{"id":457,"date":"2024-04-28T07:21:28","date_gmt":"2024-04-28T04:21:28","guid":{"rendered":"https:\/\/sms-txt.net\/?p=457"},"modified":"2024-09-05T12:46:56","modified_gmt":"2024-09-05T09:46:56","slug":"ss7-atakos-pavyzdys","status":"publish","type":"post","link":"https:\/\/sms-txt.net\/lt\/ss7-sms\/ss7-atakos-pavyzdys\/","title":{"rendered":"SS7 atakos pavyzdys"},"content":{"rendered":"<p>Atakos, nukreiptos \u012f atsisakym\u0105 teikti paslaugas, pasirod\u0117 esan\u010dios ne kitokios, o tik 7,8 proc. \u0161ios r\u016b\u0161ies atak\u0173 \u0161iuo metu tampa galingos. Netgi buvo naudojama InsertSubscriberData sistema, ta\u010diau 99 proc. prane\u0161im\u0173 liko cikliniai - jie tikrai buvo atmesti i\u0161 operatoriaus tinklo. Lankytojai ir filtravimas tur\u0117jo didel\u0119 \u012ftak\u0105 rezultatui - kad u\u017eklaus\u0173 i\u0161 \u0161i\u0173 tinkl\u0173 dalis buvo kartus ma\u017eesn\u0117 nei likusiuose tinkluose, ta\u010diau buvo ne\u012fmanoma i\u0161likti apsaugotiems nuo atak\u0173. Paslaug\u0173 atsisakymas dabar kelia gr\u0117sm\u0119 daikt\u0173 interneto \u012frenginiams. Dabar ne tik vartotoj\u0173 \u012frenginiai yra susieti su ry\u0161i\u0173 tinklais, bet ir miesto infrastrukt\u016bros komponentai, \u0161iuolaikin\u0117s \u012fmon\u0117s, energetikos, transporto ir kitos \u012fmon\u0117s.<\/p>\n<p>Kadangi mes jau sak\u0117me, kad u\u017epuolikas gali paleisti atak\u0105 d\u0117l abonento prieinamumo taip, kad ry\u0161ys negali b\u016bti atgaivintas net nesikreipiant \u012f palaikym\u0105, o laikas vir\u0161ija tris valandas paprastai.<\/p>\n<p>&nbsp;<\/p>\n<h1>SS7 atakos pavyzdys:<\/h1>\n<p>&nbsp;<\/p>\n<p>Kaip min\u0117ta anks\u010diau, vien tik saugumo veiksm\u0173, net nenaudojant saugumo priemoni\u0173, nepakanka, kad b\u016bt\u0173 galima atremti visas atakas, kuri\u0173 metu i\u0161naudojamos pa\u017eeid\u017eiamosios vietos, o tai lemia SS7 tinkl\u0173 architekt\u016bra. Panagrin\u0117kime vien\u0105 atvej\u012f. Ataka virto veiksm\u0173 seka, kuri\u0105 atakos aptikimo proced\u016bra sugeb\u0117jo sujungti \u012f tik\u0117tin\u0105 serij\u0105, nors saugumo metodai nesugeb\u0117jo suprasti eili\u0161kumo. Pirmiausia u\u017epuolikai paliko s\u0117kmingas pastangas surasti abonento IMSI. Gav\u0119 informacijos veiklai vykdyti, jie steng\u0117si surasti abonent\u0105. \u0160is atakos ta\u0161kas \u017elugo. U\u017epuolikai i\u0161siunt\u0117 peticij\u0105 abonento registracijai tinkle. Peticija buvo patvirtinta operatoriaus tinkle. Jie gal\u0117jo perimti abonento \u012feinan\u010dius telefono skambu\u010dius ir SMS \u017einutes - toks buvo j\u0173 tikslas. Kod\u0117l gi mums detaliau nei\u0161nagrin\u0117jus kiekvienos priemon\u0117s?<\/p>\n<p>PT TAD pavojaus aptikimo ir atsakymo proced\u016bra atpa\u017eino \"SendRoutingInfoForSM\" prane\u0161imus, pristatytus i\u0161oriniame serveryje \u012f tam tikr\u0105 savo operatoriaus nam\u0173 tinklo abonent\u0105. Prane\u0161imai taip pat buvo paskelbti kaip abejotini, nenuostabu, kad galiojan\u010di\u0173 veiksm\u0173 atveju, nes po j\u0173 nebuvo glaud\u017eiai sekan\u010di\u0173 SMS \u017einu\u010di\u0173. Priemon\u0117s pastangos sek\u0117 atid\u017eiai po kiekvienos med\u017eiagos, skirtos atakuoti tinkl\u0105 per ProvideSubscriberInfo, kuri buvo kliudoma su \u0161iuo tinklu. Net PT TAD metodu nustatyta, kad SendRoutingInfoForSM kartu su ProvideSubscriberInfo atak\u0173 mi\u0161inys naudojant tik vien\u0105 2 minu\u010di\u0173 laikotarp\u012f, o tai rei\u0161kia, kad abonento paie\u0161ka baigta.<\/p>\n<p>&nbsp;<\/p>\n<h2>I\u0161vados:<\/h2>\n<p>Kaip matome, daugelis mobiliojo ry\u0161io operatori\u0173 apsaugo savo SS7 mar\u017e\u0105 perkonfig\u016bruodami tinklo tiekim\u0105 ir taikydami SMS nam\u0173 \u016bkio mar\u0161ruto nustatymo priemones. Tai tikrai gali b\u016bti priemon\u0117, padedanti apsisaugoti nuo SS7 atak\u0173, ta\u010diau jos galb\u016bt nepakanka tinklui apsaugoti. M\u016bs\u0173 tyrimas, taip pat saugumo tyrim\u0173 klinikos rodo, kad yra galimybi\u0173 vykdyti SS7 i\u0161puolius, kurie praleid\u017eia toki\u0105 saugumo mechanik\u0105. Be to, atakos yra \u0161iek tiek slaptos ir jas sunku aptikti nuo ma\u017eens. Tod\u0117l sp\u0117jame, kad mobiliojo ry\u0161io operatoriai turi dalyvauti i\u0161orini\u0173 SS7 ry\u0161i\u0173 saugumo steb\u0117jime, kur\u012f skatina naujausi poveikio pagrindai.<\/p>","protected":false},"excerpt":{"rendered":"<p>Atakos, nukreiptos \u012f atsisakym\u0105 teikti paslaugas, pasirod\u0117 esan\u010dios ne kitokios, o tik 7,8 proc. \u0161ios r\u016b\u0161ies atak\u0173 \u0161iuo metu tampa galingos. Netgi buvo naudojama InsertSubscriberData sistema, ta\u010diau 99 proc. prane\u0161im\u0173 liko cikliniai - jie tikrai buvo atmesti i\u0161 operatoriaus tinklo. Lankytojai ir filtravimas tur\u0117jo nema\u017e\u0105 poveik\u012f...<\/p>","protected":false},"author":1,"featured_media":1736,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[69,1],"tags":[],"class_list":["post-457","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sms-intercept","category-ss7-sms"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.7 (Yoast SEO v26.7) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Attack example of SS7<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/sms-txt.net\/lt\/ss7-sms\/ss7-atakos-pavyzdys\/\" \/>\n<meta property=\"og:locale\" content=\"lt_LT\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Attack example of SS7\" \/>\n<meta property=\"og:description\" content=\"Attacks targeted toward denial of service proved perhaps not different, together with just 7.8 percentage of this kind of attack currently becoming powerful. Even the InsertSubscriberData system was utilized, however, 99 percent of the messages stayed cyclical &#8211;that they certainly were dismissed from the operator network. Visitors and filtering had a Considerable Impact on the...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/sms-txt.net\/lt\/ss7-sms\/ss7-atakos-pavyzdys\/\" \/>\n<meta property=\"og:site_name\" content=\"SS7 Hacking\" \/>\n<meta property=\"article:published_time\" content=\"2024-04-28T04:21:28+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-09-05T09:46:56+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/sms-txt.net\/wp-content\/uploads\/2020\/07\/Attack-example-of-SS7.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"900\" \/>\n\t<meta property=\"og:image:height\" content=\"507\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"ss7\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"ss7\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/\"},\"author\":{\"name\":\"ss7\",\"@id\":\"https:\/\/sms-txt.net\/#\/schema\/person\/fa482bf9132db58e46bb9c9df2d73be0\"},\"headline\":\"Attack example of SS7\",\"datePublished\":\"2024-04-28T04:21:28+00:00\",\"dateModified\":\"2024-09-05T09:46:56+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/\"},\"wordCount\":513,\"publisher\":{\"@id\":\"https:\/\/sms-txt.net\/#organization\"},\"image\":{\"@id\":\"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/sms-txt.net\/wp-content\/uploads\/2020\/07\/Attack-example-of-SS7.jpg\",\"articleSection\":[\"SMS Intercept\",\"SS7\"],\"inLanguage\":\"lt-LT\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/\",\"url\":\"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/\",\"name\":\"Attack example of SS7\",\"isPartOf\":{\"@id\":\"https:\/\/sms-txt.net\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/sms-txt.net\/wp-content\/uploads\/2020\/07\/Attack-example-of-SS7.jpg\",\"datePublished\":\"2024-04-28T04:21:28+00:00\",\"dateModified\":\"2024-09-05T09:46:56+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/#breadcrumb\"},\"inLanguage\":\"lt-LT\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"lt-LT\",\"@id\":\"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/#primaryimage\",\"url\":\"https:\/\/sms-txt.net\/wp-content\/uploads\/2020\/07\/Attack-example-of-SS7.jpg\",\"contentUrl\":\"https:\/\/sms-txt.net\/wp-content\/uploads\/2020\/07\/Attack-example-of-SS7.jpg\",\"width\":900,\"height\":507},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/sms-txt.net\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Attack example of SS7\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/sms-txt.net\/#website\",\"url\":\"https:\/\/sms-txt.net\/\",\"name\":\"SS7 Hacking\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/sms-txt.net\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/sms-txt.net\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"lt-LT\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/sms-txt.net\/#organization\",\"name\":\"SS7\",\"url\":\"https:\/\/sms-txt.net\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"lt-LT\",\"@id\":\"https:\/\/sms-txt.net\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/yellow-jaguar-454368.hostingersite.com\/wp-content\/uploads\/2020\/05\/logo.jpg\",\"contentUrl\":\"https:\/\/yellow-jaguar-454368.hostingersite.com\/wp-content\/uploads\/2020\/05\/logo.jpg\",\"width\":866,\"height\":680,\"caption\":\"SS7\"},\"image\":{\"@id\":\"https:\/\/sms-txt.net\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/sms-txt.net\/#\/schema\/person\/fa482bf9132db58e46bb9c9df2d73be0\",\"name\":\"ss7\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"SS7 atakos pavyzdys","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/sms-txt.net\/lt\/ss7-sms\/ss7-atakos-pavyzdys\/","og_locale":"lt_LT","og_type":"article","og_title":"Attack example of SS7","og_description":"Attacks targeted toward denial of service proved perhaps not different, together with just 7.8 percentage of this kind of attack currently becoming powerful. Even the InsertSubscriberData system was utilized, however, 99 percent of the messages stayed cyclical &#8211;that they certainly were dismissed from the operator network. Visitors and filtering had a Considerable Impact on the...","og_url":"https:\/\/sms-txt.net\/lt\/ss7-sms\/ss7-atakos-pavyzdys\/","og_site_name":"SS7 Hacking","article_published_time":"2024-04-28T04:21:28+00:00","article_modified_time":"2024-09-05T09:46:56+00:00","og_image":[{"width":900,"height":507,"url":"https:\/\/sms-txt.net\/wp-content\/uploads\/2020\/07\/Attack-example-of-SS7.jpg","type":"image\/jpeg"}],"author":"ss7","twitter_card":"summary_large_image","twitter_misc":{"Written by":"ss7","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/#article","isPartOf":{"@id":"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/"},"author":{"name":"ss7","@id":"https:\/\/sms-txt.net\/#\/schema\/person\/fa482bf9132db58e46bb9c9df2d73be0"},"headline":"Attack example of SS7","datePublished":"2024-04-28T04:21:28+00:00","dateModified":"2024-09-05T09:46:56+00:00","mainEntityOfPage":{"@id":"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/"},"wordCount":513,"publisher":{"@id":"https:\/\/sms-txt.net\/#organization"},"image":{"@id":"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/#primaryimage"},"thumbnailUrl":"https:\/\/sms-txt.net\/wp-content\/uploads\/2020\/07\/Attack-example-of-SS7.jpg","articleSection":["SMS Intercept","SS7"],"inLanguage":"lt-LT"},{"@type":"WebPage","@id":"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/","url":"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/","name":"SS7 atakos pavyzdys","isPartOf":{"@id":"https:\/\/sms-txt.net\/#website"},"primaryImageOfPage":{"@id":"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/#primaryimage"},"image":{"@id":"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/#primaryimage"},"thumbnailUrl":"https:\/\/sms-txt.net\/wp-content\/uploads\/2020\/07\/Attack-example-of-SS7.jpg","datePublished":"2024-04-28T04:21:28+00:00","dateModified":"2024-09-05T09:46:56+00:00","breadcrumb":{"@id":"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/#breadcrumb"},"inLanguage":"lt-LT","potentialAction":[{"@type":"ReadAction","target":["https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/"]}]},{"@type":"ImageObject","inLanguage":"lt-LT","@id":"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/#primaryimage","url":"https:\/\/sms-txt.net\/wp-content\/uploads\/2020\/07\/Attack-example-of-SS7.jpg","contentUrl":"https:\/\/sms-txt.net\/wp-content\/uploads\/2020\/07\/Attack-example-of-SS7.jpg","width":900,"height":507},{"@type":"BreadcrumbList","@id":"https:\/\/sms-txt.net\/ss7-sms\/attack-example-of-ss7\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/sms-txt.net\/"},{"@type":"ListItem","position":2,"name":"Attack example of SS7"}]},{"@type":"WebSite","@id":"https:\/\/sms-txt.net\/#website","url":"https:\/\/sms-txt.net\/","name":"SS7 \u012fsilau\u017eimas","description":"","publisher":{"@id":"https:\/\/sms-txt.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/sms-txt.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"lt-LT"},{"@type":"Organization","@id":"https:\/\/sms-txt.net\/#organization","name":"SS7","url":"https:\/\/sms-txt.net\/","logo":{"@type":"ImageObject","inLanguage":"lt-LT","@id":"https:\/\/sms-txt.net\/#\/schema\/logo\/image\/","url":"https:\/\/yellow-jaguar-454368.hostingersite.com\/wp-content\/uploads\/2020\/05\/logo.jpg","contentUrl":"https:\/\/yellow-jaguar-454368.hostingersite.com\/wp-content\/uploads\/2020\/05\/logo.jpg","width":866,"height":680,"caption":"SS7"},"image":{"@id":"https:\/\/sms-txt.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/sms-txt.net\/#\/schema\/person\/fa482bf9132db58e46bb9c9df2d73be0","name":"ss7"}]}},"_links":{"self":[{"href":"https:\/\/sms-txt.net\/lt\/wp-json\/wp\/v2\/posts\/457","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sms-txt.net\/lt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sms-txt.net\/lt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sms-txt.net\/lt\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sms-txt.net\/lt\/wp-json\/wp\/v2\/comments?post=457"}],"version-history":[{"count":0,"href":"https:\/\/sms-txt.net\/lt\/wp-json\/wp\/v2\/posts\/457\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sms-txt.net\/lt\/wp-json\/wp\/v2\/media\/1736"}],"wp:attachment":[{"href":"https:\/\/sms-txt.net\/lt\/wp-json\/wp\/v2\/media?parent=457"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sms-txt.net\/lt\/wp-json\/wp\/v2\/categories?post=457"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sms-txt.net\/lt\/wp-json\/wp\/v2\/tags?post=457"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}