Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 38 guests and 3 members online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Wirelessarrow cellular MITM
EH-Net
May 22, 2013, 03:38:33 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: cellular MITM  (Read 4548 times)
0 Members and 1 Guest are viewing this topic.
munkeyfreenix .batcat
Newbie
*
Offline Offline

Posts: 11



View Profile
« on: March 12, 2009, 03:28:14 PM »

Can anyone point me in the right direction for cellular phone protocols? Is there an equivalent to ARP poisoning techniques for cellular? The protocols all are pretty complicated, so I figure there is no point in reinventing the wheel.
Logged
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #1 on: March 12, 2009, 04:25:57 PM »

I believe that actual voice conversations are encrypted (non-analog calls).   You can build devices to capture cellular traffic, but you would still have to decrypt the voice.  I am sure there are backdoors to the encryption, per the feds.   

See the following links for call interception devices:
http://www.cellularintercept.com/
http://www.global-security-solutions.com/PGFDigitalCellularIntercepter.htm

I am sure if you dig, you will find someone outside of your country who is willing to sell you such a device.  I pretty sure it will cost you.
Logged

~~~~~~~~~~~~~~
Ketchup
munkeyfreenix .batcat
Newbie
*
Offline Offline

Posts: 11



View Profile
« Reply #2 on: March 12, 2009, 07:00:59 PM »

Damn, I don't think I've ever been so terrified by a website, nor intrigued.
Quote
Nothing supercedes the need to stop criminals before they strike, and bring outlaws to justice
Err, especially the bill of rights? hmm. Its not like

Honestly, I'm more interested in making really advanced prank calls by manipulating the ATM cells, that and using MitM concept to funnel traffic through my phone.

Encrypted yes, but not very advanced. I was just reading that the G3 network is still using symmetric encryption for backwards compatability, and that the SIM card holds the ticket. I'm sure the social engineers out there can convince people to let them 'borrow your SIM card for a moment', but im sure there is a way in.

anywhere I should look into how phones are identified on the network?
Logged
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #3 on: March 12, 2009, 11:16:31 PM »

Yeah, I thought that was a bit funny in a self-righteous kind of way.

I don't know much about ATM cells.   I think an easier way for you to make prank calls would be to just clone a cell phone or two.  You would have to duplicate the ESN number and the phone number in the phone.   I believe that this is how a carrier identifies a headset.

http://www.collusion.org/Article.cfm?ID=383
Logged

~~~~~~~~~~~~~~
Ketchup
munkeyfreenix .batcat
Newbie
*
Offline Offline

Posts: 11



View Profile
« Reply #4 on: March 16, 2009, 03:43:48 PM »

thanks. i'll look into that.

ATM cells are really small (about 48 bytes) but have a Virtual Channel and Virtual Path indicator in the header. But maybe going that low isn't all that necessary up front.

and prank calls are just the 'public face' of this idea. you can pass out a program with instructions on how to spoof a phone number, but those that know will be able to use it for alot more (for example, tunneling sensitive information through the audio signal of a phone conversation that is inserted and extracted using phase vocoding synthesis techniques, which then can be routed through various phones to avoid tracing). and of course, there will be little instruction (ie none) shipped with the app.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.052 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.