Skip the navigation
News

Hacker snoops on GSM cell phones in demo

By Robert McMillan
July 31, 2010 05:49 PM ET

IDG News Service - Despite concerns that federal authorities might fine or arrest him, hacker Chris Paget went ahead with a live demonstration of mobile phone interception at the Defcon hacking conference Saturday.

Using several thousand dollars worth of equipment, Paget was able to intercept mobile-phone data on the GSM (Global System for Mobile Communications) networks used by AT&T and T-Mobile. He did this using a home-made system he calls an IMSI (International Mobile Subscriber Identity) catcher.

Within minutes of activating his IMSI catcher in test mode, Paget had 30 phones connected to the system. Then, with a few keystrokes, he quickly configured the device to spoof an AT&T cell tower.

"As far as your cell phones are concerned I am now indistinguishable from AT&T," he said. He predicted that every AT&T device in the room would connect to his tower, within the next half hour.

Cell phone interception is illegal in the U.S. And while the U.S. Federal Communications Commission had raised questions about his talk, Paget believes that his demonstration was legal because his device was operating in the 900MHz band used by Ham radio devices.

Coincidentally, that 900MHz band is used by GSM devices in Europe "As far as your cell pones are concerned I am a European radio transmitter."

Not all GSM devices will connect to Paget's IMSI catcher, however. Quad band phones will connect, but U.S. phones that do not support this 900MHz band will not, he said.

By the end of the demo, Paget actually had fewer phones connected to the network -- just 17 -- something he was at a loss to explain. He said that it was possible that he had mistyped the AT&T network ID and that phones were rejecting his system because of the typo.

Android and iPhone systems would connect, however, he said. "In my experience it's generally the iPhones that connect most easily," he said. "It's actually been the bane of my existence trying to keep the damned iPhones away."

People connected to Paget's system would get a warning message, but they could dial out as normal, but anyone trying to call them would go straight to voicemail.

Paget didn't record or play back any calls, but he could have. His IMSI catcher can get around cell phone encryption by simply telling the connecting phones to drop encryption. "If I decide not to enable encryption I just disable it," he said. "It's that simple."

Earlier this week, it wasn't clear that Paget's talk would go ahead. The U.S. Federal Communications Commission (FCC) got in touch with Paget Friday morning to express concern and inform him of relevant federal regulations, he said.

The agency raised concerns that Paget's device might transmit over licensed frequencies and that he might unlawfully intercept mobile-phone calls.

On Friday, FCC spokesman Eric Bash said the agency doesn't comment on the legality of specific matters until it fully investigates and takes enforcement action.

Robert McMillan covers computer security and general technology breaking news for The IDG News Service. Follow Robert on Twitter at @bobmcmillan. Robert's e-mail address is robert_mcmillan@idg.com

(Nancy Gohring in Seattle contributed to this report.)

Reprinted with permission from IDG.net. Story copyright 2010 International Data Group. All rights reserved.

Defcon GSM hack

Additional Resources
ESG - What's Needed for Cloud Computing
WHITE PAPER
Just what is cloud computing anyway? Skeptics might say it is nothing but industry hyperbole, visionaries might say it is the future of IT. In reality, both statements are true - cloud computing has been embellished by the tech industry but it does hold real potential for new types of on-demand dynamic IT services. This paper seeks to clarify the definition of cloud computing, identify how far along users are in terms of cloud deployment, and examine the role of the network in the cloud computing model.
Driving Storage Efficiency in SAN Environments
WHITE PAPER
This ESG paper outlines the considerations for architecting an efficient SAN data storage infrastructure with a focus on the NetApp solutions for increased utilization, improved performance and streamlined protection to reduce operational costs.
Get a Quick ROI from Being Green
WEBCAST
The menu of green initiatives is long, but how do you get an early win with a solid ROI? Enterprise Print Services address sustainability issues well beyond paper usage. Learn how you can get an assessment of enterprise printing to identify underutilized devices, reduce energy consumption, cut waste, and free-up valuable space.
What People Are Saying
Networking White Papers
Seven Key Challenges You Can't Ignore
While virtualization infrastructure platforms provide considerable advantages, VMs also add complexity. By planning for your migration, and recognizing the challenges, you can seamlessly...
Innovation Through End-to-End Unified Networking Solutions
Businesses are struggling to increase revenue and retain customer loyalty due to constant competitive pressure to innovate quickly and deliver greater value to...
Network Infrastructure Growth Drivers
HP ProCurve networking products include a broad line of LAN core switches, LAN edge switches, and wireless LAN and network security solutions that...
Freeing your Network Infrastructure
Advances in technology allow businesses to spur growth, cut costs and stay ahead of competitors. Yet these same improvements have spun a complex...
Redefining the Economics of Networking
This paper provides an overview of the challenges businesses face today and how IT addresses the explicit need to manage network costs, provide...
All Networking White Papers
Networking Webcasts
The Evolution of Managed File Transfer
Managed file transfer has evolved greatly from its earliest meaning of scheduled FTP to today's meaning of complete file governance, including visibility, enforcement,...
The Business Impact of a Workshifting Culture: Corporate America and the Mobile Workforce
Download Now!
3 Steps to Transform Your Data Center
Download Now
Optimizing service modeling, discovery, and monitoring for VMware environments
Learn the challenges and best practices of managing virtualized environments.
Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".
All Networking Webcasts
IT Jobs