How to Build Your Own Rogue GSM BTS for Fun and Profit
evilsocket.net
evilsocket.net
Otherwise, in the US expect the FCC and network operators to become intimately familiar with who you are rather quickly.
Having random public phones roam onto your rouge cellular network is a public safety risk (potentially no 911 access) as well as any number of laws being directly broken (unlicensed spectrum use, denial of service to legitimate licensed networks etc).
Once you have that, you can start operating digital modes on local bands at low power. You'll be amazed how far you can stretch 5W of transmitter.
Just for reference, here's all the allocations. They've got fairly verbose rules http://www.arrl.org/frequency-allocations
They were also talking about the people that built the devices.
Totally agree with the sentiment though. Apply for an experimental FCC license!
However, recently Germany sold out part of spectrum that was used for those licenses, so it became much harder now there. The network on last CCC almost didn't happen, but the provider who bought it (T-Mobile IIRC?) allowed to use it this time anyway. The future is a one big question mark though :(
You'll see this type of antenna mounted typically right on top of the equipment housing structure. Each one you see will tell you how many providers are there.
http://www.antenna.com/media/GPSL1-TMG-SPI-40NCB-thumb.png
(Note that it is small, about 6 inches in height. And different variations abound, but they are typically painted white and mounted right on the structure for LOS view to the sky)
There are plenty of areas where you can play with this on low power without pissing off the feds or ILECs. The creators of OpenBTS did this to provide service where it doesn't exist - in the middle of a desert, providing service to 30,000 people over a 7 square kilometer area, for example.
It should go without saying that broadcasting a pirate signal in a populated area is a bad idea.
The barrier to entry for this implementation is a little over $600 USD. If someone brought this solution online in their apartment in midtown Manhattan NYC, they would potentially affect hundreds, if not thousands of devices.
Someone who is deploying an OpenBTS in the middle of the desert probably already has a good understanding of their existing RF environment.
I'm willing to bet that just about everyone participating here lives in an RF rich environment where if they brought solution online, it would impact someone.
People who buy BTS equipment are aware that they are creating a cell tower and it will affect people around them and the police and cell network providers will not be happy with them if that happens.
Unlikely since the range of this device is about a single small / medium apartment building.
There's a 1 watt/4 watt limit, but I'm really curious how easy it'd be to get full voice 2G (Euro spec standard) coverage for Manhattan. This is all on consumer-compatible Euro/Asia and/or quad-band units out of the box too. Capacity for each BTS was around 12 concurrent voice channels (IIRC) and when I ran numbers you'd get ~1.2 radial KM coverage[edit: indoors, not LOS (which is drastically further)] at the setup I spec'd out (it was a while ago, apologies, but I think it was Yagi style capable of +70dbm).
Also, similar topic - why is there such a dearth of information on hacking / forcibly opening up mobile basebands? Is it that there isn't much tinkering to be done once inside (just a lot of opaque DSP code), or are they really locked down that well, or is it simply that the people who develop such knowhow earn a living through phone unlocking etc and thus don't publicize?
I'd really like to see some device hacked open enough such that all the surveillance identifiers (IMEI etc) could be freely scrubbed. After that, psuedonymously obtain network access via a remote SIM card proxied over IP - bootstrap with an existing wifi, and then I'd hope any renegotiation could take place over the device's own connection.
RE: The dearth of information: Forcibly opening up? As in like, violating FCC rules? I mean, the knowledge is out there and readily available on the public internet if you know where to look. You can still find o-chem forums with PhD students talking about the manufacturing of research chemicals, but its masked in their own lexicon (an idiot can't just Google "how do i make {insert designer drug of choice}", but you'll find a lot re: "wacker oxidation of foo in bar" or "reductive amination in a Vigreux column").
Just like we've got specs and RFCs for all of our protocols, the mobile industry meets up and agrees on everything from MIPI standards (ever wondered how there are so many Chinese Android devices with so many different seemingly interchangable components like video cameras, GPS modules, etc? There's a spec everything). You could easily take over some of the 850mhz spectra for a day or two but a) what would you have to gain? I guess you could sell baseband equipment to private investigators for a huge premium, thats about it, b) even if you could monetize it, the FCC would storm in on you within a couple days, a week at most.
RE: devices hacked open - Shenzhen has everything.
[1] https://en.wikipedia.org/wiki/United_States_2008_wireless_sp...
For opening up, fundamentally any device should be open to inspection and modification by its owner. But my specific desire would be to eliminate the fixed identifiers from the protocol, to restore some privacy of these tracking devices we expect to carry everywhere.
Homebrew hardware and a Free stack would be a massive undertaking and capital-intensive to distribute. So a better starting point would be some already-distributed piece of consumer hardware. I'd think there would be at least one device that got reverse engineered enough to create some community flash-it-yourself distribution. Perhaps I'm just not doing the right searches, but I just run across vague allusions from either people who are in the know and NDA, independents who dug in a bit but only published summaries of results, or commercial-oriented unlockers only interested in achieving their narrow result.
I guess I'm left wondering whether Qualcomm's hardware security really is that good to destroy the enthusiasm for such tinkering, or whether it's just their legal goons have so far successfully contained the knowledge to the secretive unlocking market.
While it doesn't even intend to be "consumer friendly" firmware replacement, the project provides a lot of interesting info on hacking TI Calypso basebands used for instance in some old Motorola devices and Openmoko phones.
Proxied SIM probably won't work due to timing constraints and I don't think it could be possible on device's own connection, but I'm not really an expert in this area, so don't believe me and my educated guesses too much.
However, counter-intuitively, playing with stuff like IMEI number will probably make you even easier target. Some hardware characteristics of your device could be used to "fingerprint" it, and having a lot of IMEIs being advertised by some old Calypso device in similar area could easily bring some attention to it.
Obviously a small or singular mix group can be worse than no psuedonymity at all, but the idea would be to go for wider adoption. If I actually wanted to privately engage in illegal activity, I'd just buy burner phones and use the appropriate opsec. Really I just want to enable privacy for all of us who don't have something to hide.
The market doesn't exist in the US yet, but Europe seems to be somewhat accustomed to it.
So yes, this generally includes all bits of protocol below the simplistic IP and AT-command based session interface that's exported.
(My idea for "SIM proxying": The link between a SIM and the baseband processor is a simple serial link. So as long as latency requirements could be met, this serial link could be tunneled over IP, allowing one to rent a SIM card that wasn't actually in their possession).
So don't let other people on it.
Fun story: I worked for a company in the UK making GSM picocells with IP backhaul. One day, due to a misconfiguration, we had a lot of confused people from other offices in the building wondering why their phones were roaming onto a Canadian cell network thousands of miles across the Atlantic. Oops.
EDIT: found 2 apps claiming to be able to detect this.
https://play.google.com/store/apps/details?id=com.skibapps.c...
https://play.google.com/store/apps/details?id=de.srlabs.snoo...
Another app is called aimsicd, I use it personally. Not paranoid, but there's no reason not to use it really. No noticeable drain on battery, and it would be interesting to know if it ever did throw anything.
I think in older GSM-derived systems, the SIM just computed an authenticator based on a nonce provided by the network.
I know for sure that CDMA (IS-95 and 2000) and later AMPS systems supported one-way authentication or not, as selected by the network.
I've heard rumors that attackers have to force a protocol downgrade to something without mutual authentication by jamming the legitimate signal. The other options for the attack would seem to include
- obtaining the secret key value (or a set of authentication vectors) from the legitimate network. Either of these seems more difficult to obtain than the actual locations that the attackers claim to want.
- obtaining K from SIM manufacturers, which has happened [2].
- exploiting implementation defects in SIMs or mobiles.
[1] 3GPP/ETSI TS 133 102 "3G security: security architecture", http://www.etsi.org/deliver/etsi_ts/133100_133199/133102/13....
[2] https://hn.algolia.com/?query=gemalto&sort=byPopularity&pref...
I now also read about "femtocells" used among else by Verizon (which dievices have been hacked) that are used to extend the signal coverage by costumers. It is an interesting topic overall. I think i will dive more into it...
interesting, never saw this kind of typo before, since those two letters are quite far off..
Sorry, i do all kind of weird typos, sometimes i do not spot them.
Here's a list of apps to get cell data: http://wiki.opencellid.org/wiki/Data_sources
If you're using a CDMA phone and are still concerned, you can try modifying your own PRL and blocking carrier updates.
It's a relief that major operators today are actively rolling out 4G SIM cards, and law enforcements are taking malicious stations seriously. So today if you set up rogue GSM BTS, you might be prosecuted.
[1] http://www.theregister.co.uk/2014/03/26/spam_text_china_clam...
I thought you can't post duplicate content.?
> Are reposts ok?
> If a story has had significant attention in the last year or so, we kill reposts as duplicates. If not, a small number of reposts is ok.
> Please don't delete and repost the same story, though. Accounts that do that eventually lose submission privileges.
https://hn.algolia.com/?query=How%20to%20Build%20Your%20Own%...
Please don't mention the search bar.