Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
android712-blueborne — Android Blueborne RCE CVE-2017-0781 | Kitploit
Tools/GitHubGitHub/x3ero0/android712-blueborne
Android SecurityBluetooth SecurityMemory ForensicsVulnerability AnalysisExploitationRemote Access ToolPayload DevelopmentBinary Exploitation
GitHubx3ero0/android712-blueborne

android712-blueborne

Android Blueborne RCE CVE-2017-0781

View Repository
219168 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

android712-blueborne

Android Blueborne RCE CVE-2017-0781

In November 2017 a company called Armis published a proof of concept (PoC) of a remote code execution vulnerability in Android via Bluetooth (CVE-2017-0781), known as BlueBorne. Although BlueBorne refers to a set of 8 vulnerabilities, this PoC in this article uses only 2 of them to achieve its goal.

BlueBorne only requires that a Bluetooth connection on a device be active. No user action is required, with devices not even needing to be paired. All a hacker needs to do is be in Bluetooth range of your device to take it over.

The exploitation process is divided into 2 phases, first the memory leak vulnerability (CVE-2017-0785) is used to know the memory addresses and bypass the ASLR protection, and thus make a call to the function libc library system and execute code on the phone, create a file ("/data/local/tmp/test"). You can change the payload what you want, including making the Mobile connect to you (reverse shell).

In this article I want to show that it is possible to execute and/or take over an affected phone (those without BlueBorne patch, without Android’s September 2017 security patch).

If you are interested below are the debugger logs and exection log, along with proof of payload exection.

For testing purposes removed the CVE-2017-0781 patches and compiled Android 7.1.2 (LineageOS CM 14.1) on my test mobile Samsung S3 Neo+ GT-9301I

More info here:

https://github.com/marcinguy/S3NEO--GT301I

After dozen of executions got this condition in. Each execution is around 2-3 sec. So you can own/take over the mobile in less than a half of the minute.

License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.  Type "show copying"
and "show warranty" for details.
This GDB was configured as "arm-linux-androideabi".
Type "show configuration" for configuration details.
For bug reporting instructions, please see:
<http://www.gnu.org/software/gdb/bugs/>.
Find the GDB manual and other documentation resources online at:
<http://www.gnu.org/software/gdb/documentation/>.
For help, type "help".
Type "apropos word" to search for commands related to "word".
(gdb) attach 15513
Attaching to process 15513
[New LWP 15518]
[New LWP 15519]
[New LWP 15520]
[New LWP 15521]
[New LWP 15522]
[New LWP 15523]
[New LWP 15524]
[New LWP 15525]
[New LWP 15526]
[New LWP 15529]
[New LWP 15530]
[New LWP 15531]
[New LWP 15532]
[New LWP 15533]
[New LWP 15534]
[New LWP 15535]
[New LWP 15536]
[New LWP 15537]
[New LWP 15538]
[New LWP 15539]
[New LWP 15541]
[New LWP 15540]
[New LWP 15543]
[New LWP 15544]
[New LWP 15545]
[New LWP 15546]
[New LWP 15547]
[New LWP 15548]
[New LWP 15549]
[New LWP 15550]
[New LWP 15551]
[New LWP 15552]
[New LWP 15556]
[New LWP 15557]
[New LWP 15558]
[New LWP 15559]
[New LWP 15560]
[New LWP 15562]
[New LWP 15563]
[New LWP 15565]
[New LWP 15569]
[New LWP 15570]
[New LWP 15577]
[New LWP 15578]
0xb5219114 in __epoll_pwait () from target:/system/lib/libc.so
(gdb) b *0xb5216b4d
warning: Breakpoint address adjusted from 0xb5216b4d to 0xb5216b4c.
Breakpoint 1 at 0xb5216b4c
(gdb) disass system
Dump of assembler code for function system:
   0xb5216b4c <+0>:	push	{r4, r5, r6, lr}
   0xb5216b4e <+2>:	sub	sp, #72	; 0x48
   0xb5216b50 <+4>:	ldr	r1, [pc, #236]	; (0xb5216c40 <system+244>)
   0xb5216b52 <+6>:	cmp	r0, #0
   0xb5216b54 <+8>:	ldr	r2, [pc, #236]	; (0xb5216c44 <system+248>)
   0xb5216b56 <+10>:	add	r1, pc
   0xb5216b58 <+12>:	ldr	r1, [r1, #0]
   0xb5216b5a <+14>:	add	r2, pc
   0xb5216b5c <+16>:	vld1.64	{d16-d17}, [r2]
   0xb5216b60 <+20>:	ldr	r1, [r1, #0]
   0xb5216b62 <+22>:	str	r1, [sp, #68]	; 0x44
   0xb5216b64 <+24>:	add	r1, sp, #48	; 0x30
   0xb5216b66 <+26>:	vst1.64	{d16-d17}, [r1]
   0xb5216b6a <+30>:	beq.n	0xb5216bf6 <system+170>
   0xb5216b6c <+32>:	add	r4, sp, #12
   0xb5216b6e <+34>:	str	r0, [sp, #56]	; 0x38
   0xb5216b70 <+36>:	mov	r0, r4
   0xb5216b72 <+38>:	blx	0xb51e4a38 <sigemptyset@plt>
   0xb5216b76 <+42>:	mov	r0, r4
   0xb5216b78 <+44>:	movs	r1, #17
   0xb5216b7a <+46>:	blx	0xb51e511c <sigaddset@plt>
   0xb5216b7e <+50>:	add	r2, sp, #8
---Type <return> to continue, or q <return> to quit---q
Quit
(gdb) cont
Continuing.
[New LWP 15912]
[Switching to LWP 15540]
warning: Breakpoint 1 address previously adjusted from 0xb5216b4d to 0xb5216b4c.
Download Tool