Crazy Danish Hacker – GSM Sniffing 9 – TMSI KC Extraction
Episode 9: extracting the TMSI and Kc session key for a target GSM subscriber by correlating paging messages and SDCCH activity, a prerequisite for later voice and SMS decryption.
Episode 9: extracting the TMSI and Kc session key for a target GSM subscriber by correlating paging messages and SDCCH activity, a prerequisite for later voice and SMS decryption.
Episode 8: using gr-gsm to capture GSM broadcast channels. Decoding the control channel data and viewing raw traffic in Wireshark with the gsmtap dissector.
Episode 7: installing gr-gsm on Linux. Building the GNU Radio-based GSM decoding toolset from source: dependencies, compilation, first sanity check.
Episode 6: locating nearby GSM cell towers by decoding their broadcast identifiers. Combining kalibrate output with public cell tower databases to map the local RF environment.
Episode 5: using kalibrate-rtl to detect GSM base stations and measure the frequency offset of the RTL-SDR dongle. A calibration step required before serious sniffing work.