Eavesdropping on Bluetooth headsets
Here's a short video in which Joshua Wright demonstrates how a Bluetooth headset can be hijacked, allowing audio to be captured or sent to the device:
Few users realize that Bluetooth headsets can be exploited granting a remote attacker the ability to record and inject audio through the headset while the device is not in an active call. SANS Institute author and senior instructor Joshua Wright demonstrates.
All that is necessary is knowing the device address, which can be easily sniffed, and the secret pin, which defaults to 0000. The headset audio is tapped while not in a call, so any room conversation the headset's mic can pick up can potentially be listened to remotely.
Posted by Jason Striegel |
Dec 30, 2007 02:06 PM
Mobile Phones, Network Security, Wireless |
Permalink
| Comments (18)
Recent Entries
- Poromenos' hello world curve
- USB CapsLocker and Sun keyboard simulation
- Robosapien has a coil gun
- Faster Windows shutdown
- Assign USB drives to a folder
- Little drummer bot
- CSS ad blocking for Firefox and Safari
- Design Coding: web standards rap
- Shredz64: Guitar Hero for C64
- BATMAN: adhoc mesh routing
Comments
Newest comments listed first.
| Posted by: edisson calderon on December 31, 2007 at 4:47 PM |
thanks for the video, it is very good information.
| Posted by: fagmidnight on December 31, 2007 at 5:33 PM |
holy crap, that sissy just listened to you having phone sex with your gay boyfriend
| Posted by: peter guszti on December 31, 2007 at 6:33 PM |
, Yeah I have a wireless blootooth headset, and its great. i think they started selling like 30% more the last year., I also posted it on my blog with extra coments,www.opentopix.com/topic/gadgets/bluetooth-wireless-headsets-boom
| Posted by: Ryan on December 31, 2007 at 7:00 PM |
All 3 of my bluetooth headsets will only pair when it is put in a special "pair mode" (typically by holding the power button for 10 seconds or more).
I'd be interested if this attack will work on devices with this "feature".
| Posted by: JD on December 31, 2007 at 7:01 PM |
umm, I call BS for a few reasons.
1) The pin is used to associate two devices (the handshake) not for ongoing communication.
2) Once the headset has been associated to the device, it cannot be re-associated to another device while the first device is still active. So I would have to turn my phone off.
3) Even though you may be able to send a signal with that super nifty antenna, you most likely will not be able to receive the signal back unless they have a similar antenna.
You're more at risk with the FBI being able to remotely activate your mic.
| Posted by: lo on January 3, 2008 at 7:09 AM |
Didnt even watch the video because it sounds so retarded.
| Posted by: Karl Moerder on January 5, 2008 at 6:55 PM |
This guy is more annoying and effeminate than me !
| Posted by: nocti on February 1, 2008 at 7:24 PM |
ignore the other comments. good presentation. good info. those who think that this is lame are skr1pt k1dd1ez who just want it point-n-click so they can use it...
Bloggers
Welcome to the Hacks Blog!
Categories
- Ajax
- Amazon
- AppleTV
- Astronomy
- BlackBerry
- Blogging
- Body
- Cars
- Cryptography
- Data
- Education
- Electronics
- Energy
- Events
- Excel
- Excerpts
- Firefox
- Flash
- Flickr
- Flying Things
- Food
- Gaming
- Gmail
- Google Earth
- Google Maps
- Government
- Greasemonkey
- Hacks Series
- Hackszine Podcast
- Halo
- Hardware
- Home
- Home Theater
- iPhone
- iPod
- IRC
- iTunes
- Java
- Kindle
- Knoppix
- Language
- LEGO
- Life
- Lifehacker
- Linux
- Linux Desktop
- Linux Multimedia
- Linux Server
- Mac
- Mapping
- Math
- Microsoft Office
- Mind
- Mind Performance
- Mobile Phones
- Music
- MySpace
- MySQL
- NetFlix
- Network Security
- olpc
- OpenOffice
- Outdoor
- Parenting
- PDAs
- Perl
- Philosophy
- Photography
- PHP
- Pleo
- Podcast
- Podcasting
- Productivity
- PSP
- Retro Computing
- Retro Gaming
- Science
- Screencasts
- Shopping
- Skype
- Smart Home
- Software Engineering
- Sports
- SQL
- Statistics
- Survival
- TiVo
- Transportation
- Travel
- Ubuntu
- Video
- Virtualization
- Visual Studio
- VoIP
- Web
- Web Site Measurement
- Windows
- Windows Server
- Wireless
- Word
- World
- Xbox
- Yahoo!
- YouTube
Archives
Recent Posts
- Poromenos' hello world curve
- USB CapsLocker and Sun keyboard simulation
- Robosapien has a coil gun
- Faster Windows shutdown
- Assign USB drives to a folder
- Little drummer bot
- CSS ad blocking for Firefox and Safari
- Design Coding: web standards rap
- Shredz64: Guitar Hero for C64
- BATMAN: adhoc mesh routing
www.flickr.com
|





Leave a comment