Ainda k este tema possa caber em "segurança" a informação que se segue refere-se a telefones móveis.
Esta é uma cópia de um mail k um tipo me mandou. Basicamente menciona as falhas de segurança dos phones com BT e os links apontam para demonstrações ao vivo dessas mesmas falhas.
Os links são para os vídeos e paciência a kem gostaria k o texto/videos estivessem em PT:
Dear all,
Here some interesting information from the ISART Team about actual "SNARFING" exercises with mobile phones using Bluetooth.
To make it short: Do not use Bluetooth on mobile phones. Please advice your people to disable the Bluetooth function on mobile phones.
For your entertainment I attach the following TV video links and below the explanation about this vulnerability :
Live Interview at CNBC Europe [EN]
http://agentsmith.salzburgresearch.at/D ... awkBox.wmv
Story about BlueBug on German TV station Pro7 (Focus TV) [DE]
http://agentsmith.salzburgresearch.at/D ... ocusTV.wmv
Story about BlueBug on Swiss TV SFDRS (Kassensturz) [DE]
http://real.sri.ch/ramgen/sfdrs/ks/160k ... :14:23.597
Best regards
Uli
Long Distance Bluetooth Attacks
A group of Bluetooth and WLAN specialists has demonstrated that attacks
against vulnerable Bluetooth-enabled mobile phones are possible over
much longer distances (1.74 kilometers = 1.08 miles) than expected.
A group of hackers manipulated during their demonstration an unmodified Nokia 6310i mobile phone,
Which the current Roche standard is.
Many users of Bluetooth-enabled mobile phones assume that they are not at risk from Bluetooth attacks because vendors specify the range
of the Bluetooth wireless links at 10 meters. Optimists assume that attackers such close would probably be quickly discovered.
At first this seems to be a reasonable assumption because most Bluetooth-enabled mobile phones transmit with only 1 mW.
With normal Bluetooth devices as counterpart, the range is actually limited to 10 meters. DECT cordless phones or WLAN devices
transmit with up to 300 mW and are designed for ranges up to 300 meters. However, the team used at the attackers end a modified Bluetooth USB dongle
with a directional antenna with 19 dBi gain. This enabled them to extend the attack distance dramatically.
This can be explained by the fact that range specifications of any radio communication are only applicable for given additional parameters, such as
the background noise level, the signal loss (e.g. walls would attenuate the radio signal) and also the type of antenna used and the sensitivity of
the receiver. Bluetooth adapters with ranges higher than defined in the Bluetooth specification are readily available in computer stores.
Many Bluetooth USB dongles are specified for a range of 100 meters (so-called class 1 devices which are transmitting with 100 mW).
However, this specification is only applicable for omni directional antennas and with receiver sensitivity well below -80 dBm. In tests, dongles with higher
receiver sensitivity could establish Bluetooth links far beyond 100 meters.
Attackers using directional antennas against typical class 1 Bluetooth dongles could be successful from even greater distance. However, this requires some
additional know-how and additional equipment because the directed link is increasingly affected by vibrations the more the radio beam is focused.
In the case described here, a Bluesnarf attack against a Nokia 6310i was carried out. It was possible to modify information stored in the mobile phone - e.g. address lists,
calendar, system time, business card and also identity codes without any indication to the user of the mobile phone.
In addition to the know how, only a Linux PC or PDA with Bluetooth adapter and a special software for issuing commands are required.
Bluesnarf attacks are possible against the following mobile phones:
- Nokia 6310 (firmware 4.10)
- Nokia 6310i (firmware's 4.07, 5.50, and 5.51)
- Sony Ericsson T68i (R2B025)
- Sony Ericsson T610 (R1A081)
- Sony Ericsson T630 (R4C003)
- Sony Ericsson Z600 (R2E004)
Of course using directional antennas with high gain also enables other types of Bluetooth attacks from a greater distance.
For example the Chaos attack which enables unnoticed SMS communication or phone calls to expensive 0190 service numbers. In all cases, the attacks
are possible because security features (authentication and encryption) in the mobile phones are bypassed.
Mobile phone vendors know of these security vulnerabilities since a long time.
For some mobile phones, firmware upgrades are available. This is the case
for the popular Nokia 6310i (firmware version 5.52 closes the known security holes) as well as for the UMTS/GSM model Nokia 6650.
Other vendor have not (yet) announced availability of bug fixed firmware versions.
Until a fix is available, users are advised to disable in their mobile phones at least Bluetooth visibility (Discovery Mode). This makes it harder for an attacker to
determine the Bluetooth address of the targeted Bluetooth-enabled device. Devices which are already enabled with the mobile phone do not need
Discovery Mode any more and for linking to other devices, Discovery Mode should only be enabled for a short period of time.
For the best possible protection, users should disable Bluetooth completely.
E é tudo!



