awesome-cellular-hacking
Awesome-Cellular-Hacking
https://github.com/eric-erki/awesome-cellular-hacking
Last synced: 19 days ago
JSON representation
-
Cellular Attacks
- Privacy Attacks to the 4G and 5G Cellular Paging Protocols Using Side Channel Information
- Hacking Public Warning System in LTE Mobile Networks
- RF Exploitation: IoT/OT Hacking with SDR
- Hacking Cellular Networks
- Bye-Bye-IMSI-Catchers
- New Privacy Threat on 3G, 4G, and Upcoming 5G AKA Protocols
- White-Stingray: Evaluating IMSI Catchers Detection Applications
- Breaking_LTE_on_Layer_Two
- LTE/LTE-A Jamming, Spoofing, and Sniffing: Threat Assessment and Mitigation
- Exploring LTE security and protocol exploits with open source software and low-cost software radio by Roger Jover
- LTE PROTOCOL EXPLOITS: IMSI CATCHERS,BLOCKING DEVICES AND LOCATION LEAKS
- Using OpenBTS - "Experimental_Security_Assessment_of_BMW_Cars by KeenLab"
- 5G NR Jamming, Spoofing, and Sniffing
- LTE Security – How Good Is It?
- Small Tweaks do Not Help: Differential Power Analysis of MILENAGE Implementations in 3G/4G USIM Cards
- #root via SMS: 4G access level security assessment
- LTE security and protocol exploits
- LTE Recon - (Defcon 23)
- LTE Pwnage: Hacking HLR/HSS and MME CoreNetwork Elements
- Synacktiv
- WiFi IMSI Catcher
- Analysis of the LTE Control Plane
- Demystifying the Mobile Network by Chuck McAuley
- D1T2 - Bypassing GSMA Recommendations on SS7 Networks - Kirill Puzankov
- VoLTE Phreaking - Ralph Moonen
-
Misc
-
Recent Conference Talks/Presentations
- Insecure Connection Bootstrapping in Cellular Networks: The Root of All Evil
- 5GReasoner: A Property-Directed Security and Privacy Analysis Framework for 5G Cellular Network Protocol
- Hiding in Plain Signal:Physical Signal Overshadowing Attack on LTE
- LTE Security Disabled—Misconfiguration in Commercial Network
- Side Channel Analysis in 4G and 5G Cellular Networks
- Shupeng-All-The-4G-Modules-Could-Be-Hacked
- New Vulnerabilities in 5G Networks
-
Resources
-
Rogue BTS & CDMA/GSM Traffic Impersonation and Interception
- How to create an Evil LTE Twin/LTE Rogue BTS
- How To Build Your Own Rogue GSM BTS For Fun and Profit
- Practical attacks against GSM networks: Impersonation
- Building a Portable GSM BTS Using BladeRF/PI
- rtl.sdr.com Tutorial-Analyzing GSM with-Airprobe and Wireshark - SDR software defined radio can be used to analyze cellular phone GSM signals, using Linux based tools GR-GSM (or Airprobe) and Wireshark. This tutorial shows how to set up these tools for use with the RTL-SDR."
- Traffic Interception for Penetration Testing Engagements - exhaustively we commonly see:"
- OpenBTS software - defined radio to present a standard 3GPP air interface to user devices, while simultaneously presenting those devices as SIP endpoints to the Internet
- YateBTS
- bladRF and YateBTS Configuration
-
SIM Specific Attacks
-
SS7/Telecom Specific
Categories
Sub Categories