{"id":360,"date":"2023-12-07T03:12:42","date_gmt":"2023-12-07T00:12:42","guid":{"rendered":"https:\/\/sms-txt.net\/?p=360"},"modified":"2024-09-05T12:44:42","modified_gmt":"2024-09-05T09:44:42","slug":"ss7-aflytning-af-opkald","status":"publish","type":"post","link":"https:\/\/sms-txt.net\/da\/aflytning-af-opkald\/ss7-aflytning-af-opkald\/","title":{"rendered":"Aflytning af SS7-opkald"},"content":{"rendered":"<p>Det mobile omstillingscenter MSC har normalt de krypteringsn\u00f8gler, der bruges af hver abonnent til at etablere opkaldet. N\u00e5r abonnenten er p\u00e5 farten, letter en overdragelsesproces abonnentens glidende overgang mellem de forskellige radioceller, samtidig med at opkaldet forts\u00e6tter.<\/p>\n<p>I nogle tilf\u00e6lde flytter abonnenten fra en celle til en anden, som administreres af en anden VLR. I dette tilf\u00e6lde har den nye VLR ikke oprindeligt de autentificeringsoplysninger, der ville g\u00f8re det lettere at bevare opkaldet, og derfor er det n\u00f8dvendigt med en overdragelsesproces mellem MSC'erne for at overf\u00f8re n\u00f8glerne til den nye MSC.<\/p>\n<p>Det sker via en MAP-besked, der hedder sendIdentification. Den nye VLR sender en sendIdentification-meddelelse til den gamle VLR, som til geng\u00e6ld svarer med de n\u00f8gler, der er n\u00f8dvendige for at opretholde det igangv\u00e6rende opkald.  Blandt disse n\u00f8gler er den n\u00f8gle, der bruges til at kryptere trafikken i luften. I angrebsscenariet fanger angriberen m\u00e5lets trafik over luftgr\u00e6nsefladen (hvilket kr\u00e6ver fysisk n\u00e6rhed fra m\u00e5let).<\/p>\n<p>Med adgang til SS7 kan han derefter bruge sendIdentification-meddelelsen til at hente dekrypteringsn\u00f8glerne til m\u00e5let og bruge dem til at dekryptere trafikken. SendIdentification er kun n\u00f8dvendig inden for det interne netv\u00e6rk under<br \/>\noverdragelser. Det b\u00f8r ikke have nogen legitim brug udefra og b\u00f8r derfor filtreres p\u00e5 gr\u00e6nsen.<\/p>\n<h2>Aflytning af udg\u00e5ende opkald<\/h2>\n<p>GSM Service Control Function (gsmSCF) er en funktionel enhed, der indeholder CAMEL-servicelogikken, som for et bestemt s\u00e6t h\u00e6ndelser med sikkerhed beslutter, om den \u00f8nskede handling kan forts\u00e6tte \u00e6ndret, u\u00e6ndret eller afbrudt. Den kan f.eks. bruges til at \u00e6ndre udg\u00e5ende numre for at tilf\u00f8je omr\u00e5denummer eller internationalt format.<\/p>\n<p>En angriber med adgang til SS7 kan bruge en insertSubscriberData-besked til at \u00e6ndre abonnentens gsmSCF-adresse til en adresse under deres kontrol. Angriberen kan derefter omskrive udg\u00e5ende numre til et nummer under hans kontrol. I dette tilf\u00e6lde vil angriberen modtage det udg\u00e5ende opkald og optage opkaldet, f\u00f8r han videresender trafikken til den endelige destination.<\/p>\n<h2>Aflytning - indg\u00e5ende trafik - viderestilling af opkald<\/h2>\n<p>RegisterSS-meddelelsen bruges til at registrere supplerende tjenester til en abonnent. En af disse tjenester er viderestilling af opkald. En angriber kan bruge registerSS-meddelelsen til at aktivere viderestilling til et nummer under hans kontrol. N\u00e5r han modtager opkaldet, bruger han beskeden eraseSS til at fjerne viderestillingen og derefter sende opkaldet tilbage til abonnenten. P\u00e5 den m\u00e5de kan angriberen opfange og optage opkaldet.<\/p>","protected":false},"excerpt":{"rendered":"<p>Det mobile omstillingscenter MSC har normalt de krypteringsn\u00f8gler, der bruges af hver abonnent til at etablere opkaldet. N\u00e5r abonnenten er p\u00e5 farten, s\u00f8rger en overdragelsesproces for en smidig overgang mellem de forskellige radioceller, samtidig med at opkaldet forts\u00e6tter. I nogle tilf\u00e6lde flytter abonnenten fra...<\/p>","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[68],"tags":[],"class_list":["post-360","post","type-post","status-publish","format-standard","hentry","category-call-interception"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.7 (Yoast SEO v26.7) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>SS7 Call Interception<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/sms-txt.net\/da\/aflytning-af-opkald\/ss7-aflytning-af-opkald\/\" \/>\n<meta property=\"og:locale\" content=\"da_DK\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SS7 Call Interception\" \/>\n<meta property=\"og:description\" content=\"The mobile switching center MSC normally holds the encryption keys used by each subscriber to be able to establish the call. When the subscriber is on the move, a handover process facilitates the smooth transition of the subscriber between the different radio cells while maintain the call progress. In some cases the subscriber moves from...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/sms-txt.net\/da\/aflytning-af-opkald\/ss7-aflytning-af-opkald\/\" \/>\n<meta property=\"og:site_name\" content=\"SS7 Hacking\" \/>\n<meta property=\"article:published_time\" content=\"2023-12-07T00:12:42+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-09-05T09:44:42+00:00\" \/>\n<meta name=\"author\" content=\"ss7\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"ss7\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/\"},\"author\":{\"name\":\"ss7\",\"@id\":\"https:\/\/sms-txt.net\/#\/schema\/person\/fa482bf9132db58e46bb9c9df2d73be0\"},\"headline\":\"SS7 Call Interception\",\"datePublished\":\"2023-12-07T00:12:42+00:00\",\"dateModified\":\"2024-09-05T09:44:42+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/\"},\"wordCount\":422,\"publisher\":{\"@id\":\"https:\/\/sms-txt.net\/#organization\"},\"articleSection\":[\"Call Interception\"],\"inLanguage\":\"da-DK\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/\",\"url\":\"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/\",\"name\":\"SS7 Call Interception\",\"isPartOf\":{\"@id\":\"https:\/\/sms-txt.net\/#website\"},\"datePublished\":\"2023-12-07T00:12:42+00:00\",\"dateModified\":\"2024-09-05T09:44:42+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/#breadcrumb\"},\"inLanguage\":\"da-DK\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/sms-txt.net\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SS7 Call Interception\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/sms-txt.net\/#website\",\"url\":\"https:\/\/sms-txt.net\/\",\"name\":\"SS7 Hacking\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/sms-txt.net\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/sms-txt.net\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"da-DK\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/sms-txt.net\/#organization\",\"name\":\"SS7\",\"url\":\"https:\/\/sms-txt.net\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"da-DK\",\"@id\":\"https:\/\/sms-txt.net\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/yellow-jaguar-454368.hostingersite.com\/wp-content\/uploads\/2020\/05\/logo.jpg\",\"contentUrl\":\"https:\/\/yellow-jaguar-454368.hostingersite.com\/wp-content\/uploads\/2020\/05\/logo.jpg\",\"width\":866,\"height\":680,\"caption\":\"SS7\"},\"image\":{\"@id\":\"https:\/\/sms-txt.net\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/sms-txt.net\/#\/schema\/person\/fa482bf9132db58e46bb9c9df2d73be0\",\"name\":\"ss7\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Aflytning af SS7-opkald","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/sms-txt.net\/da\/aflytning-af-opkald\/ss7-aflytning-af-opkald\/","og_locale":"da_DK","og_type":"article","og_title":"SS7 Call Interception","og_description":"The mobile switching center MSC normally holds the encryption keys used by each subscriber to be able to establish the call. When the subscriber is on the move, a handover process facilitates the smooth transition of the subscriber between the different radio cells while maintain the call progress. In some cases the subscriber moves from...","og_url":"https:\/\/sms-txt.net\/da\/aflytning-af-opkald\/ss7-aflytning-af-opkald\/","og_site_name":"SS7 Hacking","article_published_time":"2023-12-07T00:12:42+00:00","article_modified_time":"2024-09-05T09:44:42+00:00","author":"ss7","twitter_card":"summary_large_image","twitter_misc":{"Written by":"ss7","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/#article","isPartOf":{"@id":"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/"},"author":{"name":"ss7","@id":"https:\/\/sms-txt.net\/#\/schema\/person\/fa482bf9132db58e46bb9c9df2d73be0"},"headline":"SS7 Call Interception","datePublished":"2023-12-07T00:12:42+00:00","dateModified":"2024-09-05T09:44:42+00:00","mainEntityOfPage":{"@id":"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/"},"wordCount":422,"publisher":{"@id":"https:\/\/sms-txt.net\/#organization"},"articleSection":["Call Interception"],"inLanguage":"da-DK"},{"@type":"WebPage","@id":"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/","url":"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/","name":"Aflytning af SS7-opkald","isPartOf":{"@id":"https:\/\/sms-txt.net\/#website"},"datePublished":"2023-12-07T00:12:42+00:00","dateModified":"2024-09-05T09:44:42+00:00","breadcrumb":{"@id":"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/#breadcrumb"},"inLanguage":"da-DK","potentialAction":[{"@type":"ReadAction","target":["https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/sms-txt.net\/"},{"@type":"ListItem","position":2,"name":"SS7 Call Interception"}]},{"@type":"WebSite","@id":"https:\/\/sms-txt.net\/#website","url":"https:\/\/sms-txt.net\/","name":"SS7-hacking","description":"","publisher":{"@id":"https:\/\/sms-txt.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/sms-txt.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"da-DK"},{"@type":"Organization","@id":"https:\/\/sms-txt.net\/#organization","name":"SS7","url":"https:\/\/sms-txt.net\/","logo":{"@type":"ImageObject","inLanguage":"da-DK","@id":"https:\/\/sms-txt.net\/#\/schema\/logo\/image\/","url":"https:\/\/yellow-jaguar-454368.hostingersite.com\/wp-content\/uploads\/2020\/05\/logo.jpg","contentUrl":"https:\/\/yellow-jaguar-454368.hostingersite.com\/wp-content\/uploads\/2020\/05\/logo.jpg","width":866,"height":680,"caption":"SS7"},"image":{"@id":"https:\/\/sms-txt.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/sms-txt.net\/#\/schema\/person\/fa482bf9132db58e46bb9c9df2d73be0","name":"ss7"}]}},"_links":{"self":[{"href":"https:\/\/sms-txt.net\/da\/wp-json\/wp\/v2\/posts\/360","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sms-txt.net\/da\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sms-txt.net\/da\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sms-txt.net\/da\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sms-txt.net\/da\/wp-json\/wp\/v2\/comments?post=360"}],"version-history":[{"count":0,"href":"https:\/\/sms-txt.net\/da\/wp-json\/wp\/v2\/posts\/360\/revisions"}],"wp:attachment":[{"href":"https:\/\/sms-txt.net\/da\/wp-json\/wp\/v2\/media?parent=360"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sms-txt.net\/da\/wp-json\/wp\/v2\/categories?post=360"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sms-txt.net\/da\/wp-json\/wp\/v2\/tags?post=360"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}