first commit
This commit is contained in:
Executable
+161
@@ -0,0 +1,161 @@
|
||||
My BLOG where i explain iridium (How i understand it).
|
||||
DATE: 30/10/2025 (DD:MM:YYYY)
|
||||
AUTHOR: halbg0tt
|
||||
PROCESS: [ W.I.P ]
|
||||
==============================
|
||||
|
||||
WHAT EVEN IS IRIDIUM?
|
||||
==============================
|
||||
Iridium is a constellation of many Satellites(66 Satellites) in a low earth orbit (LEO)
|
||||
and are primary used for telecommunication such as SMS or Voice Calls.
|
||||
The Benefit of using Iridium is the fact that: Iridium satellites are in a Low Earth Orbit
|
||||
and passing over both poles.
|
||||
It has a higher b/s than for example Inmarsat and the fact that inmarsat doesnt cover the both poles.
|
||||
There are many iridium satellites in orbit so you have basically at least 1-2 satellites that cover your area.
|
||||
You dont need a Cell tower near you because you satellite phone communicates directly with the satellite.
|
||||
So you can establish a connection between you and iridium basically everywhere on the whole earth.
|
||||
|
||||
WHAT CAN TX IRIDIUM?
|
||||
==============================
|
||||
Iridium has many of services and not only SMS/VC.
|
||||
Its transmit other services like for example ACARS or Pagers.
|
||||
ACARS is basically telecommunication for pilot's and groundstation over satellite.
|
||||
|
||||
DIAGRAM:
|
||||
[GROUND STATION] <-> [ IRIDIUM ] <-> [ AIR CRAFT ].
|
||||
|
||||
You can also connect to websites but it takes a longer to load since the connections are ~700 kbps
|
||||
But it should work to recv e.g. emails.
|
||||
|
||||
SOME TECHNICAL INFOS:
|
||||
==============================
|
||||
FREQ: 1616 - 1626 MHz.
|
||||
MODULATION: GMSK.
|
||||
ORBIT: Low-Earth Orbit (LEO) not like Inmarsat (GEO).
|
||||
SATELLITES: 66 currently
|
||||
SERVICES: SMS, VOICE CALLS, ACARS, PAGER, Short Burst Data (SBD) Ring Alert Channel (RAC)
|
||||
|
||||
[ Sources ]
|
||||
https://github.com/muccc/iridium-toolkit
|
||||
https://www.iridium.com/services/iridium-sbd/
|
||||
|
||||
|
||||
WHAT WE CAN DO WITH IRIDIUM?
|
||||
==============================
|
||||
We can (legality is another question) decode Data packages from the iridium
|
||||
by using for example the gr-iridium and iridium-toolkit
|
||||
|
||||
1.[ GR-IRIDUM ]
|
||||
=============================
|
||||
gr-iridium includes the iridium-extractor which receives(Actually the SDR) the data from The
|
||||
Satellite and demodulate it.
|
||||
There also configs for diff SDRs such as BladeRF, HackRF, LimeSDR or RTL SDR(i dont recommend it).
|
||||
|
||||
|
||||
CMD: [ iridium-extractor -D 4 /path/to/conf > ~/output.bits ]
|
||||
NOTE: the configs for various sdrs are located in ~/gr-iridium/examples/
|
||||
|
||||
The iridium-extractor write the recv content into the output.bits file
|
||||
Looks like this: p-1472473197 000001626.1625 1621698688 100% -59.2|-116.2|21.7 179 DL
|
||||
The Data what you can see here (lemme break it down for you): [Source is btw iridium-toolkit FORMAT.md]
|
||||
|
||||
CONTENT | MEANING
|
||||
=====================================================================================================
|
||||
- [ p-1472473197 ] | represent the time in UNIX-Format [ The prefix is always "p-{UNIX TIME}" ]
|
||||
- [ 000001626.1625 ] | Time in milliseconds inside the recording
|
||||
- [ 1621698688 ] | This is the Frequency in Hz
|
||||
- [ 100% ] | Basically the Signal Quality
|
||||
- [ -59.2|-116.2|21.7 ] | The Signal level in dBFS (decibels relative to full scale)
|
||||
- [ 179 ] | The length in symbols where 1 symbol represent 2 bits
|
||||
- [ DL ] | This is basically is this Uplink (UL) or Downlink (DL). So is it sended from satellite to ground(modem or phone) (Downlink)
|
||||
| or from ground(modem or phone) to satellite (Uplink)
|
||||
|
||||
2. [ IRIDIUM-TOOLKIT ]
|
||||
=============================
|
||||
You can now use the iridium-toolkit where you have various tools.
|
||||
the most important tool is iridium-parser.py. iridium-parser.py is a parser which convert it into useful data
|
||||
After that you COULD(legality questionable(not allowed like every other decoding))
|
||||
decode the data from the iridium satellite which includes ACARS, SMS, VOICE CALLS, PAGERS, BURSTS, RING ALERTs.
|
||||
|
||||
CMD: [ iridium-parser.py -p ~/output.bits]
|
||||
NOTE: Add the iridium-toolkit path to your $PATH. CMD: [ export PATH:"$PATH:/path/to/iridium-toolkit" ]
|
||||
It add the tools directly to your path while its needed for VOD/VOC decryption using tnt's AMBE Decoder ( An Audio Codec which is used by e.g. Inmarsat or Iridium).
|
||||
|
||||
2.2 [ VOICE DECODING ]
|
||||
=============================
|
||||
As i mentioned before you CAN decode Voice Calls which is going from the iridium satellite.
|
||||
The iridium satellite is using the AMBE Codec and we can use a AMBE Decoder
|
||||
to actually decode the voice calls and listen to it.
|
||||
|
||||
[ AMBE Decoder: https://gitea.osmocom.org/satellite/osmo-ir77 ]
|
||||
|
||||
Move it to the root of your iridium-toolkit. The play-iridium-ambe just need this Decoder
|
||||
to decode the voice transmission. If you use stats-voc.py then you can select captured
|
||||
voice frames and listen to it.
|
||||
|
||||
|
||||
2.3 [ REASSEMBLER.py ]
|
||||
=============================
|
||||
REASSEMBLER.py is used for "reconstruct" the data from the parsed output in a "higher level".
|
||||
it contains for example
|
||||
|
||||
args | meaning
|
||||
=====================================================================================================
|
||||
- ida | outputs L3 msgs in hex
|
||||
- idapp | literally ida but in pretty and a bit of parsing
|
||||
- lap | LAP is GSM-Compatible L3 messages which you can convert to GSMtap .pcap and it has
|
||||
| mostly the same like Call Ctrl [0x03], LUR, ID-R, ...[0x05], [0x09] and Non Call Related SS MSG [0x0b].
|
||||
| Iridium has also custom codes like call [0x06], SBD [0x76] and is currently unknown service [0x08].
|
||||
- sbd | short burst data msgs
|
||||
- page | ring alert channel
|
||||
- msg | pager messages (confusing)
|
||||
- burst | "Global Data Burst" assembled from pager messages
|
||||
- livemap | create/update a sats.json for interactive satellite display
|
||||
- satmap | it tries to map the iridium satellites IDs to "NORAD-Approved Names"
|
||||
- acars | parsed ACARS SBD msgs
|
||||
|
||||
|
||||
2.3 [ MODE: IDA ]
|
||||
=============================
|
||||
IDA is output the messages in hex from the Um Layer 3.
|
||||
IDAPP does the same but with parsing and pretty output/printing.
|
||||
You will see pretty much the same content as in the pcap.
|
||||
|
||||
CMD: [ reassembler.py -m idapp <your parsed file> ]
|
||||
|
||||
2.4 [ MODE: LAP ]
|
||||
=============================
|
||||
Now we take a look on LAP.
|
||||
LAP are basically GSM-Compatible L3 Messages and from the behavior the same.
|
||||
There the same Mobility MGMT MSGs (MM) such as Location Update Request(LUR), Identity Request(ID-R), TMSI Realloc etc...
|
||||
My favourite and interesting part is the proto Desc 0x09 (as mentioned earlier SMS).
|
||||
In this Data Packet you will not only see the SMS or so... No, will also see:
|
||||
|
||||
Few interesting items from an imaginary packet:
|
||||
- Sender TEL Number : [49]162xxxxxxx [ For me in Germany would it be the country code +49 ]
|
||||
- Receiver TEL Number: [8816]xxxxxxx
|
||||
NOTE: The Sender or Receiver either 8816(Iridium code) or a natural phone number [as example 49162123456 in germany]
|
||||
- The Timestamp of the message. For example [04/20/1971, 04:20 P.M.].
|
||||
- The actual content of the message. Like text ("Hello, how are you today?") or unicode (such as a emoji).
|
||||
|
||||
CMD: [ reassembler.py -i <output>.parsed -m lap -o <output>.pcap ]
|
||||
|
||||
2.5 [ MODE: SBD ]
|
||||
=============================
|
||||
Short Burst Data (SBD) is basically a quick and short data transmission in limited size of 370 Byteand its used for telemetry and
|
||||
data exchanges between origin and destination e.g. of Oil rigs or pipelines.
|
||||
|
||||
|
||||
2.6 [ MODE: ACARS ]
|
||||
=============================
|
||||
ACARS is Datalink between ground station/or satellite and the aircraft.
|
||||
ACARS is transmitting telemetry or status of the aircraft or process of e.g. boarding or refueling.
|
||||
|
||||
|
||||
Hardware i use (in an imaginary scenario):
|
||||
- LimeSDR USB (Type-A) / RSP1a.
|
||||
- RHCP Antenna from RTL-SDR Blog.
|
||||
- Just Linux (Debian)
|
||||
|
||||
|
||||
DISCLAIMER: Im not responsible for any law breaks. This is education only. Do not decode any data that are not for you.
|
||||
Reference in New Issue
Block a user