4. Bluetooth
• Bluetooth is a wireless technology standard for
exchanging data over short distances (using
short-wavelength UHF radio waves in the ISM
band from 2.4 to 2.485 GHz) from fixed and
mobile devices, and building personal area
networks (PANs). (wiki)
5. History
• Named on 10th century king Herald Bluetooth
• Proposed by Jim Kardach
• In 1997
• A system which communicate b/w phone and comp
• BSIG
6. Capability
• Wireless
• Short Range
• Less energy
• Cheap
• Personal
• Easy
• Multipoint
• Frequency hopping
• [in]secure
7. Where is being used
• Phone/Computer/Camera/Speaker
• Watch/Fitness Band/Car/door locks
• Cooker/coffee machine/trimer/dryer
• Medical devices : ventilator/blood glucose
monitor
• Payment solution
• 7 Million Devices
22. Key Exchange Protocol
• Three stage process
• 3 pairing methods
• Just Works
• 6-digit PIN
• OOB
• “None of the pairing methods provide protection
against a passive eavesdropper” -Bluetooth Core
Spec
54. Ubertooth Spectrum Analyzing
(before Kismet)
• Connect the ubertooth one to your USB port
• If you are using a virtual machine, enable it
on the Devices/Usb Ports and seek the ubertooth
one
• Two green LEDs (RST and 1.8V) and the red LED
(USB LED) that indicates Ubertooth can
communicate via USB port.
109. Handle pcap file to crackle
isaias@ubuntu:~/crackle-sample# crackle -i ltk_exchange.pcap -o
decrypted.pcap
TK found: 000000
ding ding ding, using a TK of 0! Just Cracks(tm)
Warning: packet is too short to be encrypted (1), skipping
LTK found: 7f62c053f104a5bbe68b1d896a2ed49c
Done, processed 712 total packets, decrypted 3
110. To listen in on future
communications between the two
devices : using LTK captured
isaias@ubuntu:~/crackle-sample# crackle -i encrypted_known_ltk.pcap
-o decrypted2.pcap -l 7f62c053f104a5bbe68b1d896a2ed49c
Warning: packet is too short to be encrypted (1), skipping
Warning: packet is too short to be encrypted (2), skipping
Warning: could not decrypt packet! Copying as is..
Warning: could not decrypt packet! Copying as is..
Warning: could not decrypt packet! Copying as is..
Warning: invalid packet (length to long), skipping
Done, processed 297 total packets, decrypted 7
113. Thank you all, and Special
thanks to…
• Philips and team
• Minatee Mishra
• Anirudh Duggal
• Sanjog Panda
• Pardhiv Reddy
• Ajay Pratap Singh
• Geethu Arvind