Questions tagged [blueborne]

9 questions
18
votes
2 answers

How will we stop BlueBorne on older devices?

The BlueBorne vulnerability was announced on September 12, 2017. It's a family of attacks against several implementations of the Bluetooth protocol that enable full compromises of various Bluetooth stacks, including Linux BlueZ (including Android),…
John Deters
  • 33,650
  • 3
  • 57
  • 110
7
votes
1 answer

Blueborne - Attack Scenario Clarification

Based on the Technical White Paper http://go.armis.com/hubfs/BlueBorne%20Technical%20White%20Paper-1.pdf?t=1505319664351 After reading it, I understand it as follows (Page 13, bottom) So to exploit (Linux kernel RCE vulnerability -…
dev
  • 937
  • 1
  • 8
  • 23
5
votes
0 answers

How do I protect my old devices against BlueBorne?

I have a bunch of Android devices for which there either is no patch to protect them against the BlueBorne exploit or I cannot install a patch without losing all the data. The most obvious thing would be to disable BlueTooth. But we know that…
Forivin
  • 979
  • 1
  • 11
  • 17
5
votes
2 answers

What is BlueBorne and how to protect myself?

Since this is a hot-topic this week, I'm looking for a canonical answer: What is the BlueBorne Bluetooth vulnerability? How to protect myself?
Mike Ounsworth
  • 57,707
  • 21
  • 150
  • 207
5
votes
2 answers

Are we safe from phone-to-phone-spreading BlueBorne malware horror case?

While reading through the technical whitepaper of the BlueBorne attacks I've noted that it is required for the attacker to know my Bluetooth MAC-Address. They claim it should be really easy to obtain it by using one of the following…
GameScripting
  • 233
  • 1
  • 5
1
vote
0 answers

Is there any way I can 'securely' use Bluetooth on non BlueBorne fixed Android and/or notice potential attacker?

I have Sony Xperia XA1 Android 7, and the security patch is from August, so obviously Sony doesn't consider BlueBorne any serious danger. However, I'm worried my device can be hacked. I'm using bluetooth currently only to sync data with smart band.…
1
vote
1 answer

So is the phone without BLE vulnerable before BlueBorne or not?

It is already known that BlueBorne poses no danger to Android-devices using Bluetooth Low Energy. For other cases, there were updates that were included in the September Android Security Bulletin. My phone does not support BLE. - then it is…
stackflow
  • 305
  • 1
  • 2
  • 9
1
vote
1 answer

Is Linux ​kernel ​ RCE ​vulnerability - ​CVE-2017-1000251 (BlueBorne vulnerability) practical?

In BlueBorne Technical White Paper, the authors mention It ​should ​be ​mentioned that ​testing ​and ​triggering ​this ​vulnerability ​was ​not ​an ​easy ​task, ​and required ​direct use ​of ​the ​ACL layer to ​send ​malformed ​L2CAP packets.…
bhadra
  • 111
  • 3
-4
votes
1 answer

Can code be transmitted through computers’ antennas?

I have an Acer Aspire E15 5-575. I removed its WiFi card, while kept its black and white antennas intact. I did this to avoid being discovered by long or short range wireless transmissions, wanting to perhaps sniff or inject code onto nearby laptops…
cubed
  • 33
  • 6