v4.2.1 (Sep/2026):
- global:
  - fix -up, which did not download the files added in 4.2.0, breaking scan
  - update the CVE list only when every module was updated
  - download_file() reports whether the file really landed
  - warn instead of crashing when the CVE list has more columns than known
  - fix the banner saying '(updated)' when newer than published, or unreachable
  - ask github again without the CDN cache when the local version looks newer
- scan:
  - added the CVSS of each CVE, coloured by severity
  - mark a score taken from CVSS v2, its scale is not the one of v3
  - order the CVEs by score, worst first
  - import lib/tlsinfo.py only when -tlsinfo is used
  - the fallback CVE match no longer searches the description and the URL
  - fix print_cve() unpacking into a fixed number of columns
- data/cve.csv:
  - new 6th column with the CVSS (list version 0.5), needs 4.2.1 or newer

v4.2.0 (Sep/2026):
- added TLS certificate inspection (lib/tlsx509.py, lib/tlsinfo.py)
- added RFC 8760 digest support: SHA-256 and SHA-512-256 fell back to MD5 silently
- added JSON and CSV output, and real chaining between modules
- scan:
  - added param -tlsinfo to read the certificate and report expired, self-signed,
    weak key, weak signature, name mismatch, old TLS version and vendor defaults
  - added param -tlsversions to test TLS 1.0/1.1/1.2/1.3 one by one
  - added params -oj and -ocsv (also exten, rcrack, enumerate, leak, dcrack, astami)
  - added param -ot to save found hosts as ip:port/proto, ready for -f
  - added param -header (also exten, enumerate, invite and flood)
  - compare the CVE version ranges for real, instead of a text search
  - a CVE with no version range now means every version
  - match the whole product name, not only the vendor
  - look for the version anywhere in the User-Agent
  - accept CPE punctuation in the version ranges
  - fix the SNI, always the address, hiding the certificate of a virtual host
  - fix CVE results coming back downcased
  - fix the CVE table calling 'Type' what is the description
  - fix -r ALL (was 1-65536) and validate the port range
  - fix -oi crash when nothing is found
  - fix an error hidden by an unguarded close of the TLS socket
  - force domain name when the target is a domain, per host and not per scan
  - do not skip addresses ending in .0/.255
  - do not leak the socket when the local port cannot be bound
  - order the results by address and port (also exten, rcrack, leak, astami)
  - report the number of errors swallowed during the scan (also exten)
- invite:
  - added param -hangup to send a BYE after N seconds
  - added param -replaces for attended transfer (also send)
  - fix the ACK of a 200 Ok, always CSeq 2 (RFC 3261 13.2.2.4)
  - fix a silent abort with -o and -v: resp.code() on a bytes object
  - fix the REFER response, never read, so a 403 was reported as 200 Ok
  - fix the ACK and the transfer against a PBX that answers a plain 200 Ok
  - fix the REFER of -t, built with one argument less than create_message() needs
- send:
  - added params -body and -content-type: a MESSAGE went out with no body
  - added param -refer-to, a REFER always used 999
  - added param -mf to set Max-Forwards, fixed at 70 (also ping)
  - added params -event, -accept and -se to subscribe to any event
  - added params -ppid and -paid for the domain of PPI and PAI
  - fix -header, which only replaced From, To or Contact when it was first
  - fix -nocolor, applied after the banner had been printed
  - fix a socket error reported after authenticating that never happened
  - fix the ACK when the server answers 200 Ok with no provisional response
- invite, send:
  - fix -sdes: the crypto lines went under RTP/AVP instead of RTP/SAVP (RFC 4568),
    with two static keys written in the repo
- send, ping:
  - reach an IPv6 target: every socket was AF_INET and the addresses unbracketed
- enumerate:
  - read the Allow, Supported and Allow-Events headers of the answers
  - report methods advertised but rejected, and accepted without being advertised
  - fix -ft FROM_TAG, offered in the help and never read
  - a missing header on fingerprinting no longer discards the result
  - fix a stray + in the error handler that raised TypeError
- exten:
  - added param -f to read a file of targets
  - added param -oe to save the extensions found
- rcrack:
  - added param -f to read a file of targets
  - added param -ef to read a file of extensions
- rcrack, dcrack:
  - added param -o, they were the only modules with no output file
- leak:
  - added params -realm, -alg and -nonce for the challenge sent to the victim
  - added param -t, the timeout was hardcoded to 30 seconds
  - fix the algorithm written into the -o file, always MD5
  - fix -auth proxy, written into an attribute that does not exist
  - capture the digest of a victim that answers 407 with Proxy-Authorization
  - use the port and protocol of each line with -f, and skip invalid lines
  - fix a TypeError from the console, where the port travels as text
- ping:
  - fix -user and -pass, offered in the help and never used
  - fix crash with -p TLS against a host that does not answer TLS
- flood:
  - fix -o FILE, offered in the help and doing nothing
  - -n now sends exactly that number of requests
  - -b randomizes the method too, and includes FUZZ
- dcrack, rcrack:
  - use every wordlist candidate as it is: quotes, < > and anything past the
    50th character were being removed
  - report a wordlist that cannot be read instead of 'Nothing found'
- dcrack:
  - an invalid line no longer aborts the rest of the file
  - save the resume point in bruteforce mode
  - a saved password out of the charset no longer discards the bruteforce
  - crack each user once, with the lock that was already there
- wssend:
  - -p accepts ws|wss and the Via and Contact use that transport (RFC 7118)
  - plain ws:// targets are reachable now
  - added param -t: a server that never answers left the tool waiting forever
  - honour -local-ip
- sniff:
  - added param -r PORT: the bpf filter was fixed to 5060/5061
  - do not resolve the captured domains: a DNS failure discarded the packet
  - fix the Contact header regexp, that never matched
- pcapdump:
  - fix -r, which crashed with AttributeError before reading the capture
  - print the SIP dialogs once, not once per packet
  - do not write color codes into rtp_frames.txt
  - -folder is honoured when extracting RTP
  - read IPv6 packets, and check that tshark and xxd are available
- dump:
  - read IPv6 packets and report an unreadable capture instead of a traceback
- rtpbleed, rtpbleedflood:
  - fix the sequence number, timestamp and SSRC: a byte below 0x10 lost its zero
  - close the socket and document the delay in milliseconds
- rtpbleed, rtcpbleed:
  - write the log of -o line by line, it was lost when killing the process
- rtcpbleed:
  - report only non empty answers, and say that the loop runs until Ctrl+C
- rtpbleedinject:
  - use the payload type of -p instead of always PCMU
  - skip the WAV header instead of injecting it as audio
  - fix the injection stopping when the sequence number or timestamp wrapped
- spoof:
  - resolve the MAC addresses always: the ARP packet went out 6 bytes short
  - do not include the gateway and the local address in the target list
  - restore both directions of every victim
  - require root on macOS too and wait for every thread
- astami:
  - fix -t TIMEOUT, accepted and never used
  - fix -c COMMAND, which never ran
  - validate the port range, skip the local address, remove param -p
- sippts-gui:
  - Ctrl+C while a module runs no longer closes the console
  - an error inside a module no longer closes the console
  - numeric options travel as text: fixed timeout, sdes, ping and port
  - fix 'set cve 1' on scan, which wrote over the list of CVEs found
  - fix the and/or precedence in the check for mandatory params
  - fix 'set ip' on leak answering 'Wrong option'
  - wssend offers ws|wss, TAB after 'set ' offers parameter names
  - a module that cannot be imported no longer closes the console
  - added options: -t for wssend, -o for flood, from tag for enumerate,
    threads for invite, no Contact for send
  - 'network' no longer crashes on a machine without a default route
- data/cve.csv:
  - rebuilt from the NVD of NIST: 3218 rows, 1361 CVEs, 57 vendors
  - fix 64 product names carrying words no device announces
  - fix 23 rows naming the same product with different capitalization
  - fix the row of CVE-2013-2686, with two lower bounds and no upper one
- global:
  - added -nocolor to every module, it was only in 7 of 20
  - added long aliases --timeout, --protocol and --domain
  - added param -o to wssend, enumerate, ping, rtpbleedflood and rtpbleedinject
  - read the version number from the 'version' file instead of each script
  - added write_results(), result_rows(), read_targets_file(), write_targets(),
    expand_targets(), bind_local_port(), close_sockets() and close_capture()
  - shared target expansion: comma separated lists, address ranges with -f and
    -i, unresolvable hosts reported, empty lines skipped
  - stop reading provisional answers after 10, and treat a closed TCP
    connection as the end of the answer
  - fix the banner saying 'last version 0.1' while running 0.3
  - the update check now has a timeout: it hung on a network that drops traffic
  - fix the quotes of the Cache-Control header sent to github
  - find the CVE list next to the package, so an editable install works
  - -up replaces the files where the running code lives and refuses a git checkout
  - close the TLS socket: wrap_socket() detaches the plain one
  - fix the -local-ip hint, raising AttributeError in 5 modules
  - #!/usr/bin/env python3 instead of a hardcoded interpreter path
  - fix the 'Creston' typo on the TSW- series fingerprint
  - added usage examples to flood, sniff, spoof, pcapdump and the four rtp tools
- setup.py:
  - drop 'resource' from install_requires, it is in the standard library
  - extras_require instead of extra_requires, which setuptools ignored
- README:
  - document the CVE list and the TLS inspection
  - remove the tshark module, which no longer exists
- video:
  - fix the scan demo, where three hosts were missing and two changed address

v4.1.2 (Nov/2024):
- scan:
  - control ulimit handler and adjust according to threads
- global:
  - bug fixes

v4.1.1 (Oct/2024):
- added new binary: sippts-gui
- global:
  - clean unused params
  - added stop functions in some modules
  - bug fixes

v4.1 (Sep/2024):
- added IPv6 conversions
- renamed module sippcapdump to sipdump
- removed tshark module
- added module pcapdump to dump data from a PCAP file (SIP, RTP and RTP-to-WAV)
- added module video to show animated help
- added module astami to connect to Asterisk AMI
- scan:
  - added param -t to set sockets timeout
  - added param -oi to save found ips into a file
- leak:
  - added param -t to set sockets timeout
- enumerate:
  - added param -t to set sockets timeout
-	exten:
  - added param -t to set sockets timeout
- ping:
  - added param -t to set sockets timeout
- rcrack:
  - added param -t to set sockets timeout
- send:
  - added param -t to set sockets timeout
  - added param -v for verbose mode
  - added param -template to load SIP messages
- dcrack:
  - use pyshark library instead tshark application
  - added param -th to use threads
- global:
  - bug fixes

v4.0 (May/2024):
- Unify scripts into one: sippts
- bug fixes
- Deleted script sipfuzzer
- added param -cve in scan script to show possible CVEs
- added param -up for update scripts and cve file

v3.4 (Feb/2024):
- added param -ppi for P-Preferred-Identity
- added param -pai for P-Asserted-Identity
- sipsend:
  - added param --local_port to force local port
  - added param --no_contact to send message without contact header
- sipinvite: added param --local_port to force local port
- sipexten:
  - added param -ofile to save results
  - added param -f to filter response code
- sipsend:
  - added param -header to insert custom headers
- global:
  - bug fixes
- Renamed script sipdump to sippcapdump
- Renamed script sipcrack to sipdigestcrack

v3.3 (Nov/2022):
- sipflood:
  - added param -th to allow threads
  - added params -b -a -min -max to create malformed headers
- sipscan:
  - manage large ranges of IP networks. Fixed memory leak problems
  - can now run faster. Supports 800 threads without memory consumption
  - added param -random to randomize target hosts
- sipdigestleak
  - now can attack several IP addresses or network ranges
  - added param -ping to ping the host and connect to them only if it is alive
  - added param --file lo load IPs from a file, with format (ip:port/proto)
- sipenumerate:
  - use threads to run faster
  - show fingerprinting to give more information
- sipping:
  - new module to check if a server/device is alive
- rtpbleedinject:
  - new module to inject RTP frames when RTPBleed vulnerability is present
- wssend:
  - new module to send SIP messages over WebSockets
- sipfuzzer:
  - new module to perform a SIP fuzzing test on several SIP methods
- global:
  - bug fixes

v3.2 (Sep/2022)
- sipsend:
  - added params from_tag, to_tag, branch, callid, cseq, sdp
  - added params user and pass to send a second message with auth if we obtain a code 401/407
  - added param --sdes to send cipher keys in SDP
  - added param --local-ip to force it in case of multiple IP addresses
- sipinvite:
  - added param --no-sdp to send the INVITE without SDP
  - added param --sdes to send cipher keys in SDP
  - now it is possible to send to a range of callers (To-User) and a range of callees (From-User)
  - added param --local-ip to force it in case of multiple IP addresses
- sipenumerate:
  - added verbose mode
- siprcrack:
  - added param lenght to force the size of extensions
  - added param user to set the From and To user (by default is prefix+extension). If is set, the prefix only will be applied to Auth User
- siptshark:
  - new module to extract info from a PCAP file
- arpspoof:
  - new module to do an ARP cache poisoning
- sipsniff:
  - new module to sniff SIP traffic
- sipdigestleak:
  - added tls support
  - added param --local-ip to force it in case of multiple IP addresses
- sipscan:
  - added param --output-file to save results
  - added param -fp to fingerprinting
- global:
  - added class Color and param nocolor to show console responses in ansii
  - bug fixes

v3.1.0 (Sep/2022)
- Added parameter From Domain and To Domain to SipScan, SipSend, SipInvite, SipFlood and SipDigestLeak
- SipScan can load IPs or network ranges from a file
- Bug fixes in TLS connections
- New scripts rtpbleed, rtcpbleed and rtpbleedflood to exploit RTPBleed vulnerability

v3.0.0 (Apr/2022)
- New version coded in python
- Erased some scripts: sipsniff, sipspy and sipreport
- Renamed script sipcracker to siprcrack
- New script sipenumerate to enumerate available methods of a SIP sevice/server
- New script sipdump to extract SIP Digest authentications from a PCAP file
- New script sipcrack to crack the digest authentications within the SIP protocol

v2.0.5 (Jan/2022)
- sipflood.pl: new script to flood a SIP server
- sipcracker.pl: if all password are found, the script ends
- sipdigestleak.pl: added cnonce, nc and qop params when export files with sipdump format
- sipscan.pl: bug fixes

v2.0.4 (Aug/2020)
- Hostname to IP address resolution
- TLS support
- sipinvite.pl: Fixed ACK responses and added BYE message

v2.0.3 (Dec/2019)
- Fix manpage-has-bad-whatis-entry error in man pages
- sipscan.pl: Added -th param and bug fixes in threads
- Code optimized in several scripts

v2.0.2 (Dec/2019)
- Fixes in man pages
- Moved sipcrack to sipcracker

v2.0.1 (Dec/2019)
- Bug fixes
- Added man pages

v2.0.0 (Dec/2019)
- sipscan, sipexten, sipcrack, sipinvite: New params to customize SIP headers (From User, From Name, To User, To Name, Contact Domain, SIP Domain)
- sipinvite.pl: Allow TCP connections
- Bug fixes

v1.2.13 (Oct/2019)
- New param (-version) to show current version and check for new updates
- sipscan.pl: New optional param (-web) to check for a control panel
- sipinvite.pl: New param (-log) to save data into a log file

v1.2.12 (Oct/2019)
- sipscan.pl: using threads are now optional (-noth)

v1.2.8 (May/2019)
- Bug fixes

v1.2.7 (May/2019)
- Don't save data into database bt default

v1.2.6 (Jan/2019)
- New script (sipdigestleak.pl) to exploit the vulnerability discovered by
  Sandro Gauci that affects a large number of hardware and software devices

v1.2.2 (Dec/2018)
- Bug fixes

v1.2.1 (Aug/2018)
- Bug fixes
- Change --nodb by --db (by default don't save session)
- Now it is possible to change the user-agent

v1.2 (Feb/2015)
- First commit uploaded to Github
