BLUFFS — dobĂ«sitĂ« nĂ« Bluetooth qĂ« lejojnĂ« njĂ« sulm MITM.

Daniele Antonioli, një hulumtues i sigurisë Bluetooth, i cili më parë ka zhvilluar teknika sulmi si BIAS, BLUR dhe KNOB, ka zbuluar dy vulnerabilitete të reja (CVE-2023-24023) në mekanizmin e negocimit të seancave Bluetooth, që prekin të gjitha implementimet e Bluetooth që mbështesin modet e lidhjes së sigurta 'Secure Connections' dhe 'Secure Simple Pairing', të cilat përputhen me specifikimet Bluetooth Core 4.2-5.4. Si demonstrim i përdorimit praktik të vulnerabiliteteve të zbuluara, janë zhvilluar 6 variante sulmesh që lejojnë ndërhyrjen në lidhjet midis pajisjeve Bluetooth që janë lidhur më parë. Kodi me implementimin e metodave të sulmit dhe mjeteve për të kontrolluar praninë e vulnerabiliteteve është botuar në GitHub.

Vulnerabilitetet u zbuluan gjatë analizës së mekanizmave të arritjes së sekretit të drejtpërdrejtë (Forward and Future Secrecy) të përshkruara në standard, të cilat parandalojnë komprometimin e çelësave të seancës në rast se çelësi i përhershëm përcaktohet (komprometimi i njërit nga çelësat e përhershëm nuk duhet të çojë në dekriptimin e seancave që janë kapur më parë ose të ardhshme) dhe ripërdorimin e çelësave të seancës (çelësi nga një seancë nuk duhet të aplikohet në një seancë tjetër). Vulnerabilitetet e gjetura lejojnë anashkalimin e mbrojtjes së përmendur dhe ripërdorimin e një çelësi seance të pasigurt në seanca të ndryshme. Vulnerabilitetet janë të shkaktuara nga mangësi në standardin bazë, nuk janë specifike për stekët e veçantë të Bluetooth dhe shfaqen në çipa të prodhuesve të ndryshëm.

BLUFFS - vulnerabilities in Bluetooth that allow for MITM attacks

Metodat e proponuara të sulmit implementojnë variante të ndryshme të organizimit të spufingut të lidhjeve klasike (LSC, Legacy Secure Connections të bazuara në primitivë të vjetruar kriptografikë) dhe të sigurta (SC, Secure Connections të bazuara në ECDH dhe AES-CCM) midis sistemit dhe pajisjes periferike, si dhe organizimin e sulmeve MITM për lidhjet në modet LSC dhe SC. Supozohet se të gjitha realizimet e Bluetooth, që i përkasin standardit, janë të ekspozuara ndaj varianti të caktuar të sulmit BLUFFS. Funksionimi i metodës është demonstruar në 18 pajisje nga kompani të tilla si Intel, Broadcom, Apple, Google, Microsoft, CSR, Logitech, Infineon, Bose, Dell dhe Xiaomi.

BLUFFS - vulnerabilities in Bluetooth that allow for MITM attacks

The essence of the vulnerabilities lies in the possibility of forcibly rolling back the connection to use an old LSC mode and an unreliable short session key (SK) without violating the standard, by specifying the minimal possible entropy during the connection negotiation process and ignoring the content of the authentication parameters response (CR), leading to the generation of a session key based on constant input parameters (the session key SK is calculated as KDF from the permanent key (PK) and parameters agreed upon during the session). For example, an attacker during a MITM attack can replace the session negotiation parameters đŽđ¶ and đ‘†đ· with zero values, while setting the entropy 𝑆𝐾 to 1, which will result in a session key đ‘†đŸ with an actual entropy of 1 byte (the standard minimum entropy size is 7 bytes (56 bits), which corresponds to a reliability level comparable to brute-forcing DES keys).

If the attacker manages to have a shorter key used during the connection negotiation, they can then use brute force to determine the permanent key (PK) used for encryption and achieve decryption of the traffic between devices. Since during a MITM attack one can initiate the use of the same encryption key, if this key is guessed, it can also be used to decrypt all past and future sessions intercepted by the attacker.

BLUFFS - vulnerabilities in Bluetooth that allow for MITM attacks

To block the vulnerabilities, researchers have proposed amendments to the standard that expand the LMP protocol and change the logic of using KDF (Key Derivation Function) when forming keys in LSC mode. The change does not break backward compatibility, but leads to the inclusion of an extended LMP command and the need to send an additional 48 bytes. The Bluetooth SIG organization, responsible for developing Bluetooth standards, has proposed as a protective measure to reject connections over an encrypted communication channel with keys of up to 7 bytes in size. Implementations that always apply Security Mode 4 Level 4 are recommended to reject connections with keys sized up to 16 bytes.

Burimi: opennet.ru

Blini hosting tĂ« besueshĂ«m pĂ«r faqe interneti me mbrojtje nga DDoS, serverĂ« VPS VDS đŸ”„ Blini hosting tĂ« besueshĂ«m pĂ«r faqe interneti me mbrojtje nga DDoS, serverĂ« VPS VDS | ProHoster