{"id":37225,"date":"2019-10-31T22:16:26","date_gmt":"2019-10-31T19:16:26","guid":{"rendered":"https:\/\/prohoster.info\/blog\/ataka-knob-pozvolyayushhaya-perehvatit-zashifrovannyj-trafik-bluetooth\/"},"modified":"2019-10-31T22:16:26","modified_gmt":"2019-10-31T19:16:26","slug":"ataka-knob-pozvolyayushhaya-perehvatit-zashifrovannyj-trafik-bluetooth","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/ataka-knob-pozvolyayushhaya-perehvatit-zashifrovannyj-trafik-bluetooth","title":{"rendered":"Attaque KNOB, permettant d'intercepter le trafic Bluetooth chiffr\u00e9","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex><a rel=\"nofollow\" href=\"https:\/\/francozappa.github.io\/post\/knob-announce\/\">D\u00e9voil\u00e9<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.usenix.org\/system\/files\/sec19-antonioli.pdf\">informations<\/a><\/noindex> sur l'attaque <noindex><a rel=\"nofollow\" href=\"https:\/\/knobattack.com\/\">KNOB<\/a><\/noindex> (Key Negotiation Of Bluetooth), permettant d'organiser l'interception et l'injection d'informations dans le trafic Bluetooth chiffr\u00e9. En ayant la capacit\u00e9 de bloquer la transmission directe de paquets lors de la n\u00e9gociation de la connexion entre les appareils Bluetooth, l'attaquant peut amener \u00e0 l'utilisation pour la session de cl\u00e9s ne contenant qu'un seul octet d'entropie, ce qui permet d'appliquer la m\u00e9thode de force brute (brute-force) pour d\u00e9terminer la cl\u00e9 de chiffrement. <\/p>\n<p>Le probl\u00e8me est caus\u00e9 par des d\u00e9fauts (CVE-2019-9506) dans la sp\u00e9cification Bluetooth BR\/EDR Core 5.1 et les versions ant\u00e9rieures, permettant l'utilisation de cl\u00e9s de chiffrement trop courtes et ne pr\u00e9venant pas l'intervention de l'attaquant lors de la n\u00e9gociation de la connexion pour revenir \u00e0 de telles cl\u00e9s peu fiables (il est possible d'injecter des paquets par un attaquant non authentifi\u00e9). L'attaque peut \u00eatre effectu\u00e9e au moment de la n\u00e9gociation de la connexion entre les appareils (les sessions d\u00e9j\u00e0 \u00e9tablies ne peuvent pas \u00eatre attaqu\u00e9es) et n'est efficace que pour les connexions dans les modes BR\/EDR (Bluetooth Basic Rate\/Enhanced Data Rate), si les deux appareils sont vuln\u00e9rables. En cas de succ\u00e8s dans la d\u00e9couverte de la cl\u00e9, l'attaquant peut d\u00e9chiffrer les donn\u00e9es transmises et, de mani\u00e8re imperceptible pour la victime, effectuer une substitution dans le trafic de n'importe quel texte chiffr\u00e9.<\/p>\n<p>Lors de l'\u00e9tablissement d'une connexion entre deux contr\u00f4leurs Bluetooth A et B, le contr\u00f4leur A, apr\u00e8s authentification par la cl\u00e9 de liaison (link key), peut proposer d'utiliser pour la cl\u00e9 de chiffrement (encryption key) 16 octets d'entropie, et le contr\u00f4leur B peut accepter cette valeur ou indiquer une valeur inf\u00e9rieure s'il n'est pas en mesure de former une cl\u00e9 de la taille propos\u00e9e. En r\u00e9ponse, le contr\u00f4leur A peut accepter la contre-offre et activer le canal de communication chiffr\u00e9. \u00c0 ce stade de la n\u00e9gociation des param\u00e8tres, le chiffrement n'est pas appliqu\u00e9, permettant \u00e0 l'attaquant d'intervenir dans l'\u00e9change de donn\u00e9es entre les contr\u00f4leurs et de substituer un paquet avec la taille d'entropie propos\u00e9e. \u00c9tant donn\u00e9 que la taille de cl\u00e9 autoris\u00e9e varie de 1 \u00e0 16 octets, le deuxi\u00e8me contr\u00f4leur acceptera cette valeur et enverra sa confirmation avec une taille similaire.<\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/www.usenix.org\/system\/files\/sec19-antonioli.pdf\"><img decoding=\"async\" alt=\"Attaque KNOB, permettant d&#039;intercepter le trafic Bluetooth chiffr\u00e9\" src=\"\/wp-content\/uploads\/2019\/08\/00852a72cea4b661260af415244a748b.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>Pour reproduire la vuln\u00e9rabilit\u00e9 en laboratoire (l'activit\u00e9 de l'attaquant a \u00e9t\u00e9 simul\u00e9e sur l'un des appareils), un<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/francozappa\/knob\/tree\/master\/poc-internalblue\">prototype d'outil<\/a><\/noindex> pour r\u00e9aliser l'attaque a \u00e9t\u00e9 propos\u00e9.<br \/>\nPour une attaque r\u00e9elle, l'attaquant doit se trouver dans la zone de r\u00e9ception des dispositifs cibles et \u00eatre capable de bloquer temporairement le signal de chaque appareil, ce qui pourrait \u00eatre r\u00e9alis\u00e9 par la manipulation du signal ou le brouillage r\u00e9actif. <\/p>\n<p>L'organisation Bluetooth SIG, responsable du d\u00e9veloppement des normes Bluetooth, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.bluetooth.com\/security\/statement-key-negotiation-of-bluetooth\/\">a publi\u00e9<\/a><\/noindex>  a corrig\u00e9 la sp\u00e9cification sous le num\u00e9ro 11838, dans laquelle des mesures pour bloquer la vuln\u00e9rabilit\u00e9 ont \u00e9t\u00e9 propos\u00e9es aux fabricants (la taille minimale de la cl\u00e9 de chiffrement a \u00e9t\u00e9 augment\u00e9e de 1 \u00e0 7). Le probl\u00e8me <noindex><a rel=\"nofollow\" href=\"https:\/\/www.kb.cert.org\/vuls\/id\/918987\/\">se manifeste<\/a><\/noindex> dans  <noindex><a rel=\"nofollow\" href=\"https:\/\/www.icasi.org\/br-edr-encryption-key-bluetooth-vulnerability\/\">tous<\/a><\/noindex> les stacks Bluetooth conformes et les firmwares des puces Bluetooth, y compris les produits <noindex><a rel=\"nofollow\" href=\"https:\/\/software.intel.com\/security-software-guidance\/insights\/more-information-exploiting-low-entropy-encryption-key-negotiation-bluetooth-bredr\">Intel<\/a><\/noindex>, Broadcom, <noindex><a rel=\"nofollow\" href=\"https:\/\/support.lenovo.com\/us\/en\/product_security\/LEN-27173\">Lenovo<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/support.apple.com\/kb\/HT201222\">Apple<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2019-9506\">par Microsoft<\/a><\/noindex>, Qualcomm, Linux, <noindex><a rel=\"nofollow\" href=\"https:\/\/source.android.com\/security\/bulletin\/2019-08-01\">Android<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"http:\/\/support.blackberry.com\/kb\/articleDetail?articleNumber=000057251\">Blackberry<\/a><\/noindex> et <noindex><a rel=\"nofollow\" href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20190813-bluetooth\">Cisco<\/a><\/noindex> (des 14 puces test\u00e9es, toutes se sont r\u00e9v\u00e9l\u00e9es vuln\u00e9rables). Dans le stack Bluetooth du noyau Linux,  <noindex><a rel=\"nofollow\" href=\"https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/bluetooth\/bluetooth.git\/commit\/?id=58a96fc35375ab87db7c5b69336f5befde1b548f\">un correctif a \u00e9t\u00e9 apport\u00e9<\/a><\/noindex> permettant de modifier la taille minimale de la cl\u00e9 de chiffrement. <\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source : <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51303\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e\u0431 \u0430\u0442\u0430\u043a\u0435 KNOB (Key Negotiation Of Bluetooth), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442 \u0438 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0443 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 \u0432 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c Bluetooth-\u0442\u0440\u0430\u0444\u0438\u043a\u0435. \u0418\u043c\u0435\u044f \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043f\u0440\u044f\u043c\u0443\u044e \u043f\u0435\u0440\u0435\u0434\u0430\u0447\u0443 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0432 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0435 \u0441\u043e\u0433\u043b\u0430\u0441\u043e\u0432\u0430\u043d\u0438\u044f \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f Bluetooth-\u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432, \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0439 \u043c\u043e\u0436\u0435\u0442 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0437\u0430\u0434\u0435\u0439\u0441\u0442\u0432\u043e\u0432\u0430\u043d\u0438\u044f \u0434\u043b\u044f \u0441\u0435\u0430\u043d\u0441\u0430 \u043a\u043b\u044e\u0447\u0435\u0439, \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0449\u0438\u0445 \u0432\u0441\u0435\u0433\u043e 1 \u0431\u0430\u0439\u0442 \u044d\u043d\u0442\u0440\u043e\u043f\u0438\u0438, \u0447\u0442\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u0440\u0438\u043c\u0435\u043d\u0438\u0442\u044c \u043c\u0435\u0442\u043e\u0434 \u043f\u0440\u044f\u043c\u043e\u0433\u043e \u043f\u0435\u0440\u0435\u0431\u043e\u0440\u0430 (brute-force) \u0434\u043b\u044f \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u0438\u044f \u043a\u043b\u044e\u0447\u0430 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0432\u044b\u0437\u0432\u0430\u043d\u0430 \u043d\u0435\u0434\u043e\u0440\u0430\u0431\u043e\u0442\u043a\u0430\u043c\u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":27914,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-37225","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/ataka-knob-pozvolyayushhaya-perehvatit-zashifrovannyj-trafik-bluetooth\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0410\u0442\u0430\u043a\u0430 KNOB, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u0438\u0442\u044c \u0437\u0430\u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0439 \u0442\u0440\u0430\u0444\u0438\u043a Bluetooth | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/ataka-knob-pozvolyayushhaya-perehvatit-zashifrovannyj-trafik-bluetooth\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:16:26+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:16:26+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47L'attaque KNOB, permettant d'intercepter le trafic Bluetooth chiffr\u00e9 | ProHoster","description":"D\u00e9voil\u00e9","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/ataka-knob-pozvolyayushhaya-perehvatit-zashifrovannyj-trafik-bluetooth","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0410\u0442\u0430\u043a\u0430 KNOB, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u0438\u0442\u044c \u0437\u0430\u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0439 \u0442\u0440\u0430\u0444\u0438\u043a Bluetooth | ProHoster","og:description":"\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/ataka-knob-pozvolyayushhaya-perehvatit-zashifrovannyj-trafik-bluetooth","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:16:26+00:00","article:modified_time":"2019-10-31T19:16:26+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"37225","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 16:49:21","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:31:24","updated":"2026-01-23 16:49:21","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/37225","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=37225"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/37225\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media\/27914"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=37225"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=37225"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=37225"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}