Monday, June 23, 2008

Pairing Securities for thought

When bluetooth devices pair, they cahnge idenfication information to ensure they are exchanging infomation with the right device.
Bluetooth pins can be 8 to 128 bits long. However, most phone makers use a standard 4 digit pin.
4 digit pin means that there can be a maximum of 9999 combinations of number.
Given they speed of computers that bluetooth attackers use, a pentium 4 can crack the paring code in less than 0.1 secs.
This simply means that any bluetooth attack can occur by "forcing" of "cheating" your device to pair with it as though it was a device your own bluetooth device previously paired with.
Then with a simple program, the attacker can crack the code and pair with your device to steal any information he wants.

So it you think you bluetooth device is safe because of the paring process, think twice.

Thursday, April 3, 2008

Long Distance Bluesnarfing

Just a little tip off here. Most people thinking that bluejaking/ bluesnarfing can only be done by people/ devices close by. But this is not absolutely true. For most people, usuing normal bluetooth devices/laptops, this rule stands. But all you need is a simple antenna and a class 1 toggle and you can bluesnarf anyone's phone up to a mile away, depending on terrain.

THis means that anyone can eseentially use your phone to make long distance calls, from up to a mile away, without any of your knowledge. Austrian researcher and Bluetooth expert Martin Herfurt did just that in an experiment in 2004

Thursday, January 17, 2008

Try This Poll

Found this Poll Quite interesting
See how many of us are bluesnafer vs bluejackers


Updated Jan 2009 : The poll has been completed.
visit http://bluejackingtools.com/forum for details.

Sunday, December 16, 2007

Sunday, December 9, 2007

Tools to Protect yourself

It takes a snarfer to catch a snarfer. Or almost so. If your bluetooth cannot be switched off most of the time, then your device is prone to a bluesnarfing attack.

The best way around this is to know when you're being bluesnarfed. There are several softwares which you can use for this. Most of these are simple tools that helps detect any bluetooth connection between your phone and other phones.

While bluejackers and bluesnafers use these tools to find devices to attack, you can also use these tools to see if there are any unauthorised pairing of your device by other devices.

These tools include "bluesnifff" "easyjack" "bloover" amongst many others, most of which can be found in bluejackingtools.com

Hope this helps

Thursday, November 29, 2007

Bluesnarfer Tool

As I've promised, I will be talking about the wares used for bluesnarfing.

Today's lets talk aboutr bluesnarfer. This is one of the earliest tool used for bluesnarfing and and stayed true to the original description of bluesnarfing: which is to download the phonebook of susceptible mobile phones.

This is esentially a UNIX tool....like many of the bluetooth tools, which means you can't run it on usual java phones.
What is does is simple, search for bluetooth devices around and download the phonebooks of the devices that can be attacked.

This tools has been around for more than 4 years, so it's no surprising that some if not many of the new phone models has already had the bug exploited by the original bluesnafer fixed.

Hope this helps :)

Friday, November 23, 2007

A Video on Blueblugging

As you can tell, even the producers of this video thinks bluebugging is bluejaking. But bluebuggging which this video shows is really a lot more malicious than benign bluebugging.
Like before, all words and no video makes it dull.

So here's a video of bluebugging