Active Manipulation SIM-ME

This is merely a historical archive of years 2008-2021, before the migration to mailman3.

A maintained and still updated list archive can be found at https://lists.osmocom.org/hyperkitty/list/simtrace@lists.osmocom.org/.

tsaitgaist ml at mail.tsaitgaist.info
Thu Jul 14 14:45:02 UTC 2011


Hi,

Here some corrections :

On 14.07.2011 15:37, Dirk Kirsten wrote:
> Hello,
>
> We would like to do some active manipulation between our ME and the SIM
> card. As I understood correctly, the hardware SIMtrace project is just
> about passive monitoring the traffic in between, am I right? So this
> seems to be inappropriate for our aims.
The hardware can co MitM. Only the software has to implement it.
>
> So we thought about a solution more like the RebelSIM card, which is
> documented as well in the osmocomBB wiki. Unfortunately, the information
> given there are also very vague. So maybe it is just outdated: Does
> anybody worked with the RebelSIM card in a way that they try to
> manipulate the responses from the SIM (or do something else, except from
> unlocking their phone)? Is it possible to flash it via SIM card
> interface?!
The rebelSIM can only sniff, even that is very unstable.
This is why we built SIMtrace.
>
> What we actually want to do is to replace same values, e.g. we want to
> provide another Kc than the SIM card in fact has (this is solely a
> research project). So maybe there is some other way to do is, except the
> approach based on RebelSIM? If so I would be grateful for your valuable
> feedback.
You can also try the softSIM project.
Compile osmocomBB with the SAP support from nion, and use the SAP server.
Then you can change everything in software.
>
> Cheers,
> Dirk
>
>
Kevin




More information about the simtrace mailing list