Skip to main content

Welcome to SIPVicious OSS security tools

SIPVicious mascot

SIPVicious OSS is a set of security tools that can be used to audit SIP based VoIP systems. Specifically, it allows you to find SIP servers, enumerate SIP extensions and finally, crack their password.

To get started read the following:

The GitHub wiki remains the primary home for SIPVicious OSS documentation.

For usage help make use of -h or --help switch.

A note to vendors and service providers

If you are looking for professional VoIP and WebRTC penetration testing services, please check out our offerings at Enable Security.

The tools

The SIPVicious OSS toolset consists of the following tools:

  • svmap
  • svwar
  • svcrack
  • svreport
  • svcrash

svmap

this is a sip scanner. When launched against
ranges of ip address space, it will identify any SIP servers 
which it finds on the way. Also has the option to scan hosts 
on ranges of ports.

Usage: <https://github.com/EnableSecurity/sipvicious/wiki/SVMap-Usage>

svwar

identifies working extension lines on a PBX. A working 
extension is one that can be registered. 
Also tells you if the extension line requires authentication or not. 

Usage: <https://github.com/EnableSecurity/sipvicious/wiki/SVWar-Usage>

svcrack

a password cracker making use of digest authentication. 
It is able to crack passwords on both registrar servers and proxy 
servers. Current cracking modes are either numeric ranges or
words from dictionary files.

Usage: <https://github.com/EnableSecurity/sipvicious/wiki/SVCrack-Usage>

IPv6 target syntax

  • svwar and svcrack accept -6 with either a bare IPv6 literal such as 2001:db8::10 or a URI such as udp://[2001:db8::10]:5060.
  • svmap accepts -6 with bare or bracketed IPv6 literals such as 2001:db8::10 or [2001:db8::10].
  • svmap does not accept URI syntax for IPv6 targets. Use -p to choose the destination port, for example sipvicious_svmap -6 -p 5060 [2001:db8::10].

svreport

able to manage sessions created by the rest of the tools
and export to pdf, xml, csv and plain text.

Usage: <https://github.com/EnableSecurity/sipvicious/wiki/SVReport-Usage>

svcrash

responds to svwar and svcrack SIP messages with a message that
causes old versions to crash. 

Usage: <https://github.com/EnableSecurity/sipvicious/wiki/SVCrash-FAQ>

Installation

SIPVicious OSS requires Python 3.6 or newer.

Install it from the repository root with:

python3 -m pip install .

This installs the following console scripts:

  • sipvicious_svmap
  • sipvicious_svwar
  • sipvicious_svcrack
  • sipvicious_svreport
  • sipvicious_svcrash

For more installation details, see the installation documentation.

Further information

Check out the wiki for the full documentation set.

Release files for sipvicious 0.3.8

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for sipvicious 0.3.8
File Size Uploaded
sipvicious-0.3.8.tar.gz 55.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for sipvicious 0.3.8
File Interpreter ABI Platform
sipvicious-0.3.8-py3-none-any.whl Python 3 none any Details

Total release size: 113.2 kB

Release files / sipvicious-0.3.8.tar.gz

Download URL sipvicious-0.3.8.tar.gz
Size 55.4 kB
Tags Source
SHA-256 checksum
How to use checksums
e34a8f7083df38ed85cec9ffa10aa4ea18e8a1aac776f843bcac710816f8450b
BLAKE2b-256 checksum
How to use checksums
581084cff907dbedb37f4b923828c5f1bf3da706a2f5677b2f9f60a0d0012388
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.6

Release files / sipvicious-0.3.8-py3-none-any.whl

Download URL sipvicious-0.3.8-py3-none-any.whl
Size 57.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
9955f45bfefae6083a93347e8f55e21ce55c874699562204b837920edcaba8a1
BLAKE2b-256 checksum
How to use checksums
68d45aa57c8b4175f8ae0087bf0e5549131d1300b4e661599c0fdb219fc6a353
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.6

Release history Release notifications | RSS feed

This release

0.3.8 This release

2 release files

0.3.7

2 release files

0.3.6

2 release files

0.3.5

2 release files

0.3.4

2 release files

0.3.3

2 release files

0.3.2

2 release files

0.3.0

3 release files

0.2.8

2 release files

0.2.3

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page