7 ms·
SS7 cellular network flaw being exploited to drain bank accounts
- rootsudo 6y agoThere's so many fun things you can do w/ telecom networks that it's a bit sad to see the phreaking community dead nowadays or relegated to just "modifying" roms. You could enable any phone to be a receiver for SMS and literally see the network traffic around you on the SMS paging channel. The phone real time operating system actually discards messages that do not match your number (to put it very very high level.) https://silo.tips/download/exploiting-open-functionality-in-sms-capable-cellular-networks https://silo.tips/download/exploiting-open-functionality-in-... Also, great reads if you can find them: Qualcomm standard PDF's.
- dfox 6y agoFor GSM simply receiving everything on PCH does not buy you much, because even ignoring encryption (IIRC even PCH is encrypted) most of traffic there is simply RR sublayer signaling (RR PAGING REQUEST and RR IMMEDIATE ASSIGNMENT messages and nothing much else). What the linked presentation describes is somewhat obvious DoS attack on the infrastructure that depends on ability to cheaply inject larger number of SM-MT messages into the network which authors assume will exhaust the downlink capacity of the network. My assumption is that in such case the first resource that will actually get exhausted is uplink capacity of RACH as the paged MS will attempt to allocate SDCCH in order to complete the paging procedure. I also assume that any currently deployed implementation of GSM has reasonable enough QoS implementation that this cannot happen in practice (especially in relation SMS because various SMS-related accidental RR exhaustions were somewhat common in early implementations). By the way nothing prevents you from causing cell-level DoS of similar type by simply spamming the RACH (except the fact that your local equivalent of FCC will be very unhappy and will be knocking on your door in surprisingly short time).
- doctorshady 6y agoDead!? I know not of what you speak sir :D . https://pastebin.com/QhTPLGfg https://pastebin.com/QhTPLGfg https://shadytel.su/files/necsploits.htm https://shadytel.su/files/necsploits.htm
- solstice 6y ago... that .su TLD
- doctorshady 6y agoYou jelly, comrade?
- rsync 6y ago"You could enable any phone to be a receiver for SMS and literally see the network traffic around you on the SMS paging channel. The phone real time operating system actually discards messages that do not match your number ..." This is literally true, and actually, you can do it with an SDR device and the GNURadio liveCD. However, this data will all be encrypted. Even on 2G networks, you can't just camp at a cellular base station and watch SMS fly by ...
- generalizations 6y agoWith the right decryption tools, you nearly can. All you need is the 2TB precomputed Berlin Tables and the code to implement them.
- computerphage 6y agoWhat are Berlin Tables? Are they the same as Rainbow Tables?
- mschuster91 6y agoYep, named that way after the city their discoverers are based at. https://srlabs.de/bites/decrypting-gsm/ https://srlabs.de/bites/decrypting-gsm/
- pravus 6y agoAt least from my point-of-view a lot of these activities went away as the feds started clamping down. When you can get a prison sentence for serializing URLs it just doesn't make sense to risk it anymore.
- foobarian 6y agoFor me the lightbulb went off in college with NIS and NFS when I realized the network expects me to tell it my user name so I can mount my home directory. Before that point I thought of these systems as well designed, unhackable things - after all, they had real multitasking right? Not like the dinky DOS machines I grew up with. But after that point the veil was lifted. And the older/more legacy a system was the worse it was.
- RcouF1uZ4gsC 6y ago> "In the case of stealing money from bank accounts, a hacker would typically first need a target’s online banking username and password. Perhaps they could obtain this by phishing the target. Then, once logged in, the bank may ask for confirmation of the transfer by sending the account owner a verification code in a text message. With SS7, the hackers can intercept this text and enter it themselves. Exploiting SS7 in this way is a way to circumvent the protections of two-factor authentication, where a system not only requires a password, but something else too, such as an extra code." While SS7 does seem like a problem, I think the bigger issue is using SMS for 2FA. Banks with local branch offices are especially well placed to do better. They can offer Yubikey to their customers, and also since they can see customers in person, they have a way to provision new ones if an old one gets lost (customer comes in and shows government ID, etc).
- delfinom 6y ago>While SS7 does seem like a problem, I think the bigger issue is using SMS for 2FA. These are banks. It took them over a decade to only finally implement SMS 2FA. It'll be another 2 before they implement U2F or TOTP. Actually, shockingly, Vanguard offers U2F support which is quite the minority for financial firms :D Meanwhile american express still makes passwords case insensitive AND trims the fucking lengths behind the scenes.
- the-dude 6y agoThese are US Banks. In the meantime, I have been banking with a 'calculator' for over 15 years which accepts my bank card, I enter the PIN and it spits out a code.
- TheRealPomax 6y agoSame, except rather than "typing in the challenge number" it has an image sensor that I point at my bank's login page after typing in my account and card number, because it generates a 50x50 RGB challenge image.
- _salmon 6y agoShould probably add a (2019) tag. This isn't exactly recent
- goihoiholi 6y agoMuch of the 5G progress happens in the core network and network interconnects. As far as I remember, there will be some sort of "layered" encryption. The innermost layer is the user's payload, end-to-end encrypted between operators. Each service provider (responsible for transporting the data) adds patches with modifications and a signature by the service provider. Not sure if that actually made it into the standard yet. I think the motivation is that roaming requires cost-effective routing, fraud detection,.. so there's a whole business ecosystem around that. Long story short: I think people are working on this
- microcolonel 6y ago> Much of the 5G progress happens in the core network and network interconnects. It's a bit silly to wait for a completely different radio transport before thinking of carrier and backhaul improvements, which are almost completely orthogonal. > Long story short: I think people are working on this Given the specifics of the sorts of flaws in these network standards, it's hard to come away feeling that they were anything short of intentional. I get the impression that “working on it” more or less amounts to improving plausible deniability by making the backdoors less obvious.
- goihoiholi 6y ago> It's a bit silly to wait for a completely different radio transport before thinking of carrier and backhaul improvements, which are almost completely orthogonal. Development on radio access and core network does indeed happen in parallel, and as far as I know, the core network overhaul was not delayed to wait for the radio-layer. But marketing-wise, the radio-layer is what makes the phone show a 5G icon.
- otterley 6y ago(2019)
- exabrial 6y agoTelecoms are not hardened against phishing attacks and are some of the dinosaur centric industries. Please, and I ask very nicely, if you work for a tech company, do everything you can to fight implementing SMS as an authentication factor. It not private, nor authenticated, has no delivery guarantees, easily spoofed, easily intercepted, and easily forged. One only has to look at Jack Dorsey getting jacked to prove this is an inevitability for every single one of your users.
- MaxBarraclough 6y agoDidn't the Dorsey hack occur because Twitter were using SMS for single factor? https://news.ycombinator.com/item?id=20939915 https://news.ycombinator.com/item?id=20939915
- bcrl 6y agoSS7's security model is basically the same as BGP. Peers assume they can trust one another. The cost for entry here in Canada is about $50,000. Pay that to the incumbent telco and you can basically have an SS7 connection of your very own, and announce cell phone numbers to the rest of the world. Electronic Funds Transfer is similarly based on trust. I can withdraw funds from any bank account just by knowing the account number. The only incentive is that you don't want to lose your account, but once you've been through the process of setting things up, it's quite easy to see how the system could be gamed. Maybe someday we'll be able to trust the underlying protocols our lives are built on top of.