GSM Shop GSM Shop
GSM-Forum  

Welcome to the GSM-Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features.
Only registered members may post questions, contact other members or search our database of over 8 million posts.

Registration is fast, simple and absolutely free so please - Click to REGISTER!

If you have any problems with the registration process or your account login, please contact contact us .

Go Back   GSM-Forum > GSM & CDMA Phones / Tablets Software & Hardware Area > Various > Various CDMA/TDMA Cell Phones


Various CDMA/TDMA Cell Phones All CDMA & TDMA Cell Phones Related Threads are here

Reply
 
LinkBack Thread Tools Display Modes
Old 04-22-2009, 13:57   #1 (permalink)
Insane Poster
 
Join Date: Nov 2005
Posts: 64
Member: 203880
Status: Offline
Thanks Meter: 1
Sniffing the Paging channel-Wonder where/when your friend get a call or SMS nearby?


Passive Sniffing the "Paging Channel" These "paging messages" are transmitted OTA without encryption. Wondering how the "Car warranty/Telus Scam automated messages to get your credit card number" got your secret/unlisted phone number? Wonder where/when your friend "receive" a call or "receive" SMS nearby? I think this is called Layer 3 tracing You have to monitor the "0x1007 Paging Channel Message -- General Page Msg" - Short Message Services IS-637 (tower attempts to send sms to the user) - EVRC 8K Voice (someone's calling him/her) - (RS2 Voice, QCELP) (older "Qualcomm Code Excited Linear Prediction" voice codec??) These were scanned using a normal phone connected to qxdm then log pharsed with Qcat. ---- 2009 [14] 0x1007 Paging Channel Message -- General Page Msg ( slot = x ) protocol_rev = 6 (0x6) (IS2000 Rev 0) chan_type = 1 (0x1) (Paging) chan pc_msg gen prot_disc = 0 (0x0) msg_id = 17 (0x11) (General Page) gen_page config_msg_seq = 4 (0x4) acc_msg_seq = 32 (0x20) class_0_done = 1 (0x1) class_1_done = 1 (0x1) tmsi_done = 1 (0x1) ordered_tmsis = 0 (0x0) broadcast_done = 1 (0x1) add_length = 0 (0x0) num_pages = 1 (0x1) gen_page[0] page_class = 0 (0x0) page_subclass = 0 (0x0) rec format0 msg_seq = 3 (0x3) imsi_s[HI] = 2 (0x2) imsi_s[LO] = 410xx55 (0x1xxxb7) (647-xxx-7x94) special_service = 1 (0x1) service_option = 3 (0x3) (EVRC 8K Voice) 2009 [24] 0x1007 Paging Channel Message -- General Page Msg ( slot = x ) protocol_rev = 6 (0x6) (IS2000 Rev 0) chan_type = 1 (0x1) (Paging) chan pc_msg gen prot_disc = 0 (0x0) msg_id = 17 (0x11) (General Page) gen_page config_msg_seq = 4 (0x4) acc_msg_seq = 32 (0x20) class_0_done = 1 (0x1) class_1_done = 1 (0x1) tmsi_done = 1 (0x1) ordered_tmsis = 0 (0x0) broadcast_done = 1 (0x1) add_length = 0 (0x0) num_pages = 2 (0x2) gen_page[0] page_class = 0 (0x0) page_subclass = 0 (0x0) rec format0 msg_seq = 0 (0x0) imsi_s[HI] = 2 (0x2) imsi_s[LO] = 30xx28 (0xbxx844) (705-xxx-01x9) special_service = 1 (0x1) service_option = 6 (0x6) (Short Message Services IS-637) gen_page[1] page_class = 0 (0x0) page_subclass = 0 (0x0) rec format0 msg_seq = 3 (0x3) imsi_s[HI] = 2 (0x2) imsi_s[LO] = 415xxx37 (0x1xxx59) (647-xxx-91x0) special_service = 1 (0x1) service_option = 3 (0x3) (EVRC 8K Voice) 2009 [35] 0x1007 Paging Channel Message -- General Page Msg ( slot = x) protocol_rev = 6 (0x6) (IS2000 Rev 0) chan_type = 1 (0x1) (Paging) chan pc_msg gen prot_disc = 0 (0x0) msg_id = 17 (0x11) (General Page) gen_page config_msg_seq = 4 (0x4) acc_msg_seq = 32 (0x20) class_0_done = 1 (0x1) class_1_done = 1 (0x1) tmsi_done = 1 (0x1) ordered_tmsis = 0 (0x0) broadcast_done = 1 (0x1) add_length = 0 (0x0) num_pages = 4 (0x4) gen_page[0] page_class = 0 (0x0) page_subclass = 0 (0x0) rec format0 msg_seq = 3 (0x3) imsi_s[HI] = 1 (0x1) imsi_s[LO] = 83xxx22 (0xxxb46) (416-xxx-6x49) special_service = 1 (0x1) service_option = 6 (0x6) (Short Message Services IS-637) gen_page[1] page_class = 0 (0x0) page_subclass = 0 (0x0) rec format0 msg_seq = 5 (0x5) imsi_s[HI] = 1 (0x1) imsi_s[LO] = 83xx85 (0x3xx7cd) (416-xxx-50x4) special_service = 1 (0x1) service_option = 6 (0x6) (Short Message Services IS-637) gen_page[2] page_class = 0 (0x0) page_subclass = 0 (0x0) rec format0 msg_seq = 1 (0x1) imsi_s[HI] = 2 (0x2) imsi_s[LO] = 40xx2845 (0x1xx8b8d) (647-xxx-20x0) special_service = 1 (0x1) service_option = 6 (0x6) (Short Message Services IS-637) gen_page[3] page_class = 0 (0x0) page_subclass = 0 (0x0) rec format0 msg_seq = 5 (0x5) imsi_s[HI] = 1 (0x1) imsi_s[LO] = 83xx178 (0x31xxda) (416-xxx-25x5) special_service = 1 (0x1) service_option = 3 (0x3) (EVRC 8K Voice) 2009 [04] 0x1007 Paging Channel Message -- General Page Msg ( slot = x) protocol_rev = 6 (0x6) (IS2000 Rev 0) chan_type = 1 (0x1) (Paging) chan pc_msg gen prot_disc = 0 (0x0) msg_id = 17 (0x11) (General Page) gen_page config_msg_seq = 4 (0x4) acc_msg_seq = 32 (0x20) class_0_done = 1 (0x1) class_1_done = 1 (0x1) tmsi_done = 1 (0x1) ordered_tmsis = 0 (0x0) broadcast_done = 1 (0x1) add_length = 0 (0x0) num_pages = 1 (0x1) gen_page[0] page_class = 0 (0x0) page_subclass = 0 (0x0) rec format0 msg_seq = 0 (0x0) imsi_s[HI] = 1 (0x1) imsi_s[LO] = 825xx6335 (0xxx909f) (416-xxx-4x60) special_service = 1 (0x1) service_option = 3 (0x3) (EVRC 8K Voice) ---- Also, with EVDO, you can get the tower's "location", but it needs some adjusting because its not "Exactly" Latitude and Longitude. for evdo: country_code = 1 (0xx) (BCD: 0xx) sector_id[0] = x (0xx0) sector_id[1] = x (0x0) sector_id[2] = x (0x0) sector_id[3] = x (0x0) sector_id[4] = x (0x) sector_id[5] = x (0xx) sector_id[6] = x (0xxx) sector_id[7] = x (0xx) subnet_mask = xx (0xx) sector_signature = x (0xx) latitude = xxxxxx (0xxf0)
  Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Deduction of balance without using any call or sms.....:( sannwal iPhone 2 / iPhone 3G / iPhone 3GS 7 02-24-2009 08:02
..::New sis Guardian for s60,when lost your mobile get a sms tested 100% ok::.. mehedi.h.j Nokia Multimedia 20 12-11-2007 20:11
V3im looses NETWORK when trying a outgoing call or sms blaiseid Motorola P2k 2 08-10-2006 16:45
getting pin and/or sms bwk Sim Cloning and Scaning 1 11-21-2003 19:46

 



All times are GMT +1. The time now is 21:38.



Powered by Searchlight © 2024 Axivo Inc.
vBulletin Optimisation provided by vB Optimise (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
- GSM Hosting Ltd. - 1999-2023 -
Page generated in 0.15788 seconds with 9 queries

SEO by vBSEO