Menu

Database

BT Audit

WVE ID: WVE-2005-0011

Type: Exploit

Status: Candidate

Classification:
Other

Description:
BT Audit is a suite of tools used to scan L2CAP PSMs and RFCOMM channels on a remote Bluetooth device.

Discussion:
BT Audit is used for scanning L2CAP PSMs (Protocol Service Multiplexers) and RFCOMM channels. In a way it can be thought of as the Bluetooth equivalent of a TCP/UDP port scanner. The tool is useful for discovering PSMs or RFCOMM channels that are open on a remote device, but not advertised through SDP. For instance, the BlueBug vulnerability is exploited through a hidden RFCOMM channel.

The Bluetooth L2CAP layer makes use of PSMs to enable multiple connections to higher layers in the protocol stack. L2CAP PSMs are odd-numbered and range from 1 to 65535. The component of BT Audit responsible for scanning PSMs is psm_scan.

The RFCOMM layer provides RS232 serial emulation to Bluetooth devices and allows for up to 30 channels. rfcomm_scan is used for scanning these channels.

Credits
Author: Collin Mulliner (collin@trifinite.org) : trifinite.org

References
URL: http://trifinite.org/trifinite_stuff_btaudit.html

Released: 2003-11-28

Submitter
Andrew Lockhart (alockhart@networkchemistry.com) : Network Chemistry

Submitted: Wed Oct 19 14:17:07 -0700 2005

Candidate Date: Mon Oct 24 10:05:26 -0700 2005


Recent Entries

TKIP Replay and Plaintext Discovery
WVE-2008-0013 11/18/2008

Active Https Cookie Hijacking
WVE-2008-0012 9/18/2008

Auto Immune Attack
WVE-2008-0011 9/17/2008

Marvell Null SSID Association Request
WVE-2008-0010 9/15/2008

Marvell EAPOL-Key Length Overflow
WVE-2008-0009 9/15/2008

Atheros IE Tag Overflow
WVE-2008-0008 9/15/2008

Weaknesses in the A5/1 Cipher
WVE-2008-0007 4/9/2008

Block ACK DoS
WVE-2008-0006 4/9/2008

GF Mode WIDS Rogue AP Evasion
WVE-2008-0005 4/9/2008

HT Intolerant Degradation of Service
WVE-2008-0004 4/9/2008

More Entries...

News

SANS Institute Sponsors WVE
4/19/2008

Wireless Attackers and Honeypot Technology
4/15/2008

High Speed Risks in 802.11n Slides Posted
4/11/2008

Vulnerabilities in 802.11n
4/9/2008

WVE Editors Speaking at SHARKFEST.08
1/3/2008

More News...