Skip to content

Repository files navigation

Mr.SIP

SIP Security, Attack and Audit Framework

License CI

Black Hat Arsenal Black Hat Arsenal Black Hat Arsenal Black Hat Arsenal Offzone Moscow DEF CON 28 Black Hat Arsenal Securi-Tay 2023 Black Hat MEA 2022 Black Hat Arsenal


Mr.SIP is a simple, console-based SIP audit and attack tool. It was originally developed for academic work on novel SIP-based DDoS attacks, and evolved into a fully functional SIP-based penetration testing tool. It has since been cited in several academic papers and journal articles, and can also be used as a SIP client simulator and traffic generator.

This public repository ships 3 modules — network scanning, user enumeration, and DoS attack simulation. Mr.SIP Pro extends this with more modules and a web GUI.

Documentation

  • Installation — Linux/macOS setup differences, virtual environment setup, when root is actually required
  • Lab Guide — Building a local test target: Docker (PJSIP) and VM (classic chan_sip/Trixbox) labs, generalizing to other Asterisk-based PBXs
  • Usage Guide — Full command reference, what each --mt message type actually does, --if/--pps/--mtu in depth, ngrep, debug mode, architecture/data-flow diagram
  • Mr.SIP Pro comparison — Full public-vs-Pro breakdown, module-by-module
  • CHANGELOG.md — Full version history and technical rationale for each change

Public Version Modules

Module Purpose
SIP-NES (Network Scanner) Detects SIP components on a network, along with manufacturer/product/version information.
SIP-ENUM (Enumerator) Identifies valid SIP users and their authentication requirements.
SIP-DAS (DoS Attack Simulator) Performs TDoS-based attacks, with a powerful IP-spoofing engine.

Competitive features across all three: high-performance multithreading, IP spoofing, and smart SIP message generation.

This is the public, 3-module version — see what Mr.SIP Pro adds below.

Mr.SIP Pro

Mr.SIP Pro is the most comprehensive attack-oriented VoIP product available — 10 modules across 3 categories (Information Gathering, Vulnerability Scanning, Offensive), plus IP spoofing/message-generation helper components and a GUI, versus this repo's 3 console-only modules.

→ Full Public vs. Pro comparison · mrsip.pro · Pricing · Request a demo

Quick Start

pip install -r requirements.txt

python3 mr.sip.py --help
python3 mr.sip.py --nes  --tn=<target_IP> --mt=options --from=<ext> --to=<ext>
python3 mr.sip.py --enum --from=<wordlist_file> [--tn=<target_IP>]
python3 mr.sip.py --das  --mt=invite -c <count> --tn=<target_IP> [-r|-s|-m --il=<file>]

See the Installation Guide for OS-specific setup and the Usage Guide for the full command/flag reference.

SIP-NES scan output

Development

This repo has a real test suite and CI - see CHANGELOG.md for the full technical history of fixes and hardening work.

pip install -r tests/requirements-dev.txt
pytest              # 262 tests, network-free, runs in a couple seconds
ruff check src/ tests/ mr.sip.py

Recognition

Mr.SIP started as academic research into novel SIP-based DDoS attacks and grew into a tool presented at some of the industry's largest security conferences, cited across peer-reviewed literature, and recognized in national innovation competitions.

Global Stage Recognition

See presentation links and video demos on the Demo Page.

Academic & Technical Impact

Research originating from and building on Mr.SIP has contributed to peer-reviewed academic work on SIP/VoIP security, including DDoS and DRDoS attack techniques, defensive mechanisms, and blockchain-based caller-ID authentication. This work has been published in well-established international journals, including IEEE Access, Applied Sciences, and Computers & Security.

Across these publications, Mr.SIP and the research built around it have contributed to the exploration of several SIP/VoIP attack and defense concepts, including:

  • SIP-based DRDoS attacks and mitigation strategies
  • Blockchain-based caller-ID authentication (BBCA)
  • SIP request and response reflection attacks
  • SIP registration erasure attacks targeting call-center environments
  • INVITE and REGISTER abuse techniques

Mr.SIP has also been reported as a reference in professional and graduate-level academic work, including Cisco Press material and graduate theses, representing additional practitioner and academic impact beyond the peer-reviewed publications listed above.

Beyond academic research, Mr.SIP has also been used in practical VoIP security research and testing. In 2015, it was used in Caller-ID spoofing tests conducted as part of a Turkish Standards Institute (TSE) collaboration related to national VoIP security strategy.

The project has also received international security-community recognition. Mr.SIP was featured by Black Hat and showcased at major cybersecurity conferences, including Black Hat Arsenal and DEF CON.

Awards & Recognition

Mr.SIP Pro has earned recognition through innovation-driven challenges and national competitions — including awards for ideas, early prototypes, or research projects that contributed directly to its foundation and evolution.

  • 🥇 1st Place – 2nd Cybersecurity Graduation Projects Competition (55 applications, 17 finalists, 2020)
  • 🥇 1st Place – Cybersecurity Projects Competition (130+ projects, 2020)
  • 🥈 2nd Place – Netaş Innovation Challenge (2012)
  • 🥇 1st Place – Netaş Innovation Challenge (2011)

Published References (full citations)

  • I. M. Tas and S. Baktir, "Blockchain-Based Caller-ID Authentication (BBCA): A Novel Solution to Prevent Spoofing Attacks in VoIP/SIP Networks," IEEE Access, vol. 12, pp. 60123–60137, 2024. Read more
  • I. M. Tas and S. Baktir, "A Novel Approach for Efficient Mitigation against the SIP-Based DRDoS Attack," Applied Sciences, vol. 13, no. 3, Art. no. 1864, Jan. 2023. Read more
  • I. M. Tas, B. G. Unsalver, and S. Baktir, "A Novel SIP Based Distributed Reflection Denial-of-Service Attack and an Effective Defense Mechanism," IEEE Access, vol. 8, pp. 112574–112584, 2020. Read more
  • I. M. Tas, B. Ugurdogan, and S. Baktir, "Novel Session Initiation Protocol-Based Distributed Denial-of-Service Attacks and Effective Defense Strategies," Computers & Security, vol. 63, pp. 29–44, Nov. 2016. Read more

License

GPL-3.0

Releases

Packages

Used by

Contributors

Languages