Resume

Tip

The quieter you become the most you are able to hear

đŸ›°ïž À la une — GSM de A Ă  Z, sans matĂ©riel

Deux projets open-source qui, ensemble, montent un rĂ©seau GSM complet et Ă©mulent le baseband d'un vrai tĂ©lĂ©phone — puis un cours qui dĂ©roule chaque Ă©tape.

  • qemu-calypso — Ă©mule le baseband TI Calypso (Motorola C1xx / Compal E88) dans QEMU : un ARM exĂ©cute le firmware osmocom-bb non patchĂ© et un DSP TMS320C54x exĂ©cute la vraie mask-ROM TI, reliĂ©s par la mailbox 0xFFD00000.
  • osmo_egprs — un rĂ©seau GSM multi-opĂ©rateur interconnectĂ© en SS7/IP, entiĂšrement conteneurisĂ© (« un DHCP pour SS7 »).
Danger

Point d’avancement (2026-08-24). En mode shunt_legit, la pile GSM tourne de bout en bout — camp, Location Update, auth COMP128v1, A5/1, SMS et appel voix avec audio. En mode native, le Frequency Burst est dĂ©sormais acquis par le vrai DSP (437 transitions mesurĂ©es, sans injection) ; le mur suivant est le dĂ©codage du SCH.

👉 Cours associĂ©s : Lab GSM multi-opĂ©rateur · Émulation du baseband Calypso · GSM Ă©tape par Ă©tape · Casser A5/1

Profile information

name Bastien Baranoff
tagline Cybersecurity in Software Defined Radio
email bastienbaranoff@gmail.com
timezone Paris/France
website https://bbaranoff.github.io/
linkedin Bastien Baranoff
github bbaranoff
twitter ‘@bastienbaranoff'

Languages:

Note
French: Native English: Professional

Career Profile:

Warning

Physics -> Electronics -> Computer -> Embedded -> Software Defined Radio

Education:

   
degree MSc in Electronics Computers
university University of Perpignan via Domitia
time 2011 - 2013
   
degree Licence In Computer Science
university University of Perpignan via Domitia
time 2020-2021

Experience

  • CyberSecurity Research
    • time: 2024
    • company: Penthertz
  • Former
    • time: 2024
    • company: University of Perpignan via Domitia
  • Developper
    • time: 2021
    • company: PROMES-CNRS
    • details: LoRa(WAN) connection testing
  • Developper
    • time: 2020
    • company: Tata Advanced System Limited
    • details: Mobile Security Assesment
  • Former
    • time: 2017
    • company: LycĂ©e DĂ©odat de SĂ©verac
  • Electrical Engenering
    • time: 2013
    • company: PROMES-CNRS
    • details: Junior Research

Developer

drawing0

Junior Researcher

drawing1

CyberSecurity Analyst

drawing2

Former

Former (Education Nationale)

drawing2

Quoted :

Second Time :

First TIme :

image

Cited in Academic Research

Note

My open-source work on LTE redirection attacks is referenced in peer-reviewed academic research.

M. Gronau, A. Bysewski, K. KobierzyƄski, A. Trzebiatowski, J. Filipiak, "Evaluation of 4G-LTE security and realization of a test stand for redirection attack", GdaƄsk University of Technology (Politechnika GdaƄska), Department of Radio Communication Systems and Networks, 2021.

The team built a 4G-LTE simulation test stand and used my published Docker image and tooling to carry out the LTE redirection attack, citing my GitHub as reference [29].

Project page — supervised by Dr. Eng. Piotr Rajchowski.

Community & Technical Write-ups

Stuff

Projects:

Danger

Curious about A5/1 in the 2010s I searched around the internet and found a lot of interesting resources

Open-Source Contributions

Tip

A selection of my public repositories, grouped by field. Full list on github.com/bbaranoff.

📡 LTE / 5G — Downgrade & Redirection Attacks

Forcing a target UE from a modern network down to an insecure GSM/EDGE layer.

Project ★ Description
LTE-Redirection_Attack 33 Force a target victim onto an unsafe network (the tool cited in academic research above).
openlte 18 OpenLTE stack used as a base for redirection research.
srslte_to_gsm 11 Downgrade path from srsLTE-based LTE to GSM.
openLTE2GSM 8 LTE → GSM redirection workflow.
redir5Gted2Gsm 7 Redirect from 5G-NSA down to GSM.
redirect0r 4 Dockerized redirection attack LTE/5G-NSA → EDGE/GSM.
NSA_LTE_redirect_to_EDGE 4 The long-awaited full 5G-NSA → EDGE workflow.
LTE-Cell-ScannerBladeRF2 3 LTE cell scanner for BladeRF 2.0.

đŸ“¶ 2G / GSM — Osmocom, BTS & IMSI Catchers

Standing up rogue base stations and Calypso-based mobile stations.

Project ★ Description
telco_install_sh 19 One-shot install scripts for a full 2G network-in-the-box.
srsran_4G_RTE 11 IMSI catcher, reloaded.
osmo-GUI 9 Graphical front-end for Osmocom and osmocon scripting.
osmocombb-ansible 7 Ansible automation for OsmocomBB / CalypsoBTS.
HeArTbReAkEr 6 Exploration of subscriber impersonation with Osmocom.
calypsogprs 5 GPRS support files for CalypsoBTS.
osmo_egprs 5 EGPRS on Osmocom.
OpBTS-LimeMini 4 OpenBTS on a LimeSDR Mini.
qemu-calypso 4 QEMU emulation of the Calypso baseband ("Calypso Machine" test).

🔐 Cryptography & Cracking

Project ★ Description
A53 — CUDA-accelerated A5/3 cracker.
a51_tools — Tooling around A5/1 rainbow tables.
dst80 / dst80_reversing 3 Reversing the DST80 automotive keyless cipher.
tea1-cracker — Experiments against the TETRA TEA1 cipher.

🐞 Vulnerability Research & Exploits

Project ★ Description
CVE-2022-0847 50 "Dirty Pipe" Linux local privilege escalation PoC.
CVE-2023-4863 6 libwebp heap buffer overflow PoC.
brute_ubuntu_lpe — Ubuntu local-privilege-escalation brute forcing.

☎ Signaling & Fraud

Project ★ Description
callerid_spoofing 10 Methodology to spoof caller ID.
2RFA 1 Proof of concept for catching 2FA codes over RF.

đŸ›°ïž SDR, IoT & Misc

Project ★ Description
software-defined-radio 1 General SDR utilities.
ttn-gps 2 LoRaWAN / The Things Network GPS tracker.
llm-bridge — Bridge between telco tooling and a local LLM (Ollama).
telco_story 3 A written story of the telecommunications journey.