RFC 3261 warns that a SIP request with a forged Via header can make responses go to a third party, and that requests sent to multicast addresses can amplify traffic, both of which can be used for denial of service.

Checked 2026-09-25

Vendor
IETF
Product
SIP
Subsystem
Security considerations
Deployment
any
Region
not restricted
Release range
RFC 3261
Checked
2026-09-25

Sources

Cite this note

APA

WarmTransfer. (2026, September 25). SIP scanning and telephony denial of service: source note sip-scanning-tdos-rfc3261-via-amplification. WarmTransfer. https://warmtransfer.net/knowledge/claims/sip-scanning-tdos-rfc3261-via-amplification

BibTeX

@misc{warmtransfer-claim-sip-scanning-tdos-rfc3261-via-amplification,
  title  = {SIP scanning and telephony denial of service: source note sip-scanning-tdos-rfc3261-via-amplification},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/claims/sip-scanning-tdos-rfc3261-via-amplification},
  note   = {Source note sip-scanning-tdos-rfc3261-via-amplification, checked 2026-09-25}
}

Read in context