Re: [A51] Reporting in.. (what's there, what's missing and some ideas?)

2010-07-28 Thread Fabio Pietrosanti (naif)
On 25/07/10 19.40, Harald Welte wrote: seems fine to me. USRP1 hardware are coming. The 2TB tables are coming (will share it online over a 50Mbps connection for 2-3 months). Next week i should be able to start practical hands-on hacking on the gsm security stuff. By looking at the

Re: [A51] Reporting in.. (what's there, what's missing and some ideas?)

2010-07-28 Thread Frank A. Stevenson
On Wed, 2010-07-28 at 19:20 +0200, Fabio Pietrosanti (naif) wrote: 1) Airprobe dump the phone call traffic - We know that it require important improvement for demodulation of real signals - We have to see which is the best pratical approach to do it, to detect the call, to follow it

Re: [A51] Reporting in.. (what's there, what's missing and some ideas?)

2010-07-28 Thread Dinos Pastos
So the known plain text is a fixed length string, or can it differ dramatically. If it is somewhat fixed we can ask the members to contribute their known plain text into a database in order for others to use. On Wed, Jul 28, 2010 at 10:34 PM, Frank A. Stevenson fr...@hvitehus.no wrote: On Wed,

Re: [A51] Reporting in.. (what's there, what's missing and some ideas?)

2010-07-28 Thread Sylvain Munaut
So the known plain text is a fixed length string, or can it differ dramatically. If it is somewhat fixed we can ask the members to contribute their known plain text into a database in order for others to use. Not read far enough into GSM 04.08 I see :) That plain text will depend on the

Re: [A51] Reporting in..

2010-07-26 Thread suraev
Quoting javier falbo javier_fa...@hotmail.com: In order to monitor more data channel simultaneosly, and prepare the next step which is the 3g (kasumi), which is not so difficult as the algorythm could be decoded very fast with last Asiacrypt paper. Do you have a link to this paper by any

Re: [A51] Reporting in..

2010-07-26 Thread javier falbo
Yes Max. Contact me in private to my email. Javier Date: Mon, 26 Jul 2010 13:12:03 +0200 From: sur...@stud.ntnu.no To: javier_fa...@hotmail.com CC: pe...@stuge.se; a51@lists.reflextor.com Subject: Re: Re: [A51] Reporting in.. Quoting javier falbo javier_fa...@hotmail.com: In order

Re: [A51] Reporting in..

2010-07-26 Thread javier falbo
2010 16:19:51 +0300 Subject: Re: [A51] Reporting in.. From: dino...@gmail.com To: javier_fa...@hotmail.com CC: sur...@stud.ntnu.no; pe...@stuge.se; a51@lists.reflextor.com http://eprint.iacr.org/2010/013.pdf Kasumi whitepaper On Mon, Jul 26, 2010 at 4:13 PM, javier falbo javier_fa

Re: [A51] Reporting in..

2010-07-25 Thread Harald Welte
Hi all, On Sat, Jul 24, 2010 at 08:40:42PM +0100, Cal Leeming [Simplicity Media Ltd] wrote: Yeah, technically someone with a USRP could seed a 20 minute airwave dump, and you could replay it into whatever software you were using, but again, it wouldn't be as fun.. Not sure about the legal

Re: [A51] Reporting in..

2010-07-25 Thread Harald Welte
Hi all, On Sat, Jul 24, 2010 at 09:11:19PM +0200, Clemens Gruber wrote: Yeah. The focus isn't on PCBs. As you say, this is a software intensive area, the required hardware is simple. Hardware in hand of course does not bring any software, but already thinking about that hardware helps

Re: [A51] Reporting in.. (what's there, what's missing and some ideas?)

2010-07-25 Thread Dinos Pastos
Im in the same waiting list. I ordered a USRP2 + a couple of receivers for other research also so Im killing 2 birds with 1 stone in my case. Ive started to read everything out there on the subject and its very enlightening. Regarding legalities, please keep us informed, although each country

Re: [A51] Reporting in.. (what's there, what's missing and some ideas?)

2010-07-25 Thread Sylvain Munaut
Hi, Ok, i just ordered USRP1 + DBRX + Antenna with express shipping and i'm seeing to retrieve a copy of the 2TB rainbow tables. So i should be equiped to be able to run with both OpenBTS and Airprobe. OpenBTS won't work without a RX/TX setup obviously ... (You can extract the RX code and try

Re: [A51] Reporting in..

2010-07-24 Thread Sylvain Munaut
I agree with Peter. It is completely useless to waste time on old hardware. But it'd make for dead cheap sniffer ... There are many groups that try that without success, as each hardware was done with physical limitations. Really ? do you have any specific examples of failed attempt and

Re: [A51] Reporting in..

2010-07-24 Thread Harald Welte
On Sat, Jul 24, 2010 at 01:26:31AM +0100, Cal Leeming [Simplicity Media Ltd] wrote: Besides, you gotta remember, that the USRP is a very expensive piece of kit, and just having one might not be enough depending on what you need it for. See Sylvain's earlier post reply for a good explaination

Re: [A51] Reporting in..

2010-07-24 Thread Sylvain Munaut
But whether you use a USRP2, a USD 20,000 military SDR or a small custom cheap board will not change the fact that somebody still needs to write good demodulaton/decoding software. And any work spent on new hardware development is not going to bring any progress to the project. That's the

Re: [A51] Reporting in..

2010-07-24 Thread Peter Stuge
Harald Welte wrote: what is wrong with you (sorry)? No need to apologize, I think you make a very good point. The problem with regard to practical GSM A5 cracking is not that hardware is too expensive or that you need to do your own custom hardware. The problem is that everybody wants a

Re: [A51] Reporting in..

2010-07-24 Thread sascha
As mentionned OpenBTS laurent's decomposition demod seems to be way better than the current one (from the limited testing I did). Another benefit is that you can exploit CUDA _a_lot_ for the first stage of a multi ARFCN receiver. (when you do the math you'll see that things fit together

Re: [A51] Reporting in..

2010-07-24 Thread Clemens Gruber
On Sat, 2010-07-24 at 20:29 +0200, Peter Stuge wrote: Affordable hardware options mean more people are likely to get involved with open source GSM development in general. True for every other hardware-related open source project I've seen.. Please focus your scarce resources where it is

Re: [A51] Reporting in..

2010-07-24 Thread Peter Stuge
Clemens Gruber wrote: How do you want people to contribute code to the airprobe project if they have not enough money to buy a USRP? It is quite possible even without hardware to test on. It's just not as rewarding. //Peter ___ A51 mailing list

[A51] Reporting in..

2010-07-23 Thread Cal Leeming [Simplicity Media Ltd]
Hey all, Just came across this board yesterday... Pretty amazing stuff tbh. I've always taken a really active interest in anything cellular related, however things went a bit stale about a year ago, and I found myself with less and less time available. But now I really want to get back into it

Re: [A51] Reporting in..

2010-07-23 Thread Cal Leeming [Simplicity Media Ltd]
Hey, Probably most of you already seen this, but, for anyone who doesn't already know about this: https://svn.berlin.ccc.de/projects/airprobe/wiki/DeCryption https://svn.berlin.ccc.de/projects/airprobe/wiki/DeCryptionThere's some rather interesting stuff on that page.. Quite detailed too! On

Re: [A51] Reporting in..

2010-07-23 Thread Cal Leeming [Simplicity Media Ltd]
I've actually been thinking of ways this could be done... Here's some random ideas: - Try and arrange a deal with Ettus Research, in which we could purchase the hardware at a cheaper price for academic based research. - Go to 2600 meetings, and suggest starting up a ccc.de style work

Re: [A51] Reporting in..

2010-07-23 Thread Peter Stuge
Cal Leeming [Simplicity Media Ltd] wrote: Personally, I think it would be a really cool idea to start up work shops which would look primarily at extracting the transceivers out of cheap/unwanted handsets, and putting them to a good use. It would certainly be a lot more fun than just paying

Re: [A51] Reporting in..

2010-07-23 Thread javier falbo
Date: Sat, 24 Jul 2010 06:26:32 +0200 From: pe...@stuge.se To: a51@lists.reflextor.com Subject: Re: [A51] Reporting in.. Cal Leeming [Simplicity Media Ltd] wrote: Personally, I think it would be a really cool idea to start up work shops which would look primarily at extracting

[A51] Reporting finished work

2009-10-16 Thread Terje Sannum
I tried for the first time the command on the wiki to report a completed table, but I'm not sure if that went well... Initialize implementation shortcircuit... [...] 375746560 chains done, current rate 1009015.47 chains/sec (interval: 00:01:00) 385492074 chains done, current rate 1027032.77