{"id":457,"date":"2024-04-28T07:21:28","date_gmt":"2024-04-28T04:21:28","guid":{"rendered":"https:\/\/sms-txt.net\/?p=457"},"modified":"2024-09-05T12:46:56","modified_gmt":"2024-09-05T09:46:56","slug":"ss7-runnaku-naide","status":"publish","type":"post","link":"https:\/\/sms-txt.net\/et\/ss7-sms\/ss7-runnaku-naide\/","title":{"rendered":"SS7 r\u00fcnnaku n\u00e4ide"},"content":{"rendered":"<p>Teenuste eitamise vastu suunatud r\u00fcnnakud ei erinenud, vaid ainult 7,8 protsenti sellistest r\u00fcnnakutest muutusid praegu v\u00f5imsaks. Isegi InsertSubscriberData s\u00fcsteemi kasutati, aga 99 protsenti s\u00f5numitest j\u00e4i ts\u00fckliline - et nad kindlasti j\u00e4eti operaator v\u00f5rku. K\u00fclastajad ja filtreerimine oli m\u00e4rkimisv\u00e4\u00e4rne m\u00f5ju tulemus -, et osakaal k\u00fcsib need v\u00f5rgud olid korda v\u00e4iksem kui \u00fclej\u00e4\u00e4nud, aga see oli v\u00f5imatu j\u00e4\u00e4da kaitstud r\u00fcnnakute eest. Denial of service oleks n\u00fc\u00fcd oht asjade interneti seadmete. N\u00fc\u00fcd ei ole mitte ainult tarbijaseadmed seotud sidev\u00f5rkudega, vaid lisaks linna infrastruktuuri komponendid, t\u00e4nap\u00e4eva p\u00e4eva ettev\u00f5tted, energia, transport ja ka muud ettev\u00f5tted.<\/p>\n<p>Kuna me oleme juba \u00f6elnud r\u00fcndaja v\u00f5ib k\u00e4ivitada r\u00fcnnaku tellija ligip\u00e4\u00e4setavuse viisil, et side ei pruugi olla taaselustada ilma isegi v\u00f5tmata \u00fchendust tugi, arvestades, et aeg \u00fcletab kolm tundi tavaliselt.<\/p>\n<p>&nbsp;<\/p>\n<h1>SS7 r\u00fcnnaku n\u00e4ide:<\/h1>\n<p>&nbsp;<\/p>\n<p>Nagu eelnevalt mainitud, ei ole ainu\u00fcksi turvameetmete rakendamine ilma turvameetmeid kasutamata piisav, et t\u00f5rjuda k\u00f5iki haavatavusi \u00e4ra kasutavaid r\u00fcnnakuid, mille taga on SS7-v\u00f5rkude arhitektuuris peituvad tegurid. Uurime \u00fchte juhtumit. R\u00fcnnakust sai sammude jada, mida r\u00fcnnaku tuvastamise menetlus suutis \u00fchendada usutavaks seeriaks, kuigi turvatehnika j\u00e4ttis korraldusi m\u00f5istmata. Alustuseks j\u00e4tsid r\u00fcndajad eduka p\u00fc\u00fcdluse leida abonendi IMSI. Olles saanud teavet, et saada tegevust, nad p\u00fc\u00fcdsid leida tellija. See punkt see r\u00fcnnak kukkus kokku. R\u00fcndajad saatsid petitsiooni tellija registreerimise v\u00f5rku. Petitsioon tunnistati operaatorv\u00f5rguga. Nad v\u00f5isid pealtkuulata abonendi sissetulevaid telefonik\u00f5nesid ja SMSe, see oli nende eesm\u00e4rk. Miks me ei uuri iga meedet \u00fcksikasjalikumalt?<\/p>\n<p>PT TAD ohu tuvastamise ja vastamise protseduuri tunnustatud SendRoutingInfoForSM s\u00f5numeid, mis toimetatakse v\u00e4lisserverisse m\u00f5nele abonendile nende operaatori koduv\u00f5rku. Samuti kuulutati side k\u00fcsitavaks mitte \u00fcllatavalt, kui tegemist oli kehtivate tegevustega, kuna neile ei j\u00e4rgnenud tihedalt SMS-i abil. Vahendid p\u00fc\u00fcdlus j\u00e4rgnes tihedalt iga materjali r\u00fcnnata v\u00f5rgu kaudu ProvideSubscriberInfo, mis on takistatud selle v\u00f5rgu. Isegi PT TAD tehnika leidis, et segu SendRoutingInfoForSM koos ProvideSubscriberInfo r\u00fcnnakud kasutades ajavahemikul vaid \u00fcks 2 minutit, mis t\u00e4hendab, et leida tellija on l\u00f5petatud.<\/p>\n<p>&nbsp;<\/p>\n<h2>Kokkuv\u00f5te:<\/h2>\n<p>Kuna meil on v\u00f5imalik kergesti n\u00e4ha, et paljud mobiilsideoperaatorid kaitsevad oma SS7-marginaali v\u00f5rgu tarnete \u00fcmberkonfigureerimise ja SMSi majapidamiste marsruutimise abin\u00f5udega. See v\u00f5ib t\u00f5esti olla vahend SS7-r\u00fcnnakute t\u00f5rjumiseks, kuid v\u00f5ib-olla ei piisa sellest v\u00f5rgu kaitsmiseks. Meie uuring ja ka turvalisuse uurimise kliinikus n\u00e4itab, et on olemas v\u00f5imalused teha SS7 r\u00fcnnakuid, mis j\u00e4tavad sellise turvamehhanismi vahele. Lisaks on r\u00fcnnakud m\u00f5nev\u00f5rra varjatult ja raskesti avastatavad noorest perioodist. See on p\u00f5hjus, miks me arvame, et mobiilsideoperaatorid peavad osalema turvalisuse j\u00e4lgimine v\u00e4ljaspool SS7 suhteid julgustada kokkupuute sihtasutus, mis on ajakohane.<\/p>","protected":false},"excerpt":{"rendered":"<p>Teenuste eitamise vastu suunatud r\u00fcnnakud ei erinenud, vaid ainult 7,8 protsenti sellistest r\u00fcnnakutest muutusid praegu v\u00f5imsaks. Isegi InsertSubscriberData s\u00fcsteemi kasutati, aga 99 protsenti s\u00f5numitest j\u00e4i ts\u00fckliline - et nad kindlasti j\u00e4eti operaator v\u00f5rku. K\u00fclastajad ja filtreerimine oli m\u00e4rkimisv\u00e4\u00e4rne m\u00f5ju...<\/p>","protected":false},"author":1,"featured_media":1736,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[69,1],"tags":[],"class_list":["post-457","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sms-intercept","category-ss7-sms"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.7 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Attack example of SS7<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/sms-txt.net\/et\/ss7-sms\/ss7-runnaku-naide\/\" \/>\n<meta property=\"og:locale\" content=\"et_EE\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Attack example of SS7\" \/>\n<meta property=\"og:description\" content=\"Attacks targeted toward denial of service proved perhaps not different, together with just 7.8 percentage of this kind of attack currently becoming powerful. Even the InsertSubscriberData system was utilized, however, 99 percent of the messages stayed cyclical &#8211;that they certainly were dismissed from the operator network. Visitors and filtering had a Considerable Impact on the...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/sms-txt.net\/et\/ss7-sms\/ss7-runnaku-naide\/\" \/>\n<meta property=\"og:site_name\" content=\"SS7 Hacking\" \/>\n<meta property=\"article:published_time\" content=\"2024-04-28T04:21:28+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-09-05T09:46:56+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/sms-txt.net\/wp-content\/uploads\/2020\/07\/Attack-example-of-SS7.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"900\" \/>\n\t<meta property=\"og:image:height\" content=\"507\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"ss7\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"ss7\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/sms-txt.net\\\/ss7-sms\\\/attack-example-of-ss7\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sms-txt.net\\\/ss7-sms\\\/attack-example-of-ss7\\\/\"},\"author\":{\"name\":\"ss7\",\"@id\":\"https:\\\/\\\/sms-txt.net\\\/#\\\/schema\\\/person\\\/fa482bf9132db58e46bb9c9df2d73be0\"},\"headline\":\"Attack example of SS7\",\"datePublished\":\"2024-04-28T04:21:28+00:00\",\"dateModified\":\"2024-09-05T09:46:56+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/sms-txt.net\\\/ss7-sms\\\/attack-example-of-ss7\\\/\"},\"wordCount\":513,\"publisher\":{\"@id\":\"https:\\\/\\\/sms-txt.net\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/sms-txt.net\\\/ss7-sms\\\/attack-example-of-ss7\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/sms-txt.net\\\/wp-content\\\/uploads\\\/2020\\\/07\\\/Attack-example-of-SS7.jpg\",\"articleSection\":[\"SMS Intercept\",\"SS7\"],\"inLanguage\":\"et\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/sms-txt.net\\\/ss7-sms\\\/attack-example-of-ss7\\\/\",\"url\":\"https:\\\/\\\/sms-txt.net\\\/ss7-sms\\\/attack-example-of-ss7\\\/\",\"name\":\"Attack example of SS7\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sms-txt.net\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/sms-txt.net\\\/ss7-sms\\\/attack-example-of-ss7\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/sms-txt.net\\\/ss7-sms\\\/attack-example-of-ss7\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/sms-txt.net\\\/wp-content\\\/uploads\\\/2020\\\/07\\\/Attack-example-of-SS7.jpg\",\"datePublished\":\"2024-04-28T04:21:28+00:00\",\"dateModified\":\"2024-09-05T09:46:56+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/sms-txt.net\\\/ss7-sms\\\/attack-example-of-ss7\\\/#breadcrumb\"},\"inLanguage\":\"et\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/sms-txt.net\\\/ss7-sms\\\/attack-example-of-ss7\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"et\",\"@id\":\"https:\\\/\\\/sms-txt.net\\\/ss7-sms\\\/attack-example-of-ss7\\\/#primaryimage\",\"url\":\"https:\\\/\\\/sms-txt.net\\\/wp-content\\\/uploads\\\/2020\\\/07\\\/Attack-example-of-SS7.jpg\",\"contentUrl\":\"https:\\\/\\\/sms-txt.net\\\/wp-content\\\/uploads\\\/2020\\\/07\\\/Attack-example-of-SS7.jpg\",\"width\":900,\"height\":507},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/sms-txt.net\\\/ss7-sms\\\/attack-example-of-ss7\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/sms-txt.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Attack example of SS7\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/sms-txt.net\\\/#website\",\"url\":\"https:\\\/\\\/sms-txt.net\\\/\",\"name\":\"SS7 Hacking\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/sms-txt.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/sms-txt.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"et\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/sms-txt.net\\\/#organization\",\"name\":\"SS7\",\"url\":\"https:\\\/\\\/sms-txt.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"et\",\"@id\":\"https:\\\/\\\/sms-txt.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/yellow-jaguar-454368.hostingersite.com\\\/wp-content\\\/uploads\\\/2020\\\/05\\\/logo.jpg\",\"contentUrl\":\"https:\\\/\\\/yellow-jaguar-454368.hostingersite.com\\\/wp-content\\\/uploads\\\/2020\\\/05\\\/logo.jpg\",\"width\":866,\"height\":680,\"caption\":\"SS7\"},\"image\":{\"@id\":\"https:\\\/\\\/sms-txt.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/sms-txt.net\\\/#\\\/schema\\\/person\\\/fa482bf9132db58e46bb9c9df2d73be0\",\"name\":\"ss7\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"SS7 r\u00fcnnaku n\u00e4ide","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/sms-txt.net\/et\/ss7-sms\/ss7-runnaku-naide\/","og_locale":"et_EE","og_type":"article","og_title":"Attack example of SS7","og_description":"Attacks targeted toward denial of service proved perhaps not different, together with just 7.8 percentage of this kind of attack currently becoming powerful. Even the InsertSubscriberData system was utilized, however, 99 percent of the messages stayed cyclical &#8211;that they certainly were dismissed from the operator network. Visitors and filtering had a Considerable Impact on the...","og_url":"https:\/\/sms-txt.net\/et\/ss7-sms\/ss7-runnaku-naide\/","og_site_name":"SS7 Hacking","article_published_time":"2024-04-28T04:21:28+00:00","article_modified_time":"2024-09-05T09:46:56+00:00","og_image":[{"width":900,"height":507,"url":"https:\/\/sms-txt.net\/wp-content\/uploads\/2020\/07\/Attack-example-of-SS7.jpg","type":"image\/jpeg"}],"author":"ss7","twitter_card":"summary_large_image","twitter_misc":{"Written by":"ss7","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/#article","isPartOf":{"@id":"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/"},"author":{"name":"ss7","@id":"https:\/\/sms-txt.net\/#\/schema\/person\/fa482bf9132db58e46bb9c9df2d73be0"},"headline":"Attack example of SS7","datePublished":"2024-04-28T04:21:28+00:00","dateModified":"2024-09-05T09:46:56+00:00","mainEntityOfPage":{"@id":"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/"},"wordCount":513,"publisher":{"@id":"https:\/\/sms-txt.net\/#organization"},"image":{"@id":"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/#primaryimage"},"thumbnailUrl":"https:\/\/sms-txt.net\/wp-content\/uploads\/2020\/07\/Attack-example-of-SS7.jpg","articleSection":["SMS Intercept","SS7"],"inLanguage":"et"},{"@type":"WebPage","@id":"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/","url":"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/","name":"SS7 r\u00fcnnaku n\u00e4ide","isPartOf":{"@id":"https:\/\/sms-txt.net\/#website"},"primaryImageOfPage":{"@id":"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/#primaryimage"},"image":{"@id":"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/#primaryimage"},"thumbnailUrl":"https:\/\/sms-txt.net\/wp-content\/uploads\/2020\/07\/Attack-example-of-SS7.jpg","datePublished":"2024-04-28T04:21:28+00:00","dateModified":"2024-09-05T09:46:56+00:00","breadcrumb":{"@id":"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/#breadcrumb"},"inLanguage":"et","potentialAction":[{"@type":"ReadAction","target":["https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/"]}]},{"@type":"ImageObject","inLanguage":"et","@id":"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/#primaryimage","url":"https:\/\/sms-txt.net\/wp-content\/uploads\/2020\/07\/Attack-example-of-SS7.jpg","contentUrl":"https:\/\/sms-txt.net\/wp-content\/uploads\/2020\/07\/Attack-example-of-SS7.jpg","width":900,"height":507},{"@type":"BreadcrumbList","@id":"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/sms-txt.net\/"},{"@type":"ListItem","position":2,"name":"Attack example of SS7"}]},{"@type":"WebSite","@id":"https:\/\/sms-txt.net\/#website","url":"https:\/\/sms-txt.net\/","name":"SS7 h\u00e4kkimine","description":"","publisher":{"@id":"https:\/\/sms-txt.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/sms-txt.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"et"},{"@type":"Organization","@id":"https:\/\/sms-txt.net\/#organization","name":"SS7","url":"https:\/\/sms-txt.net\/","logo":{"@type":"ImageObject","inLanguage":"et","@id":"https:\/\/sms-txt.net\/#\/schema\/logo\/image\/","url":"https:\/\/yellow-jaguar-454368.hostingersite.com\/wp-content\/uploads\/2020\/05\/logo.jpg","contentUrl":"https:\/\/yellow-jaguar-454368.hostingersite.com\/wp-content\/uploads\/2020\/05\/logo.jpg","width":866,"height":680,"caption":"SS7"},"image":{"@id":"https:\/\/sms-txt.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/sms-txt.net\/#\/schema\/person\/fa482bf9132db58e46bb9c9df2d73be0","name":"ss7"}]}},"_links":{"self":[{"href":"https:\/\/sms-txt.net\/et\/wp-json\/wp\/v2\/posts\/457","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sms-txt.net\/et\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sms-txt.net\/et\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sms-txt.net\/et\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sms-txt.net\/et\/wp-json\/wp\/v2\/comments?post=457"}],"version-history":[{"count":0,"href":"https:\/\/sms-txt.net\/et\/wp-json\/wp\/v2\/posts\/457\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sms-txt.net\/et\/wp-json\/wp\/v2\/media\/1736"}],"wp:attachment":[{"href":"https:\/\/sms-txt.net\/et\/wp-json\/wp\/v2\/media?parent=457"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sms-txt.net\/et\/wp-json\/wp\/v2\/categories?post=457"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sms-txt.net\/et\/wp-json\/wp\/v2\/tags?post=457"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}