Download Latest Version v4.2.1 source code.zip (1.0 MB) Google Add to Preferred Sources
Home / v4.2.1
Name Modified Size InfoDownloads / Week
Parent folder
README.md 2026-09-14 10.5 kB
v4.2.1 source code.tar.gz 2026-09-14 1.0 MB
v4.2.1 source code.zip 2026-09-14 1.0 MB
Totals: 3 Items   2.1 MB 5

v4.2.1 (Sep/2026):

  • global:
  • fix -up, which did not download the files added in 4.2.0, breaking scan
  • update the CVE list only when every module was updated
  • download_file() reports whether the file really landed
  • warn instead of crashing when the CVE list has more columns than known
  • fix the banner saying '(updated)' when newer than published, or unreachable
  • ask github again without the CDN cache when the local version looks newer
  • scan:
  • added the CVSS of each CVE, coloured by severity
  • mark a score taken from CVSS v2, its scale is not the one of v3
  • order the CVEs by score, worst first
  • import lib/tlsinfo.py only when -tlsinfo is used
  • the fallback CVE match no longer searches the description and the URL
  • fix print_cve() unpacking into a fixed number of columns
  • data/cve.csv:
  • new 6th column with the CVSS (list version 0.5), needs 4.2.1 or newer

v4.2.0 (Sep/2026):

  • added TLS certificate inspection (lib/tlsx509.py, lib/tlsinfo.py)
  • added RFC 8760 digest support: SHA-256 and SHA-512-256 fell back to MD5 silently
  • added JSON and CSV output, and real chaining between modules
  • scan:
  • added param -tlsinfo to read the certificate and report expired, self-signed, weak key, weak signature, name mismatch, old TLS version and vendor defaults
  • added param -tlsversions to test TLS 1.0/1.1/1.2/1.3 one by one
  • added params -oj and -ocsv (also exten, rcrack, enumerate, leak, dcrack, astami)
  • added param -ot to save found hosts as ip:port/proto, ready for -f
  • added param -header (also exten, enumerate, invite and flood)
  • compare the CVE version ranges for real, instead of a text search
  • a CVE with no version range now means every version
  • match the whole product name, not only the vendor
  • look for the version anywhere in the User-Agent
  • accept CPE punctuation in the version ranges
  • fix the SNI, always the address, hiding the certificate of a virtual host
  • fix CVE results coming back downcased
  • fix the CVE table calling 'Type' what is the description
  • fix -r ALL (was 1-65536) and validate the port range
  • fix -oi crash when nothing is found
  • fix an error hidden by an unguarded close of the TLS socket
  • force domain name when the target is a domain, per host and not per scan
  • do not skip addresses ending in .0/.255
  • do not leak the socket when the local port cannot be bound
  • order the results by address and port (also exten, rcrack, leak, astami)
  • report the number of errors swallowed during the scan (also exten)
  • invite:
  • added param -hangup to send a BYE after N seconds
  • added param -replaces for attended transfer (also send)
  • fix the ACK of a 200 Ok, always CSeq 2 (RFC 3261 13.2.2.4)
  • fix a silent abort with -o and -v: resp.code() on a bytes object
  • fix the REFER response, never read, so a 403 was reported as 200 Ok
  • fix the ACK and the transfer against a PBX that answers a plain 200 Ok
  • fix the REFER of -t, built with one argument less than create_message() needs
  • send:
  • added params -body and -content-type: a MESSAGE went out with no body
  • added param -refer-to, a REFER always used 999
  • added param -mf to set Max-Forwards, fixed at 70 (also ping)
  • added params -event, -accept and -se to subscribe to any event
  • added params -ppid and -paid for the domain of PPI and PAI
  • fix -header, which only replaced From, To or Contact when it was first
  • fix -nocolor, applied after the banner had been printed
  • fix a socket error reported after authenticating that never happened
  • fix the ACK when the server answers 200 Ok with no provisional response
  • invite, send:
  • fix -sdes: the crypto lines went under RTP/AVP instead of RTP/SAVP (RFC 4568), with two static keys written in the repo
  • send, ping:
  • reach an IPv6 target: every socket was AF_INET and the addresses unbracketed
  • enumerate:
  • read the Allow, Supported and Allow-Events headers of the answers
  • report methods advertised but rejected, and accepted without being advertised
  • fix -ft FROM_TAG, offered in the help and never read
  • a missing header on fingerprinting no longer discards the result
  • fix a stray + in the error handler that raised TypeError
  • exten:
  • added param -f to read a file of targets
  • added param -oe to save the extensions found
  • rcrack:
  • added param -f to read a file of targets
  • added param -ef to read a file of extensions
  • rcrack, dcrack:
  • added param -o, they were the only modules with no output file
  • leak:
  • added params -realm, -alg and -nonce for the challenge sent to the victim
  • added param -t, the timeout was hardcoded to 30 seconds
  • fix the algorithm written into the -o file, always MD5
  • fix -auth proxy, written into an attribute that does not exist
  • capture the digest of a victim that answers 407 with Proxy-Authorization
  • use the port and protocol of each line with -f, and skip invalid lines
  • fix a TypeError from the console, where the port travels as text
  • ping:
  • fix -user and -pass, offered in the help and never used
  • fix crash with -p TLS against a host that does not answer TLS
  • flood:
  • fix -o FILE, offered in the help and doing nothing
  • -n now sends exactly that number of requests
  • -b randomizes the method too, and includes FUZZ
  • dcrack, rcrack:
  • use every wordlist candidate as it is: quotes, < > and anything past the 50th character were being removed
  • report a wordlist that cannot be read instead of 'Nothing found'
  • dcrack:
  • an invalid line no longer aborts the rest of the file
  • save the resume point in bruteforce mode
  • a saved password out of the charset no longer discards the bruteforce
  • crack each user once, with the lock that was already there
  • wssend:
  • -p accepts ws|wss and the Via and Contact use that transport (RFC 7118)
  • plain ws:// targets are reachable now
  • added param -t: a server that never answers left the tool waiting forever
  • honour -local-ip
  • sniff:
  • added param -r PORT: the bpf filter was fixed to 5060/5061
  • do not resolve the captured domains: a DNS failure discarded the packet
  • fix the Contact header regexp, that never matched
  • pcapdump:
  • fix -r, which crashed with AttributeError before reading the capture
  • print the SIP dialogs once, not once per packet
  • do not write color codes into rtp_frames.txt
  • -folder is honoured when extracting RTP
  • read IPv6 packets, and check that tshark and xxd are available
  • dump:
  • read IPv6 packets and report an unreadable capture instead of a traceback
  • rtpbleed, rtpbleedflood:
  • fix the sequence number, timestamp and SSRC: a byte below 0x10 lost its zero
  • close the socket and document the delay in milliseconds
  • rtpbleed, rtcpbleed:
  • write the log of -o line by line, it was lost when killing the process
  • rtcpbleed:
  • report only non empty answers, and say that the loop runs until Ctrl+C
  • rtpbleedinject:
  • use the payload type of -p instead of always PCMU
  • skip the WAV header instead of injecting it as audio
  • fix the injection stopping when the sequence number or timestamp wrapped
  • spoof:
  • resolve the MAC addresses always: the ARP packet went out 6 bytes short
  • do not include the gateway and the local address in the target list
  • restore both directions of every victim
  • require root on macOS too and wait for every thread
  • astami:
  • fix -t TIMEOUT, accepted and never used
  • fix -c COMMAND, which never ran
  • validate the port range, skip the local address, remove param -p
  • sippts-gui:
  • Ctrl+C while a module runs no longer closes the console
  • an error inside a module no longer closes the console
  • numeric options travel as text: fixed timeout, sdes, ping and port
  • fix 'set cve 1' on scan, which wrote over the list of CVEs found
  • fix the and/or precedence in the check for mandatory params
  • fix 'set ip' on leak answering 'Wrong option'
  • wssend offers ws|wss, TAB after 'set ' offers parameter names
  • a module that cannot be imported no longer closes the console
  • added options: -t for wssend, -o for flood, from tag for enumerate, threads for invite, no Contact for send
  • 'network' no longer crashes on a machine without a default route
  • data/cve.csv:
  • rebuilt from the NVD of NIST: 3218 rows, 1361 CVEs, 57 vendors
  • fix 64 product names carrying words no device announces
  • fix 23 rows naming the same product with different capitalization
  • fix the row of CVE-2013-2686, with two lower bounds and no upper one
  • global:
  • added -nocolor to every module, it was only in 7 of 20
  • added long aliases --timeout, --protocol and --domain
  • added param -o to wssend, enumerate, ping, rtpbleedflood and rtpbleedinject
  • read the version number from the 'version' file instead of each script
  • added write_results(), result_rows(), read_targets_file(), write_targets(), expand_targets(), bind_local_port(), close_sockets() and close_capture()
  • shared target expansion: comma separated lists, address ranges with -f and -i, unresolvable hosts reported, empty lines skipped
  • stop reading provisional answers after 10, and treat a closed TCP connection as the end of the answer
  • fix the banner saying 'last version 0.1' while running 0.3
  • the update check now has a timeout: it hung on a network that drops traffic
  • fix the quotes of the Cache-Control header sent to github
  • find the CVE list next to the package, so an editable install works
  • -up replaces the files where the running code lives and refuses a git checkout
  • close the TLS socket: wrap_socket() detaches the plain one
  • fix the -local-ip hint, raising AttributeError in 5 modules
  • !/usr/bin/env python3 instead of a hardcoded interpreter path

  • fix the 'Creston' typo on the TSW- series fingerprint
  • added usage examples to flood, sniff, spoof, pcapdump and the four rtp tools
  • setup.py:
  • drop 'resource' from install_requires, it is in the standard library
  • extras_require instead of extra_requires, which setuptools ignored
  • README:
  • document the CVE list and the TLS inspection
  • remove the tshark module, which no longer exists
  • video:
  • fix the scan demo, where three hosts were missing and two changed address
Source: README.md, updated 2026-09-14