PentestMe tests the telephony estate most security programmes never look at: which extensions an attacker can enumerate, which will accept a weak password, and what that costs you when someone starts placing calls on your account.
Toll fraud is quiet, expensive, and usually discovered on the invoice.
The assessment identifies which SIP services are reachable and what they are, fingerprinting the platform and version behind them, then enumerates the extensions and accounts they expose. Because SIP commonly runs over UDP and many providers filter it selectively, we report what actually responded rather than inferring a result from silence.
The route from an exposed SIP port to a phone bill you did not authorise.
Servers that answer differently for a valid extension than an invalid one, handing an attacker the account list before they try a single password.
Extensions using the extension number as the password, vendor defaults, and accounts with no authentication at all.
Whether an authenticated or unauthenticated caller can place outbound calls, and whether anything limits the rate or destination when they do.
PBX administration panels and provisioning endpoints reachable from the internet, including ones on non-standard ports.
SIP and RTP carried in the clear, so call metadata and audio are readable by anyone positioned on the path.
Published vulnerabilities in the PBX or gateway platform and version we identify, filtered to those genuinely reachable in your configuration.
VoIP infrastructure is filtered in ways that make a scan easy to misread: a silent UDP port can mean hardened, or it can mean the probe never arrived. PentestMe distinguishes a tested service from an unreachable one and says which is which, so a clean VoIP report means the tests ran and found nothing, rather than that nothing answered.
Run a real, validated VoIP pentest on your own SIP infrastructure before you pay anything. No credit card.
Start your free pentest