DIY Mobile Intercept
by r0llb4ck - Sunday April 7, 2024 at 07:59 AM
#1
This may be out of the scope of this forum but I am looking  for some advice around a pet project I have been working on for a while.

The basic layout so far is:
YateBTS --> Asterisk

This set up would take calls from devices attached to the BTS and route them through asterisk then on to a voip gateway and on to the intended call recipient.  That's great but means I'm limited to setting up only in places where I have hardwired internet access.  So after some research I decided to a buy a simbox.

[Image: Hbdda3fde7a4b499f95f824fe43b03e90W.jpg]

This gives me the ability to reinsert the calls back into the mobile network without having to  worry about what raffic is going out over my ISP.  It also means my set up is now mobile..  Awesome.... yes?  No

The Simbox, while super cool and having allowed me to run some pretty cool experiments around SMS (if anyone knows the trick for getting the Cell ID back from a silent SMS please PM me) it does however run software and firmware from the company I purchased it from.  This dials out to check for valid licences for the box etc and can be controlled externally which obviously we can't have.

As Ive seen this  device for sale from multiple vendors I assume there has to be stock firmnware and software somewhere but as of yet have been unable to locate it.

If anyone can point me in the right direction or perhaps guide me in how i might be able to edit what onboard that would be amazing;
Reply
#2
What area of the world are you in? I don't know much about this, so my question comes from curiosity, not questioning whether or not it will work. But my understanding is most phone baseband protocols in countries like the US are encrypted. Does this solve that? Or are you trying to capture the devices or carriers that still use < 3g? Would love to understand more.
Reply
#3
You could route calls/texts over SS7 if you have a T1/T3/etc with a telco. You can VPN tunnel through your Simbox to an Asterisk box that has a T1 PCI card located at your homebase/remote location. As I'm making a few presumptions about your setup, I'm throwing a dart.

Secondarily: doesn't Yates only support 2G? Also curious, why not use OpenBTS?
Looking for Python WebDev to Help Build a PubNet Site
DM Me Fentanyl Supply Chain Info
Reply
#4
Here is someone using a rooted Qualcomm phone to capture raw packets of 4G/5G. This can also be a good solution to this thing: https://hackaday.com/2024/04/30/turn-you...r-sniffer/
Reply
#5
(04-23-2024, 12:42 AM)AFS_Nemesis Wrote: You could route calls/texts over SS7 if you have a T1/T3/etc with a telco. You can VPN tunnel through your Simbox to an Asterisk box that has a T1 PCI card located at your homebase/remote location. As I'm making a few presumptions about your setup, I'm throwing a dart.

Secondarily: doesn't Yates only support 2G? Also curious, why not use OpenBTS?

what is T1/T3 and how to get it???
and does it get the job done?
Reply


Forum Jump:


 Users browsing this thread: 1 Guest(s)