Sinisterly
Blueborne RCE Script - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Hacking Tools (https://sinister.li/Forum-Hacking-Tools)
+--- Thread: Blueborne RCE Script (/Thread-Blueborne-RCE-Script)



Blueborne RCE Script - O9A - 02-09-2019

Translated from German.
Based on parts on Armis Poc
dependencies:

Linux system (Tool uses bluez API, developed and tested on Kali 2018.1 and Fedora 27)
Development header of the libbluetooth (for example, install apt libbluetooth-dev via apt)
Python 2 (unfortunately no Python 3, because pwn does not work properly with it)
Python modules (best per pip or similar):
pybluez (bluetooth protocol support)
pwn (collection of useful features for PoCs and exploits)
pick (for comfortable selection of victim device, local bluetooth device, ...)
toml (for parsender device configurations in TOML format)

use

The entire script must be run as root. The commands that require this are:

Some interactions with the Bluetooth adapter via HCI
Changing the Bluetooth address of the adapter

Note: Changing the Bluetooth address is necessary because the payload of the exploit is stored in the global variable REMOTE_NAME of the compromised Bluetooth device. If the device knows the address of the attacker, the REMOTE_NAME may be loaded from the cache and the payload will not be placed correctly. Therefore, each time the script is called, the attacker's own address is changed to a random address. The actual change of the address is outsourced to the enclosed tool bdaddr (may need to be recompiled, the compilation has been compiled with GCC 7 on 64-bit Fedora 27). To explicitly prevent this process, the --no-addr option can be used. bdaddr may not work for all Bluetooth chips, as changing the address via HCI works and this interface is hardware dependent. Most manufacturers / chips should be implemented by now.

To start the script the file exploit.py is called up via Python 2.

sudo python2 exploit.py

The script also has a command line interface per argparse (attackers deserve a comfortable operation ;-)). A few things can be adjusted about that. The default settings should also be enough to try out.

Most interesting here is the argument -t | --target, which is given the Bluetooth address of the target, if one knows this. If this is not specified, it searches for Bluetooth devices in the environment and you can choose from a list of one. However, this requires that the target is visible at least for a short time (theoretically it would also be without visibility, which I have not implemented here, however, since this is relatively expensive).

The mandatory argument --device specifies the configuration / device to be used for the attack. These are specific offsets of the libraries libc.so and Bluetooth defaults of the target device. These are needed to bypass ASLR. It requires a copy of the libraries and a device that can debug the Bluetooth service at runtime (for example, by remote debugging in GDB).

Github Link


RE: Blueborne RCE Script - mothered - 02-10-2019

Looks like I'll have to fire up my Linux box and Install the said Python.

You can't go wrong with GitHub.
Appreciated.