public inbox for linux-bluetooth@vger.kernel.org
 help / color / mirror / Atom feed
* [Bluez-devel] Project about Bluetooth Security: Request for assistance
@ 2005-01-18 15:53 Khoo Teck Ping
  2005-01-18 19:48 ` Marcel Holtmann
  0 siblings, 1 reply; 2+ messages in thread
From: Khoo Teck Ping @ 2005-01-18 15:53 UTC (permalink / raw)
  To: bluez-devel

[-- Attachment #1: Type: text/plain, Size: 1883 bytes --]

Dear All

I am a newbie, please assist me if possible. 

I have some questions about bluetooth security. 

I am currently doing a project on bluetooth security and am required to develop some software (with bluetooth hardware) which can demonstrate bluetooth security weaknesses. 

Following are my ideas, please comment

1. I have a silicon wave Bluetooth USB dongle and a V3 headset, and a Nokia 6600 smartphone. I desire to capture packets sent between the phone and the headset, without a bluetooth protocol analyser (eg from mobiwave), so that I can demostrate that a hacker can listen in to unencrypted voice traffic. Is this possible at all?

hcidump is similar to a protocol analyser, but it can capture only high level traffic. My guess is that I can use hcitool scan to get the bluetooth address of the phone and the headset first, and then based on the addresses attempt to calculate the pseudo random frequency hopping sequence, so that I can stay in the same frequency as the phone and the headset. Problem is i don't understand the output of hcidump. Can hcidump capture traffic which does not belong to the host device? 

2. May I know the steps required to reproduce the work done by Adam Laurie (bluesnarfing) or the Flexilis team(bluesniper)? Will the test programs provided by the install of BlueZ be good as starting points? If so, which test program should I focus on? Please provide details if possible. This is purely for academic purposes. 

3. For the program l2ping.c, what is the end result of the victim phone of running the program? Does it cause the phone to malfunction? 

I ran it and pinged my Sony Ericsson T630. Later my phone could not initiate a bluetooth connection with my headset. Otherwise everything else is fine. 

I shall be grateful for any assistance. 

BlueZ is great software. Keep up the good work. 

Teck Ping

[-- Attachment #2: Type: text/html, Size: 3329 bytes --]

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2005-01-18 19:48 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-01-18 15:53 [Bluez-devel] Project about Bluetooth Security: Request for assistance Khoo Teck Ping
2005-01-18 19:48 ` Marcel Holtmann

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox