Known:
- i use Redmi Noe 13 Pro 5G
https://www.gsmarena.com/xiaomi_redmi_note_13_pro-12581.php
Qualcomm SM7435-AB Snapdragon 7s Gen 2 (4 nm)
- I use USRP B210
- I use my testing simcard (MCC 901, MNC 70) i have Ki, Opc, IMSI (was able to connect to my srslab/enb/epc)
but i dont register this imsi in 5Ghoul IMSI config
because i want to run the exploit case "mac_sch_rrc_setup_crash_var" so since the exploitation for this case is prior to authentication, we dont need to register the Ki, Opc, IMSI .
Case: run the :
1. sudo ./bin/5g_fuzzer --exploit=mac_sch_rrc_setup_crash_var --MCC=901 --MNC=70 --GlobalTimeout=false --EnableMutation=true
also
2.sudo bin/5g_fuzzer --MCC=901 --MNC=70 --EnableMutation=true
expected:
- My Redmi/UE initiate connection
actual behaviour:
- My UE not attracted
- I use search manual for the network, but also not found the list of that network
I provide three traces/logs which actually same trace, one from PCAP that i conver to text and the other from Celluler PRO
- Convert from PCAP
frommyPCAP.txt
- From Celluler PRO
SIB.txt
- from SCAT screen
screenscat5g.txt
Looking forward for your resolution, thank you so much.
Br,
Rifky