SIP / VoIP
Session Initiation Protocol / Voice over IP
Cisco IP Phones
Scrap Cisco IP Phone web interfaces by IPs to get the corresponding host names:
$ for i in `cat phones_ip.txt`; do curl -s http://$i | grep -oP 'SEP[A-Z0-9]+' | uniq | tee -a phones.txt; doneEnumerate usernames on a Cisco CUCM server:
$ bash cucme.sh CUCM01.megacorp.local
Or
$ python3 thief.py -H CUCM01.megacorp.local --userenum
Or
$ curl -sk 'https://cucm01.megacorp.local:8443/cucm-uds/users?lastName=' | grep -oP '<firstName>.*?</firstName><lastName>.*?</lastName>' | sort -u | tee cucm_users.txtEnumerate credential leaks on Cisco IP Phones:
VLAN Hopping on Cisco Voice
Capture the first CDP advertisement while plugged through the phone:
Relay it once a minute to simulate a legit phone device:
Configure a sub-interface to access the voice VLAN:
Last updated