{"id":111833,"date":"2023-11-29T15:10:14","date_gmt":"2023-11-29T13:10:15","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/bluffs-uyazvimosti-v-bluetooth-pozvolyayushhie-provesti-mitm-ataku"},"modified":"2023-11-29T15:10:14","modified_gmt":"2023-11-29T13:10:15","slug":"bluffs-uyazvimosti-v-bluetooth-pozvolyayushhie-provesti-mitm-ataku","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/bluffs-uyazvimosti-v-bluetooth-pozvolyayushhie-provesti-mitm-ataku","title":{"rendered":"BLUFFS \u2014 vulnerabilities in Bluetooth that allow for MITM attacks","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Daniele Antonioli, a Bluetooth security researcher who previously developed attack techniques such as BIAS, BLUR, and KNOB, has identified two new vulnerabilities (CVE-2023-24023) in the Bluetooth session establishment mechanism. These affect all Bluetooth implementations that support the &#171;Secure Connections&#187; and &#171;Secure Simple Pairing&#187; modes, corresponding to Bluetooth Core specifications 4.2-5.4. As a demonstration of the practical application of the identified vulnerabilities, six attack variants have been developed, allowing an attacker to infiltrate the connection between previously paired Bluetooth devices. The code implementing the attack methods and tools for checking vulnerability are published on GitHub.      <\/p>\n<p>The vulnerabilities were discovered during an analysis of the mechanisms outlined in the standard for achieving forward and future secrecy, which counteract the compromise of session keys if a persistent key is compromised (the compromise of one of the persistent keys should not lead to the decryption of previously intercepted or future sessions) and the reuse of session keys (the key from one session should not be applicable to another session). The identified vulnerabilities allow bypassing the stated protections and reusing an insecure session key across different sessions. These vulnerabilities are due to shortcomings in the base standard, are not specific to individual Bluetooth stacks, and manifest in chips from various manufacturers.     <center><img decoding=\"async\" alt=\"BLUFFS - vulnerabilities in Bluetooth that enable MITM attacks\" src=\"\/wp-content\/uploads\/2023\/11\/eb2b7d9e0a1b270ee116ffbb2ba86a5a.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>      <\/p>\n<p>The proposed attack methods implement different variants for spoofing classical (LSC, Legacy Secure Connections based on outdated cryptographic primitives) and secure (SC, Secure Connections based on ECDH and AES-CCM) Bluetooth connections between the system and peripheral devices, as well as organizing MITM attacks for connections in LSC and SC modes. It is assumed that all Bluetooth implementations compliant with the standard are susceptible to various forms of the BLUFFS attack. The effectiveness of the method has been demonstrated on 18 devices from companies such as Intel, Broadcom, Apple, Google, Microsoft, CSR, Logitech, Infineon, Bose, Dell, and Xiaomi.      <center><img decoding=\"async\" alt=\"BLUFFS - vulnerabilities in Bluetooth that enable MITM attacks\" src=\"\/wp-content\/uploads\/2023\/11\/497b2dc1fc82f929bd57895618bb3fa9.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>      <\/p>\n<p>The essence of the vulnerabilities lies in the ability to forcefully roll back the connection to use the old LSC mode and an unreliable short session key (SK) without violating the standard. This is achieved by specifying the minimum possible entropy during the connection negotiation and ignoring the content of the authentication parameters response (CR), resulting in the generation of a session key based on constant input parameters (the session key SK is computed as KDF from a permanent key (PK) and parameters agreed upon during the session). For instance, during a MITM attack, an attacker can replace the session negotiation parameters &#119860;&#119862; and &#119878;&#119863; with zero values and set the entropy &#119878;&#119864; to 1, leading to the formation of a session key &#119878;&#119870; with an actual entropy of 1 byte (the standard minimum entropy size is 7 bytes (56 bits), which is comparable in reliability to brute-forcing a DES key).    <\/p>\n<p>If the attacker managed to achieve the use of a shorter key during the connection negotiation, they can subsequently use brute force to determine the permanent key (PK) used for encryption and decrypt the traffic between devices. Since it is possible to initiate the use of the same encryption key during a MITM attack, if this key is guessed, it can be used to decrypt all past and future sessions intercepted by the attacker.  <center><img decoding=\"async\" alt=\"BLUFFS - vulnerabilities in Bluetooth that enable MITM attacks\" src=\"\/wp-content\/uploads\/2023\/11\/e27d88365015f585e8d6dace90547f46.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>      <\/p>\n<p>To block the vulnerabilities, researchers have proposed amendments to the standard that expand the LMP protocol and change the logic of using KDF (Key Derivation Function) when generating keys in LSC mode. This change does not disrupt backward compatibility, but it leads to the inclusion of an extended LMP command and the necessity to send an additional 48 bytes. The Bluetooth SIG organization, responsible for the development of Bluetooth standards, has proposed as a protective measure to reject connections over an encrypted communication channel with keys sized up to 7 bytes. Implementations that always apply Security Mode 4 Level 4 are recommended to reject connections with keys sized up to 16 bytes.<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=60192\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0414\u0430\u043d\u0438\u044d\u043b\u0435 \u0410\u043d\u0442\u043e\u043d\u0438\u043e\u043b\u0438 (Daniele Antonioli), \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 Bluetooth, \u0440\u0430\u043d\u0435\u0435 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u0432\u0448\u0438\u0439 \u0442\u0435\u0445\u043d\u0438\u043a\u0438 \u0430\u0442\u0430\u043a BIAS, BLUR \u0438 KNOB, \u0432\u044b\u044f\u0432\u0438\u043b \u0434\u0432\u0435 \u043d\u043e\u0432\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2023-24023) \u0432 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u0435 \u0441\u043e\u0433\u043b\u0430\u0441\u043e\u0432\u0430\u043d\u0438\u044f \u0441\u0435\u0430\u043d\u0441\u043e\u0432 Bluetooth, \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u044e\u0449\u0438\u0435 \u0432\u0441\u0435 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 Bluetooth, \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u044e\u0449\u0438\u0435 \u0440\u0435\u0436\u0438\u043c\u044b \u0437\u0430\u0449\u0438\u0449\u0451\u043d\u043d\u043e\u0433\u043e \u0441\u043e\u043f\u0440\u044f\u0436\u0435\u043d\u0438\u044f &#171;Secure Connections&#187; \u0438 &#171;Secure Simple Pairing&#187;, \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u0435 \u0441\u043f\u0435\u0446\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044f\u043c Bluetooth Core 4.2-5.4. \u0412 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0430\u0446\u0438\u0438 \u043f\u0440\u0430\u043a\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0433\u043e \u043f\u0440\u0438\u043c\u0435\u043d\u0435\u043d\u0438\u044f \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u043d\u043e 6 \u0432\u0430\u0440\u0438\u0430\u043d\u0442\u043e\u0432 \u0430\u0442\u0430\u043a, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":111834,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-111833","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0414\u0430\u043d\u0438\u044d\u043b\u0435 \u0410\u043d\u0442\u043e\u043d\u0438\u043e\u043b\u0438 (Daniele Antonioli), \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 Bluetooth, \u0440\u0430\u043d\u0435\u0435 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u0432\u0448\u0438\u0439 \u0442\u0435\u0445\u043d\u0438\u043a\u0438 \u0430\u0442\u0430\u043a BIAS, BLUR \u0438 KNOB, \u0432\u044b\u044f\u0432\u0438\u043b \u0434\u0432\u0435 \u043d\u043e\u0432\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2023-24023) \u0432 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u0435 \u0441\u043e\u0433\u043b\u0430\u0441\u043e\u0432\u0430\u043d\u0438\u044f \u0441\u0435\u0430\u043d\u0441\u043e\u0432.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/bluffs-uyazvimosti-v-bluetooth-pozvolyayushhie-provesti-mitm-ataku\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47BLUFFS \u2014 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Bluetooth, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u043f\u0440\u043e\u0432\u0435\u0441\u0442\u0438 MITM-\u0430\u0442\u0430\u043a\u0443 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0414\u0430\u043d\u0438\u044d\u043b\u0435 \u0410\u043d\u0442\u043e\u043d\u0438\u043e\u043b\u0438 (Daniele Antonioli), \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 Bluetooth, \u0440\u0430\u043d\u0435\u0435 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u0432\u0448\u0438\u0439 \u0442\u0435\u0445\u043d\u0438\u043a\u0438 \u0430\u0442\u0430\u043a BIAS, BLUR \u0438 KNOB, \u0432\u044b\u044f\u0432\u0438\u043b \u0434\u0432\u0435 \u043d\u043e\u0432\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2023-24023) \u0432 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u0435 \u0441\u043e\u0433\u043b\u0430\u0441\u043e\u0432\u0430\u043d\u0438\u044f \u0441\u0435\u0430\u043d\u0441\u043e\u0432.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/bluffs-uyazvimosti-v-bluetooth-pozvolyayushhie-provesti-mitm-ataku\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-11-29T13:10:15+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-11-29T13:10:15+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47BLUFFS \u2014 Bluetooth vulnerabilities enabling MITM attacks | ProHoster","description":"Daniele Antonioli, a Bluetooth security researcher who previously developed the BIAS, BLUR, and KNOB attack techniques, has discovered two new vulnerabilities (CVE-2023-24023) in the session negotiation mechanism.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/bluffs-uyazvimosti-v-bluetooth-pozvolyayushhie-provesti-mitm-ataku","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47BLUFFS \u2014 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Bluetooth, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u043f\u0440\u043e\u0432\u0435\u0441\u0442\u0438 MITM-\u0430\u0442\u0430\u043a\u0443 | ProHoster","og:description":"\u0414\u0430\u043d\u0438\u044d\u043b\u0435 \u0410\u043d\u0442\u043e\u043d\u0438\u043e\u043b\u0438 (Daniele Antonioli), \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 Bluetooth, \u0440\u0430\u043d\u0435\u0435 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u0432\u0448\u0438\u0439 \u0442\u0435\u0445\u043d\u0438\u043a\u0438 \u0430\u0442\u0430\u043a BIAS, BLUR \u0438 KNOB, \u0432\u044b\u044f\u0432\u0438\u043b \u0434\u0432\u0435 \u043d\u043e\u0432\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2023-24023) \u0432 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u0435 \u0441\u043e\u0433\u043b\u0430\u0441\u043e\u0432\u0430\u043d\u0438\u044f \u0441\u0435\u0430\u043d\u0441\u043e\u0432.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/bluffs-uyazvimosti-v-bluetooth-pozvolyayushhie-provesti-mitm-ataku","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-11-29T13:10:15+00:00","article:modified_time":"2023-11-29T13:10:15+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/111833","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=111833"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/111833\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/111834"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=111833"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=111833"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=111833"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}