10-19-2009, 11:31
|
#1 (permalink)
|
| Junior Member
Join Date: Aug 2009
Posts: 7
Member: 1104976
Status: Offline
Thanks: 0
Thanked 1 Time in 1 Post
| Comp128 v2 I dont know if it helps you or not, but it may interest you so I post some info I found
Im not sure about how the rules are about links to other forums so I just qoute: Quote:
FAQ's in this Groups are related to COMP V2 !
e.g. "How Can I Clone T-D1 or NEW D2 SIM's ?"
Here are some FACTS:
1st PLS read this VERY good german paper http://cryptolabs.org/gsm/ZennerWeisLucksA5.pdf
AND http://www.cryptolabs.org/gsm/funkgsm.html
ThanX
As you see it's impossible to extract the Ki from COMP128 V2 using the "collision" Method, which is used by all current Software Products (see e.g. http://WWW.UCables.com ) !
"Maybe" V2 Ki can be BruteForced, but the Key is 64 up to 128 Bit strong (stored in a special protected Register at the SIM). You will need an large amount of CPU power to compute this ! Alternatively you can treat the Chip with acid and read the register with an REM, but this will destroy the Chip.
T-D1 does *NOT* use COMP at all !
Special "patched" Software that "shoud" be able to handle T-Mob or V2 are mostly infected with TROJAN'S (e.g. special SimScan Versions posted in Forums) !
Even the roumors, that one guy inThailand made a V2 Clone with Sim Doctor are NOT proven !
Conclusion:
Current Software is only able to Clone COMP 128 V1 SIM's, but ALL of them - I mean those with Run Limited registers too | Quote: |
At first time, we were interested in the area of SIM, which responsible for Key Identification (KI). Yes, these electric changes are very little, imperceptible, they could be measured in parts of microamperes, but tracing is nevertheless possible. Furthermore, it is possible to trace the small electromagnetic waves (radiation) from microchip, because any electrical device radiates waves — more or small. The clock frequency of processor of SIM cannot be stable on various modes of work. In case with SIM, some changes have observed on 10-20 KHz during accepting of some pair of KI. Using this method, we were succeed in access to “the holy of holies” of SIM: PIN1,PIN2, PUK1, PUK2. The first model of the device for reading SIM v2 was assembled enough complex, large, bulky, it was seemed like a vacuum tube radio receiver. Some time later, we have done a big lot of work in this sphere
| http://security1.win.tue.nl/~bskoric...rtitioning.pdf
Just to raise some thoughts |
|
| |