How I hacked into a Telecom Network — Part 4 (Getting Access to CDRs, SS7 applications & VLRs) | by Harpreet Singh | InfoSec Write-ups

How I hacked into a Telecom Network — Part 4 (Getting Access to CDRs, SS7 applications & VLRs)

Recap: Red Team Engagement for a Telecom company. Found interesting subdomain, did a full port scan on that subdomain, found port 12000/tcp, 14000/tcp, and 14100/tcp found a running instance of JBoss (lucky me!), exploited JBoss for RCE, implemented TCP tunnel over HTTP for Shell Stability.

Situational Awareness (Internal Network)

Exploiting Internal Network Service

What’s SS7?

You may ask why there was an SS7 client application running on JBoss? One word — “Mobicents”

Mobicents

Going beyond

Promotion Time!