Project

General

Profile

Actions

RebelSIM Scanner » History » Revision 2

« Previous | Revision 2/15 (diff) | Next »
laforge, 02/19/2016 10:48 PM
add page outline and picture of scanner


PageOutline = Rebel Simcard Scanner =

The Rebel Simcard folks are selling a relatively inexpensive device for generating SIM card traces as ''Simcard Scanner''.

Image(rebelsim-scanner.jpg)

You can find the full kit for less than USD 25 at the
[http://rebelsimcard.com/virtu/index.php?page=shop.product_details&flypage=flypage.tpl&product_id=194&category_id=339&option=com_virtuemart&Itemid=1 Rebelsimcard shop].

Hardware architecture

The Scanner has one small plug-in SIM sized slot and one full-size (ISO 7816-1) slot for your actual simcard.

It also has a small socket for a FPC cable that goes to a small PCB in the size of a plug-in sim.

You put the FPC-attached PCB into your phone (instead of the SIM card) and put the actual SIM inside the Scanner.

Furthermore, you connect it via the USB-B connector to your PC.

The I/O line of the SIM card is wired to the RxD pin (5) of the FT232RL on the Scanner. Unfortunately, the CLK
line is not connected, and neither can the device serve as a proxy between SIM and phone.

However, by using the FT232 synchronous bit-banging mode, it is possible to obtain samples of the I/O line, decoding
the actual T=0 (or with some SIM cards + phones T=1) protocol.

Files (2)
rebelsim-scanner.jpg View rebelsim-scanner.jpg 89 KB photograph of full RebelSIM scanner kit laforge, 11/09/2010 12:51 PM
rebelsimscan_pin.jpg View rebelsimscan_pin.jpg 113 KB pinout of the RebelSIM scanner tsaitgaist, 01/09/2011 11:42 AM

Updated by laforge about 8 years ago · 2 revisions

Add picture from clipboard (Maximum size: 48.8 MB)