Hi
I'm looking for software to program SIM cards. I'm using Linux and Windows. Can you recommend any?
Thanks
what are you trying to achieve?
I would like to duplicate a SIM card I'm using in case I loose my original one.
What network are you on?
Why?
Just to be clear on your intention. You want to clone a SIM card in its totality including the key number and NAC details to have 2 SIM cards with the same access details?
Or,
You for some reason are still saving some data or contacts to a SIM that you wish to have an accessible back up of?
Because eSIM qr code may be a solution save you faffing about.
This is entirely impossible.
You can back up contacts/texts stored on a SIM, but this is basically obsolete now. You cannot make a working copy of a card.
The ability to do this stopped about 20 years ago. You used to be able to brute force it but the encryption changed and the result is that you will burn out the flash well before you find the key.
I bought a smart card reader on Amazon. Included in the package were blank sim cards for programming. Why would anyone need these?
They're not SIM card. They're for smart card access control systems, a now quite obsolete but still sometimes used form of 2FA.
You can either use the type of reader you bought, or get laptops with built in readers on the high end of business models. My work laptop has the physical slot for them, but blanked out cause it's not high end enough.
If you had sims, there would be nothing stopping you from writing to them. But as explained above, the problem will be that you won't be able to clone the required information from the original sim because the way you would need to go about that would involve reading it over and over and over again, which would cause it to burn out before you could extract the information you need.
So you could write to them……..you just won't know what you have to write to them to duplicate your original
Are you sure?
As others have explained, those aren't SIMs in the Telco sense. They are programmable 2FA access tokens. Used in network and systems access.
I tried this before but was only able to clone the contacts and other useless information to the blank card. The software I used came on the disk with the reader/writer I bought. That's not to say it cannot be done.
Don't understand this about burning out the card looking for the key. Wouldn't a direct clone action only read once and copy bit by bit?
The cryptographic key is not in readable memory.
Does this apply to EMV chips too?
Yes.
There are videos online demonstrating how KI numbers are extracted from old sim cards. One particular program sends the sim card a request which is similar to a cell tower but does it thousands of times. Eventually the program works out what the KI number is. However, new sim cards self destruct after a certain amount of requests are made.
I was wondering do staff at mobile phone companies have access to the KI numbers?
No.
I see. So I guess mobile phones are only vulnerable to MITM attacks from Stingrays and IMSI catchers then?
In the past GCHQ broke into servers of those making SIM cards so they had a copy of the secret keys on millions of SIM cards on dozens of countries networks.
They could also intercept the physical SIM cards being shipped to the networks and swap them for versions that they know the key. Phone networks in general have 1980s level of security.
There are also lots of other potential backdoors and remember most traffic stays unencrypted as soon as it hits the nearest mast, typically all back end equipment between masts and core phone network is unencrypted and even if traffic is encrypted, say to a website the meta data of who is accessing that site is not. Potentially the governments also have "law enforcement" access to all phone networks in their home country so can monitor everything unencrypted, locations, account details, meta data etc.