• XSS.stack #1 – первый литературный журнал от юзеров форума

GSM Pentest mobile

you want pentest using a mobile --> install NetHunter or Termux etc

you want learn exploit dev for androids --> start by learning java, basics of ARM
 
SS7 has nothing to do with mobile, it's basically a general telephony protocol. Yeah, its leveraged by mobile operators as well that's true, but you have even more chances to exploit it by hacking into a VoIP (SIP) - SS7 gateway device. Can be even a linux with Asterix and the right hardware/interfaces. First you must understand the protocol or just fuzzy some fields and see what happens. Just saying "scan for vulnerability" shows you don't have a plan...
In my experience is more likely to find an implementation mistake leading to a vuln with some vendor than finding a general flaw in the protocol stack. If that is what you want, I'd rather suggest a protocol emulator over messing with a real gateway without knowing what you are doing.
 
SS7 has nothing to do with mobile, it's basically a general telephony protocol. Yeah, its leveraged by mobile operators as well that's true, but you have even more chances to exploit it by hacking into a VoIP (SIP) - SS7 gateway device. Can be even a linux with Asterix and the right hardware/interfaces. First you must understand the protocol or just fuzzy some fields and see what happens. Just saying "scan for vulnerability" shows you don't have a plan...
In my experience is more likely to find an implementation mistake leading to a vuln with some vendor than finding a general flaw in the protocol stack. If that is what you want, I'd rather suggest a protocol emulator over messing with a real gateway without knowing what you are doing.
ty i already do some pt in different phone and tablet just i ask to understand better this area to learn more and compare if some procedure ll be different from course i study
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх