Tools needed to exploit mobile vulnerabilities
Proof of concept utilities have been developed, but are not yet available in the wild. They are:
- bluestumbler - Monitor and log all visible bluetooth devices (name, MAC, signal strength, capabilities), and identify manufacturer from MAC address lookup.
- bluebrowse - Display available services on a selected device (FAX, Voice, OBEX etc).
- bluejack - Send anoymous message to a target device (and optionally broadcast to all visible devices).
- bluesnarf - Copy data from target device (everything if pairing succeeds, or a subset in other cases, including phonebook and calendar. In the latter case, user will not be alerted by any bluejack message).
- bluebug - Set up covert serial channel to device.
Tools will not be released at this time, so please do not ask. However, if you are a bona-fide manufacturer of bluetooth devices that we have been otherwise unable to contact, please feel free to get in touch for more details on how you can identify your device status.
