[NEWS] Bluetooth SIG DoS

From: SecuriTeam (support_at_securiteam.com)
Date: 06/15/05

  • Next message: SecuriTeam: "[REVS] Meanwhile - On the Other Side of the Web Server"
    To: list@securiteam.com
    Date: 15 Jun 2005 10:42:57 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      Bluetooth SIG DoS
    ------------------------------------------------------------------------

    SUMMARY

    Due to the nature of "ping" in the Bluetooth protocol, where a connection
    must be established, and the limited amount of connections that (standard)
    Bluetooth stacks can manage, a simple ping flood with l2ping, and cause
    the device to stop responding as long as the attack continues.

    DETAILS

    Vulnerable Systems:
     * Nokia 7650 (Symbian 6.0)
     * Nokia 6600 (Symbian 7.0)
     * Siemens V55
     * Motorola S55
     * Conceptronic (CBTU) Bluetooth dongle on Windows 2003

    l2ping is a ping tool that was design to continue sending ping requests
    even when the device does not responding. That means that when a device
    does not responds it will continue sending packets, so rebooting the
    system will not help avoiding the DoS attack. With some systems even
    hidden mode is vulnerable for the attack (Nokia 7650 and 6600, Symbian 6
    and Symbian 7).

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:hugo@infohacking.com> hugo.
    The original article can be found at:
    <http://www.infohacking.com/INFOHACKING_RESEARCH/Our_Advisories/bt/index.html> http://www.infohacking.com/INFOHACKING_RESEARCH/Our_Advisories/bt/index.html

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[REVS] Meanwhile - On the Other Side of the Web Server"

    Relevant Pages

    • [TOOL] Redfang - The Bluetooth Hunter (Improved)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... the device's Bluetooth address and doing a read_remote_name. ... The information in this bulletin is provided "AS IS" without warranty of any kind. ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
      (Securiteam)
    • [NEWS] Car Whisperer
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... A Bluetooth passkey is used within the pairing process that takes place, ... carwhisperer binary that connects to the found device (on RFCOMM channel ...
      (Securiteam)
    • [NEWS] Apple OS X Multiple Bluetooth Vulnerabilities
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Starting with Mac OSX 10.2 Apple decided to include support for Bluetooth ... Aside from offering OBEX File Transfer OSX the bluetooth interface offers ...
      (Securiteam)
    • [NEWS] AmbiCom Bluetooth Object Push Buffer Overflow
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... AmbiCom Bluetooth Object Push Buffer Overflow ... Performing an sdp browse of an AmbiCom device will reveal an Object Push ...
      (Securiteam)
    • [NT] Toshiba Bluetooth Stack for Windows Buffer Overflow
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Toshiba Bluetooth Stack for Windows Buffer Overflow ... Attackers are able to remotely cause a critical System Exception on ...
      (Securiteam)