Spoofing a VOIP call

Having gained enough knowledge about the various users using SIP services, let's try making a fake call to the user using Metasploit. While a user is running SipXphone 2.0.6.27 on a Windows XP platform, let's send the user a phony invite request, utilizing the auxiliary/voip/sip_invite_spoof module as follows:

We will set the RHOSTS option with the IP address of the target and the EXTENSION as 4444 for the target. Let's keep SRCADDR set to 192.168.1.1, which will spoof the address source making the call.

Therefore, let's run the module as follows:

Let's see what is happening on the victim's side as follows:

We can see ...

Get Mastering Metasploit - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.