Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Blueborne RCE Script filter_list
Author
Message
Blueborne RCE Script #1
Translated from German.
Based on parts on Armis Poc
dependencies:

Linux system (Tool uses bluez API, developed and tested on Kali 2018.1 and Fedora 27)
Development header of the libbluetooth (for example, install apt libbluetooth-dev via apt)
Python 2 (unfortunately no Python 3, because pwn does not work properly with it)
Python modules (best per pip or similar):
pybluez (bluetooth protocol support)
pwn (collection of useful features for PoCs and exploits)
pick (for comfortable selection of victim device, local bluetooth device, ...)
toml (for parsender device configurations in TOML format)

use

The entire script must be run as root. The commands that require this are:

Some interactions with the Bluetooth adapter via HCI
Changing the Bluetooth address of the adapter

Note: Changing the Bluetooth address is necessary because the payload of the exploit is stored in the global variable REMOTE_NAME of the compromised Bluetooth device. If the device knows the address of the attacker, the REMOTE_NAME may be loaded from the cache and the payload will not be placed correctly. Therefore, each time the script is called, the attacker's own address is changed to a random address. The actual change of the address is outsourced to the enclosed tool bdaddr (may need to be recompiled, the compilation has been compiled with GCC 7 on 64-bit Fedora 27). To explicitly prevent this process, the --no-addr option can be used. bdaddr may not work for all Bluetooth chips, as changing the address via HCI works and this interface is hardware dependent. Most manufacturers / chips should be implemented by now.

To start the script the file exploit.py is called up via Python 2.

sudo python2 exploit.py

The script also has a command line interface per argparse (attackers deserve a comfortable operation ;-)). A few things can be adjusted about that. The default settings should also be enough to try out.

Most interesting here is the argument -t | --target, which is given the Bluetooth address of the target, if one knows this. If this is not specified, it searches for Bluetooth devices in the environment and you can choose from a list of one. However, this requires that the target is visible at least for a short time (theoretically it would also be without visibility, which I have not implemented here, however, since this is relatively expensive).

The mandatory argument --device specifies the configuration / device to be used for the attack. These are specific offsets of the libraries libc.so and Bluetooth defaults of the target device. These are needed to bypass ASLR. It requires a copy of the libraries and a device that can debug the Bluetooth service at runtime (for example, by remote debugging in GDB).

Github Link

Reply

RE: Blueborne RCE Script #2
Looks like I'll have to fire up my Linux box and Install the said Python.

You can't go wrong with GitHub.
Appreciated.
[Image: AD83g1A.png]

Reply