{"id":360,"date":"2023-12-07T03:12:42","date_gmt":"2023-12-07T00:12:42","guid":{"rendered":"https:\/\/sms-txt.net\/?p=360"},"modified":"2024-09-05T12:44:42","modified_gmt":"2024-09-05T09:44:42","slug":"ss7-avlyssning-av-samtal","status":"publish","type":"post","link":"https:\/\/sms-txt.net\/sv\/avlyssning-av-samtal\/ss7-avlyssning-av-samtal\/","title":{"rendered":"SS7 Avlyssning av samtal"},"content":{"rendered":"<p>Mobilv\u00e4xeln MSC har normalt de krypteringsnycklar som anv\u00e4nds av varje abonnent f\u00f6r att kunna etablera samtalet. N\u00e4r abonnenten \u00e4r p\u00e5 resande fot underl\u00e4ttar en \u00f6verl\u00e4mningsprocess en smidig \u00f6verg\u00e5ng mellan olika radioceller samtidigt som samtalet uppr\u00e4tth\u00e5lls.<\/p>\n<p>I vissa fall flyttar abonnenten fr\u00e5n en cell till en annan som hanteras av en annan VLR. I detta fall har den nya VLR:n inte fr\u00e5n b\u00f6rjan den autentiseringsinformation som skulle g\u00f6ra det l\u00e4ttare att uppr\u00e4tth\u00e5lla samtalet, och d\u00e4rf\u00f6r kr\u00e4vs en \u00f6verl\u00e4mningsprocess mellan MSC:er f\u00f6r att \u00f6verf\u00f6ra nycklarna till den nya MSC:en.<\/p>\n<p>Detta g\u00f6rs genom ett MAP-meddelande som heter sendIdentification. Den nya VLR:n skickar ett sendIdentification-meddelande till den gamla VLR:n, som i sin tur svarar med de nycklar som beh\u00f6vs f\u00f6r att uppr\u00e4tth\u00e5lla det p\u00e5g\u00e5ende samtalet.  Bland dessa nycklar finns den nyckel som anv\u00e4nds f\u00f6r att kryptera trafiken i luften. I angreppsscenariot f\u00e5ngar angriparen upp m\u00e5lets trafik via luftgr\u00e4nssnittet (vilket kr\u00e4ver fysisk n\u00e4rhet till m\u00e5let).<\/p>\n<p>Med tillg\u00e5ng till SS7 kan han sedan anv\u00e4nda sendIdentification-meddelandet f\u00f6r att h\u00e4mta dekrypteringsnycklarna f\u00f6r m\u00e5let och anv\u00e4nda dem f\u00f6r att dekryptera trafiken. SendIdentification beh\u00f6vs endast inom det interna n\u00e4tverket under<br \/>\n\u00d6verl\u00e4mningar. Den f\u00e5r inte ha n\u00e5gon legitim anv\u00e4ndning utifr\u00e5n och b\u00f6r d\u00e4rf\u00f6r filtreras vid gr\u00e4nsen.<\/p>\n<h2>Avlyssning av utg\u00e5ende samtal<\/h2>\n<p>GSM Service Control Function (gsmSCF) \u00e4r en funktionell enhet som inneh\u00e5ller CAMEL-tj\u00e4nstelogiken som f\u00f6r en viss upps\u00e4ttning h\u00e4ndelser med s\u00e4kerhet avg\u00f6r om den \u00f6nskade \u00e5tg\u00e4rden kan forts\u00e4tta modifierad, of\u00f6r\u00e4ndrad eller avbrytas. Den kan t.ex. anv\u00e4ndas f\u00f6r att \u00e4ndra utg\u00e5ende nummer s\u00e5 att riktnummer eller internationellt format l\u00e4ggs till.<\/p>\n<p>En angripare med tillg\u00e5ng till SS7 kan anv\u00e4nda ett insertSubscriberData-meddelande f\u00f6r att \u00e4ndra abonnentens gsmSCF-adress till en adress som angriparen kontrollerar. Angriparen kan sedan skriva om utg\u00e5ende uppringda nummer till ett nummer som st\u00e5r under hans kontroll. I detta fall kommer angriparen att ta emot det utg\u00e5ende samtalet, spela in samtalet innan trafiken vidarebefordras till slutdestinationen.<\/p>\n<h2>Avlyssning - Inkommande trafik - Vidarekoppling<\/h2>\n<p>Meddelandet registerSS anv\u00e4nds f\u00f6r att registrera till\u00e4ggstj\u00e4nster till en abonnent. En av dessa tj\u00e4nster \u00e4r tj\u00e4nsten f\u00f6r vidarekoppling av samtal. En angripare kan anv\u00e4nda registerSS-meddelandet f\u00f6r att aktivera vidarekoppling av samtal till ett nummer som han kontrollerar. N\u00e4r han tar emot samtalet anv\u00e4nder han eraseSS-meddelandet f\u00f6r att ta bort vidarekopplingen och sedan koppla tillbaka samtalet till abonnenten. P\u00e5 detta s\u00e4tt kan angriparen avlyssna och spela in samtalet.<\/p>","protected":false},"excerpt":{"rendered":"<p>Mobilv\u00e4xeln MSC har normalt de krypteringsnycklar som anv\u00e4nds av varje abonnent f\u00f6r att kunna etablera samtalet. N\u00e4r abonnenten \u00e4r p\u00e5 resande fot underl\u00e4ttar en \u00f6verl\u00e4mningsprocess en smidig \u00f6verg\u00e5ng mellan de olika radiocellerna samtidigt som samtalet forts\u00e4tter. I vissa fall flyttar abonnenten fr\u00e5n...<\/p>","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[68],"tags":[],"class_list":["post-360","post","type-post","status-publish","format-standard","hentry","category-call-interception"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.7 (Yoast SEO v26.7) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>SS7 Call Interception<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/sms-txt.net\/sv\/avlyssning-av-samtal\/ss7-avlyssning-av-samtal\/\" \/>\n<meta property=\"og:locale\" content=\"sv_SE\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SS7 Call Interception\" \/>\n<meta property=\"og:description\" content=\"The mobile switching center MSC normally holds the encryption keys used by each subscriber to be able to establish the call. When the subscriber is on the move, a handover process facilitates the smooth transition of the subscriber between the different radio cells while maintain the call progress. In some cases the subscriber moves from...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/sms-txt.net\/sv\/avlyssning-av-samtal\/ss7-avlyssning-av-samtal\/\" \/>\n<meta property=\"og:site_name\" content=\"SS7 Hacking\" \/>\n<meta property=\"article:published_time\" content=\"2023-12-07T00:12:42+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-09-05T09:44:42+00:00\" \/>\n<meta name=\"author\" content=\"ss7\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"ss7\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/\"},\"author\":{\"name\":\"ss7\",\"@id\":\"https:\/\/sms-txt.net\/#\/schema\/person\/fa482bf9132db58e46bb9c9df2d73be0\"},\"headline\":\"SS7 Call Interception\",\"datePublished\":\"2023-12-07T00:12:42+00:00\",\"dateModified\":\"2024-09-05T09:44:42+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/\"},\"wordCount\":422,\"publisher\":{\"@id\":\"https:\/\/sms-txt.net\/#organization\"},\"articleSection\":[\"Call Interception\"],\"inLanguage\":\"sv-SE\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/\",\"url\":\"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/\",\"name\":\"SS7 Call Interception\",\"isPartOf\":{\"@id\":\"https:\/\/sms-txt.net\/#website\"},\"datePublished\":\"2023-12-07T00:12:42+00:00\",\"dateModified\":\"2024-09-05T09:44:42+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/#breadcrumb\"},\"inLanguage\":\"sv-SE\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/sms-txt.net\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SS7 Call Interception\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/sms-txt.net\/#website\",\"url\":\"https:\/\/sms-txt.net\/\",\"name\":\"SS7 Hacking\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/sms-txt.net\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/sms-txt.net\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"sv-SE\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/sms-txt.net\/#organization\",\"name\":\"SS7\",\"url\":\"https:\/\/sms-txt.net\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"sv-SE\",\"@id\":\"https:\/\/sms-txt.net\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/yellow-jaguar-454368.hostingersite.com\/wp-content\/uploads\/2020\/05\/logo.jpg\",\"contentUrl\":\"https:\/\/yellow-jaguar-454368.hostingersite.com\/wp-content\/uploads\/2020\/05\/logo.jpg\",\"width\":866,\"height\":680,\"caption\":\"SS7\"},\"image\":{\"@id\":\"https:\/\/sms-txt.net\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/sms-txt.net\/#\/schema\/person\/fa482bf9132db58e46bb9c9df2d73be0\",\"name\":\"ss7\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"SS7 Avlyssning av samtal","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/sms-txt.net\/sv\/avlyssning-av-samtal\/ss7-avlyssning-av-samtal\/","og_locale":"sv_SE","og_type":"article","og_title":"SS7 Call Interception","og_description":"The mobile switching center MSC normally holds the encryption keys used by each subscriber to be able to establish the call. When the subscriber is on the move, a handover process facilitates the smooth transition of the subscriber between the different radio cells while maintain the call progress. In some cases the subscriber moves from...","og_url":"https:\/\/sms-txt.net\/sv\/avlyssning-av-samtal\/ss7-avlyssning-av-samtal\/","og_site_name":"SS7 Hacking","article_published_time":"2023-12-07T00:12:42+00:00","article_modified_time":"2024-09-05T09:44:42+00:00","author":"ss7","twitter_card":"summary_large_image","twitter_misc":{"Written by":"ss7","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/#article","isPartOf":{"@id":"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/"},"author":{"name":"ss7","@id":"https:\/\/sms-txt.net\/#\/schema\/person\/fa482bf9132db58e46bb9c9df2d73be0"},"headline":"SS7 Call Interception","datePublished":"2023-12-07T00:12:42+00:00","dateModified":"2024-09-05T09:44:42+00:00","mainEntityOfPage":{"@id":"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/"},"wordCount":422,"publisher":{"@id":"https:\/\/sms-txt.net\/#organization"},"articleSection":["Call Interception"],"inLanguage":"sv-SE"},{"@type":"WebPage","@id":"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/","url":"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/","name":"SS7 Avlyssning av samtal","isPartOf":{"@id":"https:\/\/sms-txt.net\/#website"},"datePublished":"2023-12-07T00:12:42+00:00","dateModified":"2024-09-05T09:44:42+00:00","breadcrumb":{"@id":"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/#breadcrumb"},"inLanguage":"sv-SE","potentialAction":[{"@type":"ReadAction","target":["https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/sms-txt.net\/call-interception\/ss7-call-interception\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/sms-txt.net\/"},{"@type":"ListItem","position":2,"name":"SS7 Call Interception"}]},{"@type":"WebSite","@id":"https:\/\/sms-txt.net\/#website","url":"https:\/\/sms-txt.net\/","name":"SS7-hackning","description":"","publisher":{"@id":"https:\/\/sms-txt.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/sms-txt.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"sv-SE"},{"@type":"Organization","@id":"https:\/\/sms-txt.net\/#organization","name":"SS7","url":"https:\/\/sms-txt.net\/","logo":{"@type":"ImageObject","inLanguage":"sv-SE","@id":"https:\/\/sms-txt.net\/#\/schema\/logo\/image\/","url":"https:\/\/yellow-jaguar-454368.hostingersite.com\/wp-content\/uploads\/2020\/05\/logo.jpg","contentUrl":"https:\/\/yellow-jaguar-454368.hostingersite.com\/wp-content\/uploads\/2020\/05\/logo.jpg","width":866,"height":680,"caption":"SS7"},"image":{"@id":"https:\/\/sms-txt.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/sms-txt.net\/#\/schema\/person\/fa482bf9132db58e46bb9c9df2d73be0","name":"ss7"}]}},"_links":{"self":[{"href":"https:\/\/sms-txt.net\/sv\/wp-json\/wp\/v2\/posts\/360","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sms-txt.net\/sv\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sms-txt.net\/sv\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sms-txt.net\/sv\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sms-txt.net\/sv\/wp-json\/wp\/v2\/comments?post=360"}],"version-history":[{"count":0,"href":"https:\/\/sms-txt.net\/sv\/wp-json\/wp\/v2\/posts\/360\/revisions"}],"wp:attachment":[{"href":"https:\/\/sms-txt.net\/sv\/wp-json\/wp\/v2\/media?parent=360"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sms-txt.net\/sv\/wp-json\/wp\/v2\/categories?post=360"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sms-txt.net\/sv\/wp-json\/wp\/v2\/tags?post=360"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}