💾 Archived View for gemini.spam.works › mirrors › textfiles › phreak › CELLULAR › mobfone.txt captured on 2022-06-12 at 17:29:29.
-=-=-=-=-=-=-
How to Get into the AT&T Network by Building Your own Mobile Phone. by THE RESEARCHER This article is presented for entertainment and academic study only. It is a violation of Federal laws to operate an unlicensed transmitter or make fraudulent telephone calls. It is not intended nor expected that anyone actually build the devices described. The article is simply a detailed and factual description of something that could be done. I wrote a file in collaboration with another telephone experimenter of high repute on IMTS (Improved Mobile Telephone Service) posted elsewhere on this board under the title of "Feature Article". This file was downloaded and posted on another BBS in the Midwest. From there it fell into the hands of the Chief of Security of Southwestern Bell. His words to the Sysop, who had been busted for Blue Boxing were, "A person with a knowledge of electronics could use the information in that file to build his own mobile telephone". I am going to explain in this article how you can build your own mobile phone. If you haven't figured it out already, you will soon see why the security man was concerned. This article presupposes that you have a working knowledge of two-way radio. If you don't possess this knowledge, get a copy of "The Radio Amateur's Handbook" (readily available from libraries and book stores) and study up on narrow band FM and 2-Meter transmitters. To get everything you will need in one file, I am reprinting the IMTS article here: Signaling Used in IMTS (Improved Mobile Telephone Service) Each mobile telephone channel consists of two frequencies; one for the land base station and one for the mobile phone. The base station uses two tones for signaling: Idle 2000 Hz Seize 1800 Hz The mobiles use three tones: Guard 2150 Hz Connect 1633 Hz Disconnect 1336 Hz The land base station marks the idle channel by placing the idle tone on it. All the mobiles search for the channel with the 2000 Hz idle tone and lock on to it. Each mobile phone is assigned a standard telephone number consisting of area code + 7 digits. When a land customer dials a mobile number, the idle tone (2000 Hz) changes to seize (1800 Hz). The number pulsed to the mobile phone contains 7 digits consisting of the area code and last 4 digits of the number. The digits are made up of 50 ms pulses of 2000 Hz separated by 50 ms of 1800 Hz. If there is a mismatch between the digits sent and the wired ID in the mobile, the mobile drops off and hunts for the idle channel. If the number matches, the mobile will send back an acknowledgement tone of 750 ms of guard (2150 Hz). The base station waits 3 to 4 seconds for this tone. If not received in that time, the calling party gets a recording. If the tone is received, the mobile phone will ring for up to 45 seconds. Ringing is composed of 1800 Hz and 2000 Hz shifting at 25 ms for two seconds then four seconds of 1800 Hz. When the mobile phone is picked up it sends a connect tone of 1633 Hz for 400 ms to tell the base station it has answered. When the mobile hangs up, it sends disconnect, which is 750 ms of 1336 Hz. When the base receives the disconnect tone, it will drop carrier for about 300 ms and go off. If it is the only available channel, it will return to idle. Now I will describe what happens when a call is originated by a mobile. When the mobile goes off hook, it sends 350 ms of guard (2150 Hz) followed by 50 ms of connect (1633 Hz). When the base station hears the connect tone, it removes the idle tone and stays quiet for about 250 ms. It then transmits 250 ms of seize (1800 Hz). The mobile then sends 190 ms of guard and starts transmitting the ID sequence at 20 pulses per second. The ID is the area code and last four digits of the mobile's number. The pulses are marked by 25 ms of connect (1633 Hz) followed by 25 ms of either silence or guard tone (2150 Hz). If the pulse is odd, it is followed by silence. If even, it is followed by guard tone. This is used for parity checking. The interdigit time is 190 ms and will be either silence or guard tone depending on whether the last pulse was odd or even. If the last pulse of the last digit in the ID is even it will be followed by 190 ms of guard tone. When a number is dialed from a mobile phone, 2150 Hz is sent continuously as soon a the dial goes off normal (when the dial is moved from its resting position). Dial pulses representing breaks are marked by 1633 Hz and are sent at 10 pulses per second. A pulse is 60 ms of 1633 Hz with 40 ms of 2150 Hz between pulses. The most popular mobile telephone channels are located in the VHF high band. More cities are equipped with these channels than any other band. They are listed below. Mobile Telephone Frequencies Channel Base Mobile ------- ---- ------ JL 152.51 157.77 YL 152.54 157.80 JP 152.57 157.83 YP 152.60 157.86 YJ 152.63 157.89 YK 152.66 157.92 JS 152.69 157.95 YS 152.72 157.98 YR 152.75 158.01 JK 152.78 158.04 JR 152.81 158.07