Menu

Database

Blueprint

WVE ID: WVE-2005-0010

Type: Exploit

Status: Candidate

Classification:
Other

Description:
Blueprint is a tool that can be used to identify the make and model of a particular Bluetooth device remotely.

Discussion:
The Blueprint tool can identify the make and model of a Bluetooth device remotely by looking at two key pieces of information. First the device's BD_ADDR is examined.

BD_ADDRs are a six byte number that uniquely identify any given Bluetooth device. These addresses are much like the MAC addresses used in ethernet and 802.11. The format of the address is XX:XX:XX:YY:YY:YY, where the first three bytes in the address (those denoted by X's) uniquely correspond to a vendor. Thus, the manufacturer of the device can be determined by examining this portion of the device's address.

The second piece of information examined by Blueprint is used to determine the model of the device. To do this is it examines the SDP (Service Discovery Protocol) records which advertise the services the device provides.

These two pieces of information are combined and run through a hashing function to create a unique fingerprint of the device. If a matching hash in Blueprint's database is found then the remote device's model can be successfully determined. However, if it is not in the database and the model of the remote device is known in advance, then the device's hash can be added to the database.

Credits
Author: Collin Mulliner (collin@trifinite.org) : trifinite.org
Author: Martin Herfurt (martin@trifinite.org) : trifinite.org

References
URL: http://trifinite.org/trifinite_stuff_blueprinting.html

Released: 2004-12-28

Submitter
Andrew Lockhart (alockhart@networkchemistry.com) : Network Chemistry

Submitted: Tue Oct 18 15:42:34 -0700 2005

Candidate Date: Mon Oct 24 10:04:43 -0700 2005


Recent Entries

TKIP Replay and Plaintext Discovery
WVE-2008-0013 11/18/2008

Active Https Cookie Hijacking
WVE-2008-0012 9/18/2008

Auto Immune Attack
WVE-2008-0011 9/17/2008

Marvell Null SSID Association Request
WVE-2008-0010 9/15/2008

Marvell EAPOL-Key Length Overflow
WVE-2008-0009 9/15/2008

Atheros IE Tag Overflow
WVE-2008-0008 9/15/2008

Weaknesses in the A5/1 Cipher
WVE-2008-0007 4/9/2008

Block ACK DoS
WVE-2008-0006 4/9/2008

GF Mode WIDS Rogue AP Evasion
WVE-2008-0005 4/9/2008

HT Intolerant Degradation of Service
WVE-2008-0004 4/9/2008

More Entries...

News

SANS Institute Sponsors WVE
4/19/2008

Wireless Attackers and Honeypot Technology
4/15/2008

High Speed Risks in 802.11n Slides Posted
4/11/2008

Vulnerabilities in 802.11n
4/9/2008

WVE Editors Speaking at SHARKFEST.08
1/3/2008

More News...