Unmasking SS7: Practical Attacks Exposed
SS7 attack explained by Pentester club
One of the larger security concerns with 5G, the next generation of wireless technologies, is its reliance on 4G/LTE components. However, a reliance on 2G and 3G components is also a cause for concern. An adversary with internal network access (which they gained from a physical breach, for example) could target a 4G/LTE system with a downgrade attack to use the outdated 2G/3G protocols.
The main issue with 2G/3G systems is their use of the SS7 signalling protocol, which originates from the 1970s. SS7 is responsible for setting up and terminating telephone calls. As the protocol improved, it added new features such as SMS, prepaid billing, call waiting/forwarding, and more. However, there are multiple SS7 vulnerabilities to be aware of
To understand why 3G systems are vulnerable, its cellular architecture needs to be understood. 3G systems have been implemented in several different ways, but the two most common are Universal Mobile Telecommunications System (UMTS) and Code Division Multiple Access 2000 (CDMA2000). UMTS is mainly used in Europe, the Middle East, and Africa. CDMA2000 has mainly operated in North America and Asia Pacific.
The UTRAN is also made up of two components: Node Bs and radio network controllers (RNCs). Node Bs interface with UE devices through the use of radios and antennas. In other words, Node Bs are cell towers. RNCs manage and control the Node Bs and UE devices. RNCs can help hand off a device from one tower to the next, manage congestion, handle encryption, and more.
The CN is the main focus of this article because that is where all the SS7 activity occurs. It is also the most complex aspect of the architecture because of all the subsystems involved. At a high level, this component helps move data it receives from the UTRAN to its destination (e.g. to another user or the internet). It also helps data it receives from external networks make its way to the destination (like another user). The CN is broken down into the following components:
Home Location Register (HLR): This register contains a list of all subscribers and their information. This data includes identification information (like the International Mobile Subscriber Identity (IMSI)), authentication keys, the last known location, and more.
A few years back, two researchers (Rosalia D’Alessandro and Ilario Dal Grande) came together to create SigPloit (https://github.com/alex14324/ss7), a telecommunications security testing framework. Presently, it is only capable of attacking the GTP (another 3G signalling protocol) and SS7 protocols. This framework is quick and easy to set up in a Linux environment and provides simulation executables that allow users to test attacks that target SS7.
SigPloit offers simulations for fraud attacks and attacks that compromise a user’s privacy. However, its interception simulations were not working at the time this article was written, so an alternative tool called jss7-attack-simulator was discovered to simulate these vulnerabilities. The simulation tool was written by Kristoffer Jensen for their Master’s thesis for the Norwegian University of Science and Technology.
The environment that the tools below were set up and executed on was a distribution of Debian Linux. Other operating systems will need to slightly modify the commands below to work with their respective package managers, network managers, etc.
About the Creator
pentester club
Cyber Security Expert
Enjoyed the story? Support the Creator.
Subscribe for free to receive all their stories in your feed.
Comments
There are no comments for this story
Be the first to respond and start the conversation.