Skip to content

Trace Provided: MIB already hit my 5G capable Phone, but not attracted or initiate RRCConnectionRequest #41

@arifkyi

Description

@arifkyi

Known:

  • i use Redmi Noe 13 Pro 5G
    https://www.gsmarena.com/xiaomi_redmi_note_13_pro-12581.php
    Qualcomm SM7435-AB Snapdragon 7s Gen 2 (4 nm)
  • I use USRP B210
  • I use my testing simcard (MCC 901, MNC 70) i have Ki, Opc, IMSI (was able to connect to my srslab/enb/epc)
    but i dont register this imsi in 5Ghoul IMSI config
    because i want to run the exploit case "mac_sch_rrc_setup_crash_var" so since the exploitation for this case is prior to authentication, we dont need to register the Ki, Opc, IMSI .

Case: run the :


 1. sudo ./bin/5g_fuzzer --exploit=mac_sch_rrc_setup_crash_var --MCC=901 --MNC=70 --GlobalTimeout=false --EnableMutation=true
 also
 2.sudo bin/5g_fuzzer --MCC=901 --MNC=70 --EnableMutation=true

expected:

  1. My Redmi/UE initiate connection

actual behaviour:

  1. My UE not attracted
  2. I use search manual for the network, but also not found the list of that network

I provide three traces/logs which actually same trace, one from PCAP that i conver to text and the other from Celluler PRO

  1. Convert from PCAP

frommyPCAP.txt

  1. From Celluler PRO

SIB.txt

  1. from SCAT screen

screenscat5g.txt

Looking forward for your resolution, thank you so much.

Br,
Rifky

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions