Project

General

Profile

Sniffing notes

The OsmocomBB git repository contains a branch called sylvain/burst_ind. Using this branch, you can dump the burst sequences from the network by running layer1.bin and ccch_scan. However, this is only useful if you know what you are doing or if you are sniffing on your own network. See Sylvains explanations about his sniffing attack. Also have a look at his and Karsten Nohl's presentation that they held at 27c3 (https://media.ccc.de/v/27c3-4208-en-wideband_gsm_sniffing).

In case you want to decrypt your own phone calls without knowing the Kc (which is stored e.g. on the SIM and can be read from there), you need to have Kraken and a guesser (as Sylvain explains in the mail above) that guesses the key stream that you need as input for Kraken. See Sylvain's hints for known plaintext vulnerabilities in the GSM framework.

The burst_ind branch ONLY WORKS WITH FTDI (FT232) OR CP210x BASED SERIAL CONVERTERS

Add picture from clipboard (Maximum size: 48.8 MB)