Adam Laurie Marcel Holtmann Martin Herfurt
21C3: The Usual Suspects
21st Chaos Communication Congress December 27th to 29th, 2004 Berliner Congress Center, Berlin, Germany
Bluetooth Hacking – Full Disclosure @ 21C3
Who we are
●
Adam Laurie
– – –
CSO of The Bunker Secure Hosting Ltd. Co-Maintainer of Apache-SSL DEFCON Staff/Organiser Maintainer and core developer of the Linux Bluetooth Stack BlueZ Security Researcher Founder of trifinite.org
Bluetooth Hacking – Full Disclosure @ 21C3
●
Marcel Holtmann
–
●
Martin Herfurt
– –
Outline (1)
● ● ● ● ● ● ● ●
Bluetooth Introduction History Technology Overview The BlueSnarf Attack The HeloMoto Attack The BlueBug Attack Bluetooone Long-Distance Attacking
Bluetooth Hacking – Full Disclosure @ 21C3
Outline (2)
● ● ● ● ● ●
Blooover Blueprinting DOS Attacks Sniffing Bluetooth with hcidump Conclusions – Lessons tought Feedback / Discussion
Bluetooth Hacking – Full Disclosure @ 21C3
Bluetooth Introduction (1)
● ● ● ● ●
Wire replacement technology Low power Short range 10m - 100m 2.4 GHz 1 Mb/s data rate
Bluetooth Hacking – Full Disclosure @ 21C3
Bluetooth Introduction (2)
●
Bluetooth SIG
– – – – –
Trade Association Founded 1998 Owns & Licenses IP Individual membership free Promoter members: Agere, Ericsson, IBM, Intel, Microsoft, Motorola, Nokia and Toshiba Consumer http://www.bluetooth.com Technical http://www.bluetooth.org
– –
Bluetooth Hacking – Full Disclosure @ 21C3
History (1)
●
Bluejacking
– –
Early adopters abuse 'Name' field to send message Now more commonly send 'Business Card' with message via OBEX 'Toothing' - Casual sexual liasons
–
Bluetooth Hacking – Full Disclosure @ 21C3
History (2)
●
Bluesnarfing
–
First publicised by Marcel Holtmann, October 2003
●
Wireless Technologies Congress, Sindelfingen, Germany Bugtraq, Full Disclosure