{"id":1186,"date":"2011-01-03T20:28:22","date_gmt":"2011-01-03T20:28:22","guid":{"rendered":"http:\/\/nethemba.com\/cs\/nove-trendy-v-gsm-odpocuvani\/"},"modified":"2011-01-03T20:28:22","modified_gmt":"2011-01-03T20:28:22","slug":"nove-trendy-v-gsm-odpocuvani","status":"publish","type":"post","link":"https:\/\/nethemba.com\/cs\/nove-trendy-v-gsm-odpocuvani\/","title":{"rendered":"Nov\u00e9 trendy v GSM odpo\u010d\u00favan\u00ed"},"content":{"rendered":"<p id=\"yui_patched_v3_11_0_1_1454064741035_646\">E\u0161te minul\u00fd rok svetov\u00e1 GSM asoci\u00e1cia verejne prehl\u00e1sila, \u017ee GSM odpo\u010d\u00favanie je stal\u00e9 pr\u00edli\u0161 drah\u00e9 a komplexn\u00e9, nako\u013eko \u00fato\u010dn\u00edk mus\u00ed disponova\u0165 \u0161peci\u00e1lnym odpo\u010d\u00favac\u00edm zariaden\u00edm (typu USRP2) a pou\u017eiva\u0165 komplexn\u00fd &#8222;signal processing&#8220; softv\u00e9r na identifik\u00e1ciu a zaznamen\u00e1vanie odchyt\u00e1van\u00fdch hovorov.<\/p>\n<p>Na tohtoro\u010dnom 27c3 (Chaos Communication Congress) v Berl\u00edne sme mali mo\u017enos\u0165 vidie\u0165 \u0161okuj\u00facu prezent\u00e1ciu (v\u00fdskumn\u00edkov Karstena Nohla a Sylvaina Munauta), ktor\u00e1 demon\u0161trovala, \u017ee to u\u017e v\u00f4bec nie je pravda a GSM komunik\u00e1ciu je mo\u017en\u00e9 kompletne odpo\u010d\u00fava\u0165 a prelomi\u0165 len s pou\u017eit\u00edm ve\u013emi lacn\u00fdch be\u017ene dostupn\u00fdch telef\u00f3nov so \u0161peci\u00e1lne upraven\u00fdm firmwarom (OsmocomBB).<\/p>\n<p><strong>Cena re\u00e1lneho \u00fatoku na GSM sa teda drasticky zni\u017eila na desiatky \u20ac!<\/strong><\/p>\n<p>Architekt\u00fara GSM, zn\u00e1me zranite\u013enosti a probl\u00e9my GSM<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/zedomax.com\/blog\/wp-content\/uploads\/2009\/12\/gsm-hacked.png\" alt=\"GSM hacked\" \/><br \/>\nV\u00e1\u0161 telef\u00f3n je pripojen\u00fd \/ asociovan\u00fd na BTS (Base Transceiver Station) stanicu, stovky BTS stanic s\u00fa prepojen\u00e9 na BSC (Base Station Controller), ktor\u00e9 medzi sebou komunikuj\u00fa pomocou protokolu A-BIS. Tento cel\u00fd syst\u00e9m (Base Station Subsystem) je prepojen\u00fd s NSS (Network Sub System), ktor\u00fd pozost\u00e1va z centr\u00e1lneho switchu (MSC), datab\u00e1zy \u00fa\u010dastn\u00edkov siete (HLR), datab\u00e1zy autentifika\u010dn\u00fdch k\u013e\u00fa\u010dov (AUC), registra \u00fa\u010dastn\u00edkov pou\u017eivaj\u00facich roaming (VLR) a registra ukradnut\u00fdch telef\u00f3nov (EIR).<br \/>\nMedzi telef\u00f3nom a GSM sie\u0165ou neexistuje obojstrann\u00e1 autentifik\u00e1cia, \u010do samozrejme m\u00f4\u017ee vies\u0165 k riziku podvrhnut\u00fdch GSM siet\u00ed, MITM \u00fatokov at\u010f.<\/p>\n<p>Algoritmy A5\/1, A5\/2 s\u00fa u\u017e nieko\u013eko rokov tie\u017e prelomen\u00e9. \u010co je hor\u0161ie, \u0161ifrovanie je samozrejme volite\u013en\u00e9 a vlastn\u00edk telef\u00f3nu samozrejme nikdy nie je informovan\u00fd o tom, \u010di je dan\u00e9 GSM \u0161ifrovanie zapnut\u00e9 alebo nie.<\/p>\n<p>Baseband procesor nad ktor\u00fdm be\u017ei GSM stack je obvykle ARM7 (2G\/2.5G telef\u00f3ny) alebo ARM9 (3G\/3.5G telef\u00f3ny), ktor\u00fd nedisponuje \u017eiadnymi modern\u00fdmi bezpe\u010dnostn\u00fdmi ochranami (ako napr\u00edklad ochrana vo\u010di prete\u010deniu buffra, ve\u013ea presunov v pam\u00e4ti je st\u00e1le realizovan\u00fdch cez memcpy(), ch\u00fdbaj\u00fa non-executable str\u00e1nky, \u010di randomiz\u00e1cia adries, adresovov\u00fd priestor medzi baseband procesorom a aplik\u00e1ciami nie je oddelen\u00fd at\u010f). Existuj\u00fa preto re\u00e1lne koncepty ako na dia\u013eku z\u00edska\u0165 kontrolu nad baseband \u010dipsetom napr\u00edklad pomocou prete\u010denia bufra (zn\u00e1ma zranite\u013enos\u0165 sa objavila predned\u00e1vnom napr\u00edklad v QCOM codebase).<\/p>\n<p>\u00dato\u010dn\u00edk, ktor\u00fd si je vedom\u00fd t\u00fdchto ch\u00fdb telef\u00f3nov, dok\u00e1\u017ee sfunk\u010dni\u0165 podvrhnut\u00fa BTS (napr\u00edklad pou\u017eit\u00edm USRP2) a jednoducho z\u00edska\u0165 kontrolu nad asociovan\u00fdmi telef\u00f3nmi (vr\u00e1tane nasadenie zadn\u00fdch vr\u00e1tok), nijako prehnan\u00e9 nebude ani uva\u017eova\u0165 na mobiln\u00fdmi v\u00edrmy, \u010di trojanmi, ktor\u00e9 sa bud\u00fa \u0161\u00edri\u0165 podvrhnut\u00fdmi BTS.<\/p>\n<p>GSM pou\u017e\u00edva symetrick\u00e9 A5\/1 kl\u00fa\u010de, kedy n\u00e1hodn\u00fd &#8222;nonce&#8220; a k\u013e\u00fa\u010d pre dan\u00fd GSM hovor je zasielan\u00fd zo strany &#8222;Operator Home Location Register&#8220;. Odpo\u010d\u00favan\u00edm komunik\u00e1cie medzi BTS stanicou a mobiln\u00fdm telef\u00f3nom je mo\u017en\u00e9 z\u00edska\u0165 uveden\u00fd k\u013e\u00fa\u010d pre dan\u00fd GSM hovor, nako\u013eko je zranite\u013en\u00fd na tzv. &#8222;memory trade-off&#8220; \u00fatoky. Kv\u00f4li tomu, \u017ee sa pou\u017e\u00edva v r\u00e1mcoch rovnak\u00e9 zarovnenie (padding), kedy posledn\u00fdch 12 bitov s\u00fa v\u017edy nuly, \u00fato\u010dn\u00edk dok\u00e1\u017ee determinova\u0165 bity u\u017e v \u0161ifrovan\u00fdch r\u00e1mcoch a pomocou A5\/1 rainbow tabu\u013eky z\u00edska\u0165 uveden\u00fd k\u013e\u00fa\u010d &#8222;session key&#8220; behom p\u00e1r sek\u00fand.<\/p>\n<p>Aj napriek tomu, \u017ee od roku 2008 pod\u013ea TS44.006 je potrebn\u00e9 &#8222;randomizova\u0165&#8220; uveden\u00fd &#8222;padding&#8220; (\u010do samozrejme v\u00e4\u010d\u0161ina mobiln\u00fdch oper\u00e1torov ignoruje), st\u00e1le je mo\u017en\u00e9 v samotn\u00fdch r\u00e1mcoch odhali\u0165 ve\u013ea zn\u00e1meho alebo determinovate\u013en\u00e9ho plaintextu (napr\u00edklad pri terminovan\u00ed hovoru), \u010do st\u00e1le implikuje bezpe\u010dnostn\u00e9 riziko.<\/p>\n<p>Zauj\u00edmav\u00e9 na tom je, \u017ee ve\u013ea GSM oper\u00e1torov umo\u017e\u0148uje znovupou\u017ei\u0165 &#8222;session&#8220; k\u013e\u00fa\u010de pre dan\u00fd hovor na \u010fal\u0161iu komunik\u00e1ciu (tak\u017ee k\u013e\u00fa\u010d z\u00edskan\u00fd napr\u00edklad zo zaslanej SMS spr\u00e1vy je znovupou\u017eit\u00fd na GSM hovor!).<br \/>\nPou\u017eitim RRLP protokolu (Radio Resource Location Protocol) sie\u0165 dok\u00e1\u017ee jednoducho zisti\u0165 GPS koordin\u00e1ty alebo surov\u00e9 GSM d\u00e1ta z telef\u00f3nu.<\/p>\n<p>\u010eal\u0161ie \u00faskalie predstavuje SS7 protokol, ktor\u00fdm komunikuj\u00fa samotn\u00ed telco oper\u00e1tori &#8211; oper\u00e1tori sa toti\u017e navz\u00e1jom neautentifikuj\u00fa (\u010do m\u00e1 za n\u00e1sledok v s\u00fa\u010dasnej dobe mas\u00edvne zv\u00fd\u0161enie SMS spamu) a \u010dastokr\u00e1t umo\u017e\u0148uj\u00fa prezradzova\u0165 citliv\u00e9 data o svojich \u00fa\u010dastn\u00edkoch.<\/p>\n<p>OsmocomBB (Open Source MObile COMmunication Base Band)<\/p>\n<p>D\u00f4vod na nap\u00edsanie OsmocomBB GSM stack implement\u00e1cie bol jednoduch\u00fd &#8211; GSM siete s\u00fa prudko uzavret\u00e9 (existuj\u00fa dohromady 4 GSM stack uzavret\u00e9 implement\u00e1cie, ktor\u00e9 v\u00fdrobcovia GSM \u010dipov nikdy nezverejnili a k ich zdrojov\u00fdm k\u00f3dom nemaj\u00fa dokonca pr\u00edstup ani v\u00fdrobcovia niektor\u00fdch telef\u00f3nov). Z biznis h\u013eadiska m\u00e1 t\u00e1to uzavretos\u0165 samozrejme zmysel &#8211; GSM sie\u0165ovy hardware vyr\u00e1ba na svete len p\u00e1r firiem, jeho ceny pre mobiln\u00fdch oper\u00e1torov s\u00fa potom automaticky \u00faplne premr\u0161ten\u00e9 (10-40k \u20ac za BTS). Taktie\u017e mno\u017estvo \u013eud\u00ed, ktor\u00ed h\u013abkovo vidia do GSM protokolu \/ GSM stacku je na svete ve\u013emi m\u00e1lo a samotn\u00ed mobiln\u00ed oper\u00e1tori v\u00e4\u010d\u0161inou t\u00fdmito \u013eudmi obvykle nedisponuj\u00fa. Trp\u00ed t\u00fdm samozrejme nez\u00e1visl\u00fd bezpe\u010dnostn\u00fd v\u00fdskum v oblasti GSM a ak nejak\u00fd je, tak sa t\u00fdka len aplika\u010dnej vrstvy alebo teoretickej kryptoanal\u00fdzy A5\/1 a A5\/2. Preveri\u0165 zabezpe\u010denie GSM stack implement\u00e1cii je teda temer nemo\u017en\u00e9.<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"\" src=\"http:\/\/bb.osmocom.org\/trac\/raw-attachment\/wiki\/SciphoneDreamG2\/scig2_jtag.jpg\" alt=\"osmocomBB\" width=\"315\" height=\"400\" \/>V\u0161etky tieto d\u00f4vody viedli k nap\u00edsaniu prvej opensource implement\u00e1cie OsmocomBB. Mo\u017eno by bolo dobr\u00e9 poznamena\u0165, \u017ee v minulosti bolo viacero pokusov o tvorbu opensource GSM stack implement\u00e1cie (THC GSM, mados) &#8211; \u017eiadny z t\u00fdchto projektov bohu\u017eia\u013e nebol \u00faspe\u0161n\u00fd.<br \/>\nVzh\u013eadom k tomu, \u017ee vytvorenie vlastn\u00e9ho GSM baseband chipsetu (na customizovanom hardv\u00e9ri) je \u010dasovo n\u00e1ro\u010dn\u00e1 oper\u00e1cia, autori OsmocomBB sa na to rozhodli vyu\u017ei\u0165 jednoduch\u00fd, lacn\u00fd, existuj\u00faci, hotov\u00fd a hlavne funguj\u00faci hardv\u00e9r s\u00fa\u010dasn\u00fdch mobiln\u00fdch telef\u00f3nov. Toto rozhodnutie znamenalo, \u017ee bolo potrebn\u00e9 spravi\u0165 reverzn\u00e9 in\u017einierstvo a na z\u00e1klade toho nap\u00edsa\u0165 hardv\u00e9rov\u00e9 ovl\u00e1da\u010de. Aby toho reverzn\u00e9ho in\u017einierstva bolo \u010do najmenej, boli vybran\u00e9 telef\u00f3ny, o ktor\u00fdch GSM baseband \u010dipsetov bolo &#8222;leaknut\u00fdch&#8220; \u010do najviac inform\u00e1ci\u00ed a to \u0161peci\u00e1lne &#8222;Texas Instrument Calypso&#8220; a &#8222;Mediatek MT622x&#8220;, ku ktor\u00fdm existuje (na \u010d\u00ednsk\u00fdch str\u00e1nkach) zverejnen\u00e9 SDK a pr\u00edslu\u0161n\u00e9 GSM stack kni\u017enice. Tieto baseband \u010dipsety be\u017eia napr\u00edklad v telef\u00f3noch Motorola C11x, C12x, C13x, C14x, C15X, pr\u00edpadne Openmoko Neo1973 \/ Freerunner. V\u00fdvojari OsmocomBB sa rozhodli zamera\u0165 na v\u00fdvoj a testovanie hlavne pre telef\u00f3ny Motorola C123 a C155. OsmocomBB bol nap\u00edsan\u00fd prakticky od nuly behom 9-tich mesiacov a ide o prv\u00fa funk\u010dn\u00fa opensource GSM baseband implement\u00e1ciu, ktor\u00e1 v sebe zahr\u0148uje ovl\u00e1da\u010de na v\u0161etok potrebn\u00fd GSM hardv\u00e9r (DBB, ABB, RF transceiver, LCD\/LCM) ako aj implement\u00e1ciu fyzickej, linkovej a sie\u0165ovej vrstvy (L1-L3). O tom, \u017ee je OsmocomBB skuto\u010dne funk\u010dn\u00fd sved\u010d\u00ed fakt, \u017ee je u\u017e mo\u017en\u00e9 vykonav\u00e1\u0165 GSM hovory (viac ako 30+ min\u00fat), \u0161ifrova\u0165 pomocou A5\/1, A5\/2 a pou\u017e\u00edva\u0165 Full Rate(FR) a Enhanced Full Rate(EFR) codec. Niektor\u00e9 veci (ako presmerovanie na in\u00fa BTS po\u010das samotn\u00e9ho hovoru) ale e\u0161te st\u00e1le nefunguj\u00fa.Vzh\u013eadom k tomu, \u017ee ide o kompletn\u00fa &#8222;from-scratch&#8220; opensource implement\u00e1ciu, je mo\u017en\u00e9 ma\u0165 pln\u00fa kontrolu nad zasielan\u00fdm d\u00e1tami, \u010do v praxi znamen\u00e1 mo\u017enos\u0165 zasiela\u0165 \u013eubovo\u013en\u00e9 (s \u013eubovo\u013enou hlavi\u010dkou) RR spr\u00e1vy BSC, MM\/CC spr\u00e1vy MSC, SMS spr\u00e1vy do MSC\/SMSC at\u010f &#8211; teda realizova\u0165 &#8222;kr\u00e1sne&#8220; GSM &#8222;fuzzy&#8220; testovanie. Pr\u00edstup na telef\u00f3n je cez VTY (telnet) s ve\u013emi podobn\u00fdm a pr\u00edjemn\u00fdm rozhran\u00edm ak\u00fdm disponuje Cisco, pr\u00edpadne je mo\u017en\u00e9 telef\u00f3n napoji\u0165 na linuxov\u00fd call PBX router.<\/p>\n<p>V\u010faka OsmocomBB je mo\u017en\u00e9 pou\u017ei\u0165 viacero zaujimav\u00fdch aplik\u00e1ci\u00ed ako &#8222;cell_log&#8220; &#8211; scanovanie a logovanie inform\u00e1cie &#8222;beacon&#8220; r\u00e1mcov bunky (ako napr\u00edklad GPS poz\u00edcia), &#8222;gsmmap&#8220; na zistenie presnej polohy pomocou triangul\u00e1cie, &#8222;bcch_scan&#8220; &#8211; z\u00edskavanie sily sign\u00e1lu enumer\u00e1ciou cez cel\u00e9 frekven\u010dn\u00e9 spektrum, &#8222;cbch_sniff&#8220; &#8211; dumpovanie broadcast spr\u00e1v (pou\u017eitie napr\u00edklad pre wireshark).<\/p>\n<p>GSM \u00fatok cez upraven\u00fd OsmocomBB<\/p>\n<p>Samotn\u00e9 \u0161ifrovanie hovoru sa inicializuje v riadiacom kan\u00e1li (&#8222;control channel&#8220;), pri\u010dom samotn\u00fd hlas je pren\u00e1\u0161an\u00fd v d\u00e1tovom kan\u00e1li (&#8222;traffic channel&#8220;), kde funguje &#8222;frequency hopping&#8220; (GSM hovory s\u00fa pren\u00e1\u0161an\u00e9 \u0161ifrovane cez r\u00f4zne nepredikovate\u013en\u00e9 frekvencie). Lacn\u00e9 Motorola telef\u00f3ny s OsmocomBB firmwareom a vypnut\u00fdm \u0161ifrovan\u00edm (patch DSP k\u00f3du) je mo\u017en\u00e9 pou\u017ei\u0165 na odpo\u010d\u00favanie &#8222;frequency hopping&#8220; hovoru. Na samotn\u00fd cielen\u00fd \u00fatok sta\u010dia dva telef\u00f3ny (ak nie je zn\u00e1my TMSI, tak je nutn\u00e9 viacero telef\u00f3nov) &#8211; jeden telef\u00f3n na zachyt\u00e1vanie riadiacich spr\u00e1v pre cie\u013eov\u00e9 TMSI a druh\u00fd na to, aby &#8222;sk\u00e1kal&#8220; na t\u00fdch ist\u00fdch frekvenciach ako cie\u013eov\u00fd odpo\u010d\u00favan\u00fd telefon a zachyt\u00e1val samotn\u00fd odpo\u010d\u00favan\u00fd hovor. Zo zachytenej SI spr\u00e1vy (pri vytvoren\u00ed hovoru) je pomocou Kraken crackera a pr\u00edslu\u0161n\u00fdch rainbow tabuliek z\u00edska\u0165 \u0161ifrovac\u00ed k\u013e\u00fa\u010d pre dan\u00fd hovor (&#8222;session key&#8220;) a n\u00e1sledne zachyten\u00fd hovor de\u0161ifrova\u0165. Tu je dobr\u00e9 poznamena\u0165, \u017ee samotn\u00fd &#8222;lookup&#8220; do rainbow tabuliek trv\u00e1 na be\u017enom hardv\u00e9ri menej ako 20 sek\u00fand, tak\u017ee de\u0161ifrovanie je skuto\u010dne ve\u013emi r\u00fdchle.<\/p>\n<p><strong>A ako z\u00edska\u0165 identifik\u00e1ciu adres\u00e1ta (TMSI)?<\/strong><\/p>\n<p>V SS7 je mo\u017en\u00e9 (zo strany Telco oper\u00e1tora) zasla\u0165 tzv.&#8220;HLR \u017eiados\u0165&#8220; s ot\u00e1zkou, kde presne vo svete sa nach\u00e1dza dan\u00fd \u00fa\u010dastn\u00edk X. Odpove\u010f na t\u00fato \u017eiados\u0165 je mesto + IMSI, teda pribli\u017en\u00e1 poloha dan\u00e9ho \u00fa\u010dastn\u00edka. Vzh\u013eadom k tomu, \u017ee OsmocomBB m\u00e1 pln\u00fa kontrolu nad zasielanou \u0161trukturou SMS spr\u00e1v, je mo\u017en\u00e9 pou\u017ei\u0165 tzv. &#8222;silent&#8220; (alebo naru\u0161en\u00e9) SMS spr\u00e1vy, ktor\u00e9ho cie\u013eov\u00e9mu adres\u00e1tovi s\u00edce nepr\u00eddu (lebo maj\u00fa po\u0161koden\u00fa predp\u00edsan\u00fa \u0161trukt\u00faru, tak\u017ee telef\u00f3n ich zahod\u00ed), umo\u017enia ale z\u00edska\u0165 jeho presn\u00fa polohu bunky. Odpo\u010d\u00favanie GSM siete po\u010das posielania SMS a pr\u00edjimania odpovede cie\u013eov\u00e9mu telef\u00f3nu sta\u010d\u00ed na presn\u00e9 determinovanie TMSI cie\u013eov\u00e9ho telef\u00f3nu. N\u00e1sledne je mo\u017en\u00e9 hovory pre tento telef\u00f3nov odpo\u010d\u00fava\u0165 a prelomi\u0165.<\/p>\n<p>Nutno poznamena\u0165, \u017ee OsmocomBB nebol dizajnov\u00fd ako sniffer ale ako implement\u00e1cia basebandu. <strong>Pod\u013ea Sylvain Munauta n\u00e1stroje na samotn\u00e9 prevedenie \u00fatoku nie s\u00fa a ani nebud\u00fa dostupn\u00e9 (alebo predan\u00e9 ako sa nieko\u013eko \u013eud\u00ed p\u00fdtalo).<\/strong> Vlastn\u00e1 implement\u00e1cia sniffera vy\u017eaduje h\u013abkov\u00e9 pochopenie GSM, \u010do s\u00fa tis\u00edce str\u00e1n GSM \u0161pecifik\u00e1ci\u00ed a tis\u00edce riadkov k\u00f3du.<br \/>\nOdkazy<\/p>\n<p><a href=\"https:\/\/www.nethemba.com\/sk\/blog\/-\/blogs\/prelomeny-gsm-a-legalne-problemy-s-tym-spojene\"><br \/>\nPrelomen\u00fd GSM a leg\u00e1lne probl\u00e9my s t\u00fdm spojen\u00e9<\/a><\/p>\n<p><a href=\"http:\/\/laforge.gnumonks.org\/papers\/gsm_phone-anatomy-latest.pdf\">Anatomy of contemporary GSM cellphone hardware<\/a><\/p>\n<p><a href=\"http:\/\/events.ccc.de\/congress\/2010\/Fahrplan\/events\/3952.en.html\">Running your own GSM stack on a phone<\/a><\/p>\n<p><a href=\"https:\/\/cryptolux.org\/media\/hack.lu-aybbabtu.pdf\">The Baseband Apocalypse<\/a><\/p>\n<p><a href=\"http:\/\/events.ccc.de\/congress\/2010\/Fahrplan\/events\/4208.en.html\">Wideband GSM Sniffing<\/a><\/p>\n<p><a href=\"http:\/\/events.ccc.de\/congress\/2010\/Fahrplan\/events\/4060.en.html\">SMS-o-Death<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>E\u0161te minul\u00fd rok svetov\u00e1 GSM asoci\u00e1cia verejne prehl\u00e1sila, \u017ee GSM odpo\u010d\u00favanie je stal\u00e9 pr\u00edli\u0161 drah\u00e9 a komplexn\u00e9, nako\u013eko \u00fato\u010dn\u00edk mus\u00ed disponova\u0165 \u0161peci\u00e1lnym odpo\u010d\u00favac\u00edm zariaden\u00edm (typu USRP2) a pou\u017eiva\u0165 komplexn\u00fd &#8222;signal processing&#8220; softv\u00e9r na identifik\u00e1ciu a zaznamen\u00e1vanie odchyt\u00e1van\u00fdch hovorov. Na tohtoro\u010dnom 27c3 (Chaos Communication Congress) v Berl\u00edne sme mali mo\u017enos\u0165 vidie\u0165 \u0161okuj\u00facu prezent\u00e1ciu (v\u00fdskumn\u00edkov Karstena Nohla [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[12],"tags":[362,524,525,526],"class_list":["post-1186","post","type-post","status-publish","format-standard","hentry","category-uncategorized-cs","tag-27c3-cs","tag-gsm-hacking-cs","tag-motorola-c123-cs","tag-osmocombb-cs"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Nov\u00e9 trendy v GSM odpo\u010d\u00favan\u00ed - Nethemba<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/nethemba.com\/cs\/nove-trendy-v-gsm-odpocuvani\/\" \/>\n<meta property=\"og:locale\" content=\"cs_CZ\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Nov\u00e9 trendy v GSM odpo\u010d\u00favan\u00ed - Nethemba\" \/>\n<meta property=\"og:description\" content=\"E\u0161te minul\u00fd rok svetov\u00e1 GSM asoci\u00e1cia verejne prehl\u00e1sila, \u017ee GSM odpo\u010d\u00favanie je stal\u00e9 pr\u00edli\u0161 drah\u00e9 a komplexn\u00e9, nako\u013eko \u00fato\u010dn\u00edk mus\u00ed disponova\u0165 \u0161peci\u00e1lnym odpo\u010d\u00favac\u00edm zariaden\u00edm (typu USRP2) a pou\u017eiva\u0165 komplexn\u00fd &#8222;signal processing&#8220; softv\u00e9r na identifik\u00e1ciu a zaznamen\u00e1vanie odchyt\u00e1van\u00fdch hovorov. Na tohtoro\u010dnom 27c3 (Chaos Communication Congress) v Berl\u00edne sme mali mo\u017enos\u0165 vidie\u0165 \u0161okuj\u00facu prezent\u00e1ciu (v\u00fdskumn\u00edkov Karstena Nohla [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/nethemba.com\/cs\/nove-trendy-v-gsm-odpocuvani\/\" \/>\n<meta property=\"og:site_name\" content=\"Nethemba\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/nethemba\" \/>\n<meta property=\"article:published_time\" content=\"2011-01-03T20:28:22+00:00\" \/>\n<meta property=\"og:image\" content=\"http:\/\/zedomax.com\/blog\/wp-content\/uploads\/2009\/12\/gsm-hacked.png\" \/>\n<meta name=\"author\" content=\"Pavol Lupt\u00e1k\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@nethemba\" \/>\n<meta name=\"twitter:site\" content=\"@nethemba\" \/>\n<meta name=\"twitter:label1\" content=\"Napsal(a)\" \/>\n\t<meta name=\"twitter:data1\" content=\"Pavol Lupt\u00e1k\" \/>\n\t<meta name=\"twitter:label2\" content=\"Odhadovan\u00e1 doba \u010dten\u00ed\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minut\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/nove-trendy-v-gsm-odpocuvani\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/nove-trendy-v-gsm-odpocuvani\\\/\"},\"author\":{\"name\":\"Pavol Lupt\u00e1k\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#\\\/schema\\\/person\\\/5f4ba68c8e1a2013d30e0804245b8234\"},\"headline\":\"Nov\u00e9 trendy v GSM odpo\u010d\u00favan\u00ed\",\"datePublished\":\"2011-01-03T20:28:22+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/nove-trendy-v-gsm-odpocuvani\\\/\"},\"wordCount\":1873,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/nove-trendy-v-gsm-odpocuvani\\\/#primaryimage\"},\"thumbnailUrl\":\"http:\\\/\\\/zedomax.com\\\/blog\\\/wp-content\\\/uploads\\\/2009\\\/12\\\/gsm-hacked.png\",\"keywords\":[\"27c3\",\"gsm hacking\",\"motorola c123\",\"osmocombb\"],\"articleSection\":[\"Uncategorized @cs\"],\"inLanguage\":\"cs\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/nethemba.com\\\/cs\\\/nove-trendy-v-gsm-odpocuvani\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/nove-trendy-v-gsm-odpocuvani\\\/\",\"url\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/nove-trendy-v-gsm-odpocuvani\\\/\",\"name\":\"Nov\u00e9 trendy v GSM odpo\u010d\u00favan\u00ed - Nethemba\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/nove-trendy-v-gsm-odpocuvani\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/nove-trendy-v-gsm-odpocuvani\\\/#primaryimage\"},\"thumbnailUrl\":\"http:\\\/\\\/zedomax.com\\\/blog\\\/wp-content\\\/uploads\\\/2009\\\/12\\\/gsm-hacked.png\",\"datePublished\":\"2011-01-03T20:28:22+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#\\\/schema\\\/person\\\/5f4ba68c8e1a2013d30e0804245b8234\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/nove-trendy-v-gsm-odpocuvani\\\/#breadcrumb\"},\"inLanguage\":\"cs\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/nethemba.com\\\/cs\\\/nove-trendy-v-gsm-odpocuvani\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"cs\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/nove-trendy-v-gsm-odpocuvani\\\/#primaryimage\",\"url\":\"http:\\\/\\\/zedomax.com\\\/blog\\\/wp-content\\\/uploads\\\/2009\\\/12\\\/gsm-hacked.png\",\"contentUrl\":\"http:\\\/\\\/zedomax.com\\\/blog\\\/wp-content\\\/uploads\\\/2009\\\/12\\\/gsm-hacked.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/nove-trendy-v-gsm-odpocuvani\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/home-new-2025\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Nov\u00e9 trendy v GSM odpo\u010d\u00favan\u00ed\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#website\",\"url\":\"https:\\\/\\\/nethemba.com\\\/de\\\/\",\"name\":\"Nethemba\",\"description\":\"We care about your security\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/nethemba.com\\\/de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"cs\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#\\\/schema\\\/person\\\/5f4ba68c8e1a2013d30e0804245b8234\",\"name\":\"Pavol Lupt\u00e1k\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"cs\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/978b23022518d076eaa243b375d2e0272af4f00dd502ce79cc357276d9bc2495?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/978b23022518d076eaa243b375d2e0272af4f00dd502ce79cc357276d9bc2495?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/978b23022518d076eaa243b375d2e0272af4f00dd502ce79cc357276d9bc2495?s=96&d=mm&r=g\",\"caption\":\"Pavol Lupt\u00e1k\"},\"sameAs\":[\"https:\\\/\\\/www.nethemba.com\\\/\"],\"url\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/author\\\/nethemba-admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Nov\u00e9 trendy v GSM odpo\u010d\u00favan\u00ed - Nethemba","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/nethemba.com\/cs\/nove-trendy-v-gsm-odpocuvani\/","og_locale":"cs_CZ","og_type":"article","og_title":"Nov\u00e9 trendy v GSM odpo\u010d\u00favan\u00ed - Nethemba","og_description":"E\u0161te minul\u00fd rok svetov\u00e1 GSM asoci\u00e1cia verejne prehl\u00e1sila, \u017ee GSM odpo\u010d\u00favanie je stal\u00e9 pr\u00edli\u0161 drah\u00e9 a komplexn\u00e9, nako\u013eko \u00fato\u010dn\u00edk mus\u00ed disponova\u0165 \u0161peci\u00e1lnym odpo\u010d\u00favac\u00edm zariaden\u00edm (typu USRP2) a pou\u017eiva\u0165 komplexn\u00fd &#8222;signal processing&#8220; softv\u00e9r na identifik\u00e1ciu a zaznamen\u00e1vanie odchyt\u00e1van\u00fdch hovorov. Na tohtoro\u010dnom 27c3 (Chaos Communication Congress) v Berl\u00edne sme mali mo\u017enos\u0165 vidie\u0165 \u0161okuj\u00facu prezent\u00e1ciu (v\u00fdskumn\u00edkov Karstena Nohla [&hellip;]","og_url":"https:\/\/nethemba.com\/cs\/nove-trendy-v-gsm-odpocuvani\/","og_site_name":"Nethemba","article_publisher":"https:\/\/www.facebook.com\/nethemba","article_published_time":"2011-01-03T20:28:22+00:00","og_image":[{"url":"http:\/\/zedomax.com\/blog\/wp-content\/uploads\/2009\/12\/gsm-hacked.png","type":"","width":"","height":""}],"author":"Pavol Lupt\u00e1k","twitter_card":"summary_large_image","twitter_creator":"@nethemba","twitter_site":"@nethemba","twitter_misc":{"Napsal(a)":"Pavol Lupt\u00e1k","Odhadovan\u00e1 doba \u010dten\u00ed":"9 minut"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/nethemba.com\/cs\/nove-trendy-v-gsm-odpocuvani\/#article","isPartOf":{"@id":"https:\/\/nethemba.com\/cs\/nove-trendy-v-gsm-odpocuvani\/"},"author":{"name":"Pavol Lupt\u00e1k","@id":"https:\/\/nethemba.com\/de\/#\/schema\/person\/5f4ba68c8e1a2013d30e0804245b8234"},"headline":"Nov\u00e9 trendy v GSM odpo\u010d\u00favan\u00ed","datePublished":"2011-01-03T20:28:22+00:00","mainEntityOfPage":{"@id":"https:\/\/nethemba.com\/cs\/nove-trendy-v-gsm-odpocuvani\/"},"wordCount":1873,"commentCount":0,"image":{"@id":"https:\/\/nethemba.com\/cs\/nove-trendy-v-gsm-odpocuvani\/#primaryimage"},"thumbnailUrl":"http:\/\/zedomax.com\/blog\/wp-content\/uploads\/2009\/12\/gsm-hacked.png","keywords":["27c3","gsm hacking","motorola c123","osmocombb"],"articleSection":["Uncategorized @cs"],"inLanguage":"cs","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/nethemba.com\/cs\/nove-trendy-v-gsm-odpocuvani\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/nethemba.com\/cs\/nove-trendy-v-gsm-odpocuvani\/","url":"https:\/\/nethemba.com\/cs\/nove-trendy-v-gsm-odpocuvani\/","name":"Nov\u00e9 trendy v GSM odpo\u010d\u00favan\u00ed - Nethemba","isPartOf":{"@id":"https:\/\/nethemba.com\/de\/#website"},"primaryImageOfPage":{"@id":"https:\/\/nethemba.com\/cs\/nove-trendy-v-gsm-odpocuvani\/#primaryimage"},"image":{"@id":"https:\/\/nethemba.com\/cs\/nove-trendy-v-gsm-odpocuvani\/#primaryimage"},"thumbnailUrl":"http:\/\/zedomax.com\/blog\/wp-content\/uploads\/2009\/12\/gsm-hacked.png","datePublished":"2011-01-03T20:28:22+00:00","author":{"@id":"https:\/\/nethemba.com\/de\/#\/schema\/person\/5f4ba68c8e1a2013d30e0804245b8234"},"breadcrumb":{"@id":"https:\/\/nethemba.com\/cs\/nove-trendy-v-gsm-odpocuvani\/#breadcrumb"},"inLanguage":"cs","potentialAction":[{"@type":"ReadAction","target":["https:\/\/nethemba.com\/cs\/nove-trendy-v-gsm-odpocuvani\/"]}]},{"@type":"ImageObject","inLanguage":"cs","@id":"https:\/\/nethemba.com\/cs\/nove-trendy-v-gsm-odpocuvani\/#primaryimage","url":"http:\/\/zedomax.com\/blog\/wp-content\/uploads\/2009\/12\/gsm-hacked.png","contentUrl":"http:\/\/zedomax.com\/blog\/wp-content\/uploads\/2009\/12\/gsm-hacked.png"},{"@type":"BreadcrumbList","@id":"https:\/\/nethemba.com\/cs\/nove-trendy-v-gsm-odpocuvani\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/nethemba.com\/cs\/home-new-2025\/"},{"@type":"ListItem","position":2,"name":"Nov\u00e9 trendy v GSM odpo\u010d\u00favan\u00ed"}]},{"@type":"WebSite","@id":"https:\/\/nethemba.com\/de\/#website","url":"https:\/\/nethemba.com\/de\/","name":"Nethemba","description":"We care about your security","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/nethemba.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"cs"},{"@type":"Person","@id":"https:\/\/nethemba.com\/de\/#\/schema\/person\/5f4ba68c8e1a2013d30e0804245b8234","name":"Pavol Lupt\u00e1k","image":{"@type":"ImageObject","inLanguage":"cs","@id":"https:\/\/secure.gravatar.com\/avatar\/978b23022518d076eaa243b375d2e0272af4f00dd502ce79cc357276d9bc2495?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/978b23022518d076eaa243b375d2e0272af4f00dd502ce79cc357276d9bc2495?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/978b23022518d076eaa243b375d2e0272af4f00dd502ce79cc357276d9bc2495?s=96&d=mm&r=g","caption":"Pavol Lupt\u00e1k"},"sameAs":["https:\/\/www.nethemba.com\/"],"url":"https:\/\/nethemba.com\/cs\/author\/nethemba-admin\/"}]}},"_links":{"self":[{"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/posts\/1186","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/comments?post=1186"}],"version-history":[{"count":0,"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/posts\/1186\/revisions"}],"wp:attachment":[{"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/media?parent=1186"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/categories?post=1186"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/tags?post=1186"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}