About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Technology
Phreak
Boxes, Old and New
Bugs and Taps
Cellular Phones
Introduction to Telecommunications
PBX's and Switches
Payphones
Phone Phun
VMB's, Pagers, E-Mail, and S&F Systems
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it

Cellular stuff


NOTICE: TO ALL CONCERNED Certain text files and messages contained on this site deal with activities and devices which would be in violation of various Federal, State, and local laws if actually carried out or constructed. The webmasters of this site do not advocate the breaking of any law. Our text files and message bases are for informational purposes only. We recommend that you contact your local law enforcement officials before undertaking any project based upon any information obtained from this or any other web site. We do not guarantee that any of the information contained on this system is correct, workable, or factual. We are not responsible for, nor do we assume any liability for, damages resulting from the use of any information on this site.
CELULAR.TXT BINA # ?????? ???? 6





How to Get into the At&T Network
by Building Your own MobiePoe.

I am going to explain in this article how you can build your own
mobile phone. If yo hve'tfigured it out already, you will soon see why
the security man was concerned.
This aricl prsuposes that you have a working knowledge of two-way
radio. If you don't possess this knoledg, ge a cpy of "The Radio
Amateur's Handbook" (readily available from libraries and book stors) an
stud up o narrow band Fm and 2-Meter transmitters.
To get everything you will need n one ile, Iam repinting the Imts
article here:

Signaling Used in Imts
(Improved Mobile Telephon Servic)

Each moile telephone channel consists of two frequencies; one for
the land base sttion andone for he mobie phone. The base station uses two
tones for signaling:

Idle 2000 Hz
Size 1800Hz

The mbiles usethree tones:

Guard 2150 Hz
Connect 1633 Hz
Disconnect 1336Hz

Te land bas station mrks the idle channel by placing the idle tone
on it. All the mobils search fo the channl with the 000 Hz idle tone and
lock on to it.
Each mobile phone is asigned a stadard telephoe number conisting of
area code + 7 digits. When a land customer dials amobile number the
idle ton (2000 Hz) chnges to seize (1800 Hz). The number pulsed to the
mobile hone contains digits consiting of the ara code and last 4
digits of the number. The digits are made up of 50 m pulses of 2000Hz
separated by50 ms of 1800 Hz.
If there is a mismatch betwee the digits sen and the wired I in the
mobile, he mobile drops off and hunts for the idle channl. If the number
atches, the mobil will send back a acknowledgement tone of 750 ms
of guard (215 Hz). The base staion waits 3 to 4 econds for this toe. If
not received in that time, the callin party gets a recoding. If the
tone i received, the mobie phone will ring for up to 45 seconds.Ringing
is composed f 1800 Hz and 2000 H shifting at 25 ms or two seconds then
four seconds of 100 Hz. When the mobie phone is picked up t sends a
connect ton of 1633 Hz for 400 ms to tell th base station it has aswered.
When the mobil hangs up, it sends dsconnect, which is 750 ms of 136 Hz.
When the base recives the disconnect toe, it will drop carrierfor about
300 ms and go off.If it is the only availble channel, it will retrn to
idle.
Now I wll describe what happens when a call is originatedby a mobile.
When the moble goes off hook, it sens 350 ms of guard (215 Hz)
followed by 50 ms of onnect (1633 Hz). When th base station hears the
conect tone, it removs the idle tone and stays uiet for about 250 ms.
It ten transmits 250 ms of seiz (1800 Hz). Themobile then sends 190 ms
of uard and starts transmittingthe Id sequence at 20 pulse per second.
he Id is the area code and lat four digits of the mobile' number. The
pulses are marke by 25 ms f connect (1633 Hz) followed y 25 ms of either
silence or gard tone (2150 Hz). If the puse is od, it is followed by
silence. I even, it is followed by guardtone. This is used for parity
ceckig. The interdigit time is 190 m and will be either silence or gard
tone depending on whether th ast pulse was odd or even. If th last
pulse of the last digit in he Id is even it will be followdby 190 ms of
guard tone.
Whn a number is dialed from a mobil phone, 2150 Hz is sent
continousl as soon a the dial goes off ormal (when the dial is moved from
ts resting position). Dial plses rpresenting breaks are markedby 1633
Hz and are sent at 10 pulsesper second. A pulse is 60ms of 1633Hz
with 40 ms of 2150 Hz btween pulses.
The most popular mbile telephone channelsare located i the Vhf high
band. Morecities are equipped with these channes than any other band.They are listed elow.

Mobile Telephon Frequencies

Channel Base Mobie
------- ---- ------
Jl 152.51 157.77
Y 152.54 157.80
Jp 152.5 157.83
Yp 152.60 157.86
j 152.63 57.89
Yk 152.66 157.92
Js 152.69 15795
Ys 152.72 17.98
Yr 52.75 158.01
Jk 152.78 158.0
Jr 15.81 158.07


This isa list of the omponents you will need to build your own obile
phone:
1. Cassette Tape Recorder.
2. adio Scanner(Like those used to receive police calls).
. Mobile pone dialer (build your own).
4. Lw Power Trnsmitter (Modified 2-Meter transmitter 1 - 5watts).
How to Build a Mobile Phone Dialer

Builda Wien-Bridge oscillator. These are commonlyused i red boxes.
If you don't have a red box chematc, look up Wien-Bridge in an electronics
textbok. here you would normally connect a frequenc adjstment pot, use
two multi-turn pots connected in sries. Power for the oscillator will
be supplie b a 9 volt battery.
Obtain a rotary dial of t type used on rotary telephones. The dial
will he four wires coming out of it; two white, one ble and one green.
The two white wires make a connecin when the dial is off normal (moved from
itsresing position). Connect the two white wires in srie with one of
the leads from the 9 volt battry. The oscillator will be running only
when the dil is oved off normal. It works like this: Dil is moed off
normal. Circuit is completed between ocillato and battery. Dial goes back
to restig positio. Circuit is opened.
The blue and green ires go t a normally closed contact in thedial.
This ontact opens once for each pulse in a diale digit. Forexample it
opens three times fo the digit "3. Connect these two wires (blue & green)
cross one of he pots in the oscillator. ith the dial inits
resting position, adjust the other pot for a frequenc of 2150 Hz (Guard
tone).Move the dial untl the contact opens and adjust the pot wth
the blue and geen wires going to it for a frequency of 633 Hz (Connect
tone).
When the dia is moved off norml, power will be aplied to the
oscillato, and it will begin running at 2150 Hz When the dial is relased
the short aross the second pot wil be removed each time the contacts opn
for a dial pulse. Durng these puls times the frequency wil shift down to
1633 Hz. When the dialgets back to its restingposition, ower will be
removed from te oscillator. This will exactly dupicate the dial pulsing
of amobile elephone.
Te Transmitter

Antennae used b mobile phone base stations re lcated on high
towers. This allos line-of-sight transmission to ad from the mobiles.
If you are ihin a few miles of a base statio very little power is
needed to etablish contact. 1 to 5 watts sold be completely adequate.
The les power you use, the less your hances of getting caught. More n ths
later.
2-Meter transmittes, used in amateur radio, operte in the range of
144 to 148 hz. Wit a change of crystals and a litle retuning, you
have your trnsmitter.

How to use Your Hoe brew Moble Telephone

With your canner, locate the base staton frequency which currentlyhas the idle one on it. Switch to the moble frequency on that same chnnel
and monitor it with th cassette recorer running continuously. Wht
you want is a clean recoring of a mobile unit broacasting its Id
sequnce. You also want a recordng of the disconnect tonewhen he hangs
up. Once yo have these, rewind th tape to the start of thesequence. Now
you are reay to make a call.

The pocedure For Placing a Cal

1. Set your scanner to he base station frequeny with the idle tone
an leave it there. Monitor wit earphones to avoid audo feedback
through the ransmitter.

2. Set th transmitter to the correspondng mobile frequency. Tun it
on and leave it o.

3. Play the taped d sequence.

4. Use your dial pulsr to call the desirednumber. If all has goe well,
you will hea your dial pulses in the earphones. ou can use this metho to
call one of the pecial 800 numbers and whistle off with 2600 Hz; then Mf
toanywhere in the worl. This technique wll reduce your visbility
on the bill for the Id you are using

5. When you are rady to hang up, ply the disconnecttone and switch off the
transmitter.

A Few Noes About Your Own ecurity

Youshould use only s much transmitter power as necessary to
maintai a reliable contat. If you do muh of this kind f experimenting,
the Fcc is going to be after you wih direction fining equipment. hese use
direcional antennae and a process of triangulation to locat illegal
transmtters. If you eep your powe down, stay mobile, and avoid
establishing a pattern of clling at the ame time ever day, it wil be
nearly impossible to track you down.



Press [Return] tocontinue...
 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
If you have any questions about this, please check out our Copyright Policy.

 

totse.com certificate signatures
 
 
About | Advertise | Bad Ideas | Community | Contact Us | Copyright Policy | Drugs | Ego | Erotica
FAQ | Fringe | Link to totse.com | Search | Society | Submissions | Technology
Hot Topics
Php
Withstanding an EMP
Good computer destroyer?
Wow, I never thought the navy would be so obvious.
Alternatives Internets to HTTP
Anti-Virus
a way to monitor someones AIM conversation
VERY simple question: browser history
 
Sponsored Links
 
Ads presented by the
AdBrite Ad Network

 

TSHIRT HELL T-SHIRTS