fos lte imsi catchers - h.a.c.k.catching the imsi • no more key/security context in ue • ue will...

17
FOS LTE IMSI CATCHER DOMI

Upload: others

Post on 26-May-2020

22 views

Category:

Documents


0 download

TRANSCRIPT

FOSLTEIMSICATCHERDOMI

WARNING!ThistalkwillbeaboutclassicIMSIcatchers– do

notexpectMITMcalls,dataetc.

GSMIMSIcatcher- recap• CreateafakeBTSwith• highreselectionvalue(C1,C2)• randomlocationareacode

• PhoneswillconnectandinitiateLocationUpdate• ReplywithIdentityRequest(requestIMSI)• AftergettingtheIMSIsendLUReject– cause13oranyotherdependingonyourintention

Whycouldwedothis?Nomutualauthentication,thenetworkisalwaystrusted

Rejectmessagesneedtobeunencrypted

(Sh*tty ornullcryptoalsoleadtoMITMetc.)

LTEArchitecture

EUTRANArchitecturebyCrati underCCBY-SA3.0

INTERNETPSTNPLMN

ChangesinLTE•Mutualauthentication

• Integrityprotection

• Bettercrypto

Procedureimprovements•MostproceduresrequireASsecurityenabled(integrityprotection)• UEsdropnon-protectedmessagesoncetheyhaveestablishedsecuritycontext

•Shouldbefine,right?

Tinylittleprotocolproblem…

TrackingAreaUpdateReject• UEsendsaTrackingAreaUpdateRequest• RogueeNodeB rejectsitwithcause9

3GPPTS24.301-5.5.3.2.5

CatchingtheIMSI• Nomorekey/securitycontextinUE

• UEwillinitiateattach

• ItisallowedtoaskforitsIMSIinanIDENTITYREQUEST

• AftergettingitwesendanATTACHREJECTwithcause#12(TrackingAreanotallowed)

HWandSW• USRPandlaptop•ManyopensourceLTEprojects(thisisAWESOMEbtw):•openLTE•OpenAirInterface• srsLTE andsrsUE• OwnimplementationofMME/corenetwork(pendingrequesttoopensourceit)

RogueeNodeB• Needtosomehow‘lure’UEs• InGSMyoujustneededaneighborcell’sfrequency+highreselectionvalue• InLTEalistoffrequenciesarebroadcastedwiththeirpriorities–>youneedtodecodethelist,andselectthefrequencywiththehighestpriority

ThesePeoplearegreat!*APPLAUSE*• Ravishankar Borgaonkar andAltaf ShaikfordiscoveringtheTAURejectvuln (andmanyotherproblems)inLTE• BenoitMichau forthelibrarymycorenetworkisbasedon• PhilippeLanglois andElvisPfützenreuter forpysctp

•MymentorsduringmyinternshipatQualcomm:KevinRedonandNicoGolde

Q&A

Thankyou!Key-ID:E2712651

Fingerprint:811C3FC3CFCB16E4BAEBF5FB7440DF59E2712651