A pentester must be able to identify whether it is possible to listen to the voice network using the following technique.
ARP Poisoning
The first step before implementing a Man??-in-the-Middle attack is to allow the routing of packets
Quote:echo 1> / proc/sys/net/ipv4/ip_forward
Now you can run a Man??-in-the-middle attack, in order to be able to intercept VoIP traffic This can be achieved very simply with the command below.:
![[Image: 6QxJUlp.png]](http://i.imgur.com/6QxJUlp.png)
Capture and decoding VoIP traffic
Now that traffic is being routed to your computer, you can use Wireshark to capture all SIP traffic. We are particularly interested in RTP packets as they contain the actual conversation in a VoIP call.
![[Image: MJ4n3bY.png]](http://i.imgur.com/MJ4n3bY.png)
Wireshark contains an embedded utility called VoIP, which can decode RTP data into a format playable audio.
![[Image: RbExP9b.png]](http://i.imgur.com/RbExP9b.png)
Conclusion
As we have seen, is very easy and quick to listen to a phone conversation just by performing a MITM attack and have a tool like Wireshark to capture traffic. On ratings VoIP, the pentesters should attempt to implement this attack in order to identify whether listening is possible. To avoid this type of attack must use SRTP, which is a secure protocol and provides encryption of data being transferred



 
 
 
0 comentarii:
Trimiteți un comentariu