5G SAAdvanced⏱️ 4-6 hours

5G Core Penetration Testing Guide

End-to-end methodology for auditing 5G Standalone Core Service-Based Architecture interfaces, from reconnaissance through exploitation and reporting.

5G Core Penetration Testing — Complete Methodology

This guide provides a structured, repeatable methodology for security-testing 5G Standalone (SA) Core networks. It covers Service-Based Architecture (SBA) HTTP/2 API testing, N2/N3 interface exploitation, authentication protocol analysis, and network function privilege escalation.

Prerequisites

  • TelcoChisel OS with Open5GS or free5GC installed and running
  • UERANSIM or gnbsim for UE/gNodeB simulation
  • curl, httpie, or Burp Suite for HTTP/2 API testing
  • Basic understanding of 3GPP 5G System Architecture (TS 23.501, TS 29.500)

Phase 1: Reconnaissance & Service Discovery

1.1 Identify Active Network Functions

The 5G Core SBA exposes HTTP/2 REST APIs on well-known ports. Start by discovering active NFs:

# Scan for common 5G Core SBA ports
nmap -sT -p 7777,8000,8080,8443,29518,29519 --open -oA 5g-core-scan 127.0.0.0/24

# Check NRF (Network Repository Function) for registered services
curl -k -X GET http://127.0.0.10:8000/nnrf-disc/v1/nf-instances?nf-type=AMF
curl -k -X GET http://127.0.0.10:8000/nnrf-disc/v1/nf-instances?nf-type=SMF
curl -k -X GET http://127.0.0.10:8000/nnrf-disc/v1/nf-instances?nf-type=UDM

1.2 Enumerate NF API Surfaces

# Discover AMF available APIs
curl -k http://127.0.0.5:7777/namf-comm/v1/ue-contexts

# Discover SMF session management endpoints
curl -k http://127.0.0.4:7777/nsmf-pdusession/v1/sm-contexts

# Discover UDM subscriber data endpoints
curl -k http://127.0.0.12:7777/nudm-sdm/v2/imsi-001010000000001/nssai

Phase 2: Authentication & Authorization Testing

2.1 NRF Token Authorization Bypass

Test whether NFs properly validate OAuth2 tokens issued by the NRF:

# Request an access token from NRF
curl -k -X POST http://127.0.0.10:8000/oauth2/token \
  -d "grant_type=client_credentials&nfInstanceId=test-nf-001&nfType=AMF&targetNfType=UDM&scope=nudm-sdm"

# Attempt to use the token against a different NF than authorized
curl -k -H "Authorization: Bearer <TOKEN>" \
  http://127.0.0.4:7777/nsmf-pdusession/v1/sm-contexts

2.2 SUPI/SUCI Privacy Testing

Verify that SUPI (Subscription Permanent Identifier) is properly concealed:

# Monitor N1/N2 signaling for plaintext SUPI exposure
sudo tshark -i lo -Y "ngap" -T fields -e nas_5gs.mm.supi

# Attempt registration with a crafted SUCI using null scheme
# (Tests ECIES Profile A/B implementation)

Phase 3: Protocol Fuzzing & Injection

3.1 NGAP (N2 Interface) Fuzzing

# Launch UERANSIM gNodeB against the target AMF
nr-gnb -c /etc/ueransim/gnb.yaml

# Send malformed NGAP messages
# Monitor AMF crash behavior and error handling
sudo tshark -i lo -Y "ngap" -T pdml > ngap_capture.xml

3.2 GTP-U (N3 Interface) Data Plane Testing

# Test UPF TEID allocation and GTP tunnel handling
# Use gnbsim to generate high-volume GTP-U traffic
gnbsim --cfg /etc/gnbsim/fuzz-config.json --num-ue 100

# Monitor for data plane leaks across UE sessions
sudo tshark -i ogstun -Y "gtp" -T fields -e gtp.teid -e ip.src -e ip.dst

Phase 4: Reporting & Remediation

4.1 Common Findings

FindingSeverityCVSSRemediation
NRF token not validated by NFsCritical9.8Enable mandatory OAuth2 token verification on all SBI endpoints
SUPI exposed in plaintext on N1High8.1Enforce SUCI with ECIES Profile A (curve25519)
No rate limiting on SBI APIsMedium5.3Implement per-NF request rate limiting
GTP-U cross-session data leakCritical9.1Enforce TEID isolation per PDU session

4.2 3GPP Security Specification References

  • TS 33.501: Security architecture and procedures for 5G System
  • TS 29.510: NRF Services (NFDiscovery, NFManagement, AccessToken)
  • TS 33.535: Authentication and Key Management for HTTP-based APIs
  • TS 29.244: PFCP interface specification (UPF control)

Practice in TelcoSec Academy

👉 Launch the 5G Core Red Team Lab on App.TelcoSec.Net