<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>4G on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/4g/</link>
    <description>Recent content in 4G on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 20 Sep 2016 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/4g/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Attacking BaseStations @Defcon24</title>
      <link>https://insinuator.net/2016/09/attacking-basestations-@defcon24/</link>
      <pubDate>Tue, 20 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/attacking-basestations-@defcon24/</guid>
      <description>&lt;p&gt;Hello Guys,&lt;br&gt;&#xA;back from my vacation I’d like to give you some impressions about Defcon 24 and our talk “Attacking BaseStations”. Defcon itself had a couple of great talks but was a very crowded location. Anyhow, we had a couple of great discussions with the people before and after our talk.&lt;/p&gt;&#xA;&lt;p&gt;The talk “Attacking BaseStations” focussed on attack vectors we simulated in &lt;a href=&#34;https://www.insinuator.net/2015/05/how-to-get-as-basestation/&#34;&gt;our lab&lt;/a&gt;. Besides attacking a BaseStation via Radio interface, in this talk we focussed on local and remote interfaces as introduced in &lt;a href=&#34;https://www.insinuator.net/2014/10/lte-vs-darwin-hackers-to-hackers-conference-11/&#34;&gt;“LTE vs. Darwin”&lt;/a&gt;. As target of evaluation one of our eNodeB’s came into play, which we purchased on the Internet. Anyhow, the talk covered the following attack scenarios:&lt;/p&gt;</description>
    </item>
    <item>
      <title>VoLTE Security Analysis, part 2</title>
      <link>https://insinuator.net/2016/06/volte-security-analysis-part-2/</link>
      <pubDate>Fri, 24 Jun 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/06/volte-security-analysis-part-2/</guid>
      <description>&lt;p&gt;In our talk &lt;em&gt;&lt;a href=&#34;https://www.ernw.de/download/telco/ERNW_Area41_IMSecure.pdf&#34;&gt;IMSEcure – Attacking VoLTE&lt;/a&gt;&lt;/em&gt; Brian and me presented some theoretical and practical attacks against IP Multimedia Subsystems (IMS). Some of the attacks already have been introduced in a former &lt;a href=&#34;https://www.insinuator.net/2016/01/security-analysis-of-volte-part-1/&#34;&gt;blogpost&lt;/a&gt; and Ahmad &lt;a href=&#34;https://www.insinuator.net/2016/02/denial-of-service-attacks-on-volte/&#34;&gt;continued&lt;/a&gt; with a deeper analysis of the Flooding and targeted DoS scenario. But still, there are some open topics I’d like to continue with now. The methods I am demonstrating here also help to get a better understanding of VoLTE/IMS and how it is implemented on modern smartphones.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Denial of Service attacks on VoLTE</title>
      <link>https://insinuator.net/2016/02/denial-of-service-attacks-on-volte/</link>
      <pubDate>Wed, 03 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/denial-of-service-attacks-on-volte/</guid>
      <description>&lt;p&gt;Some weeks ago Hendrik explained in his blogpost &lt;a href=&#34;https://www.insinuator.net/2016/01/security-analysis-of-volte-part-1/&#34;&gt;Security Analysis of VoLTE, Part 1&lt;/a&gt; some attack vectors for Voice over LTE (VoLTE). One attack vector introduced was Denial of Service (DoS), which I also discussed in my Masterthesis “Evaluation of IMS security and Developing penetration tests of IMS”.&lt;/p&gt;&#xA;&lt;p&gt;In general, DoS attacks aim to prevent a system or a network from efficiently providing its service to legitimate users . The impact of such attacks can vary from a big degradation of quality to total blockage. DoS can occur on users level, where a user or a group of users cannot use the service. But the common conception of DoS is on the service level, where the whole service is broken, unstable or totally down. This blog post is about targeting DoS of the whole VoLTE service by attacking IMS.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Analysis of VoLTE, Part 1</title>
      <link>https://insinuator.net/2016/01/security-analysis-of-volte-part-1/</link>
      <pubDate>Wed, 06 Jan 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/01/security-analysis-of-volte-part-1/</guid>
      <description>&lt;p&gt;Hello everybody,&lt;br&gt;&#xA;this time I’d like to share some thoughts and results about our telco research last year. We gathered a lot of information out of some projects we’d like to share and discuss with you. The following sections also provide an idea of the upcoming Telecommunication Security Workshop I will give with Kevin Redon at Troopers (&lt;a href=&#34;https://www.troopers.de/events/troopers16/573_telco_network_security/&#34;&gt;click&lt;/a&gt;). The workshop will be about Radio Network Security (covered by Kevin) and security aspects of the Core Network (covered by myself), mainly focusing on Voice over LTE (VoLTE). That’s also the topic of today’s post.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Wireless LAN Pros Conference</title>
      <link>https://insinuator.net/2015/11/wireless-lan-pros-conference/</link>
      <pubDate>Wed, 11 Nov 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/11/wireless-lan-pros-conference/</guid>
      <description>&lt;p&gt;Last week, on the 27th-28th I attended a nice wireless conference in berlin, the WLPC (Wireless LAN Pros Conference). You can visit their website at &lt;a href=&#34;http://berlin2015.wlanprosconference.com/http:/berlin2015.wlanprosconference.com/&#34;&gt;http://berlin2015.wlanprosconference.com.&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;This conference is a community-driven conference from wireless professionals with focus on typical topics that come up when you are planning or running large wireless networks. This is a mainly Twitter based community, you can see some Tweets with hashtags #WLPC for example. There were also some interesting talks about future networks, for example Marko Tisler gave a talk about wireless LAN and SDN and what we can expect and what SDN will not solve for wireless networks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Telco Research 2015</title>
      <link>https://insinuator.net/2015/01/telco-research-2015/</link>
      <pubDate>Fri, 02 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/telco-research-2015/</guid>
      <description>&lt;p&gt;Hello and a happy new year 2015 to everybody!&lt;/p&gt;&#xA;&lt;p&gt;As follow up of our 2014 talk &lt;a href=&#34;http://www.insinuator.net/2014/10/lte-vs-darwin-hackers-to-hackers-conference-11/&#34;&gt;“LTE vs. Darwin&lt;/a&gt;” I want to inform you about our telco research in 2015. We are currently dealing with the so called IP Multimedia Subsystem (IMS), which handles the call and media logic of 4G telecommunication networks. This network part provides functions like VoIP (or VoLTE) and takes care of the interconnection to other call or media related networks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>LTE vs. Darwin @ Hackers to Hackers Conference 11</title>
      <link>https://insinuator.net/2014/10/lte-vs.-darwin-@-hackers-to-hackers-conference-11/</link>
      <pubDate>Sun, 19 Oct 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/10/lte-vs.-darwin-@-hackers-to-hackers-conference-11/</guid>
      <description>&lt;p&gt;Hello Everybody and greetings from Sao Paulo,&lt;/p&gt;&#xA;&lt;p&gt; &lt;br&gt;&#xA;We’re currently enjoying the Brazilian sunshine, waiting for H2H2 11’s closing remarks and decided to give you a few details on the past three days. The conference was opened by a short welcome by our fellow Trooper Rodrigo Rubira Branco and stuffed with loads of great talks. This year’s keynotes came from Daniel J. Bernstein and Halvar Flake and gave yet another insight into the ever changing world of InfoSec. The international lineup also included Travis Goodspeed, Sergej Bratus and Fernando Gont. H2HC was a great chance for us to talk to various Hackers from around the world and share our opinions and knowledge.We can only warmly recommend a visit to next year’s H2HC in Sao Paulo.&lt;br&gt;&#xA;Many many thanks to Rodrigo, Laila and the rest of the team for an awesome weekend. And a quick hello to all new followers on Insinuator.net, we’re looking forward to meeting you all again, soon.&lt;/p&gt;</description>
    </item>
    <item>
      <title>New Tool: s1ap_enum</title>
      <link>https://insinuator.net/2014/06/new-tool-s1ap_enum/</link>
      <pubDate>Wed, 25 Jun 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/06/new-tool-s1ap_enum/</guid>
      <description>&lt;p&gt;As we continue our research in the 3GPP protocol world, there is a new tool for you to play with. It is called &lt;strong&gt;s1ap_enum&lt;/strong&gt; and thats also what it does  😉&lt;/p&gt;&#xA;&lt;p&gt;The tool itself is written in erlang, as i found no other free ASN.1 parser that is able to parse those fancy 3GPP protocol specs. It connects to an MME on sctp/36412 and tries to initiate a S1AP session by sending an S1SetupRequest PDU. To establish a S1AP session with an MME the right MCC and MNC are needed in the PLMNIdentity. The tool tries to guess the right MCC/MNC combinations. It comes with a preset of known MCC/MNC pairs from &lt;a href=&#34;http://www.mcc-mnc.com/&#34;&gt;mcc-mnc.com&lt;/a&gt;, but can try all other combinations as well.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hackito Ergo Sum 2014</title>
      <link>https://insinuator.net/2014/05/hackito-ergo-sum-2014/</link>
      <pubDate>Fri, 02 May 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/05/hackito-ergo-sum-2014/</guid>
      <description>&lt;p&gt;Greetings from Heidelberg to Paris,&lt;/p&gt;&#xA;&lt;p&gt;and thanks for a great time at &lt;a href=&#34;http://2014.hackitoergosum.org/&#34;&gt;HES14&lt;/a&gt;! A nice venue (&lt;a href=&#34;http://www.cite-sciences.fr/fr/accueil/&#34;&gt;a museum&lt;/a&gt;), sweet talks and stacks of spirit carried us through the three day con. It all set off with a keynote byTROOPERs veteran Edmond ‘bigezy’ Rogers, who stuck to a quite simple principle: “People do stupid things” and I guess every single one of you has quite a few examples for that on offer. Next to every speaker referenced that statement at some point during her/his talk. Furthermore we presented an updated version of our talk &lt;a href=&#34;http://2014.hackitoergosum.org/slides/day1_ERNW_LTEvsDarwin_HES.pdf&#34;&gt;LTE vs. Darwin&lt;/a&gt;, covering our research of security in LTE networks and potential upcoming problems.&lt;/p&gt;</description>
    </item>
    <item>
      <title>LTE@ShmooCon, a Summary</title>
      <link>https://insinuator.net/2014/01/lte@shmoocon-a-summary/</link>
      <pubDate>Tue, 28 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/lte@shmoocon-a-summary/</guid>
      <description>&lt;p&gt;Hey guys,&lt;br&gt;&#xA;as some of you may have noticed, just recently at ShmooCon we gave our talk “LTE vs. Darwin” (Slides &lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2014/01/ERNW_LTEvsDarwin.pdf&#34;&gt;here&lt;/a&gt;). There we presented some results of our research in 4G telco network security. Some of those originate from our research contribution to &lt;a href=&#34;www.asmonia.de&#34;&gt;ASMONIA&lt;/a&gt;, but we expanded the scope and also took a look at the air interface. Both the air interface and the backend links &amp;amp; protocols must be secured appropriately; otherwise communication may be eavesdropped or sensitive information may be compromised. In the following we want to provide an overview of LTE main components and potential attack vectors.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers TelcoSecDay</title>
      <link>https://insinuator.net/2012/03/troopers-telcosecday/</link>
      <pubDate>Sat, 17 Mar 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/03/troopers-telcosecday/</guid>
      <description>&lt;p&gt;As there has been some public demand for that, here we go with the final agenda for the Troopers “&lt;a href=&#34;http://www.troopers.de/troopers12/agenda/telcosec-day/&#34;&gt;TelcoSecDay&lt;/a&gt;“. The workshop is meant to provide a platform for research exchange between operators, vendors and researchers. The slides of the talks will potentially be made available as well.&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;8:30: Opening Remarks &amp;amp; Introduction&lt;/li&gt;&#xA;&lt;li&gt;9:00: Sebastian Schrittwieser (SBA Research): Guess Who’s Texting You? Evaluating the Security of Smartphone Messaging Applications.&lt;/li&gt;&#xA;&lt;li&gt;10:00: Peter Schneider (NSN): How to secure an LTE-Network: Just applying the 3GPP security standards and that’s it?&lt;/li&gt;&#xA;&lt;li&gt;10:45: Break&lt;/li&gt;&#xA;&lt;li&gt;11:00: Kevin Redon (T-Labs): Weaponizing Femtocells – The Effect of Rogue Devices on Mobile Telecommunications&lt;/li&gt;&#xA;&lt;li&gt;11:45: Christian Kagerhuber (Group IT Security, Deutsche Telekom AG): Security Compliance Audit Automation (SCA, TeleManagementForum TMF528)&lt;/li&gt;&#xA;&lt;li&gt;12:30: Lunch&lt;/li&gt;&#xA;&lt;li&gt;13:45: Philipp Langlois (P1 Security): Assault on the GRX (GPRS Roaming eXchange) from the Telecom Core Network perspective, from 2.5G to LTE Advanced.&lt;/li&gt;&#xA;&lt;li&gt;15:00: Break&lt;/li&gt;&#xA;&lt;li&gt;15:15: Harald Welte (sysmocom): Structural deficits in telecom security&lt;/li&gt;&#xA;&lt;li&gt;16:30: Closing Remarks&lt;/li&gt;&#xA;&lt;li&gt;17:00: End of workshop&lt;/li&gt;&#xA;&lt;li&gt;19:00: Joint dinner (hosted by ERNW) in Heidelberg Altstadt for those interested and/or staying for the main conference&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;====&lt;/p&gt;</description>
    </item>
    <item>
      <title>Week of releases – gtp_scan-0.7</title>
      <link>https://insinuator.net/2011/07/week-of-releases-gtp_scan-0.7/</link>
      <pubDate>Wed, 13 Jul 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/07/week-of-releases-gtp_scan-0.7/</guid>
      <description>&lt;p&gt;So, after having a completely new release yesterday, we will stay with already known but updated software today. You might have heard of gtp_scan before, which is a small python script for scanning mainly 3G and 4G devices and detecting GTP (GPRS Tunneling Protocol) enabled ports. As GTP is transported via UDP and we all know, UDP scanning is a pain, the tool uses the GTP build-in echo mechanism to detect GTP speaking ports. Since the last version I’ve implemented some new features:&lt;/p&gt;</description>
    </item>
    <item>
      <title>GTP_SCAN released</title>
      <link>https://insinuator.net/2011/03/gtp_scan-released/</link>
      <pubDate>Tue, 01 Mar 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/03/gtp_scan-released/</guid>
      <description>&lt;p&gt;gtp_scan is a small python script that scans for GTP (GPRS tunneling protocol) speaking hosts. To discover those hosts it uses the GTP build in PING mechanism, it sends a GTP packet of the type ECHO_REQUEST and listens for an incoming GTP ECHO_REPLY. Its capable of generating ECHO_REQUESTS for GTP version 1 and GTP version 2. Also the script can scan for both, GTP-C and GTP-U (the control channel and the user data channel), only the port differs here.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
