[{"data":1,"prerenderedAt":475},["ShallowReactive",2],{"guide-5g-core-penetration-testing":3},{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"protocol":10,"category":11,"difficulty":12,"estimatedTime":13,"tools":14,"body":20,"_type":469,"_id":470,"_source":471,"_file":472,"_stem":473,"_extension":474},"\u002Fguides\u002F5g-core-penetration-testing","guides",false,"","5G Core Penetration Testing Guide","End-to-end methodology for auditing 5G Standalone Core Service-Based Architecture interfaces, from reconnaissance through exploitation and reporting.","5G SA","Protocol Audit Guide","Advanced","4-6 hours",[15,16,17,18,19],"open5gs","free5gc","ueransim","gnbsim","sctpscan",{"type":21,"children":22,"toc":447},"root",[23,32,38,45,106,112,119,124,137,143,152,158,164,169,178,184,189,198,204,210,219,225,234,240,246,375,381,424,430],{"type":24,"tag":25,"props":26,"children":28},"element","h1",{"id":27},"_5g-core-penetration-testing-complete-methodology",[29],{"type":30,"value":31},"text","5G Core Penetration Testing — Complete Methodology",{"type":24,"tag":33,"props":34,"children":35},"p",{},[36],{"type":30,"value":37},"This guide provides a structured, repeatable methodology for security-testing 5G Standalone (SA) Core networks. It covers Service-Based Architecture (SBA) HTTP\u002F2 API testing, N2\u002FN3 interface exploitation, authentication protocol analysis, and network function privilege escalation.",{"type":24,"tag":39,"props":40,"children":42},"h2",{"id":41},"prerequisites",[43],{"type":30,"value":44},"Prerequisites",{"type":24,"tag":46,"props":47,"children":48},"ul",{},[49,61,77,101],{"type":24,"tag":50,"props":51,"children":52},"li",{},[53,59],{"type":24,"tag":54,"props":55,"children":56},"strong",{},[57],{"type":30,"value":58},"TelcoChisel OS",{"type":30,"value":60}," with Open5GS or free5GC installed and running",{"type":24,"tag":50,"props":62,"children":63},{},[64,69,71,75],{"type":24,"tag":54,"props":65,"children":66},{},[67],{"type":30,"value":68},"UERANSIM",{"type":30,"value":70}," or ",{"type":24,"tag":54,"props":72,"children":73},{},[74],{"type":30,"value":18},{"type":30,"value":76}," for UE\u002FgNodeB simulation",{"type":24,"tag":50,"props":78,"children":79},{},[80,85,87,92,94,99],{"type":24,"tag":54,"props":81,"children":82},{},[83],{"type":30,"value":84},"curl",{"type":30,"value":86},", ",{"type":24,"tag":54,"props":88,"children":89},{},[90],{"type":30,"value":91},"httpie",{"type":30,"value":93},", or ",{"type":24,"tag":54,"props":95,"children":96},{},[97],{"type":30,"value":98},"Burp Suite",{"type":30,"value":100}," for HTTP\u002F2 API testing",{"type":24,"tag":50,"props":102,"children":103},{},[104],{"type":30,"value":105},"Basic understanding of 3GPP 5G System Architecture (TS 23.501, TS 29.500)",{"type":24,"tag":39,"props":107,"children":109},{"id":108},"phase-1-reconnaissance-service-discovery",[110],{"type":30,"value":111},"Phase 1: Reconnaissance & Service Discovery",{"type":24,"tag":113,"props":114,"children":116},"h3",{"id":115},"_11-identify-active-network-functions",[117],{"type":30,"value":118},"1.1 Identify Active Network Functions",{"type":24,"tag":33,"props":120,"children":121},{},[122],{"type":30,"value":123},"The 5G Core SBA exposes HTTP\u002F2 REST APIs on well-known ports. Start by discovering active NFs:",{"type":24,"tag":125,"props":126,"children":131},"pre",{"className":127,"code":129,"language":130,"meta":7},[128],"language-bash","# Scan for common 5G Core SBA ports\nnmap -sT -p 7777,8000,8080,8443,29518,29519 --open -oA 5g-core-scan 127.0.0.0\u002F24\n\n# Check NRF (Network Repository Function) for registered services\ncurl -k -X GET http:\u002F\u002F127.0.0.10:8000\u002Fnnrf-disc\u002Fv1\u002Fnf-instances?nf-type=AMF\ncurl -k -X GET http:\u002F\u002F127.0.0.10:8000\u002Fnnrf-disc\u002Fv1\u002Fnf-instances?nf-type=SMF\ncurl -k -X GET http:\u002F\u002F127.0.0.10:8000\u002Fnnrf-disc\u002Fv1\u002Fnf-instances?nf-type=UDM\n","bash",[132],{"type":24,"tag":133,"props":134,"children":135},"code",{"__ignoreMap":7},[136],{"type":30,"value":129},{"type":24,"tag":113,"props":138,"children":140},{"id":139},"_12-enumerate-nf-api-surfaces",[141],{"type":30,"value":142},"1.2 Enumerate NF API Surfaces",{"type":24,"tag":125,"props":144,"children":147},{"className":145,"code":146,"language":130,"meta":7},[128],"# Discover AMF available APIs\ncurl -k http:\u002F\u002F127.0.0.5:7777\u002Fnamf-comm\u002Fv1\u002Fue-contexts\n\n# Discover SMF session management endpoints\ncurl -k http:\u002F\u002F127.0.0.4:7777\u002Fnsmf-pdusession\u002Fv1\u002Fsm-contexts\n\n# Discover UDM subscriber data endpoints\ncurl -k http:\u002F\u002F127.0.0.12:7777\u002Fnudm-sdm\u002Fv2\u002Fimsi-001010000000001\u002Fnssai\n",[148],{"type":24,"tag":133,"props":149,"children":150},{"__ignoreMap":7},[151],{"type":30,"value":146},{"type":24,"tag":39,"props":153,"children":155},{"id":154},"phase-2-authentication-authorization-testing",[156],{"type":30,"value":157},"Phase 2: Authentication & Authorization Testing",{"type":24,"tag":113,"props":159,"children":161},{"id":160},"_21-nrf-token-authorization-bypass",[162],{"type":30,"value":163},"2.1 NRF Token Authorization Bypass",{"type":24,"tag":33,"props":165,"children":166},{},[167],{"type":30,"value":168},"Test whether NFs properly validate OAuth2 tokens issued by the NRF:",{"type":24,"tag":125,"props":170,"children":173},{"className":171,"code":172,"language":130,"meta":7},[128],"# Request an access token from NRF\ncurl -k -X POST http:\u002F\u002F127.0.0.10:8000\u002Foauth2\u002Ftoken \\\n  -d \"grant_type=client_credentials&nfInstanceId=test-nf-001&nfType=AMF&targetNfType=UDM&scope=nudm-sdm\"\n\n# Attempt to use the token against a different NF than authorized\ncurl -k -H \"Authorization: Bearer \u003CTOKEN>\" \\\n  http:\u002F\u002F127.0.0.4:7777\u002Fnsmf-pdusession\u002Fv1\u002Fsm-contexts\n",[174],{"type":24,"tag":133,"props":175,"children":176},{"__ignoreMap":7},[177],{"type":30,"value":172},{"type":24,"tag":113,"props":179,"children":181},{"id":180},"_22-supisuci-privacy-testing",[182],{"type":30,"value":183},"2.2 SUPI\u002FSUCI Privacy Testing",{"type":24,"tag":33,"props":185,"children":186},{},[187],{"type":30,"value":188},"Verify that SUPI (Subscription Permanent Identifier) is properly concealed:",{"type":24,"tag":125,"props":190,"children":193},{"className":191,"code":192,"language":130,"meta":7},[128],"# Monitor N1\u002FN2 signaling for plaintext SUPI exposure\nsudo tshark -i lo -Y \"ngap\" -T fields -e nas_5gs.mm.supi\n\n# Attempt registration with a crafted SUCI using null scheme\n# (Tests ECIES Profile A\u002FB implementation)\n",[194],{"type":24,"tag":133,"props":195,"children":196},{"__ignoreMap":7},[197],{"type":30,"value":192},{"type":24,"tag":39,"props":199,"children":201},{"id":200},"phase-3-protocol-fuzzing-injection",[202],{"type":30,"value":203},"Phase 3: Protocol Fuzzing & Injection",{"type":24,"tag":113,"props":205,"children":207},{"id":206},"_31-ngap-n2-interface-fuzzing",[208],{"type":30,"value":209},"3.1 NGAP (N2 Interface) Fuzzing",{"type":24,"tag":125,"props":211,"children":214},{"className":212,"code":213,"language":130,"meta":7},[128],"# Launch UERANSIM gNodeB against the target AMF\nnr-gnb -c \u002Fetc\u002Fueransim\u002Fgnb.yaml\n\n# Send malformed NGAP messages\n# Monitor AMF crash behavior and error handling\nsudo tshark -i lo -Y \"ngap\" -T pdml > ngap_capture.xml\n",[215],{"type":24,"tag":133,"props":216,"children":217},{"__ignoreMap":7},[218],{"type":30,"value":213},{"type":24,"tag":113,"props":220,"children":222},{"id":221},"_32-gtp-u-n3-interface-data-plane-testing",[223],{"type":30,"value":224},"3.2 GTP-U (N3 Interface) Data Plane Testing",{"type":24,"tag":125,"props":226,"children":229},{"className":227,"code":228,"language":130,"meta":7},[128],"# Test UPF TEID allocation and GTP tunnel handling\n# Use gnbsim to generate high-volume GTP-U traffic\ngnbsim --cfg \u002Fetc\u002Fgnbsim\u002Ffuzz-config.json --num-ue 100\n\n# Monitor for data plane leaks across UE sessions\nsudo tshark -i ogstun -Y \"gtp\" -T fields -e gtp.teid -e ip.src -e ip.dst\n",[230],{"type":24,"tag":133,"props":231,"children":232},{"__ignoreMap":7},[233],{"type":30,"value":228},{"type":24,"tag":39,"props":235,"children":237},{"id":236},"phase-4-reporting-remediation",[238],{"type":30,"value":239},"Phase 4: Reporting & Remediation",{"type":24,"tag":113,"props":241,"children":243},{"id":242},"_41-common-findings",[244],{"type":30,"value":245},"4.1 Common Findings",{"type":24,"tag":247,"props":248,"children":249},"table",{},[250,279],{"type":24,"tag":251,"props":252,"children":253},"thead",{},[254],{"type":24,"tag":255,"props":256,"children":257},"tr",{},[258,264,269,274],{"type":24,"tag":259,"props":260,"children":261},"th",{},[262],{"type":30,"value":263},"Finding",{"type":24,"tag":259,"props":265,"children":266},{},[267],{"type":30,"value":268},"Severity",{"type":24,"tag":259,"props":270,"children":271},{},[272],{"type":30,"value":273},"CVSS",{"type":24,"tag":259,"props":275,"children":276},{},[277],{"type":30,"value":278},"Remediation",{"type":24,"tag":280,"props":281,"children":282},"tbody",{},[283,307,330,353],{"type":24,"tag":255,"props":284,"children":285},{},[286,292,297,302],{"type":24,"tag":287,"props":288,"children":289},"td",{},[290],{"type":30,"value":291},"NRF token not validated by NFs",{"type":24,"tag":287,"props":293,"children":294},{},[295],{"type":30,"value":296},"Critical",{"type":24,"tag":287,"props":298,"children":299},{},[300],{"type":30,"value":301},"9.8",{"type":24,"tag":287,"props":303,"children":304},{},[305],{"type":30,"value":306},"Enable mandatory OAuth2 token verification on all SBI endpoints",{"type":24,"tag":255,"props":308,"children":309},{},[310,315,320,325],{"type":24,"tag":287,"props":311,"children":312},{},[313],{"type":30,"value":314},"SUPI exposed in plaintext on N1",{"type":24,"tag":287,"props":316,"children":317},{},[318],{"type":30,"value":319},"High",{"type":24,"tag":287,"props":321,"children":322},{},[323],{"type":30,"value":324},"8.1",{"type":24,"tag":287,"props":326,"children":327},{},[328],{"type":30,"value":329},"Enforce SUCI with ECIES Profile A (curve25519)",{"type":24,"tag":255,"props":331,"children":332},{},[333,338,343,348],{"type":24,"tag":287,"props":334,"children":335},{},[336],{"type":30,"value":337},"No rate limiting on SBI APIs",{"type":24,"tag":287,"props":339,"children":340},{},[341],{"type":30,"value":342},"Medium",{"type":24,"tag":287,"props":344,"children":345},{},[346],{"type":30,"value":347},"5.3",{"type":24,"tag":287,"props":349,"children":350},{},[351],{"type":30,"value":352},"Implement per-NF request rate limiting",{"type":24,"tag":255,"props":354,"children":355},{},[356,361,365,370],{"type":24,"tag":287,"props":357,"children":358},{},[359],{"type":30,"value":360},"GTP-U cross-session data leak",{"type":24,"tag":287,"props":362,"children":363},{},[364],{"type":30,"value":296},{"type":24,"tag":287,"props":366,"children":367},{},[368],{"type":30,"value":369},"9.1",{"type":24,"tag":287,"props":371,"children":372},{},[373],{"type":30,"value":374},"Enforce TEID isolation per PDU session",{"type":24,"tag":113,"props":376,"children":378},{"id":377},"_42-3gpp-security-specification-references",[379],{"type":30,"value":380},"4.2 3GPP Security Specification References",{"type":24,"tag":46,"props":382,"children":383},{},[384,394,404,414],{"type":24,"tag":50,"props":385,"children":386},{},[387,392],{"type":24,"tag":54,"props":388,"children":389},{},[390],{"type":30,"value":391},"TS 33.501",{"type":30,"value":393},": Security architecture and procedures for 5G System",{"type":24,"tag":50,"props":395,"children":396},{},[397,402],{"type":24,"tag":54,"props":398,"children":399},{},[400],{"type":30,"value":401},"TS 29.510",{"type":30,"value":403},": NRF Services (NFDiscovery, NFManagement, AccessToken)",{"type":24,"tag":50,"props":405,"children":406},{},[407,412],{"type":24,"tag":54,"props":408,"children":409},{},[410],{"type":30,"value":411},"TS 33.535",{"type":30,"value":413},": Authentication and Key Management for HTTP-based APIs",{"type":24,"tag":50,"props":415,"children":416},{},[417,422],{"type":24,"tag":54,"props":418,"children":419},{},[420],{"type":30,"value":421},"TS 29.244",{"type":30,"value":423},": PFCP interface specification (UPF control)",{"type":24,"tag":39,"props":425,"children":427},{"id":426},"practice-in-telcosec-academy",[428],{"type":30,"value":429},"Practice in TelcoSec Academy",{"type":24,"tag":33,"props":431,"children":432},{},[433,435],{"type":30,"value":434},"👉 ",{"type":24,"tag":54,"props":436,"children":437},{},[438],{"type":24,"tag":439,"props":440,"children":444},"a",{"href":441,"rel":442},"https:\u002F\u002Fapp.telcosec.net",[443],"nofollow",[445],{"type":30,"value":446},"Launch the 5G Core Red Team Lab on App.TelcoSec.Net",{"title":7,"searchDepth":448,"depth":448,"links":449},2,[450,451,456,460,464,468],{"id":41,"depth":448,"text":44},{"id":108,"depth":448,"text":111,"children":452},[453,455],{"id":115,"depth":454,"text":118},3,{"id":139,"depth":454,"text":142},{"id":154,"depth":448,"text":157,"children":457},[458,459],{"id":160,"depth":454,"text":163},{"id":180,"depth":454,"text":183},{"id":200,"depth":448,"text":203,"children":461},[462,463],{"id":206,"depth":454,"text":209},{"id":221,"depth":454,"text":224},{"id":236,"depth":448,"text":239,"children":465},[466,467],{"id":242,"depth":454,"text":245},{"id":377,"depth":454,"text":380},{"id":426,"depth":448,"text":429},"markdown","content:guides:5g-core-penetration-testing.md","content","guides\u002F5g-core-penetration-testing.md","guides\u002F5g-core-penetration-testing","md",1790363496261]