---
title: "GSM cracking in penetration test methodologies (OSSTMM) ?"
url: https://infosecurity.ch/20100723/gsm-cracking-in-penetration-test-methodologies-osstmm/
date: 2010-07-23
author: Fabio Pietrosanti (naif)
language: en
tags: [encryption, hacking, privacy, voicesecurity]
---

# GSM cracking in penetration test methodologies (OSSTMM) ?

As most of this blog reader already know, in past years there was a lot of activities related to **public research** for GSM auditing and cracking.

However when there was huge media coverage to GSM cracking research results, the **tools to make the cracking** was really early stage and still very inefficient.

Now **[Frank Stevenson](http://en.wikipedia.org/wiki/Frank_A._Stevenson)** , norwegian cryptanalyst that already broke the [Content Scrambling System](http://en.wikipedia.org/wiki/DeCSS) of DVD video disc, participating to the A51 cracking project started by [Karsten Nohl](http://www.cs.virginia.edu/~kn5f/), released **[Kraken](http://lists.lists.reflextor.com/pipermail/a51/2010-July/000683.html)** , a new improved version of the A51 cracking system.

It’s interesting to notice that WiFi cracking had a similar story, as the first WiFi wep cracking discovery was quite slow in earlier techniques but later Korek, an hacker working on cracking code, improve the attack system drammatically.

That’s the story of security research cooperation, you start a research, someone follow it and improve it, some other follow it and improved it and at the end you get the result.

Read more on the [Kraken GSM Cracking software release](http://www.computerworld.com/s/article/9179529/New_Kraken_GSM_cracking_software_is_released?taxonomyId=16).

And stay tuned as next week at Blackhat Conference Karsten Nohl will explain the details of the required **[hardware setup and detailed instructions on how to do it](http://lists.lists.reflextor.com/pipermail/a51/2010-July/000694.html) :-)**

I would really like to see those tools incorporated into [Penetration Testing Linux Distribution BackTrack](http://www.backtrack-linux.org/) with [OSSTMM](http://www.isecom.org/osstmm/) methodology enforcing the testing of GSM interception and man in the middle :-)

If things proceed that way and [Ettus Research](http://www.ettus.com/) (The producer of USRP2 software radio used for low cost GSM signal receiving) will not be taken down, we can still see this.
