Telecom Security Audit Skill
When to Use
Activate this skill when the engagement involves:
- SMS-based 2FA/MFA — assessing OTP delivery, SIM swap risk, interception vectors
- SIP/VoIP infrastructure — auditing PBX, softphones, SIP trunks, WebRTC gateways
- IVR systems — interactive voice response security, DTMF handling, menu traversal
- Call center authentication — knowledge-based auth, callback verification, social engineering resistance
- Telephony APIs — Twilio, Vonage, Bandwidth, Plivo, Telnyx integration security
- Cellular security — baseband, IMSI catchers, roaming, carrier interconnects
- Carrier-grade infrastructure — SS7/SIGTRAN, Diameter, GTP, SIM provisioning
Historical Context
The name 2600 comes from a 2600 Hz tone — the exact frequency that, when played into an AT&T
long-distance trunk line, seized control of the switch. This was in-band signaling: control data
traveled on the same channel as voice, so anyone who could produce the tone could command the network.
- Blue box: generated MF (multi-frequency) tones to route calls after seizing a trunk with 2600 Hz
- Red box: simulated coin deposit tones on payphones
- Black box: manipulated line voltage to prevent billing on incoming calls
The fundamental lesson: when control signaling shares a channel with user data, users become
operators. AT&T eventually moved to out-of-band signaling (SS7), but SS7 introduced its own
trust model vulnerability — carriers implicitly trust each other, and that trust is now exploitable
by anyone with an SS7 interconnect.
Attack Surface Taxonomy
SS7/MAP (Legacy Signaling)
- Location tracking:
SendRoutingInfo / ProvideSubscriberInfo queries reveal cell tower location
- SMS interception:
UpdateLocation re-registers victim to attacker-controlled MSC
- Call interception:
InsertSubscriberData redirects call forwarding
- Authentication bypass: obtain IMSI, trigger re-authentication to capture triplets
Diameter (4G/5G Signaling)
- Roaming scenarios inherit SS7's implicit trust between carriers
- S6a/S6d interfaces expose subscriber data during inter-PLMN handoffs
- Diameter Edge Agents (DEA) provide filtering, but coverage is inconsistent
SIP/VoIP
- Registration hijacking: unauthenticated REGISTER, digest auth brute force
- Eavesdropping: RTP without SRTP, SIP without TLS
- Toll fraud: compromised endpoints used for premium-rate number dialing
- Caller ID spoofing:
From header trivially set to any value
- SRTP key negotiation: SRTP-SDES sends keys in plaintext SDP (use DTLS-SRTP instead)
SMS/OTP
- SS7 interception: redirect SMS at the network level (proven in real attacks)
- SIM swap: social engineering carrier support to port number to attacker SIM
- Smishing: SMS phishing with shortened/obfuscated URLs
- OTP interception: malware with SMS read permission on Android
IVR/DTMF
- Brute force: PIN/account number guessing via rapid DTMF input
- Menu traversal: undocumented options, debug menus, operator escape sequences
- Information disclosure: reading back account details, SSN, balances without strong auth
- Recording exposure: call recordings stored without encryption or access control
Caller ID / ANI
- Caller ID (CNAM): trivially spoofable — no cryptographic verification in legacy PSTN
- STIR/SHAKEN: adds certificate-based attestation but adoption is still incomplete
- ANI vs Caller ID: ANI is harder to spoof but not immune in VoIP-to-PSTN transitions
SIM Security
- SIM swap: social engineering carrier reps, insider threats, automated porting attacks
- SIM cloning: legacy Comp128v1 vulnerability (historical, mostly patched)
- eSIM provisioning: QR code interception, SM-DP+ server compromise
- SIM toolkit (STK): Simjacker-style attacks via crafted OTA SMS
Telephony APIs
- Webhook spoofing: attacker sends fake status callbacks to application endpoints
- Credential leakage: API keys/auth tokens in client-side code, logs, or VCS history
- Rate limiting gaps: no throttle on verification SMS sends (cost amplification, spam)
- Number enumeration: carrier lookup APIs reveal active numbers and carrier info
Audit Methodology
Enumerate telephony-dependent auth paths
- Map every flow that uses phone numbers: login, password reset, transaction verification
- Identify which are SMS-only vs. offering TOTP/WebAuthn alternatives
Assess SMS 2FA for known bypass vectors
- Can an attacker SIM-swap the target? (carrier policy, account PIN, port-out protection)
- Is the application vulnerable if SMS is intercepted? (session fixation, race conditions)
- Are OTPs time-limited and single-use? Are they sufficiently long (6+ digits)?
Test caller ID verification
- Can a spoofed caller ID bypass IVR authentication?
- Does the system use callback verification for sensitive operations?
- Is STIR/SHAKEN attestation level checked for incoming SIP calls?
Audit VoIP configuration
- SIP: TLS enabled? Certificate validation? Digest auth or mutual TLS?
- Media: SRTP enforced? DTLS-SRTP or SDES? Key management reviewed?
- Registration: rate limiting on REGISTER? Fail2ban or equivalent?
Review IVR security
- Lockout after N failed PIN attempts?
- Sensitive data readback requires step-up authentication?
- Debug/admin menus accessible from external callers?
Test telephony API integration
- Webhook endpoints validate request signatures (e.g., Twilio
X-Twilio-Signature)?
- Replay protection via timestamp validation?
- API credentials rotated, scoped to minimum permissions?
Assess carrier/provider resilience
- Single carrier dependency? Failover path?
- Geographic number portability risks?
- Provider SLA and incident response capability?
Code Review Patterns
Look for these anti-patterns during source review:
# FINDING: SMS as sole second factor — no TOTP/WebAuthn alternative
if user.mfa_method == "sms":
send_otp(user.phone_number) # No fallback offered
# FINDING: Phone number as primary account identifier
user = User.objects.get(phone=request.data["phone"]) # SIM swap = account takeover
# FINDING: Caller ID trusted for authentication
if call.caller_id == expected_number:
grant_access() # Trivially spoofable
# FINDING: SIP credentials in plaintext config
SIP_PASSWORD = "oops-plaintext" # Should use secrets manager
# FINDING: No SRTP — voice traffic sent unencrypted
media_encryption = "none" # Should be "srtp" with DTLS key exchange
# FINDING: Telephony webhook without signature verification
@app.route("/twilio/status", methods=["POST"])
def status_callback():
process(request.form) # No X-Twilio-Signature check
# FINDING: No rate limiting on phone verification endpoint
@app.route("/verify/send", methods=["POST"])
def send_verification():
send_sms(request.json["phone"]) # Unlimited sends = cost amplification
# FINDING: Phone number enumeration via error differences
if not user_exists(phone):
return {"error": "User not found"} # vs. "Invalid credentials"
Remediation Quick Reference
| Issue |
Remediation |
| SMS as sole 2FA |
Offer TOTP (RFC 6238) or WebAuthn as alternatives |
| SIM swap risk |
Enable carrier port-out PIN, number lock, SIM swap detection alerts |
| Caller ID trusted |
Never authenticate on caller ID alone; use callback verification |
| SIP without TLS |
Enforce TLS 1.2+ for signaling, validate certificates |
| RTP without SRTP |
Enforce SRTP with DTLS-SRTP key exchange (not SDES) |
| IVR PIN brute force |
Lockout after 3-5 failures, exponential backoff, CAPTCHA for web-initiated calls |
| Webhook spoofing |
Validate HMAC signatures, check timestamps, reject replays >5 min |
| Number enumeration |
Uniform error responses, rate limit lookup endpoints |
| API key exposure |
Use environment variables or secrets manager, rotate regularly, scope permissions |
| No OTP expiry |
OTPs expire in 5-10 minutes, single-use, minimum 6 digits |
Tools Reference
- SIPVicious (
sipvicious): SIP scanning, enumeration, password cracking
- Ohrwurm: RTP fuzzer for VoIP
- Mr.SIP: SIP-based audit and attack tool
- SigPloit: SS7/Diameter/GTP pentesting framework
- Owasp VoIPAudit: VoIP security testing methodology
- Owasp Owasp Telephony cheatsheet: telephony security reference
- Owasp Testing Guide: relevant sections on OTP, 2FA bypass
Related Skills
social-engineering-audit — SIM swap and call center pretexting vectors
entry-point-analyzer — mapping telephony-dependent authentication surfaces
static-security-analyzer — scanning for hardcoded SIP credentials and API keys
1---2name: telecom-security3description: Assess telecommunications infrastructure security including VoIP/SIP, SS7/Diameter, cellular networks, SMS-based authentication, and telephony-integrated applications. Identifies vulnerabilities in phone-based verification, call routing, and telecom protocol implementations. Use when auditing SMS 2FA, VoIP systems, IVR applications, or any telephony-dependent security controls.4---56# Telecom Security Audit Skill78## When to Use910Activate this skill when the engagement involves:1112- **SMS-based 2FA/MFA** — assessing OTP delivery, SIM swap risk, interception vectors13- **SIP/VoIP infrastructure** — auditing PBX, softphones, SIP trunks, WebRTC gateways14- **IVR systems** — interactive voice response security, DTMF handling, menu traversal15- **Call center authentication** — knowledge-based auth, callback verification, social engineering resistance16- **Telephony APIs** — Twilio, Vonage, Bandwidth, Plivo, Telnyx integration security17- **Cellular security** — baseband, IMSI catchers, roaming, carrier interconnects18- **Carrier-grade infrastructure** — SS7/SIGTRAN, Diameter, GTP, SIM provisioning1920## Historical Context2122The name **2600** comes from a 2600 Hz tone — the exact frequency that, when played into an AT&T23long-distance trunk line, seized control of the switch. This was in-band signaling: control data24traveled on the same channel as voice, so anyone who could produce the tone could command the network.2526- **Blue box**: generated MF (multi-frequency) tones to route calls after seizing a trunk with 2600 Hz27- **Red box**: simulated coin deposit tones on payphones28- **Black box**: manipulated line voltage to prevent billing on incoming calls2930The fundamental lesson: **when control signaling shares a channel with user data, users become31operators.** AT&T eventually moved to out-of-band signaling (SS7), but SS7 introduced its own32trust model vulnerability — carriers implicitly trust each other, and that trust is now exploitable33by anyone with an SS7 interconnect.3435## Attack Surface Taxonomy3637### SS7/MAP (Legacy Signaling)38- **Location tracking**: `SendRoutingInfo` / `ProvideSubscriberInfo` queries reveal cell tower location39- **SMS interception**: `UpdateLocation` re-registers victim to attacker-controlled MSC40- **Call interception**: `InsertSubscriberData` redirects call forwarding41- **Authentication bypass**: obtain IMSI, trigger re-authentication to capture triplets4243### Diameter (4G/5G Signaling)44- Roaming scenarios inherit SS7's implicit trust between carriers45- S6a/S6d interfaces expose subscriber data during inter-PLMN handoffs46- Diameter Edge Agents (DEA) provide filtering, but coverage is inconsistent4748### SIP/VoIP49- **Registration hijacking**: unauthenticated REGISTER, digest auth brute force50- **Eavesdropping**: RTP without SRTP, SIP without TLS51- **Toll fraud**: compromised endpoints used for premium-rate number dialing52- **Caller ID spoofing**: `From` header trivially set to any value53- **SRTP key negotiation**: SRTP-SDES sends keys in plaintext SDP (use DTLS-SRTP instead)5455### SMS/OTP56- **SS7 interception**: redirect SMS at the network level (proven in real attacks)57- **SIM swap**: social engineering carrier support to port number to attacker SIM58- **Smishing**: SMS phishing with shortened/obfuscated URLs59- **OTP interception**: malware with SMS read permission on Android6061### IVR/DTMF62- **Brute force**: PIN/account number guessing via rapid DTMF input63- **Menu traversal**: undocumented options, debug menus, operator escape sequences64- **Information disclosure**: reading back account details, SSN, balances without strong auth65- **Recording exposure**: call recordings stored without encryption or access control6667### Caller ID / ANI68- **Caller ID (CNAM)**: trivially spoofable — no cryptographic verification in legacy PSTN69- **STIR/SHAKEN**: adds certificate-based attestation but adoption is still incomplete70- **ANI vs Caller ID**: ANI is harder to spoof but not immune in VoIP-to-PSTN transitions7172### SIM Security73- **SIM swap**: social engineering carrier reps, insider threats, automated porting attacks74- **SIM cloning**: legacy Comp128v1 vulnerability (historical, mostly patched)75- **eSIM provisioning**: QR code interception, SM-DP+ server compromise76- **SIM toolkit (STK)**: Simjacker-style attacks via crafted OTA SMS7778### Telephony APIs79- **Webhook spoofing**: attacker sends fake status callbacks to application endpoints80- **Credential leakage**: API keys/auth tokens in client-side code, logs, or VCS history81- **Rate limiting gaps**: no throttle on verification SMS sends (cost amplification, spam)82- **Number enumeration**: carrier lookup APIs reveal active numbers and carrier info8384## Audit Methodology85861. **Enumerate telephony-dependent auth paths**87 - Map every flow that uses phone numbers: login, password reset, transaction verification88 - Identify which are SMS-only vs. offering TOTP/WebAuthn alternatives89902. **Assess SMS 2FA for known bypass vectors**91 - Can an attacker SIM-swap the target? (carrier policy, account PIN, port-out protection)92 - Is the application vulnerable if SMS is intercepted? (session fixation, race conditions)93 - Are OTPs time-limited and single-use? Are they sufficiently long (6+ digits)?94953. **Test caller ID verification**96 - Can a spoofed caller ID bypass IVR authentication?97 - Does the system use callback verification for sensitive operations?98 - Is STIR/SHAKEN attestation level checked for incoming SIP calls?991004. **Audit VoIP configuration**101 - SIP: TLS enabled? Certificate validation? Digest auth or mutual TLS?102 - Media: SRTP enforced? DTLS-SRTP or SDES? Key management reviewed?103 - Registration: rate limiting on REGISTER? Fail2ban or equivalent?1041055. **Review IVR security**106 - Lockout after N failed PIN attempts?107 - Sensitive data readback requires step-up authentication?108 - Debug/admin menus accessible from external callers?1091106. **Test telephony API integration**111 - Webhook endpoints validate request signatures (e.g., Twilio `X-Twilio-Signature`)?112 - Replay protection via timestamp validation?113 - API credentials rotated, scoped to minimum permissions?1141157. **Assess carrier/provider resilience**116 - Single carrier dependency? Failover path?117 - Geographic number portability risks?118 - Provider SLA and incident response capability?119120## Code Review Patterns121122Look for these anti-patterns during source review:123124```python125# FINDING: SMS as sole second factor — no TOTP/WebAuthn alternative126if user.mfa_method == "sms":127 send_otp(user.phone_number) # No fallback offered128129# FINDING: Phone number as primary account identifier130user = User.objects.get(phone=request.data["phone"]) # SIM swap = account takeover131132# FINDING: Caller ID trusted for authentication133if call.caller_id == expected_number:134 grant_access() # Trivially spoofable135136# FINDING: SIP credentials in plaintext config137SIP_PASSWORD = "oops-plaintext" # Should use secrets manager138139# FINDING: No SRTP — voice traffic sent unencrypted140media_encryption = "none" # Should be "srtp" with DTLS key exchange141142# FINDING: Telephony webhook without signature verification143@app.route("/twilio/status", methods=["POST"])144def status_callback():145 process(request.form) # No X-Twilio-Signature check146147# FINDING: No rate limiting on phone verification endpoint148@app.route("/verify/send", methods=["POST"])149def send_verification():150 send_sms(request.json["phone"]) # Unlimited sends = cost amplification151152# FINDING: Phone number enumeration via error differences153if not user_exists(phone):154 return {"error": "User not found"} # vs. "Invalid credentials"155```156157## Remediation Quick Reference158159| Issue | Remediation |160|-------|-------------|161| SMS as sole 2FA | Offer TOTP (RFC 6238) or WebAuthn as alternatives |162| SIM swap risk | Enable carrier port-out PIN, number lock, SIM swap detection alerts |163| Caller ID trusted | Never authenticate on caller ID alone; use callback verification |164| SIP without TLS | Enforce TLS 1.2+ for signaling, validate certificates |165| RTP without SRTP | Enforce SRTP with DTLS-SRTP key exchange (not SDES) |166| IVR PIN brute force | Lockout after 3-5 failures, exponential backoff, CAPTCHA for web-initiated calls |167| Webhook spoofing | Validate HMAC signatures, check timestamps, reject replays >5 min |168| Number enumeration | Uniform error responses, rate limit lookup endpoints |169| API key exposure | Use environment variables or secrets manager, rotate regularly, scope permissions |170| No OTP expiry | OTPs expire in 5-10 minutes, single-use, minimum 6 digits |171172## Tools Reference173174- **SIPVicious** (`sipvicious`): SIP scanning, enumeration, password cracking175- **Ohrwurm**: RTP fuzzer for VoIP176- **Mr.SIP**: SIP-based audit and attack tool177- **SigPloit**: SS7/Diameter/GTP pentesting framework178- **Owasp VoIPAudit**: VoIP security testing methodology179- **Owasp Owasp Telephony cheatsheet**: telephony security reference180- **Owasp Testing Guide**: relevant sections on OTP, 2FA bypass181182## Related Skills183184- `social-engineering-audit` — SIM swap and call center pretexting vectors185- `entry-point-analyzer` — mapping telephony-dependent authentication surfaces186- `static-security-analyzer` — scanning for hardcoded SIP credentials and API keys