VoIP Security and Hacking

  1. VoIP Reconnaissance and Enumeration
    1. Discovering VoIP Infrastructure
      1. DNS Enumeration for SRV Records
        1. Identifying SIP and H.323 Services
          1. ENUM Lookups
            1. DNS Zone Transfers
              1. Subdomain Enumeration
              2. Port Scanning for VoIP Services
                1. Identifying Open SIP, H.323, MGCP Ports
                  1. Scanning for RTP/RTCP Ports
                    1. UDP Port Scanning Techniques
                      1. TCP Port Scanning for VoIP
                      2. Network Topology Discovery
                        1. Traceroute Analysis
                          1. Network Mapping
                            1. Identifying Network Devices
                          2. Enumerating VoIP Users and Extensions
                            1. SIP Extension Scanning
                              1. Brute Force Extension Discovery
                                1. Identifying Active Extensions
                                  1. Dictionary-Based Attacks
                                  2. Directory Harvesting Attacks
                                    1. Harvesting Usernames via Responses
                                      1. Exploiting Directory Services
                                        1. LDAP Enumeration
                                        2. User Agent Identification
                                          1. Analyzing SIP User-Agent Headers
                                            1. Device Fingerprinting
                                            2. Registration Analysis
                                              1. Monitoring Registration Attempts
                                                1. Identifying Valid Accounts
                                              2. Tools for VoIP Discovery
                                                1. Nmap Scripts (NSE)
                                                  1. SIP and H.323 NSE Scripts
                                                    1. Custom Script Development
                                                    2. Specialized VoIP Scanners
                                                      1. SIPVicious
                                                        1. Smap
                                                          1. VoiPenum
                                                            1. SiVuS
                                                            2. Network Analysis Tools
                                                              1. Wireshark for VoIP Analysis
                                                                1. tcpdump for Packet Capture
                                                                2. Custom Reconnaissance Scripts
                                                                  1. Python-Based Tools
                                                                    1. Bash Scripting for Automation