BLUFFS - ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ื‘ืœื•ื˜ื•ืช' ื”ืžืืคืฉืจื•ืช ืžืชืงืคืช MITM

ื“ื ื™ืืœ ืื ื˜ื•ื ื™ื•ืœื™, ื—ื•ืงืจ ืื‘ื˜ื—ืช Bluetooth ืฉืคื™ืชื— ื‘ืขื‘ืจ ืืช ื˜ื›ื ื™ืงื•ืช ื”ื”ืชืงืคื” BIAS, BLUR ื•-KNOB, ื–ื™ื”ื” ืฉืชื™ ืคื’ื™ืขื•ื™ื•ืช ื—ื“ืฉื•ืช (CVE-2023-24023) ื‘ืžื ื’ื ื•ืŸ ื”ืžืฉื ื•ืžืชืŸ ืฉืœ ื”ืคืขืœืช Bluetooth, ื”ืžืฉืคื™ืขื•ืช ืขืœ ื›ืœ ื™ื™ืฉื•ืžื™ Bluetooth ื”ืชื•ืžื›ื™ื ื‘ืžืฆื‘ื™ ื—ื™ื‘ื•ืจื™ื ืžืื•ื‘ื˜ื—ื™ื. "Secure Simple Pairing", ืชื•ืื ืœืžืคืจื˜ื™ Bluetooth Core 4.2-5.4. ื›ื”ื“ื’ืžื” ืœื™ื™ืฉื•ื ื”ืžืขืฉื™ ืฉืœ ื”ืคื’ื™ืขื•ื™ื•ืช ืฉื–ื•ื”ื•, ืคื•ืชื—ื• 6 ืืคืฉืจื•ื™ื•ืช ืชืงื™ืคื” ื”ืžืืคืฉืจื•ืช ืœื ื• ืœื”ืฉืชืœื‘ ื‘ื—ื™ื‘ื•ืจ ื‘ื™ืŸ ืžื›ืฉื™ืจื™ ื‘ืœื•ื˜ื•ืช' ืฉื”ื•ืชืืžื• ื‘ืขื‘ืจ. ื”ืงื•ื“ ืขื ื™ื™ืฉื•ื ืฉื™ื˜ื•ืช ื”ืชืงืคื” ื•ื›ืœื™ ืขื–ืจ ืœื‘ื“ื™ืงืช ืคืจืฆื•ืช ืžืชืคืจืกื ื‘-GitHub.

ื”ืคื’ื™ืขื•ืช ื–ื•ื”ื• ื‘ืžื”ืœืš ื ื™ืชื•ื— ื”ืžื ื’ื ื•ื ื™ื ื”ืžืชื•ืืจื™ื ื‘ืชืงืŸ ืœื”ืฉื’ืช ืกื•ื“ื™ื•ืช ืงื“ื™ืžื” (Forward and Future Secrecy), ื”ืžื•ื ืขื™ื ืืช ื”ืคืฉืจื” ืฉืœ ืžืคืชื—ื•ืช ื”ืคืขืœื” ื‘ืžืงืจื” ืฉืœ ืงื‘ื™ืขืช ืžืคืชื— ืงื‘ื•ืข (ื”ืชืคืฉืจื•ืช ืขืœ ืื—ื“ ื”ืžืคืชื—ื•ืช ื”ืงื‘ื•ืขื™ื ืœื ืืžื•ืจื” ืœื”ื•ื‘ื™ืœ ืœืคื™ืขื ื•ื— ืฉืœ ื”ืคืขืœื•ืช ืฉื™ื™ืจื˜ื• ื‘ืขื‘ืจ ืื• ื‘ืขืชื™ื“) ื•ืฉื™ืžื•ืฉ ื—ื•ื–ืจ ื‘ืžืคืชื—ื•ืช ืฉืœ ืžืคืชื—ื•ืช ื”ืคืขืœื” (ืžืคืชื— ืžื”ืคืขืœื” ืื—ืช ืœื ืืžื•ืจ ืœื”ื™ื•ืช ื™ืฉื™ื ืœื”ืคืขืœื” ืื—ืจืช). ื”ืคื’ื™ืขื•ื™ื•ืช ืฉื ืžืฆืื• ืžืืคืฉืจื•ืช ืœืขืงื•ืฃ ืืช ื”ื”ื’ื ื” ืฉืฆื•ื™ื ื” ื•ืœืขืฉื•ืช ืฉื™ืžื•ืฉ ื—ื•ื–ืจ ื‘ืžืคืชื— ื”ืคืขืœื” ืœื ืืžื™ืŸ ื‘ื”ืคืขืœื•ืช ืฉื•ื ื•ืช. ื”ืคื’ื™ืขื•ื™ื•ืช ื ื’ืจืžื•ืช ืขืœ ื™ื“ื™ ืคื’ืžื™ื ื‘ืชืงืŸ ื”ื‘ืกื™ืก, ืื™ื ืŸ ืกืคืฆื™ืคื™ื•ืช ืœืขืจื™ืžื•ืช ื‘ืœื•ื˜ื•ืช' ื‘ื•ื“ื“ื•ืช, ื•ืžื•ืคื™ืขื•ืช ื‘ืฉื‘ื‘ื™ื ืžื™ืฆืจื ื™ื ืฉื•ื ื™ื.

BLUFFS - ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ื‘ืœื•ื˜ื•ืช' ื”ืžืืคืฉืจื•ืช ืžืชืงืคืช MITM

ืฉื™ื˜ื•ืช ื”ื”ืชืงืคื” ื”ืžื•ืฆืขื•ืช ืžื™ื™ืฉืžื•ืช ืืคืฉืจื•ื™ื•ืช ืฉื•ื ื•ืช ืœืืจื’ื•ืŸ ื–ื™ื•ืฃ ืฉืœ ื—ื™ื‘ื•ืจื™ ื‘ืœื•ื˜ื•ืช' ืงืœืืกื™ื™ื (LSC, Legacy Secure Connections ื”ืžื‘ื•ืกืกื™ื ืขืœ ืคืจื™ืžื™ื˜ื™ื‘ื™ื ืงืจื™ืคื˜ื•ื’ืจืคื™ื™ื ืžื™ื•ืฉื ื™ื) ื•ืžืื•ื‘ื˜ื—ื™ื (SC, Secure Connections ื”ืžื‘ื•ืกืกื™ื ืขืœ ECDH ื•- AES-CCM) ื‘ื™ืŸ ื”ืžืขืจื›ืช ืœื‘ื™ืŸ ื”ืชืงืŸ ื”ื™ืงืคื™, ื›ืžื• ื›ืžื• ื’ื ืืจื’ื•ืŸ ื—ื™ื‘ื•ืจื™ MITM.ื”ืชืงืคื•ืช ืœื—ื™ื‘ื•ืจื™ื ื‘ืžืฆื‘ื™ LSC ื•-SC. ื”ื”ื ื—ื” ื”ื™ื ืฉื›ืœ ืžื™ืžื•ืฉื™ ื”-Bluetooth ืฉืขื•ืžื“ื™ื ื‘ืชืงืŸ ืจื’ื™ืฉื™ื ืœื’ืจืกื” ื›ืœืฉื”ื™ ืฉืœ ื”ืชืงืคืช BLUFFS. ื”ืฉื™ื˜ื” ื”ื•ื“ื’ืžื” ื‘-18 ืžื›ืฉื™ืจื™ื ืฉืœ ื—ื‘ืจื•ืช ื›ืžื• ืื™ื ื˜ืœ, ื‘ืจื•ื“ืงื•ื, ืืคืœ, ื’ื•ื’ืœ, ืžื™ืงืจื•ืกื•ืคื˜, CSR, Logitech, Infineon, Bose, Dell ื•-Xiaomi.

BLUFFS - ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ื‘ืœื•ื˜ื•ืช' ื”ืžืืคืฉืจื•ืช ืžืชืงืคืช MITM

ืžื”ื•ืช ื”ืคื’ื™ืขื•ืช ืžืกืชื›ืžืช ื‘ื™ื›ื•ืœืช, ืžื‘ืœื™ ืœื”ืคืจ ืืช ื”ืชืงืŸ, ืœืืœืฅ ื—ื™ื‘ื•ืจ ืœื”ืฉืชืžืฉ ื‘ืžืฆื‘ LSC ื”ื™ืฉืŸ ื•ื‘ืžืคืชื— ื”ืคืขืœื” ืงืฆืจ (SK) ืœื ืืžื™ืŸ, ืขืœ ื™ื“ื™ ืฆื™ื•ืŸ ื”ืื ื˜ืจื•ืคื™ื” ื”ืžื™ื ื™ืžืœื™ืช ื”ืืคืฉืจื™ืช ื‘ืžื”ืœืš ืชื”ืœื™ืš ื”ืžืฉื ื•ืžืชืŸ ืขืœ ื”ื—ื™ื‘ื•ืจ ื•ื”ืชืขืœืžื•ืช ืชื•ื›ืŸ ื”ืชื’ื•ื‘ื” ืขื ืคืจืžื˜ืจื™ ืื™ืžื•ืช (CR), ืžื” ืฉืžื•ื‘ื™ืœ ืœื™ืฆื™ืจืช ืžืคืชื— ื”ืคืขืœื” ื”ืžื‘ื•ืกืก ืขืœ ืคืจืžื˜ืจื™ ืงืœื˜ ืงื‘ื•ืขื™ื (ืžืคืชื— ื”ื”ืคืขืœื” SK ืžื—ื•ืฉื‘ ื›-KDF ืžื”ืžืคืชื— ื”ืงื‘ื•ืข (PK) ื•ืคืจืžื˜ืจื™ื ืฉืกื•ื›ืžื• ื‘ืžื”ืœืš ื”ื”ืคืขืœื”) . ืœื“ื•ื’ืžื”, ื‘ืžื”ืœืš ืžืชืงืคืช MITM, ืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ื—ืœื™ืฃ ืืช ื”ืคืจืžื˜ืจื™ื ๐ด๐ถ ื•- ๐‘†๐ท ื‘ืขืจื›ื™ ืืคืก ื‘ืžื”ืœืš ืชื”ืœื™ืš ื”ืžืฉื ื•ืžืชืŸ ืขืœ ื”ืคื’ื™ืฉื”, ื•ืœื”ื’ื“ื™ืจ ืืช ื”ืื ื˜ืจื•ืคื™ื” ๐‘†๐ธ ืœ-1, ืžื” ืฉื™ื•ื‘ื™ืœ ืœื™ืฆื™ืจืช ืžืคืชื— ื”ืคืขืœื” ๐‘†๐พ ืขื ืื ื˜ืจื•ืคื™ื” ื‘ืคื•ืขืœ ืฉืœ 1 ื‘ื™ื™ื˜ (ื’ื•ื“ืœ ื”ืื ื˜ืจื•ืคื™ื” ื”ืžื™ื ื™ืžืœื™ ื”ืกื˜ื ื“ืจื˜ื™ ื”ื•ื 7 ื‘ืชื™ื (56 ืกื™ื‘ื™ื•ืช), ืืฉืจ ื ื™ืชืŸ ืœื”ืฉื•ื•ืช ื‘ืืžื™ื ื•ืช ืœื‘ื—ื™ืจืช ืžืคืชื— DES).

ืื ื”ืชื•ืงืฃ ื”ืฆืœื™ื— ืœื”ืฉื™ื’ ืฉื™ืžื•ืฉ ื‘ืžืคืชื— ืงืฆืจ ื™ื•ืชืจ ื‘ืžื”ืœืš ื”ืžืฉื ื•ืžืชืŸ ืขืœ ื”ื—ื™ื‘ื•ืจ, ืื– ื”ื•ื ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ื›ื•ื— ื’ืก ื›ื“ื™ ืœืงื‘ื•ืข ืืช ื”ืžืคืชื— ื”ืงื‘ื•ืข (PK) ื”ืžืฉืžืฉ ืœื”ืฆืคื ื” ื•ืœื”ืฉื™ื’ ืคืขื ื•ื— ืฉืœ ืชืขื‘ื•ืจื” ื‘ื™ืŸ ืžื›ืฉื™ืจื™ื. ืžื›ื™ื•ื•ืŸ ืฉื”ืชืงืคืช MITM ื™ื›ื•ืœื” ืœื”ืคืขื™ืœ ืืช ื”ืฉื™ืžื•ืฉ ื‘ืื•ืชื• ืžืคืชื— ื”ืฆืคื ื”, ืื ืžืคืชื— ื–ื” ื ืžืฆื, ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื• ื›ื“ื™ ืœืคืขื ื— ืืช ื›ืœ ื”ืคืขืœื•ืช ื”ืขื‘ืจ ื•ื”ืขืชื™ื“ ืฉื™ื™ืจื˜ื• ืขืœ ื™ื“ื™ ื”ืชื•ืงืฃ.

BLUFFS - ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ื‘ืœื•ื˜ื•ืช' ื”ืžืืคืฉืจื•ืช ืžืชืงืคืช MITM

ื›ื“ื™ ืœื—ืกื•ื ื ืงื•ื“ื•ืช ืชื•ืจืคื”, ื”ื—ื•ืงืจ ื”ืฆื™ืข ืœื‘ืฆืข ืฉื™ื ื•ื™ื™ื ื‘ืชืงืŸ ื”ืžืจื—ื™ื‘ื™ื ืืช ืคืจื•ื˜ื•ืงื•ืœ LMP ื•ืžืฉื ื™ื ืืช ื”ื”ื™ื’ื™ื•ืŸ ืฉืœ ื”ืฉื™ืžื•ืฉ ื‘-KDF (Key Derivation Function) ื‘ืขืช ื™ืฆื™ืจืช ืžืคืชื—ื•ืช ื‘ืžืฆื‘ LSC. ื”ืฉื™ื ื•ื™ ืื™ื ื• ืฉื•ื‘ืจ ืืช ื”ืชืื™ืžื•ืช ืœืื—ื•ืจ, ืืš ื›ืŸ ื’ื•ืจื ืœื”ืคืขืœืช ืคืงื•ื“ืช LMP ื”ืžื•ืจื—ื‘ืช ื•ืœืฉืœื•ื— ืฉืœ 48 ื‘ืชื™ื ื ื•ืกืคื™ื. ื”-Bluetooth SIG, ื”ืื—ืจืื™ ืขืœ ืคื™ืชื•ื— ืชืงื ื™ ื‘ืœื•ื˜ื•ืช', ื”ืฆื™ืข ืœื“ื—ื•ืช ื—ื™ื‘ื•ืจื™ื ื“ืจืš ืขืจื•ืฅ ืชืงืฉื•ืจืช ืžื•ืฆืคืŸ ืขื ืžืคืชื—ื•ืช ื‘ื’ื•ื“ืœ ืฉืœ ืขื“ 7 ื‘ืชื™ื ื›ืืžืฆืขื™ ืื‘ื˜ื—ื”. ื™ื™ืฉื•ื ืฉืชืžื™ื“ ืžืฉืชืžืฉ ื‘ืžืฆื‘ ืื‘ื˜ื—ื” 4 ืจืžื” 4 ืžื•ืžืœืฅ ืœื“ื—ื•ืช ื—ื™ื‘ื•ืจื™ื ืขื ืžืคืชื—ื•ืช ื‘ื’ื•ื“ืœ ืฉืœ ืขื“ 16 ื‘ืชื™ื.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”