The Register Home Page

back to article Boffins say tool can sniff 5G traffic, launch 'attacks' without using rogue base stations

Security boffins have released an open source tool for poking holes in 5G mobile networks, claiming it can do up- and downlink sniffing and a novel connection downgrade attack - plus "other serious exploits" they're keeping under wraps, for now. "Sni5Gect [is] a framework that sniffs messages from pre-authentication 5G …

  1. elsergiovolador Silver badge

    Facepalm

    The collective facepalm from intelligence services when this dropped must have sounded like a sonic boom. They’ve spent billions building bespoke interception systems, and now some grad students with an SDR and a GitHub repo have gift-wrapped a downgrade attack that works in a parking garage. The 5G marketing hype was all about security and resilience, but apparently the handshake is as fragile as a car Bluetooth pairing. Now the spooks have to decide whether to quietly thank the researchers for doing their job, or curse them for blowing the cover off vulnerabilities they were probably already abusing.

    1. Flak

      Incredible (but to be expected)

      Quite crazy when you consider that mobile devices are likely to negotiate new encrypted sessions so regularly.

      Probably so fundamental that an improved protocol to establish sessions is needed.

      1. Strahd Ivarius Silver badge
        Devil

        Re: Incredible (but to be expected)

        6G or 7G, perhaps?

        With a need to change all the network equipments to handle it?

        1. Claptrap314 Silver badge

          Re: Incredible (but to be expected)

          When features aren't enough to get people to buy new devices, uncover a security issue, then create a new generation of incompatible "better" devices.

          This is not new.

        2. Alumoi Silver badge

          Re: Incredible (but to be expected)

          No, no, no, the suckers will have to buy new phones.

    2. This post has been deleted by its author

    3. JoeCool Silver badge

      Re: Facepalm

      Surely you realize that those "billions" were pre 5G systems.

      And, there's no reason to believe the cia, etc. don't already have proprietary versions.

    4. Pier Reviewer

      Re: Facepalm

      It feels a *little* over-egged if I’m honest. There’s some truly interesting and impressive work in there, particularly around the engineering side. Winning the race condition between the UE and gNB is far from trivial!

      On the impact front they’ve gunned for headlines a bit. They can capture the SUCI from <20m away. At that distance you may as well take the lad’s photo and run it through a reverse image search if you want to ID him. The SUCI is useless for that purpose - that’s its entire function! The SUCI can be abused as a session identifier, but not a permanent device identifier. You can say “this SUCI moved from the office at 123 Blah Street to Wetherspoons at lunchtime” but you can’t correlate that with other movements on other days, or even as they state themselves, between the UE going into and out of a lift/other poor signal area. If the UE loses signal and needs to handshake again, it’s using a new SUCI.

      If they’d managed to get a SUPI then that would be proper news! Not a great analogy, but think of it a bit like sniffing a TLS handshake (the SUCI in this example) vs the private key (the SUPI). The SUCI is expected to be exposed by design.

      The attacks were mostly performed against non-realistic gNBs (basically test gear). When they used a proper one they discovered that they absolutely hammer bandwidth so there was no “slack” for them to inject messages and their success rate (already not great at 80%) tanked. Tbf attacks only get better, but there’s still a lot of getting better to do :D

      They say that the benefit of their attack is it doesn’t require a rogue base station so it’s much harder to passively detect (they can use beam forming etc to ensure only the target UE “sees” their messages). Then, the only interesting actual attack (4G downgrade) uses a rogue base station :D The downgrade is interesting, but there’s no evidence it works on anything recent, and it’s wholly detectable.

      Finally, the UEs weren’t exactly brand spanking new. Pixel 7?! Sure, plenty of people outside of the US/Western Europe etc are using older models, but are they even supported any more?

      Like I say, great engineering, shit sample sizes, poor headline grab.

      1. Blazde Silver badge

        Re: Facepalm

        Pixel 7 has security updates through to Oct 2027. It's truly sick that a phone released 3 years ago can be criticised for being not new in research initiated over a year ago. 5G itself is basically brand spanking new in this context. (Good post otherwise :) )

      2. Anonymous Coward
        Anonymous Coward

        Re: Facepalm

        Kind of agree with you as none of this is really new and already been written about for 4G systems. Though if they can win the race with the gNB they can send an ILLEGAL_UE in the reject message. This rejection means that for local radio regulations the user equipement is illegal (transmits in illegal bands) and the phone must not be used in this country. This would mean that they could not only stop the phone connecting to the spoofed network but to any network. Think multi-SIM phones. The phone will have to be rebooted before it'll again try to connect anywhere.

    5. CrazyOldCatMan Silver badge

      Re: Facepalm

      now some grad students with an SDR and a GitHub repo have gift-wrapped a downgrade attack that works in a parking garage

      Presumably, they strip the COVID chips out of the 5G signals before decoding them? Or is it the other way round? I get so confused by the moronic conspiracy theories..

  2. Tron Silver badge

    Snee-five-ject...

    ...is a crap name. Plus why are they assisting crims in this way?

    1. Pascal Monett Silver badge

      Re: Snee-five-ject...

      Well, it's pretty simple.

      When you can submit better code, you can name whatever you want.

  3. GNU Enjoyer
    FAIL

    >under the GNU Affero General Public Licence 3

    As per the COPYRIGHT and debian/copyright files, only some of the C files are in fact licensed under the AGPLv3-or-later - not AGPLv3-ambigious.

    Although there are a bunch of other files licensed under MIT expat or BSD 3-clause and the python scripts under scripts/ have no license.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like