<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Telco on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/telco/</link>
    <description>Recent content in Telco on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 26 Feb 2018 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/telco/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>TelcoSecDay 2018 – Talks Part2</title>
      <link>https://insinuator.net/2018/02/telcosecday-2018-talks-part2/</link>
      <pubDate>Mon, 26 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/telcosecday-2018-talks-part2/</guid>
      <description>&lt;p&gt;We have the next set of selected talks being announced here. I am super excited about the variety of applications we had this year. Here are some of the talks we will have.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Title: From LoRa technology to deployment within Orange affiliates&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;Speakers: Franck L’Hereec and  Albert Nguyen&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;Just deployed, the LoRa technology has already passed into the hands of hackers who have analyzed the LoRaWAN protocol as well as the objects and gateways that implement it. At Orange, Orange Labs’ security experts have therefore looked into those issues, first to understand it better, and also ensure the network’s deployment in optimal security conditions. Demonstration via the example of the treatment of the security of an innovation project by Orange. During the presentation we will present :&lt;/p&gt;</description>
    </item>
    <item>
      <title>TelcoSecDay 2018 – CFP and First talks</title>
      <link>https://insinuator.net/2018/02/telcosecday-2018-cfp-and-first-talks/</link>
      <pubDate>Thu, 08 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/telcosecday-2018-cfp-and-first-talks/</guid>
      <description>&lt;p&gt;We have a short update from the TelcoSecDay 2018 Agenda. But before that, a short reminder. The CFP for TelcoSecDay 2018 is still open. If you are into telco research, and if you have something interesting to talk, please make a submission &lt;a href=&#34;https://cfp.ernw-insight.de/tsd18/&#34;&gt;here&lt;/a&gt;. The deadline is &lt;strong&gt;17th February 2018.&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Here are the first two confirmed speakers who are going to talk about the below mentioned topics:&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Title: Data Security for 4G Interconnection and 5G Interconnection Risk Areas&lt;/strong&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hacking 101 to mobile data</title>
      <link>https://insinuator.net/2018/02/hacking-101-to-mobile-data/</link>
      <pubDate>Tue, 06 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/hacking-101-to-mobile-data/</guid>
      <description>&lt;p&gt;Here is a short blog post that explains how you can make your own Man-in-the-Middle (MitM) setup for sniffing the traffic between a SIM card and the backend server. This is** NOT a new research** but I hope this will help anyone who doesn’t have a telco background to get started to play with mobile data sniffing and fake base stations. This is applicable to many scenarios today as we have so many IoT devices with SIM cards in it that connects to the backend.&lt;br&gt;&#xA;In this particular case, I am explaining the simplest scenario where the SIM card is working with 2G and GPRS. You can probably expect me with more articles with 3G, 4G MitM in future. But lets stick to 2G and GPRS for now.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Notes on Hijacking GSM/GPRS Connections</title>
      <link>https://insinuator.net/2016/07/notes-on-hijacking-gsm/gprs-connections/</link>
      <pubDate>Sun, 17 Jul 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/07/notes-on-hijacking-gsm/gprs-connections/</guid>
      <description>&lt;p&gt;As shown in previous blogposts we regularly work with GSM/GPRS basestations for &lt;a href=&#34;https://www.insinuator.net/2016/05/some-notes-on-utilizing-telco-networks-for-penetration-tests/&#34;&gt;testing devices with cellular uplinks&lt;/a&gt; or to simply run a &lt;a href=&#34;https://www.insinuator.net/2016/03/troopers16-gsm-network/&#34;&gt;private network during TROOPERS&lt;/a&gt;. Here the core difference between a random TROOPERS attendee and a device we want to hack is the will to join our network, or not! While at the conference we hand out own SIM cards which accept the TROOERPS GSM network as their “home network” some device need to be pushed a little bit.&lt;br&gt;&#xA;Every SIM card has it’s own home network, which is encoded in the fist five (European standard) or six (North American standard) digits of its IMSI – International Subscriber Number. The first three digits are the MCC, the Mobile Country Code, the next two/three the MNC, Mobile Network Code. International network overview are publicly available and for example &lt;a href=&#34;https://www.itu.int/dms_pub/itu-t/opb/sp/T-SP-E.212B-2014-PDF-E.pdf&#34;&gt;can be found &amp;gt;here&amp;lt;&lt;/a&gt;. For instance, Germany has the MCC 262 and Vodafone Germany uses MNC 02. So a SIM card with an IMSI starting with 26202 belongs to them.&lt;br&gt;&#xA;Sticking to the settings in its own SIM card a device will always prefer to connect to it’s own home network above all others. If the home network is not available it will usually go for the strongest signal. To protect users from unnecessary costs, an operator will usually add certain rules to prevent the device from connecting to other networks in the same country. So if you’re an O2 customer in Germany, visit a shopping center and only have reception for a T-Mobile cell, your phone will not directly jump into this network, even though it’s the strongest signal source.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some Notes on Utilizing Telco Networks for Penetration Tests</title>
      <link>https://insinuator.net/2016/05/some-notes-on-utilizing-telco-networks-for-penetration-tests/</link>
      <pubDate>Wed, 25 May 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/05/some-notes-on-utilizing-telco-networks-for-penetration-tests/</guid>
      <description>&lt;p&gt;After a couple of years in pentesting Telco Networks, I’d like to give you some insight into our pentesting methodology and setup we are using for testing “Mobile and Telecommunication Devices”. I am not talking about pentesting professional providers’ equipment (as in previous blogposts), it is about pentesting of devices that have a modem in place like a lot of IoT devices (you know about the fridge having a GSM Modem, right?) do.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TelcoSecDay 2016 – Second Round of Talks</title>
      <link>https://insinuator.net/2016/02/telcosecday-2016-second-round-of-talks/</link>
      <pubDate>Wed, 03 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/telcosecday-2016-second-round-of-talks/</guid>
      <description>&lt;p&gt;I am very happy to announce the second round of talks for the &lt;a href=&#34;https://www.troopers.de/events/troopers16/580_telcosecday_2016_invitation_only/&#34;&gt;TelcoSecDay 2016&lt;/a&gt;. As mentioned in my &lt;a href=&#34;https://www.insinuator.net/2016/01/telcosecday-first-round-of-talks/&#34;&gt;previous post&lt;/a&gt; it will take place on March 15th. All invitations should be out by now; if you think you can contribute to the group and you are willing to join us – please let me know (&lt;a href=&#34;mailto:hschmidt@ernw.de&#34;&gt;hschmidt@ernw.de&lt;/a&gt;).&lt;/p&gt;&#xA;&lt;p&gt;Still, not all talks are confirmed but the newly published talks will provide an idea about TSD 2016 and its discussions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TelcoSecDay – First Round of Talks</title>
      <link>https://insinuator.net/2016/01/telcosecday-first-round-of-talks/</link>
      <pubDate>Sat, 16 Jan 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/01/telcosecday-first-round-of-talks/</guid>
      <description>&lt;p&gt;Dear all,&lt;br&gt;&#xA;This year the &lt;a href=&#34;https://www.troopers.de/events/troopers16/580_telcosecday_2016_invitation_only/&#34;&gt;TelcoSecDay&lt;/a&gt; will take place on March 15th. For those of you who does not know about: the TelcoSecDay it is a sub-event of &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; bringing together researchers, vendors and practitioners from the telecommunication / mobile security field.&lt;/p&gt;&#xA;&lt;p&gt;The event is celebrating its 5th anniversary now, that’s why I’d like to say “thank you” to everybody taking part at this very great discussion round in the last few years. We always had a lot of very good feedback and interesting discussions and the increasing participation list of operators from year to year says (almost) everything!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Welcome to Brazil!</title>
      <link>https://insinuator.net/2015/12/welcome-to-brazil/</link>
      <pubDate>Tue, 01 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/welcome-to-brazil/</guid>
      <description>&lt;p&gt;Welcome to Brazil!&lt;/p&gt;&#xA;&lt;p&gt;“Welcome to Brazil”, I think, turned to being the most used statement during the past Hackers to Hackers Conference in Sao Paulo. It was used as the main reaction to every speech taking moment, and there were a lot of those! To honor the moments and give you a quick insight into was what going on in Sao Paulo, here is a quick summary of the overall event and our own contribution.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How to Get a BaseStation</title>
      <link>https://insinuator.net/2015/05/how-to-get-a-basestation/</link>
      <pubDate>Sun, 17 May 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/05/how-to-get-a-basestation/</guid>
      <description>&lt;p&gt;In our &lt;a href=&#34;http://www.insinuator.net/2014/10/lte-vs-darwin-hackers-to-hackers-conference-11/&#34;&gt;talks&lt;/a&gt; in the past we showed what might be possible if an attacker gets access to backhaul and/or core network of a telecommunication provider. In a security analysts perspective this is really disgusting, but provider always will argument that those attack scenarios are not realistic.&lt;/p&gt;&#xA;&lt;p&gt; Because of legal restrictions we are not able to demonstrate this in practice (e.g. by breaking in into a BTS environment somewhere in the woods) but what we can do is this: building a lab.&lt;br&gt;&#xA;Sometimes it is really shocking what you can buy on Ebay, right? Here we got one very interesting component: a Huawei BBU3900 BaseStation which is used by a couple of providers. Okay, it is for GSM-Rail, but the technology behind is very equal. And for 100 dollars (plus shipping) you don’t ask further questions…&lt;/p&gt;</description>
    </item>
    <item>
      <title>GSM@Troopers</title>
      <link>https://insinuator.net/2015/03/gsm@troopers/</link>
      <pubDate>Wed, 18 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/gsm@troopers/</guid>
      <description>&lt;p&gt;Additionally to Wifi, Troopers is also offering a GSM network.&lt;br&gt;&#xA;If you want to use it, simply ask your phone to scan for available mobile networks. There you should see the usual T-Mobile D, Vodafone.de, E-Plus, O2-de operators, but also the unusual D 23 or 262 23. Just select this one, and your are done. You also can use the Troopers SIMs which you get on the welcome desk on the ground floor.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
