Menu

Database

Car Whisperer

WVE ID: WVE-2005-0001

Type: Exploit

Status: Candidate

Classification:
Authentication Management
Hijacking

Description:
Car Whisperer is a tool that can be used to eavesdrop on and broadcast audio to a Bluetooth headset or hands-free device. It accomplishes this by relying on the well-known and static nature of the PIN codes that these types of devices use.

Discussion:
The Car Whisperer tool consists of three programs. The cw_scanner script is used to discover Bluetooth devices within range that have either a headset or hands-free profile. Once a device is discovered, the script invokes the carwhisperer binary which then opens a RFCOMM connection on channel 1 to the device.

It then establishes a syncrhonous connection to be used to send and receive audio from the remote device. This allows the attacker to broadcast audio to the device and covertly receive audio from its microphone.

To provide the numerical PIN needed to complete the connection, the carwhisperer binary invokes the cw_pin.pl script using the OUI of the remote device's BD address. This allows the script to easily identify the manufacturer of the device and then determine what PIN is commonly used by the manufacturer for such devices. It's ability to do this relies on the common manufacturing procedure of hard-coding in non-unique PIN codes into devices that do not have a method for inputting a user specified PIN.

Once the correct PIN has been determined, then the connection is established and the carwhisperer binary begins to send audio to the remote device while recording the audio it receives from it.

Credits
Author: Martin Herfurt (martin@trifinite.org) : trifinite.org

References
URL: http://trifinite.org/trifinite_stuff_carwhisperer.html

Released: 2005-07-31

Submitter
Andrew Lockhart (alockhart@networkchemistry.com) : Network Chemistry

Submitted: Mon Oct 24 09:53:28 -0700 2005

Candidate Date: Thu Oct 06 13:59:22 -0700 2005


Recent Entries

TKIP Replay and Plaintext Discovery
WVE-2008-0013 11/18/2008

Active Https Cookie Hijacking
WVE-2008-0012 9/18/2008

Auto Immune Attack
WVE-2008-0011 9/17/2008

Marvell Null SSID Association Request
WVE-2008-0010 9/15/2008

Marvell EAPOL-Key Length Overflow
WVE-2008-0009 9/15/2008

Atheros IE Tag Overflow
WVE-2008-0008 9/15/2008

Weaknesses in the A5/1 Cipher
WVE-2008-0007 4/9/2008

Block ACK DoS
WVE-2008-0006 4/9/2008

GF Mode WIDS Rogue AP Evasion
WVE-2008-0005 4/9/2008

HT Intolerant Degradation of Service
WVE-2008-0004 4/9/2008

More Entries...

News

SANS Institute Sponsors WVE
4/19/2008

Wireless Attackers and Honeypot Technology
4/15/2008

High Speed Risks in 802.11n Slides Posted
4/11/2008

Vulnerabilities in 802.11n
4/9/2008

WVE Editors Speaking at SHARKFEST.08
1/3/2008

More News...