer overflow strings
# - Format string payloads
# - Integer overflow values
# - Null bytes
# - Invalid characters
# - Missing required headers
# - Duplicate headers
# - Extremely long header values

EXAMPLES#

# Basic SIP fuzzing (UDP)
siparmyknife 192.168.1.1

# Fuzz on custom port
siparmyknife -p 5061 192.168.1.1

# Fuzz INVITE method specifically
siparmyknife -m INVITE 192.168.1.1

# Log results
siparmyknife -l results.log 192.168.1.1

# Fuzz over TCP
siparmyknife -P TCP 192.168.1.1

VOIP TESTING WORKFLOW#

# 1. Discover SIP devices (nmap, svmap)
# 2. Enumerate SIP extensions (svwar)
# 3. Fuzz SIP stack (siparmyknife)
# 4. Monitor targets for crashes
# 5. Test authentication (svcrack)
# 6. Attempt call manipulation
# SIPVicious suite:
# svmap    - SIP device scanner
# svwar    - SIP extension enumerator
# svcrack  - SIP password cracker

# Other:
# ohwurm   - RTP fuzzer
# voiphopper - VLAN hopping for VoIP
# rtpflood   - RTP flood testing

NOTES#

- Targets SIP protocol on UDP port 5060 by default
- Can crash VoIP devices and services
- Use in controlled lab environments only
- Monitor target devices during fuzzing
- SIP is text-based, making it suitable for fuzzing
- Test both UDP and TCP SIP transport
- VoIP infrastructure is often poorly tested
- Only for authorized VoIP security assessments