Into the wild: Gaining access to SS7 - Part 1: Finding an access point

Anyone know when part 2 of the article on ss7 exploiting coming out?

https://www.itu.int/dms_pub/itu-t/opb/sp/T-SP-Q.708B-2020-PDF-E.pdf

3 Likes

in json
https://github.com/Lexonight1/ISPC-json
raw grab
[https://raw.githubusercontent.com/Lexonight1/ISPC-json/main/ISPC.json]
seperated by country
each array is as follows :
‘ispc’ =ISPC
‘dec’ = DEC
‘usp’ = Unique name of the signalling point
‘nsp’ = Name of the signalling point operator

some usp’s are empty so replaced with # tag
have fun with it
not sure if a normalized sqlite file would be smaller

3 Likes

And if evil twin is used with a usrp in 2/3/4 g, to capture sms, then reset accounts, mail, whats…, telge… obtaining technical documents, configurations, manuals…, accounts of the employees of a telephone company, it would be necessary to be close, it may be possible to obtain information, where or how to access.
PS: Now the operators are using AI in the firewalls

2 Likes

How exactly would ss7 firewalls stop SS7 usage at certain points? And what’s the point of putting AI in the firewalls anyway?

Like how do SS& firewalls even work? I saw something for Cellusys, but I couldn’t find any documentation.

Hello id like to talk about the pdu type0 i have the source code but it stopped working can you help me mqking it work again?

I have some docs and interesting stuff, if you have enough knowledge maybe we can achieve something

gracias por la info y compartir tu conocimiento, saludos
!

Just stumbled across this post. That’s super neat!
Amazing job!

I’d love to get ahold of some SIGTRAN software used by commercial telcos.

From what I understand of it, you can use an open source smsc release like an osmocom module and weave a little plugin magic to send silent sms
https://nickvsnetworking.com/gsm-with-osmocom-silent-sms-silent-calls/
All you need is a sub to an sms service or the details of someone else’s you can spoof…

FInding an iin to the SS7 network is only half the battle… Routing, point codes, global titles need to be sussed out, or your SS7 anytimeInterogation request won’t make it to the target. BUt I guess thats half the fun of figuring how to crack this nut…

1 Like

Its all out there man…

1 Like

[http://www.mobicents.org/ss7/docs/ss7/1.0.0.CR2/en-US/pdf/Mobicents_SS7Stack_User_Guide.pdf](https://Mobicent SS7 stack guide)

1 Like

This is some good shit. Thanks bro!

My pleasure man… I’ve been grinding at this ss7 thing for a couple of years… I’m happy to share what I know…

What I do know is that I signed up to this place yesterday and was so inspired last night after reading some intelligent convo on the topoic, I took one little nugget from one of the posts, and bingo bango I’m finally where I need to be…

Took @Shellsquids advice and just leaned into some real solid meticulous scanning… Probably more than I should have as my parsing set up i s only good to about 1000 assets … gets glitchy after that… anyway this is the sign your on the right traxck

Aww man, that mindmap/network diagram got compressed to the point I can’t read it. Mind if I DM you?

Anytime brother… That was kind of on purpose…

Found a killer resource if you want to get your head around routing messages in SS7
https://melroselabs.com/tools/sccphub/
https://developers.melroselabs.com/docs/sccp-hub-demo-mtu-mtr
Pretty handy little sandbox & a SS7 SMS demo app to spin up…
good times… good times…

2 Likes

This is the post that keeps on giving