Cain VoIP Recording & Cracking Utility

There's an interesting "security" software product called Cain & Abel that can record your SIP-based VoIP applications. Cain's sniffer can now extract audio conversations based on SIP/RTP protocols and save them into WAV files. The following codecs are supported: G711 uLaw, G711 aLaw, GSM, MS-GSM, ADPMC, DVI, LPC, L16, G729, Speex, iLBC.

Cain & Abel was designed as a "network administrator security tool" to pinpoint security holes. I put that it quotes, since it can also be used as a hacker's tool. For instance, Cain & Abel can capture your encrypted keystrokes during a Remote Desktop session. According to their website, "Cain can now perform man-in-the-middle attacks against the heavy encrypted Remote Desktop Protocol (RDP), the one used to connect to the Terminal Server service of a remote Windows computer. The entire session from/to the client/server is decrypted and saved to a text file. Client-side key strokes are also decoded to provide some kind of password interception. The attack can be completely invisible because of the use of APR (Arp Poison Routing) and other protocol weakness."

Yikes! I use RDP to connect to my home PC and my work PC.

But that's not all.
Credential Manager is a new SSO solution that Microsoft offers in Windows Server 2003 and Windows XP. Cain can now dump passwords from user's credential files and show them in they're clear text form.

Basically Cain recovers the passwords and Abel does the brute force attacks.

It also supports:
- Wireless scanner using Winpcap protocol driver & WEP cracking
- The sniffer can analyze encrypted protocols such as SSH-1 and HTTPS if used with APR and a man-in-the-middle situation.
-
Microsoft SQL Server 2000 Password Cracker
- MySQL Hashes Cryptanalysis via Sorted Rainbow Tables
-
MySQL Password Cracker (works with both v3.23 and SHA1 Hashes)
- Brute-Force and Dictionary attacks rewritten for all crackers
- Cisco PIX Hashes Cryptanalysis via Sorted Rainbow Tables
- and much more...

So basically, Cain aims to be an "all-in-one" security tooll. Yup, I will have to play with this "security tool" in the lab. Hope I don't break some DMCA rule or something. Please use this tool at your own risk. You didn't hear about this tool from me, got it?

| 3 Comments | 0 TrackBacks

Listed below are links to sites that reference Cain VoIP Recording & Cracking Utility:

Cain VoIP Recording & Cracking Utility TrackBack URL : http://blog.tmcnet.com/mt/mt-tb.cgi/12314

3 Comments

| Reply

this is a great product and tools

Well, Avast AV is picking it as a Virus...

how i can record voice of specific IP address.such as one is source and the second is destination.

Leave a comment

Recent Activity

Saturday

  • Tom Keating tweeted, "Spending 4th of July with in-laws on their lake-side house. Coming soon - fireworks!"

Friday

  • Tom Keating queued Star Trek
  • Tom Keating queued Stardust
  • Tom Keating queued The Fountain

Thursday

More...

Recent Comments

  • ctjames: Yes , I've tried several times by using Cydia installed read more
  • http://openid.aol.com/drdaraban: Yes, I confirm antonioj's comment, both skype and the app read more
  • cmytroops: I was browsing the net and cam across a great read more
  • mike: Sorry if this is off topic but I’m thinking of read more
  • @NumberGarage: Our military service men and women should be driving new read more
  • https://www.google.com/accounts/o8/id?id=AItOawlacBYIyCFI8mz5HS_pdsnSDV1wLz6Vgc8: We have implemented over 50 VoIP systems in the last read more
  • Theo Barton: Its a good phone. I have had a lot of read more
  • https://me.yahoo.com/a/ea7WMvNu2Mlud7dBwQPAAus9JCfo9qE-#27391: I don't want to go through all the problems, I read more
  • Claudio G.: I contacted these folks via e-mail recently (June 2009)and they read more
  • Kinjudah De- Morgan: I am using a strong satelite receiver and a Gateway read more

Subscribe to Blog

    View my Microsoft MVP Profile:

Blogroll

Archives

Around TMCnet Blogs

  • Communications and Technology Blog - Tehrani.com:
    Problems at Joost
  • On Rad's Radar?:
    USF and Rural Reform
  • VoIP & Gadgets Blog:
    Worst Google News Headline Ever! - No public viewing
  • Communications and Technology Blog - Tehrani.com:
    Heading to Rhode Island
  • First Coffee:
    SugarCRM Studied, Broadband 'Crucial,' EGain, OOCOSPI, NetSuite's Zander
  • On Rad's Radar?:
    Bells Giving Up on Landlines?
  • The Readerboard:
    Tougher Actions To Save Telemarketing
  • VoIP & Gadgets Blog:
    eBuddy for iPhone Supports Push Notifications
  • Latest Whitepapers

    TMCnet Videos