Resume
The quieter you become the most you are able to hear
đ°ïž Ă la une â GSM de A Ă Z, sans matĂ©riel
Deux projets open-source qui, ensemble, montent un rĂ©seau GSM complet et Ă©mulent le baseband d'un vrai tĂ©lĂ©phone â puis un cours qui dĂ©roule chaque Ă©tape.
-
qemu-calypsoâ Ă©mule le baseband TI Calypso (Motorola C1xx / Compal E88) dans QEMU : un ARM exĂ©cute le firmware osmocom-bb non patchĂ© et un DSP TMS320C54x exĂ©cute la vraie mask-ROM TI, reliĂ©s par la mailbox0xFFD00000. -
osmo_egprsâ un rĂ©seau GSM multi-opĂ©rateur interconnectĂ© en SS7/IP, entiĂšrement conteneurisĂ© (« un DHCP pour SS7 »).
Point dâavancement (2026-08-24). En mode shunt_legit, la pile GSM tourne de bout en bout â camp, Location Update, auth COMP128v1, A5/1, SMS et appel voix avec audio. En mode native, le Frequency Burst est dĂ©sormais acquis par le vrai DSP (437 transitions mesurĂ©es, sans injection) ; le mur suivant est le dĂ©codage du SCH.
đ Cours associĂ©s : Lab GSM multi-opĂ©rateur · Ămulation du baseband Calypso · GSM Ă©tape par Ă©tape · Casser A5/1
Profile information
| name | Bastien Baranoff |
| tagline | Cybersecurity in Software Defined Radio |
| bastienbaranoff@gmail.com | |
| timezone | Paris/France |
| website | https://bbaranoff.github.io/ |
| Bastien Baranoff | |
| github | bbaranoff |
| â@bastienbaranoff' |
Languages:
| French: Native | English: Professional |
Career Profile:
Physics -> Electronics -> Computer -> Embedded -> Software Defined Radio
Education:
| Â | Â |
| degree | MSc in Electronics Computers |
| university | University of Perpignan via Domitia |
| time | 2011 - 2013 |
| Â | Â |
| degree | Licence In Computer Science |
| university | University of Perpignan via Domitia |
| time | 2020-2021 |
Experience
- CyberSecurity Research
- time: 2024
- company: Penthertz
- Former
- time: 2024
- company: University of Perpignan via Domitia
- Developper
- time: 2021
- company: PROMES-CNRS
- details: LoRa(WAN) connection testing
- Developper
- time: 2020
- company: Tata Advanced System Limited
- details: Mobile Security Assesment
- Former
- time: 2017
- company: Lycée Déodat de Séverac
- Electrical Engenering
- time: 2013
- company: PROMES-CNRS
- details: Junior Research
Developer
Junior Researcher
CyberSecurity Analyst
Former
Former (Education Nationale)
Quoted :
Second Time :
First TIme :
Cited in Academic Research
My open-source work on LTE redirection attacks is referenced in peer-reviewed academic research.
M. Gronau, A. Bysewski, K. KobierzyĆski, A. Trzebiatowski, J. Filipiak, "Evaluation of 4G-LTE security and realization of a test stand for redirection attack", GdaĆsk University of Technology (Politechnika GdaĆska), Department of Radio Communication Systems and Networks, 2021.
The team built a 4G-LTE simulation test stand and used my published Docker image and tooling to carry out the LTE redirection attack, citing my GitHub as reference [29].
Project page â supervised by Dr. Eng. Piotr Rajchowski.
Community & Technical Write-ups
- Osmocom Forum â Porting QEMU to Layer1 highram ELF in a no-RF Osmocom Network-in-the-Box environment â running the Calypso Layer 1 firmware under QEMU emulation, with no RF hardware, inside an Osmocom network-in-the-box. Related work: qemu-calypso.
Stuff
Projects:
Curious about A5/1 in the 2010s I searched around the internet and found a lot of interesting resources
Open-Source Contributions
A selection of my public repositories, grouped by field. Full list on github.com/bbaranoff.
đĄ LTE / 5G â Downgrade & Redirection Attacks
Forcing a target UE from a modern network down to an insecure GSM/EDGE layer.
| Project | â | Description |
|---|---|---|
| LTE-Redirection_Attack | 33 | Force a target victim onto an unsafe network (the tool cited in academic research above). |
| openlte | 18 | OpenLTE stack used as a base for redirection research. |
| srslte_to_gsm | 11 | Downgrade path from srsLTE-based LTE to GSM. |
| openLTE2GSM | 8 | LTE â GSM redirection workflow. |
| redir5Gted2Gsm | 7 | Redirect from 5G-NSA down to GSM. |
| redirect0r | 4 | Dockerized redirection attack LTE/5G-NSA â EDGE/GSM. |
| NSA_LTE_redirect_to_EDGE | 4 | The long-awaited full 5G-NSA â EDGE workflow. |
| LTE-Cell-ScannerBladeRF2 | 3 | LTE cell scanner for BladeRF 2.0. |
đ¶ 2G / GSM â Osmocom, BTS & IMSI Catchers
Standing up rogue base stations and Calypso-based mobile stations.
| Project | â | Description |
|---|---|---|
| telco_install_sh | 19 | One-shot install scripts for a full 2G network-in-the-box. |
| srsran_4G_RTE | 11 | IMSI catcher, reloaded. |
| osmo-GUI | 9 | Graphical front-end for Osmocom and osmocon scripting. |
| osmocombb-ansible | 7 | Ansible automation for OsmocomBB / CalypsoBTS. |
| HeArTbReAkEr | 6 | Exploration of subscriber impersonation with Osmocom. |
| calypsogprs | 5 | GPRS support files for CalypsoBTS. |
| osmo_egprs | 5 | EGPRS on Osmocom. |
| OpBTS-LimeMini | 4 | OpenBTS on a LimeSDR Mini. |
| qemu-calypso | 4 | QEMU emulation of the Calypso baseband ("Calypso Machine" test). |
đ Cryptography & Cracking
| Project | â | Description |
|---|---|---|
| A53 | â | CUDA-accelerated A5/3 cracker. |
| a51_tools | â | Tooling around A5/1 rainbow tables. |
| dst80 / dst80_reversing | 3 | Reversing the DST80 automotive keyless cipher. |
| tea1-cracker | â | Experiments against the TETRA TEA1 cipher. |
đ Vulnerability Research & Exploits
| Project | â | Description |
|---|---|---|
| CVE-2022-0847 | 50 | "Dirty Pipe" Linux local privilege escalation PoC. |
| CVE-2023-4863 | 6 | libwebp heap buffer overflow PoC. |
| brute_ubuntu_lpe | â | Ubuntu local-privilege-escalation brute forcing. |
âïž Signaling & Fraud
| Project | â | Description |
|---|---|---|
| callerid_spoofing | 10 | Methodology to spoof caller ID. |
| 2RFA | 1 | Proof of concept for catching 2FA codes over RF. |
đ°ïž SDR, IoT & Misc
| Project | â | Description |
|---|---|---|
| software-defined-radio | 1 | General SDR utilities. |
| ttn-gps | 2 | LoRaWAN / The Things Network GPS tracker. |
| llm-bridge | â | Bridge between telco tooling and a local LLM (Ollama). |
| telco_story | 3 | A written story of the telecommunications journey. |







