Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

Bluetooth Security

  • 13-05-2009 9:19pm
    #1
    Closed Accounts Posts: 4


    Just finished a college project on bluetooth security and was wondering has anyone else looked into this.

    Found a couple of java apps for attacking from phone to phone but i'm more interested in PC to phone. I used BackTrack 3 with a bluetooth dongle and managed to get a DoS attack working which shut the phone off with no warning. All other attacks where unsuccessful, but I'm gonna still look into it over the summer.

    I'm interested in peoples views, are these bluetooth attacks a thing of 4 years ago where it was relatively easy to gain access to bluetooth enabled phones? Has anyone had any success in testing bluetooth security and found vulnerabilities?


Comments

  • Closed Accounts Posts: 1,567 ✭✭✭Martyr


    i was interested in the btpincrack project looking at ways to optimise SAFER+ performance on desktop computers.

    after some time researching info it became clear that good analysis required expensive hardware and i hadn't the money or interest after this point.

    it might be interesting to look into Symbian OS, reverse engineering its bluetooth stack, since it has large market share of mobile devices, probably would raise few eyebrows.

    in last 1 or 2 years, there has been more research into symbian exploits..
    simple shellcodes can be written using gcc-arm toolchain.nobody (published publicly) has bothered to completely reverse how the kernel works so will be a while before we see anything..but it won't be too long.

    arteam is good source of info on that stuff..

    indeed, there are guys out there with the tools/software to break some systems that use bluetooth..i wouldn't use it for controlling access, just my own opinion.


  • Closed Accounts Posts: 752 ✭✭✭JimmyCrackCorn!


    Bluetooth has been hacked the crap out of

    Try 23c3 video on it from a few years back covered basic auditing.

    I cant remember the tools names but allot ran off the blues stack.

    Usual things like pin cracking
    Sniffing
    Audio stream injection (car kits)


  • Closed Accounts Posts: 1,567 ✭✭✭Martyr


    A protocol analyser costs anything from $5,000 or more.. correct me if i'm wrong here but the hardware needed to fully test the security of bluetooth is too expensive for average joe..

    the only other route is reverse engineering the software implementations, how many of you are willing to do that? :P

    Lower the cost of the hardware required to sniff this type of traffic and more vulnerabilities would surface but that probably won't happen anytime soon.


  • Closed Accounts Posts: 4 domoKon


    yeah its pretty expensive to get this equipment but I've seen some walkthroughs of turning a €20 usb dongle into a €5000 sniffing tool. One of the best is http://drgr33nsblog.blogspot.com/. Personally I haven't tried it cause you need a particular type of dongle.

    I've seen that 23c3 vid, it actually got me interested in Bluetooth security, but as I said
    I used the OS they use, BackTrack 3 with Bluebugger and Bluesnarfer etc, and was unsuccessful in any of these exploits. The only attack that was successful was overloading the buffer with packets which just crashes the phone.

    thanks for the info on btpincrack Martyr, it wud be interesting to see if I manage to flash a usb dongle and see if the claims that it works as $5000 piece of equipment are true?


  • Closed Accounts Posts: 1,567 ✭✭✭Martyr


    yeah its pretty expensive to get this equipment but I've seen some walkthroughs of turning a €20 usb dongle into a €5000 sniffing tool

    wow..see what you mean :D

    certain types of adapters allow firmware modification..gotta be an inside hack ;)

    if someone were willing to upload some bluetooth PIN pair captures..i'd be happy to play with PIN crackers, optimizing them, running them on GPU's..just for the fun.

    i had been researching this stuff over 2 years ago and hadn't bothered checking since, but if thats true you can obtain certain adapters, modify the firmware, then use them to sniff BT traffic..i'm all up for researching how to crack the PIN faster.


  • Advertisement
Advertisement