So let's start with some general theory
Almost every Sim has directories like:
RD (Root Directory)
MF (Master File)DF-tel (Directory- Telcom)DF-gsm (Directory-GSM)DF-3g (Directory-3G)
EF (Elementary File)More Spesific tha location of DF(tel/gsm/3g) are subsets of MF and MF is subset of RD
EF is the Directory that info of SIM kept, like: Phone-contacts, Sended sms etc.
Every SIM has uniqe : IMSI-TMSI / LAI / BCCH IMSI-TMSI : permanent-temporary customer identity network
LAI: Location of customer
BCCH: control channel
and you can access on these only if you know KI and KC
[Pin also need to access some directories]
Ki: key [password for encryption]
KC: session key (Key for the encryption - not stable/ can change)
Encryption that GSM - 3G networks use: A5/2 > A5/1 > A5/3 > A5/0 [A3, A8]
*On AuC-(Authentication Center) is saved the Ki*
A5/2 most powerful than: A5/1 >A5/3 > A5/0
A5/1 most powerful than: A5/3 A5/0 - actually is means no encryption
a) to testify the network provider the phone compare the Ki that the phone has with the one on their system to see if it is the same [to do that they use A3 algorithm]
b) with Ki data & A8
algorithm the Kc is created.
c) with the Kc now ready the A5/x encryption (=
algorithm ) encrypts the singal for a call Or sms Or internet (3G).
NOW about the "free" 3G internet. There are 2 (maybe 3 ) possible ways I've thought.
*That doesn't means that they will work :p BUT they have great possibilities to work! *
1. Hijack the:
IMSI-TMSI / LAI / BCCH and Ki from an other User to get "free" access on the net with him/her paying the bill :p ( Too risky, but it can work)
2. by bypassing the security network and get free access ( working on that)
3. By exloiting the free 0.facebook access and gain access to other sites without paying ( Needs advanced knowlegde to Mobile networks
Because it takes lot's of time to write all these and also i do not have complete my thoughts i will continue to P2 (part 2)
A photo i found that explains how Directories of sim are: (don't have 3G network)
P.S.: Sorry for my english