{"id":112103,"date":"2023-12-10T09:10:17","date_gmt":"2023-12-10T07:10:17","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-bluetooth-stekah-linux-macos-android-i-ios"},"modified":"2023-12-10T09:10:17","modified_gmt":"2023-12-10T07:10:17","slug":"uyazvimost-v-bluetooth-stekah-linux-macos-android-i-ios","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-bluetooth-stekah-linux-macos-android-i-ios","title":{"rendered":"Sicherheitsanf\u00e4lligkeit in den Bluetooth-Stacks von Linux, macOS, Android und iOS","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex>      <noindex><\/p>\n<p>Marc Newlin, der eine Sicherheitsanf\u00e4lligkeit aufgedeckt hat <a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=43934\">MouseJack<\/a> vor sieben Jahren, enth\u00fcllte Informationen \u00fcber <a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2023-45866\">eine \u00e4hnliche Sicherheitsanf\u00e4lligkeit (CVE-2023-45866)<\/a>, die Bluetooth-Stacks von Android, Linux, macOS und iOS betrifft. Diese Sicherheitsanf\u00e4lligkeit erm\u00f6glicht die Manipulation von Tasteneingaben durch die Simulation von Aktivit\u00e4ten eines per Bluetooth verbundenen Eingabeger\u00e4ts. Wenn der Angreifer Zugriff auf die Tastatureingaben hat, kann er verschiedene Aktionen ausf\u00fchren, wie das Ausf\u00fchren von Befehlen im System, das Installieren von Anwendungen und das Umleiten von Nachrichten.<\/p>\n<p><\/noindex><\/noindex>  <\/p>\n<p>Die Sicherheitsanf\u00e4lligkeit entsteht durch die Tatsache, dass die Host-HID-Treiber (Human Interface Device) f\u00fcr Bluetooth-Ger\u00e4te einen Modus besitzen, der es einem entfernten Peripherieger\u00e4t erm\u00f6glicht, verschl\u00fcsselte Verbindungen ohne Authentifizierung zu erstellen und zu etablieren. Solche verbundenen Ger\u00e4te k\u00f6nnen Tastennachrichten senden, die vom HID-Stack verarbeitet werden, was die M\u00f6glichkeit f\u00fcr eine Angriffsmethode auf die Manipulation von HID-Nachrichten er\u00f6ffnet, die ohne Benutzereingriff durchgef\u00fchrt werden kann. Dieser Angriff kann aus einer Entfernung von bis zu 100 Metern von dem Opfer erfolgen.<\/p>\n<p>Der Pairing-Mechanismus f\u00fcr Ger\u00e4te ohne Authentifizierung ist in der Bluetooth-Spezifikation definiert und erlaubt es abh\u00e4ngig von den Einstellungen des Bluetooth-Stacks, ein Ger\u00e4t ohne Best\u00e4tigung durch den Benutzer zu verbinden. Zum Beispiel muss in Linux, bei Verwendung des Bluetooth-Stacks BlueZ, der Bluetooth-Adapter im Entdeckungs- und Verbindungsmodus sein, um ein verstecktes Pairing zu erm\u00f6glichen. Bei Android reicht es aus, Bluetooth zu aktivieren. Bei iOS und macOS muss Bluetooth aktiviert sein, und eine drahtlose Tastatur muss verbunden sein, um einen erfolgreichen Angriff durchzuf\u00fchren.<\/p>\n<p>Die M\u00f6glichkeit zur Manipulation von Eingaben wurde in Ubuntu 18.04, 20.04, 22.04 und 23.10 mit dem Bluetooth-Stack auf Basis des BlueZ-Pakets demonstriert. ChromeOS ist nicht anf\u00e4llig f\u00fcr diese Sicherheitsanf\u00e4lligkeit, da seine Bluetooth-Stack-Einstellungen keine Verbindungen ohne Authentifizierung zulassen. In Android betrifft die Sicherheitsanf\u00e4lligkeit Ger\u00e4te mit Plattformversionen von 4.2.2 bis 14. In macOS wurde die Sicherheitsanf\u00e4lligkeit auf einem MacBook Pro 2022 mit Apple M2-Prozessor und macOS 13.3.3 sowie auf einem MacBook Air 2017 mit Intel-Prozessor und macOS 12.6.7 demonstriert. In iOS wurde die Sicherheitsanf\u00e4lligkeit auf einem iPhone SE mit iOS 16.6 demonstriert. Der Aktivierungsmodus f\u00fcr Lockdown bietet keinen Schutz vor Angriffen auf macOS und iOS.<\/p>\n<p> <noindex><\/p>\n<p>In Linux wurde die Sicherheitsanf\u00e4lligkeit <a rel=\"nofollow\" href=\"https:\/\/git.kernel.org\/pub\/scm\/bluetooth\/bluez.git\/commit\/profiles\/input?id=25a471a83e02e1effb15d5a488b3f0085eaeb675\">behebbar gemacht<\/a> In der Codebasis von Bluez wird durch Setzen der Einstellung &laquo;ClassicBondedOnly&raquo; auf &laquo;true&raquo; der sichere Modus aktiviert, der Verbindungen nur nach einer Kopplung erlaubt. Zuvor war der Wert auf &laquo;false&raquo; gesetzt, was aus Kompatibilit\u00e4tsgr\u00fcnden mit einigen Eingabeger\u00e4ten das Sicherheitsniveau senkte.<\/p>\n<p><\/noindex> <noindex><\/p>\n<p>Im Bluetooth-Stack Fluoride, der in den neuesten Versionen von Android verwendet wird, <a rel=\"nofollow\" href=\"https:\/\/android.googlesource.com\/platform\/packages\/modules\/Bluetooth\/+\/5673b3c6bbe8c6c9edb8afb5e9499dc3a41d3943\">wurde die Schwachstelle behoben<\/a> durch die zwingende Anwendung von Authentifizierung f\u00fcr alle verschl\u00fcsselten Verbindungen. Die Patches f\u00fcr Android wurden nur f\u00fcr die Versionen 11-14 ver\u00f6ffentlicht. F\u00fcr Pixel-Ger\u00e4te wurde die Schwachstelle im Dezember-Firmware-Update behoben. F\u00fcr Android-Versionen von 4.2.2 bis 10 bleibt die Schwachstelle jedoch bestehen.<\/p>\n<p><\/noindex><\/p>\n<p>Quelle: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.linux.org.ru\/news\/security\/17447666\">linux.org.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041c\u0430\u0440\u043a \u041d\u044c\u044e\u043b\u0438\u043d (Marc Newlin), \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0432\u044b\u044f\u0432\u0438\u043b \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c MouseJack \u0441\u0435\u043c\u044c \u043b\u0435\u0442 \u043d\u0430\u0437\u0430\u0434, \u0440\u0430\u0441\u043a\u0440\u044b\u043b \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e \u0430\u043d\u0430\u043b\u043e\u0433\u0438\u0447\u043d\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2023-45866), \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u044e\u0449\u0435\u0439 Bluetooth-\u0441\u0442\u0435\u043a\u0438 Android, Linux, macOS \u0438 iOS. \u042d\u0442\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0438\u0442\u044c \u043f\u043e\u0434\u043c\u0435\u043d\u0443 \u043d\u0430\u0436\u0430\u0442\u0438\u0439 \u043a\u043b\u0430\u0432\u0438\u0448 \u043f\u0443\u0442\u0435\u043c \u0441\u0438\u043c\u0443\u043b\u044f\u0446\u0438\u0438 \u0430\u043a\u0442\u0438\u0432\u043d\u043e\u0441\u0442\u0438 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430 \u0432\u0432\u043e\u0434\u0430, \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u043d\u043e\u0433\u043e \u043f\u043e Bluetooth. \u041f\u043e\u043b\u0443\u0447\u0438\u0432 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043a\u043b\u0430\u0432\u0438\u0430\u0442\u0443\u0440\u043d\u043e\u043c\u0443 \u0432\u0432\u043e\u0434\u0443, \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a \u043c\u043e\u0436\u0435\u0442 \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0442\u044c \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0435 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044f, \u0442\u0430\u043a\u0438\u0435 \u043a\u0430\u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u043a\u043e\u043c\u0430\u043d\u0434 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-112103","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041c\u0430\u0440\u043a \u041d\u044c\u044e\u043b\u0438\u043d (Marc Newlin), \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0432\u044b\u044f\u0432\u0438\u043b \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c MouseJack \u0441\u0435\u043c\u044c \u043b\u0435\u0442 \u043d\u0430\u0437\u0430\u0434, \u0440\u0430\u0441\u043a\u0440\u044b\u043b \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-bluetooth-stekah-linux-macos-android-i-ios\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Bluetooth-\u0441\u0442\u0435\u043a\u0430\u0445 Linux, macOS, Android \u0438 iOS | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041c\u0430\u0440\u043a \u041d\u044c\u044e\u043b\u0438\u043d (Marc Newlin), \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0432\u044b\u044f\u0432\u0438\u043b \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c MouseJack \u0441\u0435\u043c\u044c \u043b\u0435\u0442 \u043d\u0430\u0437\u0430\u0434, \u0440\u0430\u0441\u043a\u0440\u044b\u043b \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-bluetooth-stekah-linux-macos-android-i-ios\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-12-10T07:10:17+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-12-10T07:10:17+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Die Schwachstelle in den Bluetooth-Stacks von Linux, macOS, Android und iOS | ProHoster","description":"Marc Newlin, der vor sieben Jahren die MouseJack-Schwachstelle entdeckte, hat Informationen \u00fcber","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-bluetooth-stekah-linux-macos-android-i-ios","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Bluetooth-\u0441\u0442\u0435\u043a\u0430\u0445 Linux, macOS, Android \u0438 iOS | ProHoster","og:description":"\u041c\u0430\u0440\u043a \u041d\u044c\u044e\u043b\u0438\u043d (Marc Newlin), \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0432\u044b\u044f\u0432\u0438\u043b \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c MouseJack \u0441\u0435\u043c\u044c \u043b\u0435\u0442 \u043d\u0430\u0437\u0430\u0434, \u0440\u0430\u0441\u043a\u0440\u044b\u043b \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-bluetooth-stekah-linux-macos-android-i-ios","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-12-10T07:10:17+00:00","article:modified_time":"2023-12-10T07:10:17+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/112103","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=112103"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/112103\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=112103"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=112103"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=112103"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}