Showing posts with label IMSI. Show all posts
Showing posts with label IMSI. Show all posts

Friday, March 27, 2015

Last SIM Details

Has anyone else run any tests using LSD.exe free tool?

This program is from lastsimdetails.blogspot.co.uk/.

The concept behind this tool is very good and it is a great credit to the authors to allow free distribution of LSD.exe.


Screen dump for LSD.exe v1.2.0 - Samsung D500 flash file

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
- HELP About
- Able to parse .bin and .pm data files.
 - Regex customiser allows you to define country and network parameters to eliminate false positives
 - Generic network search allows you to search for all Mobile Network Codes (MNC), however using this method may bring back more false positives
 - Advanced view provides the user with all IMSI matches and offsets within the data file
 - The summary view counts recurrences of IMSIs in order to display unique values

 Limitations
 -Limited testing has been performed on live data. Please verify your results
 This program was designed and developed by Jason Nicolaou and Daniel Roe.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

There are in fact three Option tests that can be can be applied and not two as offered by the menu:

 1. Make no option selection at all
 2. Generic search
 3. Samsung mode

All return search data depending upon the flash file being read.

The authors have explicitly stated the limitations of the program. I emailed and left messages at the authors website but have not received any replies.

 =====================================================
 IMSI UK prefix *9 = (T) telecommunications / 234 = MCC United Kingdom / MNC = xxx
 =====================================================
 *This is different from TE.118 prefix 89 in use as Mobile Industry Identifier (MII) ISO/IEC 7812-1

The program's GUI search window, above, returns (along with other details) values e.g.

Offset: 3962356 IMSI: MCC/MNC/Subscriber detail = 234919011221080

HxD (used for examination of the raw flash file), below, the offset identifies

e.g. reverse nibble: 29 43 19 09 11 22 01 08

Screen dump for HxD.exe - Samsung D500 flash file

OBSERVATIONS
LSD.exe searches the flash file and performs translation. The translation (top of page) was obtained using Option: Generic search.

LSD.exe returns the MNC as "unknown" - verified.
LSD.exe returns known MNC also - verified

From flash file library stocks selection was made using two old Samsung models D500 and D600 to see if LSD.exe would work with older flash files. LSD.exe did work and false-positives were obtained as the authors point out.

LSD.exe also revealed that when comparisons were made between D500 and D600 there were repetition of identical IMSIs found in both D500/D600 one example being (which I have anonymised):

 - 2341007xxxxxxxx

The fact the D500 flash file and the D600 flash file were apparently not connected in any way introduced the proposition are the results positive-positive or false-positive.

Furthermore, if positive-positive are correct then the authors statement that the tool should be used for intelligence purposes lives up to that expectation.

Saturday, January 04, 2014

Tracing Packet Switch (PS) Users

Investigations into mobile activity tend largely to concentrate on recovering data from the user handset, mast (tower) data and call records. The core network (CN) is less well understood and therefore picking through a GSM/3GPP standard can often assist in understanding the identity and form of tarried/empheral data surviving in a network. The standard to be used for this discussion is:

3GPP TS 25.413 V12.0.0 (2013-12)
3rd Generation Partnership Project;
Technical Specification Group Radio Access Network;
UTRAN Iu interface
Radio Access Network Application Part (RANAP) signalling
(Release 12)


Now with an investigation underway initial enquiries lead to an active smartphone user operating in the pack switched (PS) domain. The target under surveillance requires the investigator to combine visual logs and the use of the of the handset. Unlike CS, packet data communications requires a range of information BUT for the purposes of the current investigation understanding the services being used and the geographical area where services are being obtained the trainee investigator can start with understanding what can be learned from:

Cell ID - Cell Identity
C-ID - Common Identity
IMEI - International Mobile Equipment Identity

IMSI - International Mobile Subscriber Identity
IPAddress - Internet Protocol Address
SAI - Service Area Identifier

SAP - Service Access Point
LAI  - Location Area Identifier
RNC - Radio Network Controller

RNS  - Radio Network Subsystem

Some examples of trainee investigation elements for consideration:

Para 8.16.1

The purpose of the Common ID procedure is to inform the RNC about the permanent NAS UE Identity (i.e. IMSI) of a user. This is used by the RNC e.g. to create a reference between the permanent NAS UE identity of the user and the RRC connection of that user for UTRAN paging co-ordination. The procedure may also be used to provide the SNA Access Information IE to the RNC or to provide the Management Based MDT Allowed IE to the RNC or to provide the Management Based MDT PLMN List IE to the RNC.


Para 8.17.2

If Trace Collection Entity IP Address IE is included and if the MDT Configuration IE is also included then the RNC shall, if supported, store the Trace Collection Entity IP address and use it when transferring Trace records, otherwise if MDT Configuration IE is not included, the RNC may use the Trace Collection Entity IP address when transferring trace records.


Para 8.35.2
When the transferred information in the Information Transfer Type IE relates to a Trace Session in the RNC, the Trace Activation Indicator IE indicates whether the Trace Session identified by the Trace Reference IE is activated or deactivated in the RNC. In case the Trace Session is activated, the Equipments To Be Traced IE gives the Equipment Identity of the UEs that the RNC has to trace. If the Trace Recording Session Reference IE, Trace Collection Entity IP Address IE, the IMSI IE and optionally the Serving Cell Identifier IE are included in the message, the CN shall take the information into account for anonymization of MDT data (TS 32.422 [10]).
 
The purpose of this brief discussion is to illustrate mobile networks naturally hold surviving data in the network for a range of reasons to enable the network to a have uniformed approach for the objective of operational performance, enquiry and, equally, to trace user terminals and roaming user terminals active in or obtaining services from a network.

Saturday, September 22, 2012

Threats and Forcing SMS delay

Following my article France Car Shootings and Mobile Evidence http://www.trewmte.blogspot.co.uk/2012/09/france-car-shootings-and-mobile-evidence.html an investigator, previously working with a well-known cellular and fixed network manufacturer, confirmed to me the results of an internal forensics investigation which he conducted.


An employee had made threats to a Director. The employee had been found to use a 'prepaid sim' card to send theat messages but added a delay period for the sent messages of 2-hours. The employee then switched OFF the handset and inserted the company SIM card into the same handset which had previously held the prepaid SIM that had sent the threat messages. The handset with the company SIM card in it was then switched ON; the employee claimed not to have been responsible for the threats sent from a different IMSI (SIM card).  The intention of the employee was to mask any connection with the threats. However, tracing the IMSIs of the prepaid SIM card and the company SIM card found both to have been operating in the same handset (IMEI). Such trace capability can be made from enquiries of network databases such as BTS, HLR etc. Moreover with high levels of text messaging that are sent and received whilst roaming there is trace capability that can be made by interrogating CAMEL.

There is also useful data that can be obtained for linking with cell site analysis (CSA), which is a bonus although there appears to be some confusion occuring in the US at the moment as to the value of CSA evidence http://www.forensicfocus.com/Forums/viewtopic/t=9679/ and how the material may be applied on a case by case basis. I am not convinced that licenced operators with highly developed as they are in the US cellular networks simply could not/would not sufficient call record/cell data available to know what is happening when an MS has been active in their networks, about the arrangement at a particular mast (cell tower) as used by an MS, the configuration of the radio network operating at the time an MS has been used and so on.

Sunday, September 02, 2012

Catching the IMSI Catchers

 
“IMSI catcher catcher”—a device designed to snoop on the snoopers, 
sniffing out anyone operating an IMSI catcher in a given location.

Spying has been going on since one human wanted to know what another human was doing or saying. A common-sense expectation of modern Government is to limit or place a choke on how spying is conducted and, importantly, who can do it (spying, that is). Sadly, the warnings (loss of privacy, unlawful interception etc) to not allow 'pandora's box' [http://en.wikipedia.org/wiki/Pandora%27s_box] to be opened rather than apply pro-active controls appears to be have ignored those warnings as some form of  'cry wolf ' [http://en.wikipedia.org/wiki/Cry_Wolf], particularly if those warnings had merit afterall. It comes as no surprise then to find a recent news report indicating spying devices such as IMSI grabbers/catchers now creating concern that such devices could be in use in the criminal community: [imsi_catchers_criminals_law_enforcement_using_high_tech_portable_devices_to_intercept_communications_.html]

The development of IMSI catchers is not a recent development. Indeed, in a number of long running court battles (that I have been following for some years) a recent 2012 Court of Appeal Patent decision concluded [http://www.bailii.org/ew/cases/EWCA/Civ/2012/7.html] that shed light on the development of a particular IMSI Catcher. On the three cases they set out a history of development dates that uncover that this IMSI Catcher prototypes and the finished product appeared before (as a time reference) the Omagh Bombing of 1998.

IMSI grabbers/catchers present a huge potential for privacy rights abuses if one considers the pace at which mobile technology is causing redundancy of fixed landline phones and fixed PCs [http://www.itpro.co.uk/642538/cios-ring-desk-phone-death-knell] and unlawful interception at one end of the scale. At the other end of the scale IMSI grabbers/catchers could undermine serious crime investigations (where investigating officers might have their contact details tapped etc).

The fight back against invasion of privacy has taken amplified recently through the annoucement of a new development of a prototype that has been dubbed the "IMSI Catcher Catcher" [http://twitter.com/e3i5/status/197753799606153216/photo/1] as shown in the image above and that might provide the solid proof privacy campaigners seek to uncover. But this device could equally backfire if those investigating officers in the field are being tracked in the operation of IMSI Catching.

The above represents a tip of the iceberg material that is available through research about devices development for the express intent of obtaining subscriber identity and other personal information without the subscriber/user knowledge or consent where a man-in-the-middle attack has taken place [http://en.wikipedia.org/wiki/Man-in-the-middle_attack].

Sunday, April 24, 2011

Faraday containers found unsafe

Faraday containers found unsafe

A report that focuses on the results, following conducted practical tests, on the reliability of mobile phone shielding devices (eg 'faraday' containers) found the device shielding failed in a number of instances that the author of the report placed under test and did not prevent RF signalling reaching the test mobile phones inside the containers, the findings in this recently published paper suggests:

https://www.cerias.purdue.edu/assets/pdf/bibtex_archive/2010-27.pdf

The implications might require that an 'impact assessment' on evidence that is seized and placed in shielding devices at the scene of a crime and transported from Police Station to Police Station etc may need to be 'reconducted'. The findings in the report raise the notion whether published Guidelines advocating the use of shielding devices may now need to identify exactly the tests and research considered prior to adopting published policy on the use of shielding devices, although it is unclear at present whether that will happen at all.

Whilst the report dealt primarily with external factors (radio communications) and how the shielding devices  coped with them, it also includes some other influences shielding devices can have on touch screen mobile phones, for example.

There have previously been mixed reviews about shielding devices and their impact on seized evidence that is left switched ON within shielding containers:

http://www.forensicfocus.com/index.php?name=Forums&file=viewtopic&t=3914
http://www.forensicfocus.com/index.php?name=Forums&file=viewtopic&t=4277&postdays=0&postorder=asc&start=0 

If a mobile phone is already OFF, or is switched OFF at the point of seizure, then such shielding devices shouldn't be necessary at that particular juncture.

Friday, July 31, 2009

Cellphone Examination and Myths

Cellphone Examination and Myths
.
There are still, surprisingly, many who still promulgate myths by unwittingly conducting examinations in a particular way or use a product/device for cellphone examination to combat a particular perceived problem.
.
I am launching this discussion thread, which will be updated from time to time, to identify cellphone examination myths. In doing so, it is not aimed at a criticising an individual, manufacurer's product or someone selling a service. The point of the discussion is to allow people to make informed decisions as opposed to buying into a particular mythology. Do remember, I am not telling you what you should or should not do, it is your choice, my comments are only intended as helpful observations.
.
CELLPHONE CLOCKS
There is a claim the examiner should examine the cellphone first before examining the SIM Card. Two myths that are still circulating today (a) is that by removing the SIM Card from the phone that is switched OFF the handset clock will be lost, (b) and using a Faraday shield or RF dampening field can help prevent that. I find this rather surprising to apply these myths as a reason for creating a universal principle that handsets should be examined first and using Faraday/RF is the optimum choice for containment and examinations. To me these myths are nothing more than over exaggerated examination procedures. They transfer the skills away from the human to expecting the device and postulated procedure to be capable of coping with everyday common scenarios.
.
Most mobile phones today have a memory system with an on-board battery to keep data live for period of time after the external battery has been removed or the clock data along with an offset stored in flash to calculate the clock upon power up and intialisation to give the time. It is true that there are some phones (but not every phone) that can lose the clock setting when the SIM is removed, so the use of a particular examination procedure should be on a case by case basis. User-defined clocks can be quite unreliable as well and in most cases (but not all) does the clock setting of the handset ever feature as a prominent piece of evidence.
.
Additionaly, Faraday/RF Dampening do not influence the clock at all unless of course as is becoming more popular the user has activated the handset to use the mobile network clock, in which case Faraday/RF Dampening would have a detrimental effect by losing the clock timing on the handset whilst the handset in an isolation containment.
.
Any special procedures needed for very serious crime or terrorism, it is understandible that the use of a particular containment field might be needed. Majority of mobile phone seizures and recovery are pretty bog-standard occasions, so why would anyone leave a mobile phone switched ON in a containment bag where there is a high degree of chance that the bag could be knocked and potentially a key being pressed generating and/or altering data on the phone.
.
FARADAY/RF DAMPENING - LOSING DATA
For road traffic accidents, using containiment bag methodology for seized or recovered switch ON cellphones can be problematical because location data can be lost by isolation in a containment field whether that be mobile network data and/or where GPS data.
.
FARADAY/RF DAMPENING - WIPING DATA
Many of the high-end, sophisticated smart phones like Blackberry may have security policies in place whereby a prolonged absence from the radio network can force a lock and/or data wipe.
.
FARADAY/RF DAMPENING - IMSI
SIM cards have the ability to store up to a number of IMSIs, which are commonly used where countries have multiple network operators on a State by State basis. Roaming users may have a choice to use one or several IMSIs whilst roaming in another State or Country. Activating a particular IMSI can require selection of a profile and pressing the "SEND" key to inform the network of an altered state of subscriber identity, a response from the network can be requird for that change to take affect. The protocol in some handsets has been designed to wait for the response from the newtork to be received before the IMSI change takes place inside the SIM releasing the profile to the handset. Consequently, revealing data for a particular IMSI profile might not be possible.
.
FEEDBACK
If anyone wants to contribute to this myths discussion send an email to me with your observations. If you want to debunk my debunking then by all means do so, I am always willing to learn.

Friday, July 10, 2009

Mobile Phone Flash Memory Chip Evidence

Mobile Phone Flash Memory Chip Evidence
.
When recovering data using flasher box devices it may be useful to support the notion of obtaining a detail (IMSI/ICCID/etc) about a previously inserted paricular SIM Card in a particular mobile telephone that the notion about storing such data in memory is:
.
- not new
- not clandestine shady black-box technology
- not a security breach by the handset manufacturer
.
In fact the entire process of maintaining a SIM List in the phone was designed to allow a user with more than one SIM Card to gain access to previously held memory data associated with each particular SIM Card.
.
In order to support that statement it would be helpful to see practitioners using authoratitive statements about the forensic 'reliability' and 'accuracy' of recovered data being obtained using flash reading devices and the evidential 'weight' and 'value' to be given to the data.
.
To assist, here is a statement from a 1996 published Electronic User Guide for the Nokia 2110:
.
SECURITY LEVEL (Menu 5 2) Page 71
"The phone keeps a list of the SIM cards which are used with the phone. This list may contain the information on up to five different SIM cards."
.
However under the same section in the User Guide it states:
.
"Regardless of the selected security level, all temporarily stored phone numbers are erased when a new SIM card is installed. On the other hand, these phone numbers are not erased when a previously used SIM card is inserted, regardless of the selected security level."
.
As a query about forensic reliability and accuracy:
.
- During the acquisition process and the harvesting of the data acquired is there/ has there been anything lost in translation of the data themselves, at first instance? If the IMSI you have recovered from flash memory is presented along with call logs etc, how do you know that those call logs relate to that IMSI and not another IMSI?
.
As a query about evidential weight and value:
.
- What weight can be given to the recovered IMSI being directly associated with those call logs? Moreover, what value is there in using such potentially uncorroborated evidence assigned to the recovered data being presented as evidence?

Mobile Phone Flash Memory Chip Evidence

Mobile Phone Flash Memory Chip Evidence
.
When recovering data using flasher box devices it may be useful to support the notion of obtaining a detail (IMSI/ICCID/etc) about a previously inserted paricular SIM Card in a particular mobile telephone that the notion about storing such data in memory is:
.
- not new
- not clandestine shady black-box technology
- not a security breach by the handset manufacturer
.
In fact the entire process of maintaining a SIM List in the phone was designed to allow a user with more than one SIM Card to gain access to previously held memory data associated with each particular SIM Card.
.
In order to support that statement it would be helpful to see practitioners using authoratitive statements about the forensic 'reliability' and 'accuracy' of recovered data being obtained using flash reading devices and the evidential 'weight' and 'value' to be given to the data.
.
To assist, here is a statement from a 1996 published Electronic User Guide for the Nokia 2110:
.
SECURITY LEVEL (Menu 5 2) Page 71
"The phone keeps a list of the SIM cards which are used with the phone. This list may contain the information on up to five different SIM cards."
.
However under the same section in the User Guide it states:
.
"Regardless of the selected security level, all temporarily stored phone numbers are erased when a new SIM card is installed. On the other hand, these phone numbers are not erased when a previously used SIM card is inserted, regardless of the selected security level."
.
As a query about forensic reliability and accuracy:
.
- During the acquisition process and the harvesting of the data acquired is there/ has there been anything lost in translation of the data themselves, at first instance? If the IMSI you have recovered from flash memory is presented along with call logs etc, how do you know that those call logs relate to that IMSI and not another IMSI?
.
As a query about evidential weight and value:
.
- What weight can be given to the recovered IMSI being directly associated with those call logs? Moreover, what value is there in using such potentially uncorroborated evidence assigned to the recovered data being presented as evidence?

Tuesday, August 12, 2008

Dual International Mobile station Equipment Identity (IMEI)

Dual International Mobile station Equipment Identity (IMEI)


When we think of mobile telephones we mostly think in terms of them of having a single International Mobile station Equipment Identity number. For two decades, whether for an analogue or digital mobile 'phone, we have often associated, to assist in showing importance of, and drawing anology about, that mobile 'phone serial numbers are alike to vehicle chassis numbers - in essence IMEIs are intended to be unique numbers.
.
Because of that unique numbering scheme, it follows that each mobile phone should only have one IMEI. That has changed and mobile 'phone manufacturers can include two IMEIs. The two IMEIs can be viewed via the label under the battery pack (see photo below Samsung SGH-D888), or by entering *#06# (asterisk, octothorp, 0, 6, octothorp).
.



.

Having reviewed the Standards and other documentation and found no definitive statement about the requirement for a dual IMEI numbering scheme, I put out some enquiries and I am grateful to those who assisted. I am told it would appear the occurrence of the dual IMEIs are due to there being two radio chipsets in some handsets. As I understand it, also, I won't find anything in the Standards about this matter - just yet. Moreover, it does not automatically follow that a handset having Dual SIM/USIM slots implies or infers that the handset has two radio chipsets, thus two IMEIs.

.

Evidentially, of course it is noted this matter impacts in numerous ways when conducting examination using automated physical and/or logical harvesting of data and the much-needed handset (manual) examination.

Friday, April 25, 2008

Looking back at the future of SIM in 2002

Looking back at the future of SIM in 2002
.
I have always thought looking to the future is important, but equally looking back at what we know or think might be happening, from an historical perspective, can help see what problems can occur in the future and also to note whether foreseeable problems have been addressed or not, over time.
.
I have selected a summary of issues discussed in training back in 2002, which are set out in the downloadable .pdf document "SIM - The Future as Viewed in 2002".
.
.
For example, did you know or remember the slow down in SIM Card manufacturing in 2001? This is hard to believe when we think about the saturation levels of SIMs and handsets in the marketplace today.
.
What about SIM Application Toolkits, applets and the exciting development of Java Standard Edition for mobile phones (KJava and PJava)? Our concerns then were how these advancements were going to impact on mobile telephone and SIM examination. Remember at that time we saw problems and tried to anticipate how to combat problems, but we had no immediate solutions which invariable had to be produced in some instance "on-the-hoof", so to speak.
.
Cloning of SIM Cards had raised its head back in 1998 and devices were starting to appear on the market in 2000/01. The problems we faced then was knowing what to look for to deternmine whether a SIM was cloned or not? And then if the SIM was a clone what impact on evidence could/would it have?
.
What about SIM Cards with multiple IMSIs? Still an issue today as it was then in 2002. The problem being is that SIM readers do not have the capability to read more than one IMSI from a SIM Card at any one time. Consequently, invocation of an IMSI selection in EF-7F20 6F07 is not possible other than the SIM being placed in the handset and another IMSI being selected using the handset menu Network selection. Moreover, once that has been done the green button on the handset needs to be pushed and a location update (and an IMSI-attach) to the network is required, which cannot be performed in a faraday bag, radio dampening field or isolation chamber. The question arises when do you search for more than one IMSI recorded into a SIM? What cases warrant it? How many cases have been missed in the past where more than one IMSI resided in SIM but has gone undetected? Put simply, when should allocution take place?
.
There were a huge range of issues to be addressed then in early 2000, as there are now. When reading these brief discussion documents representing issues spoken about on my training courses, I hope they convey the message that plug and play (PnP) or universal plug and play (UPnP) systems used to extract and harvest data are simply not enough to satisfy the requirements for mobile telephone examination.

Looking back at the future of SIM in 2002

Looking back at the future of SIM in 2002
.
I have always thought looking to the future is important, but equally looking back at what we know or think might be happening, from an historical perspective, can help see what problems can occur in the future and also to note whether foreseeable problems have been addressed or not, over time.
.
I have selected a summary of issues discussed in training back in 2002, which are set out in the downloadable .pdf document "SIM - The Future as Viewed in 2002".
.
.
For example, did you know or remember the slow down in SIM Card manufacturing in 2001? This is hard to believe when we think about the saturation levels of SIMs and handsets in the marketplace today.
.
What about SIM Application Toolkits, applets and the exciting development of Java Standard Edition for mobile phones (KJava and PJava)? Our concerns then were how these advancements were going to impact on mobile telephone and SIM examination. Remember at that time we saw problems and tried to anticipate how to combat problems, but we had no immediate solutions which invariable had to be produced in some instance "on-the-hoof", so to speak.
.
Cloning of SIM Cards had raised its head back in 1998 and devices were starting to appear on the market in 2000/01. The problems we faced then was knowing what to look for to deternmine whether a SIM was cloned or not? And then if the SIM was a clone what impact on evidence could/would it have?
.
What about SIM Cards with multiple IMSIs? Still an issue today as it was then in 2002. The problem being is that SIM readers do not have the capability to read more than one IMSI from a SIM Card at any one time. Consequently, invocation of an IMSI selection in EF-7F20 6F07 is not possible other than the SIM being placed in the handset and another IMSI being selected using the handset menu Network selection. Moreover, once that has been done the green button on the handset needs to be pushed and a location update (and an IMSI-attach) to the network is required, which cannot be performed in a faraday bag, radio dampening field or isolation chamber. The question arises when do you search for more than one IMSI recorded into a SIM? What cases warrant it? How many cases have been missed in the past where more than one IMSI resided in SIM but has gone undetected? Put simply, when should allocution take place?
.
There were a huge range of issues to be addressed then in early 2000, as there are now. When reading these brief discussion documents representing issues spoken about on my training courses, I hope they convey the message that plug and play (PnP) or universal plug and play (UPnP) systems used to extract and harvest data are simply not enough to satisfy the requirements for mobile telephone examination.