DSINet.org
last site update
world news : 06-09-2006 14:00
dutch news : 14-06-2006 18:30
world news
latest dutch news
Never change a
Beer for a girl
Winning Team
Shell for a candy
[See results]
by tonus - 04-06-2005 02:15 - Source: DSINet
Cryptographers from Israel have accomplished a relatively simple way to crack Bluetooth devices and/or their communication with others. Where earlier cracking methods worked only during the pairing-phase of two devices this new technique allows an attacker to pick any time of attack.

Avishai Wool and Yaniv Shaked of the University of Tel Aviv found a way to force two Bluetooth devices to reinitiate a pairing-session. “Our attack makes it possible to crack every communication between two Bluetooth devices, and not only if it is the first communication between those devices,” says Shaked.
During the pairing-phase two Bluetooth devices exchange a 128-bit key with which they encrypt the rest of their communication. Research in 2004 showed that this key is relatively easily sniffed and the user-PIN is easy to crack on a modern laptop.

With this new technique Wool and Shaked showed that an attacker will not have to wait for a pairing session but that the two devices can be forced to pair again. This is accomplished by spoofing one of the devices and sending a forget-message. The other device thinks its communication partner forgot the key and agrees to exchange a new one, start a new pairing-session. All that is needed to spoof a device is its ID, which is broadcasted constantly.

Shaked and Wool will present their findings at the MobiSys conference next Monday in Seattle, Washington, US.
full article at DSINet
secunia
virus alerts
Win32.Gimmiv.a - 10/26/2008 - Threat Level: Low
Win32.ACVE.o - 10/2/2008 - Threat Level: Low
Win32.Adload.aro - 10/2/2008 - Threat Level: Low
Win32.Adload.asj - 10/2/2008 - Threat Level: Low
Win32.Adload.ask - 10/2/2008 - Threat Level: Low
Win32.Adload.asn - 10/2/2008 - Threat Level: Low
bugtraq