| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| README.md | 2026-09-14 | 10.5 kB | |
| v4.2.1 source code.tar.gz | 2026-09-14 | 1.0 MB | |
| v4.2.1 source code.zip | 2026-09-14 | 1.0 MB | |
| Totals: 3 Items | 2.1 MB | 5 | |
v4.2.1 (Sep/2026):
- global:
- fix -up, which did not download the files added in 4.2.0, breaking scan
- update the CVE list only when every module was updated
- download_file() reports whether the file really landed
- warn instead of crashing when the CVE list has more columns than known
- fix the banner saying '(updated)' when newer than published, or unreachable
- ask github again without the CDN cache when the local version looks newer
- scan:
- added the CVSS of each CVE, coloured by severity
- mark a score taken from CVSS v2, its scale is not the one of v3
- order the CVEs by score, worst first
- import lib/tlsinfo.py only when -tlsinfo is used
- the fallback CVE match no longer searches the description and the URL
- fix print_cve() unpacking into a fixed number of columns
- data/cve.csv:
- new 6th column with the CVSS (list version 0.5), needs 4.2.1 or newer
v4.2.0 (Sep/2026):
- added TLS certificate inspection (lib/tlsx509.py, lib/tlsinfo.py)
- added RFC 8760 digest support: SHA-256 and SHA-512-256 fell back to MD5 silently
- added JSON and CSV output, and real chaining between modules
- scan:
- added param -tlsinfo to read the certificate and report expired, self-signed, weak key, weak signature, name mismatch, old TLS version and vendor defaults
- added param -tlsversions to test TLS 1.0/1.1/1.2/1.3 one by one
- added params -oj and -ocsv (also exten, rcrack, enumerate, leak, dcrack, astami)
- added param -ot to save found hosts as ip:port/proto, ready for -f
- added param -header (also exten, enumerate, invite and flood)
- compare the CVE version ranges for real, instead of a text search
- a CVE with no version range now means every version
- match the whole product name, not only the vendor
- look for the version anywhere in the User-Agent
- accept CPE punctuation in the version ranges
- fix the SNI, always the address, hiding the certificate of a virtual host
- fix CVE results coming back downcased
- fix the CVE table calling 'Type' what is the description
- fix -r ALL (was 1-65536) and validate the port range
- fix -oi crash when nothing is found
- fix an error hidden by an unguarded close of the TLS socket
- force domain name when the target is a domain, per host and not per scan
- do not skip addresses ending in .0/.255
- do not leak the socket when the local port cannot be bound
- order the results by address and port (also exten, rcrack, leak, astami)
- report the number of errors swallowed during the scan (also exten)
- invite:
- added param -hangup to send a BYE after N seconds
- added param -replaces for attended transfer (also send)
- fix the ACK of a 200 Ok, always CSeq 2 (RFC 3261 13.2.2.4)
- fix a silent abort with -o and -v: resp.code() on a bytes object
- fix the REFER response, never read, so a 403 was reported as 200 Ok
- fix the ACK and the transfer against a PBX that answers a plain 200 Ok
- fix the REFER of -t, built with one argument less than create_message() needs
- send:
- added params -body and -content-type: a MESSAGE went out with no body
- added param -refer-to, a REFER always used 999
- added param -mf to set Max-Forwards, fixed at 70 (also ping)
- added params -event, -accept and -se to subscribe to any event
- added params -ppid and -paid for the domain of PPI and PAI
- fix -header, which only replaced From, To or Contact when it was first
- fix -nocolor, applied after the banner had been printed
- fix a socket error reported after authenticating that never happened
- fix the ACK when the server answers 200 Ok with no provisional response
- invite, send:
- fix -sdes: the crypto lines went under RTP/AVP instead of RTP/SAVP (RFC 4568), with two static keys written in the repo
- send, ping:
- reach an IPv6 target: every socket was AF_INET and the addresses unbracketed
- enumerate:
- read the Allow, Supported and Allow-Events headers of the answers
- report methods advertised but rejected, and accepted without being advertised
- fix -ft FROM_TAG, offered in the help and never read
- a missing header on fingerprinting no longer discards the result
- fix a stray + in the error handler that raised TypeError
- exten:
- added param -f to read a file of targets
- added param -oe to save the extensions found
- rcrack:
- added param -f to read a file of targets
- added param -ef to read a file of extensions
- rcrack, dcrack:
- added param -o, they were the only modules with no output file
- leak:
- added params -realm, -alg and -nonce for the challenge sent to the victim
- added param -t, the timeout was hardcoded to 30 seconds
- fix the algorithm written into the -o file, always MD5
- fix -auth proxy, written into an attribute that does not exist
- capture the digest of a victim that answers 407 with Proxy-Authorization
- use the port and protocol of each line with -f, and skip invalid lines
- fix a TypeError from the console, where the port travels as text
- ping:
- fix -user and -pass, offered in the help and never used
- fix crash with -p TLS against a host that does not answer TLS
- flood:
- fix -o FILE, offered in the help and doing nothing
- -n now sends exactly that number of requests
- -b randomizes the method too, and includes FUZZ
- dcrack, rcrack:
- use every wordlist candidate as it is: quotes, < > and anything past the 50th character were being removed
- report a wordlist that cannot be read instead of 'Nothing found'
- dcrack:
- an invalid line no longer aborts the rest of the file
- save the resume point in bruteforce mode
- a saved password out of the charset no longer discards the bruteforce
- crack each user once, with the lock that was already there
- wssend:
- -p accepts ws|wss and the Via and Contact use that transport (RFC 7118)
- plain ws:// targets are reachable now
- added param -t: a server that never answers left the tool waiting forever
- honour -local-ip
- sniff:
- added param -r PORT: the bpf filter was fixed to 5060/5061
- do not resolve the captured domains: a DNS failure discarded the packet
- fix the Contact header regexp, that never matched
- pcapdump:
- fix -r, which crashed with AttributeError before reading the capture
- print the SIP dialogs once, not once per packet
- do not write color codes into rtp_frames.txt
- -folder is honoured when extracting RTP
- read IPv6 packets, and check that tshark and xxd are available
- dump:
- read IPv6 packets and report an unreadable capture instead of a traceback
- rtpbleed, rtpbleedflood:
- fix the sequence number, timestamp and SSRC: a byte below 0x10 lost its zero
- close the socket and document the delay in milliseconds
- rtpbleed, rtcpbleed:
- write the log of -o line by line, it was lost when killing the process
- rtcpbleed:
- report only non empty answers, and say that the loop runs until Ctrl+C
- rtpbleedinject:
- use the payload type of -p instead of always PCMU
- skip the WAV header instead of injecting it as audio
- fix the injection stopping when the sequence number or timestamp wrapped
- spoof:
- resolve the MAC addresses always: the ARP packet went out 6 bytes short
- do not include the gateway and the local address in the target list
- restore both directions of every victim
- require root on macOS too and wait for every thread
- astami:
- fix -t TIMEOUT, accepted and never used
- fix -c COMMAND, which never ran
- validate the port range, skip the local address, remove param -p
- sippts-gui:
- Ctrl+C while a module runs no longer closes the console
- an error inside a module no longer closes the console
- numeric options travel as text: fixed timeout, sdes, ping and port
- fix 'set cve 1' on scan, which wrote over the list of CVEs found
- fix the and/or precedence in the check for mandatory params
- fix 'set ip' on leak answering 'Wrong option'
- wssend offers ws|wss, TAB after 'set ' offers parameter names
- a module that cannot be imported no longer closes the console
- added options: -t for wssend, -o for flood, from tag for enumerate, threads for invite, no Contact for send
- 'network' no longer crashes on a machine without a default route
- data/cve.csv:
- rebuilt from the NVD of NIST: 3218 rows, 1361 CVEs, 57 vendors
- fix 64 product names carrying words no device announces
- fix 23 rows naming the same product with different capitalization
- fix the row of CVE-2013-2686, with two lower bounds and no upper one
- global:
- added -nocolor to every module, it was only in 7 of 20
- added long aliases --timeout, --protocol and --domain
- added param -o to wssend, enumerate, ping, rtpbleedflood and rtpbleedinject
- read the version number from the 'version' file instead of each script
- added write_results(), result_rows(), read_targets_file(), write_targets(), expand_targets(), bind_local_port(), close_sockets() and close_capture()
- shared target expansion: comma separated lists, address ranges with -f and -i, unresolvable hosts reported, empty lines skipped
- stop reading provisional answers after 10, and treat a closed TCP connection as the end of the answer
- fix the banner saying 'last version 0.1' while running 0.3
- the update check now has a timeout: it hung on a network that drops traffic
- fix the quotes of the Cache-Control header sent to github
- find the CVE list next to the package, so an editable install works
- -up replaces the files where the running code lives and refuses a git checkout
- close the TLS socket: wrap_socket() detaches the plain one
- fix the -local-ip hint, raising AttributeError in 5 modules
-
!/usr/bin/env python3 instead of a hardcoded interpreter path
- fix the 'Creston' typo on the TSW- series fingerprint
- added usage examples to flood, sniff, spoof, pcapdump and the four rtp tools
- setup.py:
- drop 'resource' from install_requires, it is in the standard library
- extras_require instead of extra_requires, which setuptools ignored
- README:
- document the CVE list and the TLS inspection
- remove the tshark module, which no longer exists
- video:
- fix the scan demo, where three hosts were missing and two changed address