16 dépôts
Open-source software for auditing, penetration testing, and vulnerability assessment of RTC protocols.
Explore 16 awesome GitHub repositories matching part of an awesome list · Security Testing Tools. Refine with filters or upvote what's useful.
The framework is a comprehensive penetration testing platform designed for the development, testing, and execution of security exploits. It serves as a research toolkit and automated assessment environment, enabling security professionals to identify and validate vulnerabilities within networked systems and infrastructure through repeatable, standardized procedures. The platform distinguishes itself through a modular architecture that supports reflective payload injection, allowing for the execution of code directly in memory without writing to disk. It utilizes an asynchronous event loop to
Industry standard penetration testing framework for exploit development and execution.
SIPVicious OSS is a set of security tools that can be used to audit SIP based VoIP systems. Specifically, it allows you to find SIP servers, enumerate SIP extensions and finally, crack their password.
A set of tools to audit SIP based systems
Stunner is a tool to test and exploit STUN, TURN and TURN over TCP servers. TURN is a protocol mostly used in videoconferencing and audio chats (WebRTC).
a tool to test and exploit STUN, TURN and TURN over TCP servers.
Set of tools to audit SIP based VoIP Systems
Another set of tools to audit VoIP servers and devices using SIP protocol.
Mr.SIP is a simple console based SIP-based Audit and Attack Tool. Originally it was developed to be used in academic work to help developing novel SIP-based DDoS attacks and then as an idea to convert it to a fully functional SIP-based penetration testing tool. So far Mr SIP resulted several…
SIP based audit and attack tool.
Viproy was a PoC VoIP security assessment tool which had several modules and exploits to maintain. However, it was developed as a modules set to Metasploit Framework. As Metasploit Framework had significant updates, Viproy's current modules won't be able to work unless you use legacy Kali Linux…
VoIP pentest framework which can be used with the metasploit-framework.
SigPloit: Telecom Signaling Exploitation Framework - SS7, GTP, Diameter & SIP
Tool which covers all used SS7, GTP (3G), Diameter (4G) or even SIP protocols for IMS and VoLTE infrastructures.
Pentesting framework using Node.js powers. Focused in VoIP.
Pentesting framework using Node.js powers, focused in VoIP. (public archive)
Multi-threaded tool to automatically download and parse configuration files from Cisco phone systems searching for SSH credentials. Features intelligent caching, automatic backoff protection, and MAC address brute forcing capabilities.
download and parse configuration files from Cisco phone systems searching for SSH credentials
A proof of concept for tunnelling HTTP over a permissive/open TURN server. This will connect to the server, setting up any TCP channels required. A local HTTP proxy is created on 8080, which can be used to "tunnel" the traffic to a target host, for example 169.254.169.254, which the TURN server…
PoC for tunnelling HTTP over a permissive/open TURN server.
REQUIREMENTS
SIP swiss army knife, has some features that can be used for security testing (e.g. flood more or random mode)
VoIPShark is a open source VoIP Analysis Platform which will allow people to analyze live or stored VoIP traffic, easily decrypt encrypted SRTP stream, perform macro analysis, generate summary specific to VoIP traffic/nodes and export calls/SMS/DTMF in popular user friendly file formats.
Open Source VoIP Analysis Platform
VoIP Hopper - Jumping from one VLAN to the next!
a tool to exploit insecure VLANs that are often found in IP Telephony infrastructure.
A minimalistic command line tool to check if your RTP proxy / NAT helper is vulnerable to RTP NAT stealing attacks.
Tool which tests for rtpbleed vulnerability.