githubEdit

Bluetooth

circle-exclamation

Theory

Bluetooth is a short-range wirelessarrow-up-right technology standard that is used for exchanging data between fixed and mobile devices over short distances and building personal area networksarrow-up-right (PANs). In the most widely used mode, transmission power is limited to 2.5 milliwattsarrow-up-right, giving it a very short range of up to 10 metres (33 ft). It employs UHFarrow-up-right radio wavesarrow-up-right in the ISM bandsarrow-up-right, from 2.402 GHzarrow-up-right to 2.48 GHz

Practice

Tools

BlueToolkitarrow-up-right is an extensible Bluetooth Classic vulnerability testing framework that helps uncover new and old vulnerabilities in Bluetooth-enabled devices.

sudo bluekit -t <TARGET_MAC_ADDR>

Vulnerabilities

CVE-2023-45866

CVE-2023–45866 is a significant vulnerability affecting Android and iOS devices. It involves "Improper Authentication" in Bluetooth connections, which could allow attackers execute commands, keyboard inputs on devices

BlueDuckyarrow-up-right allow to exploit CVE-2023-45866 using DuckyScript, mleading to Code Execution (Using HID Keyboard).

python3 BlueDucky.py

Last updated