本帖最后由 longas 于 2008-12-15 18:34 编辑 " N! t o8 D' ~$ g( `$ y
% z4 ^5 s v; S; Y8 E蓝牙攻击分类
" e! j, ]: q1 h+ A同无线攻击一样,蓝牙攻击也按照原理分为多种方式BlueBug、BlueDump attack、BlueSnarf等,涵盖了蓝牙扫描、模块漏洞利用、暴力破解、交互数据嗅探等多个方面,我们就分别来看一看其具体实现。. x* @' ]' U& E! \5 U& s
1。BuleTooth Scan 蓝牙设备扫描1 S2 i8 c. l' z+ C# e
BuleTooth Scan蓝牙设备扫描+ @" b0 c7 b7 e( M! W
随着带有蓝牙功能的智能手机及蓝牙适配器价格的下降,促使了更多的人开始接触蓝牙技术,尤其是在蓝牙耳机等附加设备的推动下,使得开启了蓝牙功能的智能手机、PDA等比比皆是。去年我去赛格电脑城给找配件,随手打开笔记本,使用笔记本自带的蓝牙模块就可以轻易地发现周围如此多的蓝牙设备,如下图,其中大部分是智能手机。至于机场、大型宾馆、会馆等人口稠密区域,开启蓝牙的设备更是数不胜数。
. n" \3 B' a+ C9 Z8 s- t
/ s$ }8 X6 {# u ?2 B除了通过查看其中对应设备属性来识别目标蓝牙设备类型外,还可以通过分析通信中的蓝牙数据包来获知目标设备类型,如下为蓝牙设备扫描中的交互数据报文(为方便大家查看,我已将主要部分提取)。</span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: Verdana; mso-hansi-font-family: Verdana;"></span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana;">---------------------------------------</span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana;"></span><span lang="FR" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana; mso-ansi-language: FR;">Frame 73: (Controller) Len=17</span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt;"><span lang="FR" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana; mso-ansi-language: FR;"></span><span lang="FR" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana; mso-ansi-language: FR;">HCI:</span><span lang="FR" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana; mso-ansi-language: FR;"><span style="mso-tab-count: 1;"><br/></span>HCI Event: </span><span lang="FR" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana; mso-ansi-language: FR;"><span style="mso-tab-count: 3;"><br/></span></span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana;">Class of Device: </span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana;"><span style="mso-tab-count: 4;"><br/></span>Service Class: </span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana;">Bit_22: Telephony (Cordless telephony, Modem, Headset serivce,...)</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana;"><span style="mso-tab-count: 5;"><br/></span>Bit_20: Object Transfer (v-Inbox, v-Folder,...)</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana;"><span style="mso-tab-count: 5;"><br/></span>Bit_19: Capture (Scanner, Microphone,...)</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana;"><span style="mso-tab-count: 5;"><br/></span>Bit_17: Networking (LAN, Ad hoc,...)</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana;"><span style="mso-tab-count: 4;"><br/></span>Major Device Class: Phone (cellular, cordless, payphone, modem,...)</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana;"><span style="mso-tab-count: 4;"><br/></span>Minor Device Class: Cellular</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana;"><span style="mso-tab-count: 4;"><br/>F</span>ormat type: 0x0</span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana;"></span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana;">---------------------------------------</span></p><div style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0cm; BORDER-TOP: medium none; PADDING-LEFT: 0cm; PADDING-BOTTOM: 1pt; BORDER-LEFT: medium none; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; mso-element: para-border-div; mso-border-bottom-alt: solid windowtext .75pt;"><p class="MsoNormal" style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0cm; BORDER-TOP: medium none; PADDING-LEFT: 0cm; PADDING-BOTTOM: 0cm; MARGIN: 0cm 0cm 0pt; BORDER-LEFT: medium none; TEXT-INDENT: 24pt; PADDING-TOP: 0cm; BORDER-BOTTOM: medium none; mso-char-indent-count: 2.0; mso-border-bottom-alt: solid windowtext .75pt; mso-padding-alt: 0cm 0cm 1.0pt 0cm;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: Verdana; mso-hansi-font-family: Verdana;">可以看到,在</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana;">Class of Device</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: Verdana; mso-hansi-font-family: Verdana;">栏中</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana;">Major Device Class</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: Verdana; mso-hansi-font-family: Verdana;">即主要设备类型已经识别出为</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana;">hone</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: Verdana; mso-hansi-font-family: Verdana;">即电话,而在下栏</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana;">Minor Device Class</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: Verdana; mso-hansi-font-family: Verdana;">即次要设备类型处显示为</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana;">Cellular</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: Verdana; mso-hansi-font-family: Verdana;">,与前面内容连在一起对应的设备而</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana;">16</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: Verdana; mso-hansi-font-family: Verdana;">进制编码为:</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana;">5a0204</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: Verdana; mso-hansi-font-family: Verdana;">对应是</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: Verdana;">Cell Phone</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: Verdana; mso-hansi-font-family: Verdana;">,也就是我们所说的移动电话即手机设备。</span></p></div>6 v8 l3 ?; ~1 ]+ W; V3 X
[此贴子已经被作者于2008-4-22 1:40:22编辑过] |