5G Core Penetration Testing — Complete Methodology
This guide provides a structured, repeatable methodology for security-testing 5G Standalone (SA) Core networks. It covers Service-Based Architecture (SBA) HTTP/2 API testing, N2/N3 interface exploitation, authentication protocol analysis, and network function privilege escalation.
Prerequisites
- TelcoChisel OS with Open5GS or free5GC installed and running
- UERANSIM or gnbsim for UE/gNodeB simulation
- curl, httpie, or Burp Suite for HTTP/2 API testing
- Basic understanding of 3GPP 5G System Architecture (TS 23.501, TS 29.500)
Phase 1: Reconnaissance & Service Discovery
1.1 Identify Active Network Functions
The 5G Core SBA exposes HTTP/2 REST APIs on well-known ports. Start by discovering active NFs:
# Scan for common 5G Core SBA ports
nmap -sT -p 7777,8000,8080,8443,29518,29519 --open -oA 5g-core-scan 127.0.0.0/24
# Check NRF (Network Repository Function) for registered services
curl -k -X GET http://127.0.0.10:8000/nnrf-disc/v1/nf-instances?nf-type=AMF
curl -k -X GET http://127.0.0.10:8000/nnrf-disc/v1/nf-instances?nf-type=SMF
curl -k -X GET http://127.0.0.10:8000/nnrf-disc/v1/nf-instances?nf-type=UDM
1.2 Enumerate NF API Surfaces
# Discover AMF available APIs
curl -k http://127.0.0.5:7777/namf-comm/v1/ue-contexts
# Discover SMF session management endpoints
curl -k http://127.0.0.4:7777/nsmf-pdusession/v1/sm-contexts
# Discover UDM subscriber data endpoints
curl -k http://127.0.0.12:7777/nudm-sdm/v2/imsi-001010000000001/nssai
Phase 2: Authentication & Authorization Testing
2.1 NRF Token Authorization Bypass
Test whether NFs properly validate OAuth2 tokens issued by the NRF:
# Request an access token from NRF
curl -k -X POST http://127.0.0.10:8000/oauth2/token \
-d "grant_type=client_credentials&nfInstanceId=test-nf-001&nfType=AMF&targetNfType=UDM&scope=nudm-sdm"
# Attempt to use the token against a different NF than authorized
curl -k -H "Authorization: Bearer <TOKEN>" \
http://127.0.0.4:7777/nsmf-pdusession/v1/sm-contexts
2.2 SUPI/SUCI Privacy Testing
Verify that SUPI (Subscription Permanent Identifier) is properly concealed:
# Monitor N1/N2 signaling for plaintext SUPI exposure
sudo tshark -i lo -Y "ngap" -T fields -e nas_5gs.mm.supi
# Attempt registration with a crafted SUCI using null scheme
# (Tests ECIES Profile A/B implementation)
Phase 3: Protocol Fuzzing & Injection
3.1 NGAP (N2 Interface) Fuzzing
# Launch UERANSIM gNodeB against the target AMF
nr-gnb -c /etc/ueransim/gnb.yaml
# Send malformed NGAP messages
# Monitor AMF crash behavior and error handling
sudo tshark -i lo -Y "ngap" -T pdml > ngap_capture.xml
3.2 GTP-U (N3 Interface) Data Plane Testing
# Test UPF TEID allocation and GTP tunnel handling
# Use gnbsim to generate high-volume GTP-U traffic
gnbsim --cfg /etc/gnbsim/fuzz-config.json --num-ue 100
# Monitor for data plane leaks across UE sessions
sudo tshark -i ogstun -Y "gtp" -T fields -e gtp.teid -e ip.src -e ip.dst
Phase 4: Reporting & Remediation
4.1 Common Findings
| Finding | Severity | CVSS | Remediation |
|---|---|---|---|
| NRF token not validated by NFs | Critical | 9.8 | Enable mandatory OAuth2 token verification on all SBI endpoints |
| SUPI exposed in plaintext on N1 | High | 8.1 | Enforce SUCI with ECIES Profile A (curve25519) |
| No rate limiting on SBI APIs | Medium | 5.3 | Implement per-NF request rate limiting |
| GTP-U cross-session data leak | Critical | 9.1 | Enforce TEID isolation per PDU session |
4.2 3GPP Security Specification References
- TS 33.501: Security architecture and procedures for 5G System
- TS 29.510: NRF Services (NFDiscovery, NFManagement, AccessToken)
- TS 33.535: Authentication and Key Management for HTTP-based APIs
- TS 29.244: PFCP interface specification (UPF control)