On November 3rd, 2019, we have reported a critical vulnerability affecting the
Android Bluetooth subsystem. This vulnerability has been assigned
CVE-2020-0022
and was now patched in the
latest security patch
from February 2020. The security impact is as follows:
On Android 8.0 to 9.0, a remote attacker within proximity can silently execute
arbitrary code with the privileges of the Bluetooth daemon as long as
Bluetooth is enabled. No user interaction is required and only the Bluetooth
MAC address of the target devices has to be known. For some devices, the
Bluetooth MAC address can be deduced from the WiFi MAC address. This
vulnerability can lead to theft of personal data and could potentially be used
to spread malware (Short-Distance Worm).
On Android 10, this vulnerability is not exploitable for technical reasons and
only results in a crash of the Bluetooth daemon.
Android versions even older than 8.0 might also be affected but we have not
evaluated the impact.
Users are strongly advised to install the latest available security patch from
February 2020. If you have no patch available yet or your device is not
supported anymore, you can try to mitigate the impact by some generic behavior
rules:
This blogpost contains summaries of talks from this year’s
TROOPERS19 Active Directory Security Track.
Microsoft IT (Secure) Journey to IPv6-Only
Veronika McKillop, Network Architect, Cloud and Connectivity Engineering (CCE)
The speaker, Veronika McKillop, working at Microsofts network infrastructure
services, has given a talk about the process of switching a company network from
IPv4 to IPv6-only.
Within the talk the following topics were introduced: Dual Stack, Drivers for
IPv6, Status of IPv6 in Networks and Security in IPv6 Networks. The talk covers
the reasons why a company would like to switch from IPv4 to IPv6. Technics like
NAT64 and DNS64 are introduced. The requirements to software and especially
drivers to work in IPv6 environments are described. Also the problems to switch
from IPv4 to IPv6-only in heterogeneous networks are addressed.
Recently we posted
first part of our
Bluetooth research diary. Today, we want to continue on that topic and tell you
about Bluetooth proxying and packet replay with a new tool.
This time we had a new gadget to play with: our colleague Florian Grunow shared
with us a curious IoT device – Bluetooth socks… real socks that you control with
an app to heat your feet. The future is here… 😉
As you probably know we perform research on a regular base at ERNW.
We – Olga and Rafael – started with a research project about Bluetooth. Our
first goal was to gain some knowledge about the tools used by most Linux systems
to communicate with Bluetooth hardware, such as BlueZ. A good help for that was
the amazing Bluetooth hacking workshop we had before (check
the link in
our blog!)
To get a better understanding of the tools you need some Bluetooth hardware to
interact with.
The hardware we used for our research so far are the very cool TexasInstruments
SimpleLink™ Bluetooth low energy/Multi-standard SensorTag (CC2650STK) and a
Fitness Wristband found at home.
Internal workshops are one of the reoccurring events at ERNW, that help us to
gain knowledge in areas outside our usual expertise. One of the recent workshops
which happened during the week from August 22nd-25th was Hardware Hacking. Held
by Brian Butterly (@BadgeWizard) and Dominic
Spill (@dominicgs), this workshop took place in two parts.
Brian kickstarted the introductory session by guiding us through the fundamental
steps of Hardware Hacking. Brian did an excellent job of making things simpler
by giving a detailed explanation on the basic concepts. For a beginner in
hardware hacking, the topic could be rather intimidating if not handled
properly.
About
two months ago the Bluetooth SIG
renamed their latest standard,
which was previously known as “Bluetooth v4.0”. When version numbers get higher
and higher marketing likes to interfere and try something new. In this case:
Bluetooth Smart.
Sounds smart, but is it?
Without getting into too much detail, let me quickly quote Wikipedia to get
started:
“Cost-reduced single-mode chips, which enable highly integrated and
compact devices, feature a lightweight Link Layer providing
ultra-low power idle mode operation, simple device discovery, and
reliable point-to-multipoint data transfer with advanced power-save
and secure encrypted connections at the lowest possible cost.”