
Awesome-Cellular-Hacking
Eine umfassend kuratierte Liste von Ressourcen für die 2G/3G/4G/5G-Mobilfunksicherheitsforschung und -analyse
Dieses Repository bündelt das Wissen der Community im Bereich der Mobilfunksicherheit, einschließlich Exploits, Forschungsarbeiten, Werkzeugen und Bildungsmaterialien. Ziel ist es, wichtige Sicherheitsforschung zu bewahren und zu organisieren, die sonst schwer auffindbar werden könnte.
Haftungsausschluss: Diese Informationen dienen ausschließlich Bildungs- und defensiven Sicherheitsforschungszwecken. Verwenden Sie sie verantwortungsbewusst und in Übereinstimmung mit geltenden Gesetzen und Vorschriften.
Neu in der Mobilfunksicherheitsforschung? In diesem Abschnitt wird der empfohlene Weg zum Aufbau grundlegender Fähigkeiten skizziert.
Anfänger (nur passives Mithören)
Fortgeschritten (aktives Forschungslabor)
Experte (Protokoll-Fuzzing und Basisband-Forschung)
uhd_find_devices)How To Build Your Own Rogue GSM BTS For Fun and Profit
Anleitung zum Erstellen einer tragbaren GSM-BTS für private Netzwerke oder Sicherheitstests. Deckt die technische Einrichtung mit relativ günstiger Hardware ab.
How to Create an Evil LTE Twin / LTE Rogue BTS
Tutorial zur Einrichtung einer 4G/LTE-Evil-Twin-Basisstation mit srsRAN und USRP-SDR-Geräten.
Practical Attacks Against GSM Networks: Impersonation
Detaillierte Analyse der GSM-Basisstations-Imitation mit SDR und Open-Source-Tools.
Tutorial: Analyzing GSM with Airprobe and Wireshark
Schritt-für-Schritt-Anleitung zur Verwendung von RTL-SDR zur Analyse von GSM-Signalen mit GR-GSM/Airprobe und Wireshark.
GSM/GPRS Traffic Interception for Penetration Testing
NCC-Group-Forschung über GSM/GPRS-Abfangmöglichkeiten für Penetrationstest-Einsätze.
RANsacked: 100+ Flaws in LTE and 5G Implementations — University of Florida / NC State, Jan. 2025
Forscher haben 119 Schwachstellen (97 CVEs) in sieben LTE- und drei 5G-Implementierungen offengelegt, darunter Open5GS, Magma, OpenAirInterface, Athonet, SD-Core, srsRAN. Jeder Fehler kann genutzt werden, um die zellulare Kommunikation einer ganzen Stadt dauerhaft zu stören. Einige erfordern keine SIM-Karte – ein einziges nicht authentifiziertes Paket kann eine MME oder einen AMF zum Absturz bringen.
CITesting: Context Integrity Violations in LTE Core Networks — KAIST, ACM CCS 2025 (Distinguished Paper)
KAIST-Forscher identifizierten eine neue Klasse von Uplink-Angriffen auf LTE-Kernnetze. Anders als traditionelle Downlink-Angriffe funktionieren diese über legitime Basisstationen und können jeden im gleichen MME-Abdeckungsbereich betreffen. Alle vier getesteten Implementierungen (Open5GS, srsRAN, Amarisoft, Nokia) waren verwundbar.
Uncovering Hidden Paths in 5G: Protocol Tunneling and Network Boundary Bridging — ACM CCS 2025
Neue Forschung zur Ausnutzung von Protokoll-Tunneling in 5G-Netzen, um Netzwerkgrenzen zu überschreiten und Komponenten zu erreichen, die isoliert sein sollten.
BaseBridge: Over-the-Air and Emulation Testing for Cellular Baseband Firmware — IEEE S&P 2025
Überbrückt die Lücke zwischen Over-the-Air- und emulationsbasierten Tests für die Analyse von Mobilfunk-Basisband-Firmware.
5G Network Slicing: Security Challenges, Attack Vectors, and Mitigation — PMC, Juli 2025
Umfassende Klassifizierung von Angriffen auf Orchestrierungs-, Virtualisierungs- und Interslice-Kommunikationsebenen in 5G.
Survey on 5G Physical Layer Security Threats and Countermeasures — MDPI Sensors, 2024
Ausführlicher Überblick über die PHY-Layer-Angriffsfläche in 4G/5G: Jamming, Spoofing, Eavesdropping, Pilot Contamination und aktuelle SDR-basierte Forschungswerkzeuge.
sudo add-apt-repository ppa:ettusresearch/uhd sudo apt-get update
sudo apt-get install libuhd-dev libuhd003 uhd-host
uhd_find_devices
cd /usr/lib/uhd/utils/ ./uhd_images_downloader.py
sudo uhd_usrp_probe
### SDR Hardware-Optionen
| Hardware | Frequenzbereich | Bandbreite | Preisbereich | Anwendungsfall | Link |
|----------|----------------|-----------|-------------|----------|------|
| **Ettus Research (USRP)** | | | | | |
| **USRP B210** | 70 MHz - 6 GHz | 61.44 MHz | $2,100 | Professionelle Entwicklung, 2x2 MIMO | [Ettus](https://www.ettus.com/all-products/ub210-kit/) |
| **USRP B200mini** | 70 MHz - 6 GHz | 61.44 MHz | $775 | Kompaktes USRP B-Serie | [Ettus](https://www.ettus.com/) |
| **USRP N210** | DC - 6 GHz | 25 MHz | $1,700 | Hochleistungs-Netzwerk-SDR | [Ettus](https://www.ettus.com/) |
| **USRP N320** | 1 MHz - 6 GHz | 200 MHz | $8,000 | Vernetztes 2x2 MIMO | [Ettus](https://www.ettus.com/) |
| **USRP X310** | DC - 6 GHz | 160 MHz | $6,000 | Hochleistungs-Desktop/Rack | [Ettus](https://www.ettus.com/all-products/x310-kit/) |
| **USRP X410** | 1 MHz - 7.2 GHz | 400 MHz | $15,000 | Neuestes Hochleistungs-4x4 MIMO | [Ettus](https://www.ettus.com/) |
| **USRP X440** | 30 MHz - 4 GHz | 1.6 GHz | $25.000+ | Neueste 8x8 MIMO RFSoC-Plattform | [Ettus](https://www.ettus.com/) |
| **USRP E320** | 70 MHz - 6 GHz | 56 MHz | $4,000 | Eingebettetes 2x2 MIMO SDR | [Ettus](https://www.ettus.com/) |
| **Nuand (BladeRF)** | | | | | |
| **BladeRF 2.0 xA4** | 47 MHz - 6 GHz | 61.44 MHz | $420 | Budget 2x2 MIMO-Entwicklung | [Nuand](https://www.nuand.com/product/bladerf-xa4/) |
| **BladeRF 2.0 xA9** | 47 MHz - 6 GHz | 61.44 MHz | $720 | Hohe FPGA-Ressourcen, 2x2 MIMO | [Nuand](https://www.nuand.com/product/bladerf-xa9/) |
| **BladeRF x40 (Legacy)** | 300 MHz - 3.8 GHz | 40 MHz | $400 | Einsteiger-Legacy-Modell | [Nuand](https://www.nuand.com/product/bladerf-x40/) |
| **Great Scott Gadgets** | | | | | |
| **HackRF One** | 1 MHz - 6 GHz | 20 MHz | $350 | Budget-TX/RX-Entwicklung | [GSG](https://greatscottgadgets.com/hackrf/) |
| **YARD Stick One** | 300-348, 391-464, 782-928 MHz | 2.5 MHz | $110 | Sub-GHz-IoT-Frequenzen | [GSG](https://greatscottgadgets.com/yardstickone/) |
| **Lime Microsystems** | | | | | |
| **LimeSDR USB** | 100 kHz - 3.8 GHz | 61.44 MHz | $289 | Open-Source 2x2 MIMO | [Lime Micro](https://limemicro.com/sdr/limesdr-usb/) |
| **LimeSDR Mini** | 10 MHz - 3.5 GHz | 30.72 MHz | $139 | Kompakte LimeSDR-Variante | [Lime Micro](https://limemicro.com/boards/limesdr-mini/) |
| **LimeSDR Mini 2.0** | 10 MHz - 3.5 GHz | 30.72 MHz | $169 | Aktualisiert mit ECP5 FPGA | [Lime Micro](https://limemicro.com/sdr/limesdr-mini-2-0/) |
| **LimeSDR X3** | Verschiedene Bänder | Bis zu 61.44 MHz | $3.000+ | Professioneller 3x Transceiver PCIe | [Lime Micro](https://limemicro.com/sdr/limesdr-x3/) |
| **Analog Devices** | | | | | |
| **PlutoSDR** | 325 MHz - 3.8 GHz | 20 MHz | $150 | Bildungs- und Lernplattform | [Analog Devices](https://www.analog.com/en/design-center/evaluation-hardware-and-software/evaluation-boards-kits/adalm-pluto.html) |
| **RTL-SDR Blog** | | | | | |
| **RTL-SDR V3** | 500 kHz - 1.75 GHz | 3.2 MHz | $35 | Ultra-Budget RX-Only-Scanner | [RTL-SDR](https://www.rtl-sdr.com/buy-rtl-sdr-dvb-t-dongles/) |
| **RTL-SDR V4** | 500 kHz - 1.75 GHz | 3.2 MHz | $40 | Neueste mit R828D Tuner | [RTL-SDR](https://www.rtl-sdr.com/rtl-sdr-blog-v4-dongle-initial-release/) |
| **Airspy** | | | | | |
| **Airspy R2** | 24 MHz - 1.8 GHz | 10 MHz | $200 | Hochleistungs-VHF/UHF-Scanner | [Airspy](https://airspy.com/) |
| **Airspy Mini** | 24 MHz - 1.8 GHz | 6 MHz | $99 | Kompakter Airspy im Dongle-Format | [Airspy](https://airspy.com/) |
| **Airspy HF+ Discovery** | 9 kHz - 31 MHz, 60-260 MHz | 768 kHz | $169 | Dedizierter HF-Empfang | [Airspy](https://airspy.com/) |
| **SDRplay** | | | | | |
| **RSP1A** | 1 kHz - 2 GHz | 10 MHz | $119 | Breitbandiger Allzweck | [SDRplay](https://www.sdrplay.com/) |
| **RSPdx** | 1 kHz - 2 GHz | 10 MHz | $299 | Professionelle Funktionen, Dual-Antenne | [SDRplay](https://www.sdrplay.com/) |
| **Red Pitaya** | | | | | |
| **STEMlab 125-14** | DC - 60 MHz | 50 MHz | $600 | HF-Transceiver, Laborinstrument | [Red Pitaya](https://redpitaya.com/) |
| **STEMlab 122-16** | DC - 50 MHz | Variabel | $625 | Hochauflösendes HF-SDR/Oszilloskop | [Red Pitaya](https://redpitaya.com/) |
### Häufige SDR-Probleme und Fehlerbehebung
| Problem | Mögliche Ursachen |
|-------|----------------|
| Gerät nicht erkannt | Fehlerhafte Firmware, USB-Verbindungsprobleme |
| Schlechte Signalqualität | Falsche Antennen, falsche Frequenzkonfiguration |
| Verbindungsfehler | Falsche SIM, falsche MCC/MNC-Codes |
| Leistungsprobleme | Einschränkungen virtualisierter Plattformen, falsche SDR-Firmware |
---
## Test- und Forschungsmethoden
### Modernes Baseband-Fuzzing (2024-2025)
- **[Budget-Friendly Baseband Fuzzing Setup](https://t2.fi/schedule/2024/)** — DefCon 32, Janne Taponen
Behandelt den Aufbau kosteneffizienter Baseband-Fuzzing-Setups mit SDRs, die Nutzung von LLMs zur Beschleunigung der Protokollparser-Entwicklung sowie das Testen von Fahrzeug-ECUs, Zahlungsterminals und Mobilgeräten.
- **[RANsacked Fuzzing Framework](https://dl.acm.org/doi/10.1145/3658644.3670320)** — University of Florida / NC State, ACM CCS 2024
Domäneninformierter Fuzzing-Ansatz, der auf RAN-Core-Schnittstellen abzielt. Es wurden 119 Schwachstellen in zehn Netzwerkimplementierungen entdeckt.
- **[BaseBridge](https://dl.acm.org/doi/10.1145/3658644.3670320)** — IEEE S&P 2025
Framework, das Over-the-Air- und emulationsbasiertes Testen von zellulärer Basisband-Firmware verbindet.
### Tools zur Schwachstellenforschung
- **[5GBaseChecker](https://github.com/SyNSec-den/5GBaseChecker)** — Automatische Erkennung von 5G-Basisband-Schwachstellen
- **[CITesting](https://dl.acm.org/doi/10.1145/3719027.3765230)** — Testen auf Verletzungen der Kontextintegrität in LTE-Kernnetzen
- **[certmitm](https://github.com/juurlink/certmitm)** — TLS-Implementierungstest-Tool
---
## Angriffsvektoren
### Radio-Jamming-Angriffe
Aus [NIST SP 800-187](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-187.pdf):
- **Smart Jamming** — Gezielte Kanalstörung, zeitlich so abgestimmt, dass sie nicht erkannt wird
- **Dumb Jamming** — Breitbandrauschen über Frequenzbereiche
- **UE Interface Jamming** — Verhindern der UE-Signalisierung zur eNodeB
- **eNodeB Interface Jamming** — Stören der Basisstationskommunikation
### 5G-Sicherheitsforschung
- **[Privacy Attacks on 4G/5G Paging Protocols](https://assets.documentcloud.org/documents/5749002/4G-5G-paper-at-NDSS-2019.pdf)** — NDSS 2019
- **[European 5G Security in the Wild](https://arxiv.org/pdf/2305.08635.pdf)** — 2023
- **[5G Threat Modeling Framework](https://arxiv.org/pdf/2005.05110v1.pdf)**
- **[ENISA 5G Threat Landscape](https://github.com/W00t3k/Awesome-Cellular-Hacking/blob/master/papers/5g/ENISA-5G-threat-landscape.pdf)**
- **[5GReasoner Analysis Framework](https://github.com/W00t3k/Awesome-Cellular-Hacking/blob/master/papers/5g/5GReasoner.pdf)**
- **[5G NR Jamming, Spoofing, and Sniffing](https://github.com/W00t3k/Awesome-Cellular-Hacking/blob/master/papers/5g/5gjam.pdf)**
- **[New Privacy Threat on 3G, 4G, and 5G AKA Protocols](https://arxiv.org/pdf/1905.07617.pdf)**
- **[Insecure Connection Bootstrapping in Cellular Networks](https://github.com/W00t3k/Awesome-Cellular-Hacking/blob/master/papers/lte/wisec19-preprint.pdf)**
- **[Protecting 4G and 5G Cellular Paging Protocols](https://github.com/W00t3k/Awesome-Cellular-Hacking/blob/master/papers/5g/popets-2020-0008.pdf)**
- **[Uncovering Hidden Paths in 5G: Protocol Tunneling](https://dl.acm.org/doi/10.1145/3719027.3765206)** — ACM CCS 2025
- **[5G Network Slicing Attack Classification](https://pmc.ncbi.nlm.nih.gov/articles/PMC12251764/)** — MDPI, Juli 2025
### LTE/4G-Sicherheitsforschung
- **[LTRACK: Stealthy Mobile Phone Tracking](https://www.usenix.org/system/files/sec22summer_kotuliak.pdf)** — USENIX Security 2022
- **[Detecting Fake 4G Base Stations in Real Time](https://i.blackhat.com/USA-20/Wednesday/us-20-Quintin-Detecting-Fake-4G-Base-Stations-In-Real-Time.pdf)** — Black Hat 2020
- **[BaseSAFE: Baseband Fuzzing](https://arxiv.org/pdf/2005.07797.pdf)**
- **[LTE Public Warning System Attacks](https://netstech.org/wp-content/uploads/2019/06/cmas-mobisys2019.pdf)**
- **[Signal Overshadowing Attacks](https://www.usenix.org/system/files/sec19-yang-hojoon.pdf)** — USENIX Security 2019
- **[Breaking LTE on Layer Two](https://github.com/W00t3k/Awesome-Cellular-Hacking/blob/master/papers/lte/breaking-lte-layer-two.pdf)**
- **[LTE/LTE-A Jamming, Spoofing, and Sniffing](https://github.com/W00t3k/Awesome-Cellular-Hacking/blob/master/papers/lte/LTE-jamming-magazine.pdf)**
- **[LTE Protocol Exploits](https://github.com/W00t3k/Awesome-Cellular-Hacking/blob/master/papers/lte/LTE-security-TakeDownCon.pdf)**
- **[Practical Attacks Against Privacy and Availability](https://github.com/W00t3k/Awesome-Cellular-Hacking/blob/master/papers/lte/Prac-4G-Attacks.pdf)**
- **[LTE Security Assessment](https://github.com/W00t3k/Awesome-Cellular-Hacking/blob/master/papers/lte/LTE-open-source-HackerHalted.pdf)**
- **[LTE Security Disabled: Misconfiguration in Commercial Networks](https://www.infsec.ruhr-uni-bochum.de/media/infsec/veroeffentlichungen/2019/04/23/wisec19-final123.pdf)**
- **[All The 4G Modules Could Be Hacked](https://i.blackhat.com/USA-19/Wednesday/us-19-Shupeng-All-The-4G-Modules-Could-Be-Hacked.pdf)** — Black Hat 2019
- **[Paging Storm Attacks Against 4G/LTE Networks](https://www.cs.binghamton.edu/~ghyan/papers/wisec20.pdf)**
- **[Analysis of the LTE Control Plane](https://syssec.kaist.ac.kr/pub/2019/kim_sp_2019.pdf)** — IEEE S&P 2019
- **[Baseband Attacks: Remote Exploitation of Memory Corruptions](https://www.usenix.org/system/files/conference/woot12/woot12-final24.pdf)** — WOOT 2012
- **[CITesting: Context Integrity Violations in LTE Core Networks](https://dl.acm.org/doi/10.1145/3719027.3765230)** — ACM CCS 2025 (Distinguished Paper)
- **[New Vulnerabilities in 4G and 5G Cellular Access Network Protocols](https://dl.acm.org/doi/10.1145/3317549.3319728)** — WiSec 2019
---
## Konferenzvorträge
### ACM CCS 2025
- **[CITesting: Systematic Testing of Context Integrity Violations in LTE Core Networks](https://dl.acm.org/doi/10.1145/3719027.3765230)** — KAIST (Distinguished Paper)
Neue Klasse von Uplink-Angriffen auf LTE-Kernnetzwerke, die über legitime Basisstationen funktionieren – keine schurkische BTS erforderlich. Alle vier getesteten Implementierungen waren verwundbar, einschließlich kommerzieller Systeme von Nokia und Amarisoft.
- **[Uncovering Hidden Paths in 5G: Exploiting Protocol Tunneling and Network Boundary Bridging](https://dl.acm.org/doi/10.1145/3719027.3765206)**
Zeigt, wie Angreifer Protocol Tunneling nutzen können, um Netzwerkgrenzen zu überwinden und isolierte 5G-Komponenten zu erreichen.
### IEEE S&P 2025
- **[BaseBridge: Bridging Over-the-Air and Emulation Testing for Cellular Baseband Firmware](https://dl.acm.org/doi/10.1145/3658644.3670320)**
Neues Framework für Sicherheitstests von Mobilfunk-Basisband-Firmware, das Emulations- und OTA-Testansätze kombiniert.
### Black Hat USA 2024
- **[5G Baseband Vulnerabilities — Penn State University](https://techcrunch.com/2024/08/07/hackers-could-spy-on-cellphone-users-by-abusing-5g-baseband-flaws-researchers-say/)**
Forscher haben 12 Schwachstellen in 5G-Basisbändern von Samsung, MediaTek und Qualcomm offengelegt, die Geräte von Google, OPPO, OnePlus, Motorola und Samsung betreffen. Begleitet von der Veröffentlichung des 5GBaseChecker-Tools.
### DefCon 32 (2024)
- **[Economizing Mobile Network Warfare: Budget-Friendly Baseband Fuzzing](https://t2.fi/schedule/2024/)** — Janne Taponen
Baseband-Fuzzing mit erschwinglicher SDR-Hardware zugänglich machen. Behandelt LLM-gestützte Protokollparser-Entwicklung und Schwachstellenerkennung in Fahrzeug-ECUs, Zahlungsterminals und Mobilfunkmodems.
### Black Hat USA 2022
- **[Attacks from a New Front Door in 4G and 5G Networks](https://i.blackhat.com/USA-22/Wednesday/US-22-Shaik-Attacks-From-a-New-Front-Door-in-4G-5G-Mobile-Networks.pdf)**
### Black Hat USA 2021
- **[Over The Air Baseband Exploit: 5G RCE](https://i.blackhat.com/USA21/Wednesday-Handouts/us-21-Over-The-Air-Baseband-Exploit-Gaining-Remote-Code-Execution-On-5G-Smartphones.pdf)** — [White Paper](https://i.blackhat.com/USA21/Wednesday-Handouts/us-21-Over-The-Air-Baseband-Exploit-Gaining-Remote-Code-Execution-On-5G-Smartphones-wp.pdf)
### Black Hat USA 2020
- **[Detecting Fake 4G Base Stations in Real Time](https://i.blackhat.com/USA-20/Wednesday/us-20-Quintin-Detecting-Fake-4G-Base-Stations-In-Real-Time.pdf)**
### Zusätzliche Konferenzressourcen
- **[NSA PLAYSET GSM](https://www.defcon.org/images/defcon-22/dc-22-presentations/Pierce-Loki/DEFCON-22-Pierce-Loki-NSA-PLAYSET-GSM.pdf)** — DEF CON 22
- **[VoLTE Phreaking](https://github.com/W00t3k/Awesome-Cellular-Hacking/blob/master/papers/talks/HAXPO-VoLTE-Phreaking-Ralph-Moonen.pdf)** — Ralph Moonen
- **[RF Exploitation: IoT/OT Hacking with SDR](https://conference.hitb.org/hitbsecconf2019ams/materials/HAXPO%20D2%20-%20Demystifying%20IoT:OT%20Hacks%20With%20SDR%20-%20Himanshu%20Mehta%20&%20Harshit%20Agrawal.pdf)** — HITB 2019
- **[Bye-Bye IMSI Catchers: Security Enhancements in 5G](https://conference.hitb.org/hitbsecconf2018pek/materials/D2T2%20-%20Bye%20Bye%20IMSI%20Catchers%20-%20Security%20Enhancements%20in%205g%20-%20Lin%20Huang.pdf)** — HITB 2018
- **[Side Channel Attacks in 4G and 5G](https://i.blackhat.com/eu-19/Thursday/eu-19-Hussain-Side-Channel-Attacks-In-4G-And-5G-Cellular-Networks.pdf)** — Black Hat Europe 2019
- **[Dirty Use of USSD Codes in Cellular Networks](https://troopers.de/wp-content/uploads/2012/12/TROOPERS13-Dirty_use_of_USSD_codes_in_cellular-Ravi_Borgaonkor.pdf)** — TROOPERS 2013, Ravi Borgaonkar
- **[Hacking LTE Public Warning Systems](https://conference.hitb.org/hitbsecconf2019ams/materials/HAXPO%20D1%20-%20Hacking%20LTE%20Public%20Warning%20Systems%20-%20Weiguang%20Li.pdf)** — HITB 2019
---
## Forschungspapiere
### 2025
- **[CITesting: Systematic Testing of Context Integrity Violations in LTE Core Networks](https://dl.acm.org/doi/10.1145/3719027.3765230)** — ACM CCS 2025 (Distinguished Paper Award)
KAISTs CITesting-Tool führt Tausende von Testfällen gegen LTE-Kernimplementierungen durch und übertrifft damit die 31-Fälle-Abdeckung früherer Tools (LTEFuzz). Alle vier getesteten Implementierungen enthielten CIV-Schwachstellen.
- **[Uncovering Hidden Paths in 5G: Protocol Tunneling and Network Boundary Bridging](https://dl.acm.org/doi/10.1145/3719027.3765206)** — ACM CCS 2025
- **[5G Network Slicing: Security Challenges, Attack Vectors, and Mitigation Approaches](https://pmc.ncbi.nlm.nih.gov/articles/PMC12251764/)** — MDPI, Juli 2025
- **[Starshields for iOS: Navigating the Security Cosmos in Satellite Communication](https://www.ndss-symposium.org/wp-content/uploads/2025-124-paper.pdf)** — NDSS 2025
Erste umfassende Sicherheitsanalyse der Satellitenkommunikationsfunktionen von Apple. Forscher haben das proprietäre Protokoll rückentwickelt, Umgehungen von Einschränkungen demonstriert und eine Simulationsplattform aufgebaut, die Emergency SOS, Find My, Pannenhilfe und iMessage über Satellit abdeckt.
### 2024
- **[RANsacked: A Domain-Informed Approach for Fuzzing LTE and 5G RAN-Core Interfaces](https://dl.acm.org/doi/10.1145/3658644.3670320)** — ACM CCS 2024
119 Schwachstellen, 97 CVEs, in zehn Implementierungen. Jede einzelne von ihnen ermöglicht eine stadttaweite Störung der Mobilfunkkommunikation.
- **[Survey on 5G Physical Layer Security Threats and Countermeasures](https://www.mdpi.com/1424-8220/24/17/5523)** — MDPI Sensors 2024
Umfassender Überblick über die Angriffsfläche der PHY-Schicht, die Abhören, Stören, Spoofing, Pilotkontamination und SDR-basierte Forschungsframeworks abdeckt.
- **[5GBaseChecker Tool Release](https://github.com/SyNSec-den/5GBaseChecker)** — Penn State University
Open-Source-Tool zur Erkennung von Schwachstellen in 5G-Basisbandimplementierungen. Wurde verwendet, um 12 kritische Fehler in Chipsätzen von Samsung, MediaTek und Qualcomm zu finden.
### 2019-2023
- **[Privacy Attacks on 4G/5G Paging Protocols](https://assets.documentcloud.org/documents/5749002/4G-5G-paper-at-NDSS-2019.pdf)** — NDSS 2019
- **[New Vulnerabilities in 4G and 5G Cellular Access Network Protocols](https://dl.acm.org/doi/10.1145/3317549.3319728)** — WiSec 2019
Drei neue Angriffsklassen, die ungeschützte Gerätefähigkeitsinformationen ausnutzen: Identifikation, Bidding-down und Batterieentladung.
- **[New Privacy Threat on 3G, 4G, and Upcoming 5G AKA Protocols](https://arxiv.org/pdf/1905.07617.pdf)**
- **[BaseSAFE: Baseband SAnitized Fuzzing through Emulation](https://arxiv.org/pdf/2005.07797.pdf)**
- **[European 5G Security in the Wild](https://arxiv.org/pdf/2305.08635.pdf)** — 2023
---
## Ausrüstung und Hardware
### Forschungsequipment verwendet in „Over The Air Baseband Exploit"
| Komponente | Zweck | Link |
|-----------|---------|------|
| Ettus USRP B210 | Software Defined Radio | [Produktseite](https://www.ettus.com/all-products/ub210-kit/) |
| srsENB | 4G/5G-Basisstationssoftware | [GitHub](https://github.com/srsran/srsRAN/tree/master/srsenb) |
| Open5GS | 5G-Kernnetz | [GitHub](https://github.com/open5gs) |
| sysmo-usim-tool | SIM-Programmierung | [Projektseite](https://osmocom.org/projects/cellular-infrastructure/wiki/SysmoISIM-SJA2) |
| pysim | SIM-Analyse-Tool | [GitHub](https://github.com/osmocom/pysim) |
| CoIMS | VoLTE-Tests | [Play Store](https://play.google.com/store/apps/details?id=com.sherle.coims) |
| Docker Open5GS | Containerisiertes Kernnetz | [Tutorial](https://open5gs.org/open5gs/docs/tutorial/03-VoLTE-dockerized/) |
---
## Erkennung und Verteidigung
### Schutz vor Stingrays und IMSI-Catchern
- **[CellGuard](https://github.com/seemoo-lab/CellGuard)** — SEEMOO Lab, 2024
iOS-App, die schurkische Basisstationen durch Echtzeitanalyse von Basisbandpaketen erkennt. Integriert sich mit der Apple Cell Location Database zur Anomalieerkennung. [Website](https://cellguard.seemoo.tu-darmstadt.de/) — [TestFlight Beta](https://testflight.apple.com/join/HrsaoHM3)
### IMSI-Catcher-Erkennung und -Forschung
- **[SeaGlass: City-Wide IMSI-Catcher Detection](https://seaglass.cs.washington.edu/)** — UW
- **[SeaGlass Research Paper](https://seaglass-web.s3.amazonaws.com/SeaGlass___PETS_2017.pdf)** — PETS 2017
- **[Evaluating IMSI Catcher Detectors](http://www.cs.ox.ac.uk/files/9192/paper-final-woot-imsi.pdf)** — Oxford
- **[IMSI-Catcher Detector (Android)](https://github.com/CellularPrivacy/Android-IMSI-Catcher-Detector)**
### Sicherheitshinweise
- **[CERT-Warnung: Schwachstellen in VoLTE-Implementierungen](https://www.kb.cert.org/vuls/id/943167/)**
---
## Sicherheit von Cellular IoT und NB-IoT
- **[NB-IoT-Sicherheitsanalyse-Framework](https://arxiv.org/search/?query=NB-IoT+security)** — Narrowband IoT-Sicherheitsforschung
- **[Cat-M1/LTE-M-Angriffsvektoren](https://www.gsma.com/iot/mobile-iot-security/)** — GSMA IoT-Sicherheitsrichtlinien
- **[Überwachung von Schwachstellen in 5G-Kernnetzwerken mit eBPF](https://ieeexplore.ieee.org/document/10870553)** — IEEE Networking Letters 2025
---
## Satelliten-Mobilfunk-Integration
- **[Starshields for iOS: Satellite Communication Security](https://www.ndss-symposium.org/wp-content/uploads/2025-124-paper.pdf)** — NDSS 2025
- **[3GPP Non-Terrestrial Networks (NTN) Security](https://www.3gpp.org/specifications/specification-numbering)** — Offizielle 5G-Satellitenintegrationsspezifikationen
- **[Schwachstellen in der LEO-Satelliten-Mobilfunkkommunikation](https://arxiv.org/search/?query=satellite+cellular+security)** — Niedrige Erdumlaufbahn-Sicherheitsforschung
---
## Sicherheit privater 5G-Netzwerke
- **[O-RAN-Sicherheitsforschung](https://www.o-ran.org/specifications)** — Open RAN-Sicherheitsspezifikationen
- **[Leitfaden für Penetrationstests in privaten 5G-Netzwerken](https://www.nist.gov/cybersecurity)** — Tests für private Unternehmensnetzwerke
- **[Sicherheitsbewertung von Campus-5G-Netzwerken](https://csrc.nist.gov/)** — NIST-Leitfaden zur Sicherheit privater 5G-Netzwerke
---
## Network Slicing und Edge-Sicherheit- **[5G Network Slicing Attack Research](https://pmc.ncbi.nlm.nih.gov/articles/PMC12251764/)** — MDPI, Juli 2025
- **[Multi-Access Edge Computing (MEC) Vulnerabilities](https://www.etsi.org/technologies/multi-access-edge-computing)** — ETSI MEC-Sicherheitsspezifikationen
- **[Network Function Virtualization (NFV) Attacks](https://www.etsi.org/technologies/nfv)** — Sicherheit virtueller Netzwerkfunktionen
---
## Automotive und industrieller Mobilfunk
- **[V2X Security Research](https://www.its.dot.gov/research_areas/emerging_tech/htm/EmerTech_V2X.htm)** — Fahrzeug-zu-Alles-Kommunikation
- **[Cellular-V2X Attack Vectors](https://ieeexplore.ieee.org/search/searchresult.jsp?queryText=C-V2X+security)** — Automobiler Mobilfunksicherheit
- **[BMW Security Assessment using OpenBTS](https://keenlab.tencent.com/en/whitepapers/Experimental_Security_Assessment_of_BMW_Cars_by_KeenLab.pdf)** — Keen Lab / Tencent
---
## Forensik und Untersuchung
- **[XRY Mobile Forensics](https://msab.com/products/xry/)** — Kommerzielle Mobilfunk-Forensik-Plattform
- **[Cellebrite UFED](https://cellebrite.com/)** — Werkzeuge zur Extraktion mobiler Geräte
- **[NIST Mobile Forensics Guidelines](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-101r1.pdf)** — NIST SP 800-101r1
---
## Schwachstellenmeldung
- **[Android Security Bulletins](https://source.android.com/docs/security/bulletin)** — Regelmäßige Android-/Baseband-Patches
- **[Qualcomm Security Bulletins](https://www.qualcomm.com/company/product-security/bulletins)** — Snapdragon-Sicherheitsupdates
- **[Samsung Mobile Security](https://security.samsungmobile.com/)** — Galaxy-Sicherheitsforschungsprogramm
- **[Apple Security Research](https://security.apple.com/)** — iOS-/Baseband-Sicherheitsprogramm
---
## SIM-Sicherheit
- **[Rooting SIM Cards](https://media.blackhat.com/us-13/us-13-Nohl-Rooting-SIM-cards-Slides.pdf)** — Black Hat 2013, Karsten Nohl
- **[SIM Port Hack Case Study](https://medium.com/coinmonks/the-most-expensive-lesson-of-my-life-details-of-sim-port-hack-35de11517124)**
- **[Cloning 3G/4G SIM Cards With a PC and an Oscilloscope](https://www.blackhat.com/docs/us-15/materials/us-15-Yu-Cloning-3G-4G-SIM-Cards-With-A-PC-And-An-Oscilloscope-Lessons-Learned-In-Physical-Security-wp.pdf)** — Black Hat 2015
---
## SS7- und Telekommunikationsinfrastruktur
### SS7-Angriffsforschung
- **[Bypassing GSMA SS7 Recommendations](https://github.com/W00t3k/Awesome-Cellular-Hacking/blob/master/papers/ss7/Bypassing-GSMA-SS7-Kirill-Puzankov.pdf)** — Kirill Puzankov
- **[Attacking SS7 Networks](http://www.hackitoergosum.org/2010/HES2010-planglois-Attacking-SS7.pdf)** — HES 2010
- **[SS7: Locate. Track. Manipulate.](https://media.ccc.de/v/31c3_-_6249_-_en_-_saal_1_-_201412271715_-_ss7_locate_track_manipulate_-_tobias_engel)** — 31C3 2014, Tobias Engel; Live-Demonstration der netzübergreifenden Teilnehmerverfolgung
- **[SS7 Map](https://ss7map.p1sec.com/)** — P1 Security; Karte der SS7-Exposition bei globalen Betreibern
- **[Diameter Vulnerabilities Exposure](https://www.gsma.com/security/resources/fs-07-diameter-security/)** — GSMA FS.07; offizielle Diameter-Sicherheitsleitlinien für 4G-Roaming
- **[GSMA FS.11 SS7 Security](https://www.gsma.com/security/resources/fs-11-ss7-security/)** — GSMA-Basissicherheitsanforderungen für SS7-Netzwerke
### SS7/Diameter-Testwerkzeuge
- **[SigPloit](https://github.com/SigPloiter/SigPloit)** — Modulares Testframework für SS7, Diameter, GTP und SIP; deckt Standortverfolgung, Anruf-/SMS-Abfangen und DoS-Szenarien ab
- **[ss7map](https://ss7map.p1sec.com/)** — Automatisierte SS7-Netzwerktopologie- und Expositionskartierung
- **[SCTP scanner](https://github.com/adagilabs/sctp_scanner)** — Erkennt SCTP-basierte SS7-Endpunkte in IP-Netzwerken
---
## Überwachungstechnologie
### Stingray / IMSI-Catcher
- **[DHS Stingray Surveillance](https://www.wired.com/story/dcs-stingray-dhs-surveillance/)** — Wired
- **[Stingray Cost Analysis](https://www.vice.com/en_us/article/gv5k3x/heres-how-much-a-stingray-cell-phone-surveillance-tool-costs)** — Vice
- **[NYCLU Stingray Information](https://www.nyclu.org/en/stingrays)**
- **[EFF: Cell Site Simulators / IMSI Catchers](https://www.eff.org/pages/cell-site-simulatorsimsi-catchers)**
- **[WiFi IMSI Catcher](https://www.blackhat.com/docs/eu-16/materials/eu-16-OHanlon-WiFi-IMSI-Catcher.pdf)** — Black Hat Europe 2016
---
## Aktuelle CVEs und Updates
- **[NVD CVE Search](https://nvd.nist.gov/vuln/search)** — Suche nach mobilfunkbezogenen CVEs
- **[Google Project Zero](https://googleprojectzero.blogspot.com/)** — Laufende mobile Sicherheitsforschung
- **[Samsung Security Bulletins](https://security.samsungmobile.com/securityUpdate.smc)** — Regelmäßige Baseband-Updates
- **[SIMjacker Research](https://simjacker.com/)** — SIM-basierte Angriffsentwicklung
---
## Internationale Forschung
- **[ENISA 5G Reports](https://www.enisa.europa.eu/)** — EU 5G-Sicherheitsbewertungen
- **[KAIST SysSec Lab](https://syssec.kaist.ac.kr/)** — Führende Mobilfunksicherheitsforschungsgruppe (CITesting, LTEFuzz, LTESniffer)
- **[Japanese 5G Security Guidelines](https://www.nisc.go.jp/eng/)** — Japanische nationale Cybersicherheitsstrategie
---
## Schulung und Ausbildung
- **[SANS Mobile Security](https://www.sans.org/)** — Professionelle Mobilfunksicherheitskurse
- **[Offensive Security Mobile Testing](https://www.offensive-security.com/)** — Fortgeschrittenes mobiles Penetrationstesting
- **[OpenAirInterface Lab Setup](https://github.com/OpenAirInterface/openairinterface5g)** — Open-Source-5G-Laborumgebung
- **[GNU Radio / SDR University Courses](https://www.gnuradio.org/)** — SDR-Schulungsmaterialien
---
## Herstellerspezifische Forschung
- **[Ericsson Security Research](https://www.ericsson.com/en/security)**
- **[Nokia Bell Labs Security](https://www.bell-labs.com/)**
- **[Qualcomm Security Bulletins](https://www.qualcomm.com/company/product-security/bulletins)**
- **[MediaTek Product Security](https://www.mediatek.com/)**
---
## Roaming- und Interconnect-Sicherheit
- **[GRX/IPX Security Research](https://www.gsma.com/newsroom/)** — GSMA-Roaming-Sicherheit
- **[Diameter Protocol Security](https://tools.ietf.org/html/rfc6733)** — 4G/5G-Signalisierungssicherheit
- **[GSMA FS.19 IPX Security](https://www.gsma.com/security/resources/fs-19-ipe-security/)** — Sicherheitsanforderungen für IPX-Anbieter, die Roaming-Verkehr abwickeln
- **[Roaming Attacks via Diameter](https://www.p1sec.com/blog/diameter-roaming-attacks/)** — P1 Security Analyse der Diameter-basierten Roaming-Angriffsfläche
- **[GTP Vulnerabilities in 4G/5G Roaming](https://www.a1qa.com/blog/gtp-vulnerabilities-mobile-network-security/)** — GTP-C- und GTP-U-Angriffsfläche an der Roaming-Schnittstelle
- **[AdaptiveMobile SS7 Firewall Research](https://www.adaptivemobile.com/resources)** — Trägergestützte SS7/Diameter-Firewall-Umgehungstechniken
---
## Ressourcen
### Entwicklungs- und Analysetools
- **[RTL-SDR Community](https://www.rtl-sdr.com/)** — SDR-Ressourcen und Tutorials
- **[MCC-MNC Database](http://www.mcc-mnc.com/)** — Referenz für Mobilfunk-Länder-/Netzwerkcodes
- **[RFSec-ToolKit](https://github.com/cn0xroot/RFSec-ToolKit)** — RF-Sicherheitstestwerkzeuge
- **[cellularsecurity.org](https://cellularsecurity.org/)** — Community-Ressource für Mobilfunksicherheitsforschung
### Forschungssammlungen
- **[RF Security Documentation](https://rmusser.net/docs/Wireless.html#cn)**
- **[USENIX Security Papers](https://www.usenix.org/conferences)** — Sicherheitskonferenzbeiträge
- **[ACM Digital Library](https://dl.acm.org/)** — ACM-Forschungspapiere
- **[IEEE Xplore](https://ieeexplore.ieee.org/)** — IEEE-Forschungsdatenbank
### Rechtliches und Regulierung
- **[FCC Equipment Authorization Rules](https://www.fcc.gov/general/equipment-authorization-procedures)** — US-amerikanische Mobilfunkgerätevorschriften
- **[CISA 5G Security Guidance](https://www.cisa.gov/)** — US-Leitlinien für kritische Infrastrukturen
- **[NIST 5G Cybersecurity](https://www.nist.gov/cybersecurity)** — NIST-Mobilfunksicherheits-Frameworks
### Zusätzliche Lektüre
- **[Analyzing GSM Downlink with USRP](http://leetupload.com/blagosphere/2014/03/28/analyze-and-crack-gsm-downlink-with-a-usrp/)**
- **[AT&T Microcell Analysis](https://fail0verflow.com/blog/2012/microcell-fail/)**
- **[LTE Recon — DefCon 23](https://www.rtl-sdr.com/one-more-rtl-sdr-talk-from-defcon-23/)**
- **[LTE Security Guide — NIST SP 800-187](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-187.pdf)**
- **[LTE Pwnage: Core Network Elements](https://conference.hitb.org/hitbsecconf2013ams/materials/D1T2%20-%20Philippe%20Langlois%20-%20Hacking%20HLR%20HSS%20and%20MME%20Core%20Network%20Elements.pdf)** — HITB 2013
---
## Community
### Mailinglisten und Foren
- **[Osmocom Mailing Lists](https://lists.osmocom.org/mailman/listinfo)** — Aktive Entwickler- und Benutzerlisten für OpenBTS, OsmocomBB, srsRAN-Themen
- **[srsRAN Discussions](https://github.com/srsran/srsRAN_Project/discussions)** — GitHub-Diskussionen zum srsRAN-Projekt
- **[OpenAirInterface Forum](https://gitlab.eurecom.fr/oai/openairinterface5g/-/issues)** — OAI-Issue-Tracker und Community-Support
- **[Reddit r/RTLSDR](https://www.reddit.com/r/RTLSDR/)** — Aktive SDR-Community, die Mobilfunkscanning und -analyse abdeckt
- **[Reddit r/cellmapper](https://www.reddit.com/r/cellmapper/)** — Community zur Kartierung und Analyse von Mobilfunkmasten
### IRC und Chat
- **[Osmocom IRC](https://osmocom.org/projects/cellular-infrastructure/wiki/IRC)** — #osmocom auf libera.chat; Echtzeit-Support für Osmocom-Werkzeuge
- **[DEF CON RF Village](https://rfvillage.org/)** — Jährlicher RF-Hacking-Community-Track auf der DEF CON
### Empfehlenswerte Konferenzen
- **[DEF CON](https://defcon.org/)** — RF Village, Wireless Village und Mobilfunkvorträge im Hauptprogramm
- **[Black Hat USA/Europe](https://www.blackhat.com/)** — Regelmäßige Mobilfunk-/Baseband-Forschungspräsentationen
- **[WiSec](https://wisec.acm.org/)** — ACM-Konferenz zu Sicherheit und Privatsphäre in drahtlosen und mobilen Netzwerken
- **[IEEE S&P / CCS / USENIX Security](https://www.ieee-security.org/TC/SP/)** — Top akademische Veranstaltung für Mobilfunksicherheitspapiere
- **[HITB](https://conference.hitb.org/)** — Regelmäßige Telekommunikationssicherheitsvorträge
---
## Mitwirken
Forken Sie das Repo, fügen Sie Ressourcen mit Beschreibungen hinzu, überprüfen Sie, ob Links aktiv sind, und reichen Sie einen Pull-Request mit Kontext zum Hinzugefügten ein.
## Rechtlicher Hinweis
Dieses Repository dient ausschließlich Bildungs- und Forschungszwecken. Die Nutzer sind für die Einhaltung aller geltenden Gesetze und Vorschriften verantwortlich. Die Betreuer befürworten oder fördern keine illegalen Aktivitäten.
---
**Letzte Aktualisierung:** März 2026
**Betreuer:** [@W00t3k](https://github.com/W00t3k)
*Kaputte Links oder neue Ressourcen? Eröffnen Sie ein Issue oder reichen Sie einen PR ein.*
| Software | Beschreibung | Link |
|---|
| OpenBTS (2024 Reloaded) | Aktualisierte Linux-SDR-basierte GSM-Luftschnittstelle für moderne Systeme | GitHub |
| OpenBTS (Original) | Range-Networks-Implementierung | SourceForge |
| YateBTS | GSM/GPRS-Funkzugangsnetz-Implementierung | Website |
| srsRAN Project | Open-Source-5G-O-RAN-CU/DU-Softwaresuite | GitHub |
| srsRAN 4G | Open-Source-4G-Softwarefunksuite | GitHub |
| OpenAirInterface | Vollständiger 4G/5G-Protokollstapel | Website |
| Free5GC | Open-Source-5G-Kernnetz-Implementierung | GitHub |
| Kamailio | Open-Source-SIP-Server, verwendet in IMS/VoLTE-Laboren | Website |