I have successfully used airprobe (and gr-gsm, derived from airprobe) to
see broadcast, unencrypted status messages from GSM base stations.
It is my understanding that other protocols (like CDMA, UMTS, HSPA, LTE)
have similar unencrypted, broadcast or "beacon" traffic that could be
viewed the same way ...
But there are no tools like airprobe for CDMA or 3G or LTE ... why is that
?
Is there a technical reason that they are much more difficult, or has it
just not been done yet out of lack of interest ?
Thank you.
Hello fellow phone hackers,
Back in March-April of 2014 there was a user on this list (Rusty Dekema,
Cc'ed) who wanted to use OsmocomBB tools with a Mot C139 phone, but was
stopped by a locked-down bootloader; the phone had Cingular firmware
version 1.9.24 which none of us knew how to unlock back then.
Fast-forwarding to the present, I recently got yet another batch of
Mot C139 phones from ebay, and one of them came with that same fw
version with a locked-down bootloader. This encounter prompted me to
research the problem some more and develop a new shellcode injection-
based method of breaking into these phones that should work with all
existing Mot C1xx fw versions, gaining code execution on the phone's
Calypso and allowing one to reflash the bootloader with an unlocked
version, among arbitrary other reflashing and hacking operations.
The new "universal" Mot C1xx unlocking tool is released as part of
fc-host-tools-r4; the link to the tarball appears at the bottom of
this web page:
https://www.freecalypso.org/c139.html
Happy hacking,
Mychaela
Hi all!
This is the announcement for the re-incarnation of our bi-weekly
Osmocom Berlin Meeting.
Dec 09, 8pm @ CCC Berlin, Marienstr. 11, 10117 Berlin
There is no formal presentation this time, but
* there will be SIMtrace equipment in case somebody wants to play with
it there will be a sysmoBTS with OsmoBTS, OsmoPCU, OsmoNITB, OsmoSGSN
and OpenGGSN if somebody wants to play with it
* there will be Huawei Femtocells to play with
The meeting is open to anyone interested in mobile communications. You
do not have to be involved with the Osmocom projects in order to attend.
Anyone interested in mobile communications protocols is welcome.
If you are interested to show up, feel free to do so. The meeting is
"free as in free beer", despite no actual free beer being around ;)
More information can be found at
http://openbsc.osmocom.org/trac/wiki/OsmocomMeeting/Berlin
Regards,
Harald
--
- Harald Welte <laforge(a)gnumonks.org>
============================================================================
"Privacy in residential applications is a desirable marketing option."
(ETSI EN 300 175-7 Ch. A6)
Hi all!
This is the announcement for the re-incarnation of our bi-weekly
Osmocom Berlin Meeting.
Nov 11, 8pm @ CCC Berlin, Marienstr. 11, 10117 Berlin
There is no formal presentation this time, but
* there will be SDR equipment, antenna and a working/tested setup of a
gnuradio based MPT1327 decoder
* there will be SIMtrace equipment in case somebody wants to play with
it there will be a sysmoBTS with OsmoBTS, OsmoPCU, OsmoNITB, OsmoSGSN
and OpenGGSN if somebody wants to play with it
* there will be Huawei Femtocells to play with
* Harald would like to discuss OpenBSC website / documentation improvements
The meeting is open to anyone interested in mobile communications. You
do not have to be involved with the Osmocom projects in order to attend.
Anyone interested in mobile communications protocols is welcome.
If you are interested to show up, feel free to do so. The meeting is
"free as in free beer", despite no actual free beer being around ;)
More information can be found at
http://openbsc.osmocom.org/trac/wiki/OsmocomMeeting/Berlin
Regards,
Harald
--
- Harald Welte <laforge(a)gnumonks.org>
============================================================================
"Privacy in residential applications is a desirable marketing option."
(ETSI EN 300 175-7 Ch. A6)
Hi all!
This is the announcement for the re-incarnation of our bi-weekly
Osmocom Berlin Meeting.
Oct 21, 8pm @ CCC Berlin, Marienstr. 11, 10117 Berlin
There is no formal presentation this time, but
* there will be SDR equipment in case more people are interested
to have a look at MPT1327 and/or Tetrapol signals that can be
received in Berlin
* Harald would like to discuss OpenBSC website / documentation
improvements
The meeting is open to anyone interested in mobile communications. You
do not have to be involved with the Osmocom projects in order to attend.
Anyone interested in mobile communications protocols is welcome.
If you are interested to show up, feel free to do so. The meeting is
"free as in free beer", despite no actual free beer being around ;)
More information can be found at
http://openbsc.osmocom.org/trac/wiki/OsmocomMeeting/Berlin
Regards,
Harald
--
- Harald Welte <laforge(a)gnumonks.org>
============================================================================
"Privacy in residential applications is a desirable marketing option."
(ETSI EN 300 175-7 Ch. A6)
Hello,
I am using a SDR device (a BladeRF) and there is a nice tool called 'kal' that will show me all of my nearby GSM base stations.
In addition to listing base stations and their frequencies, I could also use that frequency info to monitor the beacon channel with gr-scan/airprobe.
So at this point I know:
- base station exists
- I know its frequency
- based on beacon channel assignments, etc., I *sort of* know how busy it is.
But what else can be learned about a particular base station with simply passive observation and no decryption (and no sim card) ? If all I have is a passive monitor with a SDR, what else can I learn frmo the beacon channel or from the station itself ?
Is it possible to learn things like software version, protocols supported, connectivity to network, or to other base stations ?
My goal is to learn about the GSM networks around me and I wonder how deeply I can understand them with just passive observation of the beacon channel (or other sources of info that can be seen with SDR).
Thank you.
Hi all!
This is an announcement for an "irregular" Berlin Osmocom User Group
event.
David Rupprecht of Ruhr-Uni Bochum has offered to give us a presentation
sharing his experience in Running OpenAirInterface.
OpenAirInterface (http://openairinterface.eurecom.fr/) is a project of
the Eurecom research institute in Sofia Antipoils / France. For many
years they have been working towards an open source SDR LTE
implementation.
The presentation will be held on
Oct 15, 8pm @ IN-Berlin, Lehrter Str. 53, 10557 Berlin
(yes, this is _NOT_ CCC Berlin where regular OSMUG meetings are held!)
The meeting is open to anyone interested in mobile communications. You
do not have to be involved with the Osmocom projects in order to attend.
Anyone interested in mobile communications protocols is welcome.
If you are interested to show up, feel free to do so. The meeting is
"free as in free beer", despite no actual free beer being around ;)
More information about the venue can be found at
http://www.in-berlin.de/space/
The official event announcement website is
http://openbsc.osmocom.org/trac/blog/david-rub-openair-20151015
Regards,
Harald
--
- Harald Welte <laforge(a)gnumonks.org>
============================================================================
"Privacy in residential applications is a desirable marketing option."
(ETSI EN 300 175-7 Ch. A6)