#03 — The rest
Lab
GSM sniffing, SDR experiments, smart home automation on Home Assistant, NAS infrastructure and other tinkering at the edges of curiosity.
20
Posts
17
GSM Sniffing
SDR
RPi · radio
-
Setting up an SDR lab on macOS Apple Silicon: Part 2
Part 2 of the macOS ARM64 SDR lab port. A 9-daemon Osmocom 2G+3G core runs native on the LibreSDR B220, with SCTP shim v0.3.x, AF_UNIX SOCK_STREAM fallback for PCUIF, utun…
-
Kraken A5/1 on macOS ARM64 (port notes)
Frank Stevenson’s Kraken builds on Apple Silicon with three patches and a semaphore shim. CPU cracker only. Cross-checked against libosmocore.
-
Setting up an SDR lab on macOS Apple Silicon: Part 1
A small passive SDR research lab on MacBook Pro M4 with LibreSDR B220 Mini. GSM BCCH decode from wideband capture, 35 2G and 34 4G cells inventoried across all Bucharest…
-
Sample density bias in Zigbee temperature averages
Consumer Zigbee sensors report on change, not on schedule. A naive mean() weights every sample equally regardless of how much real time it stands for. When a transient produces hundreds…
-
Why Grafana MCP clients fail behind the Home Assistant ingress proxy
Grafana as a Home Assistant add-on serves its API under a hassio_ingress prefix, not at /api/. Every third-party client I tested hardcodes the shorter path and fails silently with HTTP…
-
Crazy Danish Hacker – SDR Series – International Space Station
Crazy Danish Hacker traces the ISS overhead using RTL-SDR, a directional antenna, and open-source tracking software. A fun radio experiment that shows how much you can hear from low Earth…
-
Crazy Danish Hacker – Signal jamming
Crazy Danish Hacker demonstrates GSM signal jamming with a Raspberry Pi running RPITX: a low-power transmitter that can disrupt cellular reception in a controlled test environment. Illegal in the wild;…
-
Crazy Danish Hacker – Spy on anyone’s location
Crazy Danish Hacker uses GSM sniffing techniques to correlate cell tower interactions and infer a target device’s approximate location: a demonstration of how the GSM protocol leaks location metadata by…
-
Crazy Danish Hacker – GSM Sniffing 16 – Cracking SMS w/ Kraken
Final episode: end-to-end SMS cracking. Feeding captured GSM bursts into Kraken, recovering the A5/1 session key from the rainbow tables, and decrypting the target SMS in plaintext.
-
Crazy Danish Hacker – GSM Sniffing 15 – Kraken install and test
Episode 15: installing Kraken on the Linux server and running the first sanity-check queries against the A5/1 rainbow tables. Confirming the cracker is operational before pointing it at captured traffic.
-
Crazy Danish Hacker – GSM Sniffing 14 – Getting the A5/1 Tables
Episode 14: obtaining the A5/1 rainbow tables used by Kraken to break the GSM stream cipher. Where they come from, storage size, and how they map ciphertext bits to key…
-
Crazy Danish Hacker – GSM Sniffing 13 – Server config install
Episode 13: installing and configuring the Linux server that will host Kraken. Storage layout, network setup, and preparing the environment for the A5/1 rainbow tables.
-
Crazy Danish Hacker – GSM Sniffing 12 – ESXi Server
Episode 12: setting up ESXi as the hypervisor for the GSM lab. Preparing a Linux VM to host the Kraken rainbow-table cracker and other heavier tools.
-
Crazy Danish Hacker – GSM Sniffing 11 – Voice Decryption 101
Episode 11: voice decryption basics. How A5/1-encrypted GSM voice traffic is structured on the traffic channel and what’s needed to move from decoded bursts to intelligible audio.
-
Crazy Danish Hacker – GSM Sniffing 10 – SMS Decryption
Episode 10: SMS decryption. Feeding the captured Kc session key back into the GSM traffic capture to decrypt SMS bursts and recover the plaintext message.
-
Crazy Danish Hacker – GSM Sniffing 9 – TMSI KC Extraction
Episode 9: extracting the TMSI and Kc session key for a target GSM subscriber by correlating paging messages and SDCCH activity, a prerequisite for later voice and SMS decryption.
-
Crazy Danish Hacker – GSM Sniffing 8 – Using GR GRSM
Episode 8: using gr-gsm to capture GSM broadcast channels. Decoding the control channel data and viewing raw traffic in Wireshark with the gsmtap dissector.
-
Crazy Danish Hacker – GSM Sniffing 7 – Installing GR GSM
Episode 7: installing gr-gsm on Linux. Building the GNU Radio-based GSM decoding toolset from source: dependencies, compilation, first sanity check.
-
Crazy Danish Hacker – GSM Sniffing 6 – Locating cell towers
Episode 6: locating nearby GSM cell towers by decoding their broadcast identifiers. Combining kalibrate output with public cell tower databases to map the local RF environment.
-
Crazy Danish Hacker – GSM Sniffing 5 – Kalibrate RTL
Episode 5: using kalibrate-rtl to detect GSM base stations and measure the frequency offset of the RTL-SDR dongle. A calibration step required before serious sniffing work.
-
Crazy Danish Hacker – GSM Sniffing 4 – GQRX Installation and usage
Episode 4: installing and using GQRX, an open-source SDR receiver front-end. First hands-on look at the GSM band with an RTL-SDR dongle.
-
Crazy Danish Hacker – GSM Sniffing 3 – Identifying downlinks
Episode 3: identifying GSM downlink frequencies. Using a spectrum viewer to scan the GSM 900 and 1800 bands and pick out active downlink channels used by nearby cell towers.
-
Crazy Danish Hacker – GSM Sniffing 2 – Requirements
Episode 2: hardware requirements for GSM sniffing. RTL-SDR dongle with E4000 tuner, appropriate antennas, and a Linux workstation. Overview of the toolchain needed for later episodes.
-
Crazy Danish Hacker – GSM Sniffing 1
Episode 1 of Crazy Danish Hacker’s GSM Sniffing series: introduction to the topic, what the series will cover, and the legal boundaries of intercepting GSM traffic in a controlled lab.
-
Building a homemade FM repeater with a Raspberry PI, RPITX and RTL SDR dongle
A radio repeater is usually a radio tower that receives weak signals from handheld, desktop or other radio, and rebroadcasts the same signal at a higher power over a wide…