[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/g/ - Technology


Thread archived.
You cannot reply anymore.


[Advertise on 4chan]


File: sorrynotmyphoto.jpg (38 KB, 339x294)
38 KB JPG
Hey guys,
Been messing with DMR for a while, mostly MOTOTRBO gear. Recently got interested in the Belarusian police network – saw some patrol units carrying DP4600e (probably the older ones), but I've also heard they're slowly migrating to R7 series. I managed to get a peek at one radio – channels were labeled like "Moscow District PD", "Duty Unit", etc. No signs of RAS or trunking info on the display, but the owner claimed all channels are AES-256 encrypted.
I've already done some spectrum sniffing with SDR + DMRDecode in the 430–450 MHz range (Minsk area). I can see the usual DMR sync frames, but the voice payloads are encrypted – no Basic Privacy, definitely Enhanced Privacy (AES). Also tried to capture OTAR packets during rekey events, but no luck so far.
A couple of specific questions for those who've dug deeper:

Firmware vulnerabilities: I've read about some older DP series bootloader flaws (e.g., USB DFU patching to dump flash). Does anyone know if the DP4600e (or later R7) still has that exploit, or did they patch it?

Key extraction: If you can't OTAR, is there any way to retrieve the KEK (Key Encryption Key) from the radio's EEPROM without desoldering the CPU? I've seen some Russian forums mention JTAG dumping, but the details were vague.

Network architecture: Is the whole country using a single MOTOTRBO Capacity Plus / Linked Capacity Plus system, or does each region have its own standalone repeaters? That would affect how often keys rotate.

RAS enabled? I couldn't detect any RAS handshake in the control frames – maybe they don't use it? If RAS is off, then spoofing a legitimate radio ID might be easier.
I'm not asking for handouts – just looking for technical insights or pointers to relevant research (papers, toolchains, etc.). If anyone has successfully decoded traffic from this network, I'd appreciate a nudge in the right direction.
Cheers.
>>
>>109400232
>is there any way to retrieve the KEK (Key Encryption Key)
Yes. I've had extensive experience with these models in the past and I've been given permission from my supervisor to post this:
So basically in order to retrieve the KEK you need to decrypt the NIGGER (Network Internet General Generated Encryption Record) using a symmetric AES-128 key, which, while "weak" by many standards, can only practically be achieved by stealing a working CUNT (central universal NIGGER transponder) from a police car in the oblast the police radio was last used. That's basically the only hard part. After you use the CUNT key to decrypt the NIGGER, it will contain a layered form of SHIT (SHA-based Heuristic Internal Technology) which can be XORed with the plaintext in order to obtain the KEK.
Hope this helps.
>>
would've expected it to be TETRA though anything tetraburst should be patched by now
>>
>>109400232
JTAG is a basic bitch and you better do that first. the fuck do you mean "vague", nigger.
stupid frogposter



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.