Site Sponsors

Digital Wild & Wireless Bluetooth opens vulnerability window

Bluetooth opens vulnerability window

The technology can be easily hacked, leaving many digital devices open to attack. Connectivity is vital for doing business these days. The cellphone, laptop PC and PDA are essential connectivity tools – but at the same time these devices may leave us vulnerable to intrusion.

Take the simple technology of Bluetooth, which can be quite easily hacked with a range of different techniques that leave devices – cellphone, laptop or PDA – transparent and usable to unscrupulous eavesdroppers.

Bluetooth hacking techniques include making unauthorised calls and transactions, reading and sending SMSes on a target phone, erasing information and downloading personal information such as phone books and access codes.

I routinely make use of Bluetooth vulnerabilities to test the security level of corporate clients` networks. I recently addressed the annual Hack-in-the-Box security conference in Malaysia on the subject of Bluetooth hacking and the audience was shocked to see just how easy it is to compromise devices through Bluetooth.

Accessing a Bluetooth-enabled device is achieved by hacking the Bluetooth stack. Specific implementations of Bluetooth are susceptible to exploitation because of design flaws and various other factors. By using Bluetooth, one can literally control the device completely once it is exploited or paired.

For example, successful exploitation would include being able to access the entire contents of the phone such as call records, SMSes, key lock codes and so on. This is different to a situation where Bluetooth is left on and discoverable, because then the user will still have to accept a file download if someone sends something to the phone.

Listening in

Bluetooth hacking can be used to obtain personal information, particularly when in a public place. It can be used in fraud schemes where fraudsters make illegitimate calls using the phone to call prime rate numbers – so the user ends up with an enormous cellphone bill at the end of the month.

We are seeing many real life scenarios of Bluetooth car devices being compromised with the Carwhisperer program. This software tool was designed to connect to Bluetooth car kits, but it also enables attackers to listen in on other people`s conversations – either a specific person or a range of cellphone conversations on the road.

To hack a car kit, a fixed four-digit PIN code is needed, and obviously the kit cannot be already connected to a mobile device otherwise pairing cannot take place. Those who have a generic unlocking code on their handset, such as 0000 or 1234, should contact their manufacturer for applicable updates.

There are many different methods to gain confidential information off a mobile device. Hacking methods such as Bluebugging, BlueSnarfing and Carwhispering are just a few of the most common methods of attack.

The Bluebug attack, for example, allows attackers to perform unauthorised transactions on vulnerable devices, for example reading and sending SMSes or making phone calls from the other person`s phone. The attack creates a serial profile connection by providing access to the AT command. Distance is very important and is limited by the transmitting power of class two Bluetooth radios (10-15 metres). It can, however, be increased with directional antennas.

Bluesnarfing attacks are the best known and attackers take advantage of the OBEX Push Profile, which was developed for reasons such as business card exchange. In most instances, this service does not require authentication, so attackers can conduct an OBEX GET and request common filenames such as pb.vcf (the phonebook).

Worms such as Cabir have spread via Bluetooth. Cabir runs on Symbian mobile that supports the series 60 platform. Cabir, for example, arrives as a .sis file (with .app and .mdl and .rsc), so the worm activates and starts looking for new devices to infect via Bluetooth.

No place to hide

Even a Bluetooth device that is set on `hidden` can be found and broken into. This is possible through brute force scanning. A proof-of-concept application called RedFang is available to download. This helps in finding non-discoverable Bluetooth devices by brute forcing the last six bytes of the Bluetooth address of the device and doing a read_remote_name().

Attack and penetration tests show that alarm codes, passwords, private and confidential information such as banking details can all be found from phonebook entries and SMSes.

There are various ways to prevent phones, PDAs or PCs from being exploited. Firstly, turn off Bluetooth when it`s not required all of the time. Enable `hidden mode` and change the phone name from the default one because hackers will usually first go for such known vulnerabilities.

At the very least, enable PIN-based authentication and use anti-virus software, although this is a cost factor. Also, keep up-to-date with firmware and any security updates for the device.

* Dino Covotsos is the founder and CEO of Telspace Systems.

Comments (0)Add Comment

Write comment
You must be logged in to post a comment. Please register if you do not have an account yet.

busy

Related news items:
Newer news items:

Back

Blog Tags

2009 2010 Accessibility Adam adsense adwords afrigator aid ajax Ali amatomu aMaze Amazon ANCYL Angola animation apartheid Apple Art artist author avatar avi on imovie baby city bad credit loans battery BBC best Mac DVD Backup software Birthday reminder blackberry blackberry 9700 Blackberry Bold Blackberry Bold 9700 blacklisted Blacklisted Loans blog blogging books Bossa Nova Bridging Finance Brilliance broadcast Browser Buenos Aires Burns CAF Cafe de Paris cannabis legalisation cape town Cape Town Book Fair Cape Town Stadium car insurance carbon war room carter cartoons Cell phone GPS Cell phones cellphone Censorship children Chrome Chrome 4 class action Clint Eastwood Cloud Computing coffee competition competitions contracts convert .mov format to .mp4 OS X convert .mxf files on mac convert flip video on mac converting MXF files to FLV format Copy iPod Copy iPod to mac corruption Crime solving delay Dell Axim Design Indaba Die Antwoord Digi rands digirands Digital digital format digital lifestyle debate Disability divorce divorce attorney divorce lawyers divorces Don't click on the porn link doppelganger Draw drivers driving DRM Dropbox Easy Personal Loans ebooks ecology eLearning emigration ereaders eskom external Facebook Facebook profile family law fantasy fiction farmville fiction FIFA Firefox foreign players Forum free download Friends fring funeral cover gadget gadgets Gaming Garmap for Mobile gauteng gay rights gdrive gizmo Google google earth google maps Google Search GPS Grand Ole Opry GreatSoft greenhouse Greenpoint gtalk Guitar Hero Gulf War Haggis haiti Harmony Health help Hercules hits home loan calculator how to guide how to split MOV files snow leopard htc human contact HydraQ i-tunes iburst IE6 on Win 7 IE8 im insomnia interesting links Interesting Pictures internet internet basics for beginners internet explorer ipad iPhone iphone to itunes for vista iPod iTablet jacob maroga JAVA Jazz Joao Gilberto joburg johannesburg Joomla Keep WorldSpace Alive Kindle Kodu laptop leopard Liberty Media Linkedin Linux Linux on Windows lithium-ion Living Stories Loans for homeowners local loop unbundling lolcats love love in a time of blackouts lyttleton mac mod to ipod converter Macmillan maintenance Mark Zuckerberg marketing marriage Medical aid quotes medical facilities messenger microsoft Miles Davis mobile mobile apps Mobile Blogging mobile device Mobile Games money monitor Motorcycle Insurance MOV files to MPEG Snow Leopard mpg to mp4 for mac MTN mtv Multiple operating systems music My Digital Life My digital wishlist myblog mydl Myspace Naked Blogger Nashville Nav4All neotel Netbook network wide phenomena New Year Nexus 1 non-fiction NPR Obama Obit Office 2010 Beta office coffee service onile divorce online divorce online flight bookings online insurance quote online privacy online shopping OnLive open source Opening game opera ouch Palin passwords Patriot Gearbox pc Personal Computer Petition photography PJ poetry police privacy Privacy of speech profile pictures Psychology and Medicine PVR quotations removal Resident Evil 4 resolutions restaurants review RPS Rupert Murdoch safari Samsung San Francisco Sattelite Internet. Scams ScriptFrenzy search engine Search engines service Shaun Shortwave Radio sites I use Skype small business Smartphone snap social media Social Networking Social networks software sony south africa Space statistics Stephen Colbert Steve Jobs storm 2 Sundance Symbols tablet PC technology technorati Telcoms television Terrorism testament The Grammys thegatesnotes Thelonius Monk thenack tile Tim Minchin TomTom transfer iphone to itunes mac transfer iPhone to PC trojan Twitter ubuntu url USB video dvd to flash video to swf mac viewership Virtual Box Virtual Machine VirtualBox vlog Weather Web 3.0 Webcam western white wii sports resort wills & testaments Win 7 windows 7 flv to avi converter Windows on Mac wishlist work from home world cup WorldSpace Satellite Radio India WorldSpace Satellite Radio South Africa xp
You are here: Digital Wild & Wireless Bluetooth opens vulnerability window