03/25/2023
SS7 — THE DEADLIEST ☠️ATTACK 📱
Signaling System 7 (SS7) , a protocol which is used for exchanging data between network devices in worldwide network infrastructure.
Consider you are attempting to make a phone call (from Carrier A) to your friend who is far from(to Carrier B). This is how your voice messages get transmitted to the other end.
Phone signals are reached to the base stations by nearby towers and transmitted to the SS7 network in carrier A. Every SS7 Network has components such as:
1️⃣🔹HLR(Home Location Register): contains a database with subscriber’s information such as phone number, pre-paid contract, call/text data permissions
2️⃣🔹VLR(Visitors Location Register): contains a database of the geographical location which are close to subscriber’s location.
➡️Once a hacker gets access to the SS7 network, he can ..
🔸listen and record your Phone calls
🔸read SMS messages that are sent & received
🔸track geographical locations
🔸They can also easily bypass two-factor authentication which is usually sent via SMS to a user.
🔸 A hacker who listens to the particular network can intercept that SMS message and exploit the information shared
➡️ How do they Attack?
🔹In order to attach the SS7 on real life target you should have an access to the SS7 network. It is often provided by VoIP providers, SMS providers, HLR lookup web application providers, you just need to dig deeper to find a suitable provider.
➡️Why Sigploit
🔹SigPloit a signaling security testing framework dedicated to Telecom Security professionals and reasearchers to pentest and exploit vulnerabilites in the signaling protocols used in mobile operators regardless of the geneartion being in use. SigPloit aims to cover all used protocols used in the operators interconnects SS7, GTP (3G), Diameter (4G) or even SIP for IMS and VoLTE infrastructures used in the access layer and SS7 message encapsulation into SIP-T. Recommendations for each vulnerability will be provided to guide the te..........