SIP / VoIP

Session Initiation Protocol / Voice over IP

Cisco IP Phones

Scrap Cisco IP Phone web interfaces by IPs to get the corresponding host names:

$ for i in `cat phones_ip.txt`; do curl -s http://$i | grep -oP 'SEP[A-Z0-9]+' | uniq | tee -a phones.txt; done

Enumerate usernames on a Cisco CUCM server:

$ bash cucme.sh CUCM01.megacorp.local
Or
$ python3 thief.py -H CUCM01.megacorp.local --userenum
Or
$ curl -sk 'https://cucm01.megacorp.local:8443/cucm-uds/users?lastName=' | grep -oP '<firstName>.*?</firstName><lastName>.*?</lastName>' | sort -u | tee cucm_users.txt

Enumerate credential leaks on Cisco IP Phones:

VLAN Hopping on Cisco Voice

Capture the first CDP advertisement while plugged through the phone:

Relay it once a minute to simulate a legit phone device:

Configure a sub-interface to access the voice VLAN:

Last updated