# OSMOCOM, Application Test Audit

**URL:** <https://discourse.myriadrf.org/t/osmocom-application-test-audit/5929>\
**Category:** RAN Forum\
**Created:** [26 March 2020 18:33 UTC](https://discourse.myriadrf.org/t/osmocom-application-test-audit/5929 "2020-03-26T18:33:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rezatelekom](https://avatars.discourse-cdn.com/v4/letter/r/3be4f8/32.png) [@rezatelekom](https://discourse.myriadrf.org/u/rezatelekom)\
**Post date:** [26 March 2020 18:33 UTC](https://discourse.myriadrf.org/t/osmocom-application-test-audit/5929/1 "2020-03-26T18:33:40Z")

</div>

Hello All,

I have already installed osmocom-nitb on the ubuntu. Now, i am trying to show the subscriber information (retrieving authentication info and the MSISDN for a known IMSI Depending on the details of the OSMOCOM implementation and more in-depth possible attacks) out of the HLR (core network vulnerability). Could you please provide me information about how to proceed further !?

---

<div class="post-metadata">

**Author:** ![andrewback](https://avatars.discourse-cdn.com/v4/letter/a/22d042/32.png) [@andrewback](https://discourse.myriadrf.org/u/andrewback)\
**Post date:** [27 March 2020 11:57 UTC](https://discourse.myriadrf.org/t/osmocom-application-test-audit/5929/2 "2020-03-27T11:57:03Z")

</div>

> [@rezatelekom](#):
>
> retrieving authentication info and the MSISDN for a known IMSI

If you mean ascertaining the Ki, you would have to know what this is for a SIM card in order to provision it in the HLR. You cannot simply have an MS attach and then use the Osmocom stack to find the Ki when you did not previously know this.

---

<div class="post-metadata">

**Author:** ![rezatelekom](https://avatars.discourse-cdn.com/v4/letter/r/3be4f8/32.png) [@rezatelekom](https://discourse.myriadrf.org/u/rezatelekom)\
**Post date:** [27 March 2020 19:07 UTC](https://discourse.myriadrf.org/t/osmocom-application-test-audit/5929/3 "2020-03-27T19:07:05Z")

</div>

Ki also takes places during the MS authentication you are right, but in parallel SRES is calculated on the HLR, which is the result of the Ki and RAND using A 1 to 5 encryption.  
I have virtualised the HLR, MSC, STP and BSC and also created a subscriber on the HLR. The aim of my work is to disclose network information on wireshark.

---

<div class="post-metadata">

**Author:** ![andrewback](https://avatars.discourse-cdn.com/v4/letter/a/22d042/32.png) [@andrewback](https://discourse.myriadrf.org/u/andrewback)\
**Post date:** [28 March 2020 09:05 UTC](https://discourse.myriadrf.org/t/osmocom-application-test-audit/5929/4 "2020-03-28T09:05:47Z")

</div>

This question is not SDR specific and probably best directed to the Osmocom mailing list.
