Building a Passive IMSI Catcher
harrisonsand.com
harrisonsand.com
I was accepted for a presentation "SigInt for the Masses;Building and Using a Signals Intelligence Platform for Less than $150"
I already have the device built, and so does someone else on the west coast!
My repo is here, which includes 3d printables (that I designed and printed), Bill of Materials, and bash standup scripts from current Raspbian. https://gitlab.com/crankylinuxuser/siginttablet
What does it look like? https://imgur.com/a/rImW7av
With the nrf mousejack / gr-nordic: https://twitter.com/CrankyLinuxUser/status/11188788307463086...
If you look through my scripts, I compile both gr-gsm and gr-lte, along with https://github.com/Oros42/IMSI-catcher.git as referenced in the project. The signals I can work with/attack/listen are as follows:
tx: 100KHz-1.5GHz
rx: 20MHz-1.7GHz
duplex: 802.11abgn
duplex: nRF24LU1 (nearly all non-BT wireless keyboards and mice)If you join the wi-fi network that any kiosk advertises, you will definitely “re-attach” when you encounter a new kiosk (so some MAC related tracking is possible).
But... do municipal CCTV setups usually go beyond video only and attempt to track people using various methods around bluetooth/MAC/IMSI?
Is it probable? Improbable? We’ll only know in N years when someone leaks about it..? Has it already been done?
Since many networks don't actually have VoLTE fully implemented and working yet (and many popular Android handsets have quirks/bugs/issues around it, coupled with MNOs trying to "pitch" VoLTE as an exclusive feature when you buy the handset direct on their own MNO-modified firmware), a 2G catcher should still work in many scenarios. If 3G is switched off, that (ironically) means that many people's calls will end up going over original 2G networks, where the handset doesn't authenticate the network at all! 3G handsets at least do a mutual authentication of the network.
If you want to look at a real LTE catcher, take a look at this paper [1]. Worth noting this is not passive however, and requires transmitting in licensed spectrum, which defeats the point of this passive one.
East Asia is leading the way in regard to switching-off 2G networks. In certain countries in the region, such as Japan, Macau, Singapore and South Korea, there is no 2G available at all. In Taiwan and Thailand, the major network operators have already phased out 2G with some operators in those countries still offering 2G services for a limited time. https://www.emnify.com/blog/global-2g-phase-out
Active IMSI catchers abuse 2). At this stage of early connection setup, the network is not yet authenticated (the IMSI is required for the authentication). Therefore the smartphone must assume the IMSI request comes from the operator network -- and it cannot tell that it's actually a IMSI catcher.
Case 1) is obviously pretty rare, so it might be a bit boring to perform IMSI catching on 4G.
For example, set up your IMSI catcher next to a numberplate reader. If you repeatedly see a particular IMSI at the same time as a particular numberplate, then there's a fair chance that that phone travels with that car, and therefore that it likely belongs to the driver of the car.
This is easily automated on a large scale, and if anything gets easier as the scale gets larger as you get more data points.
Am I wrong?