[srslte-users] Options to demonstrate the vulnerability in LTE network

Nehemiah Chan nehemiahchan1999 at gmail.com
Wed May 29 01:25:44 UTC 2019


Hi everyone,


I am currently to look for options to demonstrate vulnerability in LTE
attacks. To start with, I am currently an intern in a cybersecurity
company, and I have been looking for several attacks that I can demonstrate
the weakness in LTE network. They have been several studies like PIERCER,
TORPEDO and aLTEr and many more. Well, I am not proficient in programming
but I do hope someone is able to guide me here. I am planning to use a UE
with programmable USIM( I am still waiting for syscom USIM card to arrive
to configure it).

I read on a study on the PIERCER attack which modified the srsLTE's
pdsch_ue application. I unable to understand how they managed to get the
sniffer to switch decoding mode between the MIB blocks and paging
protocols(I am unable to find it in the pdsch_ue.c file).
While I looked and understand the terms in the programming, I got it
confused knowing that
If any of you have completed any of the experiments, regarding the attacks
between eNb and UE like rouge eNbs to obtain the IMSI of the target's UE/
sniffing base station to obtain information of the target's UE, I would
appreciate it. I currently do have the b210 and srsLTE software. I am
wondering if I can use srsLTE as the only open source software, or do I
need openLTE/ other open source software to utilise?

Truly appreciate if anyone can offer some advice to a newbie like me and
steps to approach it.
Thanks in advance.

Best regards,
Nehemiah
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.srsran.com/pipermail/srsran-users/attachments/20190529/1b05d103/attachment.htm>


More information about the srsran-users mailing list