Wrong confirmation ID
  • Email
  • Favorite
  • Download
  • Embed
  • Private Content

Attacking GRX - GPRS Roaming eXchange

by p1sec on Oct 27, 2011

  • 3,839 views

GRX is the global private network where telecom network operators exchange GPRS roaming traffic of their users. It’s also used for all M2M networks where roaming is used, and that is the case from so...

GRX is the global private network where telecom network operators exchange GPRS roaming traffic of their users. It’s also used for all M2M networks where roaming is used, and that is the case from some company’s truck fleet management system down to intelligence GPS location spybug tracking system.

GPRS has been there from 2.5G GSM networks to the upcoming LTE Advanced networks, and is now quite widespread technology, along with its attacks. GRX has had a structuring role in the global telecom world at a time where IP dominance was beginning to be acknowledged. Now it has expanded to a lightweight structure using both IP technologies and ITU-originated protocols.

In this presentation, we’ll see how this infrastructure is protected and how it can be attacked. We’ll discover the issues with specific telco equipment inside GRX, namely GGSN and SGSN but also now PDN Gateways in LTE and LTE Advanced “Evolved Packet Core”. We will see the implications of this with GTP protocol, DNS infrastructure, AAA servers and core network technologies such as MPLS, IPsec VPNs and their associated routing protocols. These network elements were rarely evaluated for security, and during our engagements with vulnerability analysis, we’ve seen several vulnerabilities that we will be showing in this speech.

We will demo some of the attacks on a simulated “PS Domain” network, that it the IP part of the Telecom Core Network that transports customers’ traffic, and investigate its relationships with legacy SS7, SIGTRAN IP backbones, M2M private corporate VPNs and telecom billing systems. We will also seem how automation enable us to succeed at attacks which are hard to perform and will show how a “sentinel” attack was able to compromise a telecom Core Network during one penetration test.

Accessibility

Categories

Tags

network security ss7 hacking hack lte

More...

Upload Details

Uploaded via SlideShare as Adobe PDF

Usage Rights

© All Rights Reserved

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

Cancel

9 Embeds 3,430

http://www.p1sec.com 2652
http://www.p1security.com 690
http://p1security.com 65
http://translate.googleusercontent.com 10
http://xss.yandex.net 6
http://p1-security.com 3
http://anonymouse.org 2
http://www.p1-security.com 1
http://www.google.nl 1

More...

Statistics

Favorites
2
Downloads
67
Comments
0
Embed Views
3,430
Views on SlideShare
409
Total Views
3,839
Post Comment
Edit your comment Cancel

Attacking GRX - GPRS Roaming eXchange — Presentation Transcript