6 ms·
This is not a SS7 attack. SS7 attacks doesn't work in practice. Eg A lot of carriers in US are CDMA. GSMA Carriers like AT&T has great firewalls in place to blo
by wealthyyy 6y ago
This is not a SS7 attack. SS7 attacks doesn't work in practice. Eg A lot of carriers in US are CDMA. GSMA Carriers like AT&T has great firewalls in place to block SS7 attacks.
Further, You can detect SS7 attacks. Major Banks already has measures in place...
- baybal2 6y agoSS7 attacks work in practice. Any network in existence that has roaming enabled is vulnerable to fake roaming requests, and they cannot be "firewalled." Seeing you implying that CDMA is somehow more resistant than GSM means you know very little how cell networks work. The telephony layer for both is SS7.
- wealthyyy 6y agoThe Banks already has anti fraud detection systems in place to detect Roaming attacks. They can see whether number is Roaming enabled or not. The Telecoms do prevent it with Firewalls. As for CDMA, Please see, https://www.wyden.senate.gov/imo/media/doc/Verizon%20SS7%20Letter.pdf https://www.wyden.senate.gov/imo/media/doc/Verizon%20SS7%20L...
- baybal2 6y agoBanks cannot see if a number is in roaming or not, unless the phone company explicitly tells them through some means. I so far never heard of anything like this.
- wealthyyy 6y agoHow come you forget about HLR? Banks can see. There are lot of APIs on the web that provides this capability. One example, https://www.messagebird.com/lookup/ https://www.messagebird.com/lookup/
- baybal2 6y agoThat looks more interesting. Never heard of such APIs being sold for more than a single operator. How many operators in the world sell them this access?
- deleted 6y ago[deleted]
- wealthyyy 6y agohttps://positive-tech.com/products/signalling-firewall/ https://positive-tech.com/products/signalling-firewall/ Please try attacking this Firewall.
- nulbyte 6y agoIsn't it? SMS relies on SS7 to exchange messages. It may not be a direct attack on the network itself, but because of outside dependencies and a history of telcos trusting themselves to get it right (or simply not caring when it's wrong), this attack successfully results in messages getting routed elsewhere on the network.
- wealthyyy 6y agoThis attack is based on a Routing network not SS7. CDMA carriers don't use SS7 for SMS unless you're on Roaming.