Re: [Full-Disclosure] Re: Serious flaws in bluetooth security lead to disclosure of personal data

From: Pentest Security Advisories (alerts_at_pentest.co.uk)
Date: 11/15/03

  • Next message: Valdis.Kletnieks_at_vt.edu: "Re: [Full-Disclosure] SSH Exploit Request"
    To: nosp <nosp@xades.com>
    Date: Sat, 15 Nov 2003 13:40:14 +0000
    
    

    On Fri, Nov 14, 2003 at 04:05:36PM +0000, nosp wrote:
    > On Fri, 2003-11-14 at 10:21, Pentest Security Advisories wrote:
    > [...]
    > > No, you didn't misread - The T610, whilst still vulnerable to some
    > > attacks, does provide more protection
    > > of OBEX profiles. In this respect, it's better than the other phones /
    > > devices we've tested.
    > >
    > > On the particular T610 that was tested, we found that whilst it was
    > > possible to upload files to the phone we could not download files from it.
    >
    > It is very possible (and easy) to download (very) sensitive files from a
    > T610 as long as the MAC is known; no pairing necessary. Firmware rev
    > R3C002. Files include calendar and phonebook.
    >

    I retested the T610 and got the following,

    Service Name: Dial-up Networking
        Channel: 1
    State: Closed.

    Service Name: Voice gateway
        Channel: 3
    State: Closed.

    Service Name: Serial Port 1
        Channel: 4
    State: Closed.

    Service Name: Serial Port 2
        Channel: 5
    State: Closed.

    Service Name: OBEX Object Push
        Channel: 10
    State: Open.
    GET telecom/pb.vcf
    Returns Unauthorised
    GET telecom/cal.vcs
    Returns Unauthorised
    GET telecom/pb/0.vcf
    Returns Unauthorised

    Service Name: IrMC Synchronization
        Channel: 11
    State: Closed.

    Service Name: HF Voice gateway
        Channel: 6
    State: Closed.

    Service Name: OBEX Basic Imaging
        Channel: 15
    State: Open.
    GET telecom/pb.vcf
    Returns Unauthorised
    GET telecom/cal.vcs
    Returns Unauthorised
    GET telecom/pb/0.vcf
    Returns Unauthorised

    Service Name: OBEX File Transfer
        Channel: 7
    State: Closed.

    The firmware version is: R1L013

    It appears that this firmware version is not vulnerable. A quick google
    shows that it may be due to other problems in the firmware.

    Tim.

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Valdis.Kletnieks_at_vt.edu: "Re: [Full-Disclosure] SSH Exploit Request"

    Relevant Pages

    • Re: The E815 has to go. Samsung or Lg Which one?
      ... Does it cost anything to have the firmware updated? ... into a Verizon office and hand them the phone? ... Firmware updates are free at VZW stores. ... But you still have to hack the phone to get OBEX to work with the 815. ...
      (alt.cellular.verizon)
    • Re: The E815 has to go. Samsung or Lg Which one?
      ... Does it cost anything to have the firmware updated? ... do you just march into a Verizon office and hand them the phone? ... The comment about OBEX still working with the new software is a reference to the new version of the RAZR V3c firmware, where it appears that the code for OBEX functionality was outright removed from the firmware, not just disabled. ...
      (alt.cellular.verizon)
    • Re: Firmware Update for RAZR?
      ... This is VERY thoroughly discussed on Howard Forums. ... takes away OBEX. ... The consensus is that it gives nothing - takes away only. ... Most feel that the initial firmware is the way to go. ...
      (alt.cellular.verizon)
    • SUMMARY: A1000 not responding
      ... Anyway I connected to the A1000 via serial port. ... > something I can do without calling SUN? ... to it and you should begin seeing messages from the controller ... Make sure you have the latest version of the firmware that you were ...
      (SunManagers)
    • Re: Super Serial Card Question?
      ... Appletalk compatibility and a 'fast' serial port as it uses the ACIA's ... compatibility with any software that doesn't use the Apple firmware ... interface, which also unfortunately, is most useful comms software :-( ... Apple seemed to go through a period of shoddy I/O firmware. ...
      (comp.sys.apple2)