Jump to content

dBz

Active Members
  • Posts

    3
  • Joined

  • Last visited

Everything posted by dBz

  1. OSMOCOM most certainly can't "play" with that timing advance. GSM would break if you fiddled with it. Every piece/parameter of the GSM standard has a purpose and reason for implementation. If it wasn't crucial, teleco wouldn't have used it since it would suck up bandwidth, which is money to them. What I'm getting at is there is a value, an integer if you will, that correlates to 550 meters. Its the amount of distance the speed of light (aka radio wave) will travel in 3.6 micro seconds. Additionally, you can't mess with the timing advance because it's not yours to mess with, the phone calculates it, then given to the tower. I should have pointed to something with a bit more meat, like this page. http://www.telecomhall.com/parameter-timing-advance-ta.aspx
  2. If you're really wanting to "triangulate" cellular, more specifically GSM, you should check this out, use your imagination after that. http://en.wikipedia.org/wiki/Timing_advance V/r dBz
  3. Hey all, I'm a bit of a RF geek so I love layer 1 stuff. I'm going to list some lessons learned/commentary on some wifi cards and also give a few tips/tricks. All of this is relevant to kali... Cards: Alfas: AWUS051NH "Gold" Alfa - 500 mw (27 db) A/B/G/N MiMo RP-SMA. Ralink RT2770/2750. B/G operates via RP-SMA jack, A/N(5) operates via internal printed board. Do not expect proper results using 5ghz Yagi antenna with this product since you can't access the 5ghz input via the RP-SMA jack!!! Best Alfa card for receiving. I use this card 90% of the time. AWUS036NHA "Black" Alfa - 2000 mw (33 db) B/G/N MiMo RP-SMA. Atheros AR9271. Great injecting card due to wattage output. Highest wattage. Make sure to set your region to BO so you can push over 27 db output. This card is the best card to use if you're hunting off-band wifi; Atheros chips are the best at raw frequency input instead of channel # input. AWUS036NH "Green" or "Teal" Alfa - 2000 mw (33 db) B/G/N MiMo RP-SMA. Ralink RT3070. Basically a second option for a 2 watt card. I prefer the "Black" card but I'll use this one of the device doesn't play well with the Atheros. Doesn't do raw frequency input as well as the "Black" card. AWUS036H "Silver" Alfa - 1000 mw (30 db) B/G/N RP-SMA. Ralink RT8187L. Ushered in the Alfa products. No longer the "only card supported". It should be noted that USB-OTG over android tablets currently only support this card (although I'm sure that'll change soon) so I keep a few of these around. Also cheap at only $20 bucks from retailers. Ubiquity: Expensive, overpriced, overhyped. The "Gold" Alfa has consistently outproduced the SR71s (PCMCIA, PC-Express, USB, etc) in collection, sensitivity, injection, support, etc. The tiny u.fl antenna ports suck and have to be taped down on the SR71 and like products. That being said, whenever I replace a PC-Express WiFi card in a laptop, I use an Ubiquity product. Rosewill (What?!?!): RNX-N600UBE (20db???) A/B/G/N SMAx2. Ralink 3572/5572 (v1/v2). Best card for receiving - hands down! I'm not sure which jack does B/G and which does A/N. If you're not injecting, use this card!!! Wattage is a little low but injects just fine with appropriate directionals. It also doesn't look like an Alfa/SR71 so you're not automagically labeled a 'hacker' around tech-literate people. Pretty sure this is the only article on the public internet that mentions this card as good at WiFi stuff. Other notes: USB 2.0 provides 5 volts at .500 amps so the maximum theoretical TX power of a USB based card is 2500 mw. Of course you have to run the overhead so it'll be less so the 2 watt Alfas are about the hottest cards you can get TX wise. So that 6000 mw USB card on chinabay might be a little bit of an stretch!!! If you don't own a directional antenna and you're into wifi, you're wrong. Also, creative use of tinfoil (besides making hats) can greatly enhance your collection (by reducing unwanted collection on the same channels) Use wireshark to look at datarates of collected packets when 'honing' in on a client or AP. You may see plenty of 1 rate broadcasts but do you actually see data packets at 11 rate or 54 rate? Are there lots of retransmits (flooded environment)? Do you get plenty of target traffic but the ammount of target traffic compared to total traffic in the area on the channel is very small (block out environmental traffic/noise with directionals, a new position, tinfoil...)? Just wanted to throw out some thoughts/experience/tips! V/r dBz
×
×
  • Create New...