SIPARMYKNIFE
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
SIPArmyKnife is a SIP (Session Initiation Protocol) fuzzer that tests VoIP infrastructure by sending malformed SIP messages. It discovers vulnerabilities in SIP proxies, phones, and PBX systems.
BASIC USAGE#
siparmyknife <target> # Fuzz SIP target siparmyknife -p <port> <target> # Custom port
OPTIONS#
siparmyknife <target> # Target IP address siparmyknife -p <port> # SIP port (default: 5060) siparmyknife -P <protocol> # Protocol (UDP/TCP) siparmyknife -m <method> # SIP method to fuzz siparmyknife -l <file> # Log results to file
SIP METHODS FUZZED#
# INVITE - Call initiation # REGISTER - Registration # OPTIONS - Capabilities query # ACK - Acknowledgment # BYE - Call termination # CANCEL - Cancel pending request # INFO - Mid-session information # NOTIFY - Event notification # SUBSCRIBE - Event subscription # MESSAGE - Instant messaging # REFER - Call transfer # UPDATE - Session update
FUZZ TARGETS#
# SIP headers fuzzed: # - From / To / Contact headers # - Via header # - Call-ID # - CSeq # - Content-Length # - Max-Forwards # - Authorization # - Route / Record-Route # - Content-Type # Fuzzing techniques: # - Buffer overflow strings # - Format string payloads # - Integer overflow values # - Null bytes # - Invalid characters # - Missing required headers # - Duplicate headers # - Extremely long header values
EXAMPLES#
# Basic SIP fuzzing (UDP) siparmyknife 192.168.1.1 # Fuzz on custom port siparmyknife -p 5061 192.168.1.1 # Fuzz INVITE method specifically siparmyknife -m INVITE 192.168.1.1 # Log results siparmyknife -l results.log 192.168.1.1 # Fuzz over TCP siparmyknife -P TCP 192.168.1.1
VOIP TESTING WORKFLOW#
# 1. Discover SIP devices (nmap, svmap) # 2. Enumerate SIP extensions (svwar) # 3. Fuzz SIP stack (siparmyknife) # 4. Monitor targets for crashes # 5. Test authentication (svcrack) # 6. Attempt call manipulation
RELATED TOOLS#
# SIPVicious suite: # svmap - SIP device scanner # svwar - SIP extension enumerator # svcrack - SIP password cracker # Other: # ohwurm - RTP fuzzer # voiphopper - VLAN hopping for VoIP # rtpflood - RTP flood testing
NOTES#
- Targets SIP protocol on UDP port 5060 by default - Can crash VoIP devices and services - Use in controlled lab environments only - Monitor target devices during fuzzing - SIP is text-based, making it suitable for fuzzing - Test both UDP and TCP SIP transport - VoIP infrastructure is often poorly tested - Only for authorized VoIP security assessments