Skip to content
KitploitKITPLOIT
도구블로그
Log in
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
whisperpair-poc-tool — CVE-2025-36911: Fast Pair Pairing Mode Bypass 취약점을 식별하고 시연하는 보안 연구 도구 | Kitploit
도구/GitHubGitHub/aalex954/whisperpair-poc-tool
ReconnaissanceBluetooth SecurityVulnerability AnalysisExploitationInformation GatheringWireless SecurityPenetration TestingHardware SecurityRed Teaming
GitHubaalex954/whisperpair-poc-tool

whisperpair-poc-tool

CVE-2025-36911: Fast Pair Pairing Mode Bypass 취약점을 식별하고 시연하는 보안 연구 도구

7238개월 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
저장소 보기

WhisperPair-PoC-Tool 및 연구

CVE-2025-36911과 Google Fast Pair 생태계의 보안 취약점에 대한 심층 분석

블로그 게시물

데모

요약

Google Fast Pair는 Bluetooth 페어링을 매끄럽게 만들기 위해 설계되었습니다. 알림을 탭하면 연결되는 방식입니다. 하지만 이 매끄러운 경험이 보안상의 책임이 되면 어떻게 될까요? WhisperPair-PoC-Tool은 수백만 개의 Bluetooth 액세서리에 영향을 미치는 두 가지 중요한 취약점 클래스, 즉 무단 페어링 우회와 Find My Device 네트워크 추적 악용을 드러내는 보안 연구 도구입니다.

이 글은 WhisperPair-PoC-Tool의 기술적 내부 구조, 이 도구가 악용하는 프로토콜 취약점, 그리고 이것이 Bluetooth 액세서리 생태계에 의미하는 바를 자세히 설명합니다.


목차

  1. 취약점
  2. Fast Pair 프로토콜 입문
  3. WhisperPair-PoC-Tool 작동 방식
  4. 공격 표면
  5. 탐지 방법론
  6. 악용 기능
  7. 수정 지침
  8. 윤리적 고려 사항

취약점

CVE-2025-36911: Fast Pair 페어링 모드 우회

Google Fast Pair 사양은 명시적으로 다음과 같이 명시합니다:

"선택적 공개 키(Public Key) 필드가 있는 경우: 기기가 페어링 모드가 아니면 쓰기를 무시하고 종료합니다."

  • Google Fast Pair GATT 프로시저 사양

이것이 중요한 보안 관문입니다. 기기는 사용자가 명시적으로 페어링 모드로 전환한 경우(일반적으로 버튼을 길게 누름)에만 키 기반 페어링(Key-Based Pairing) 요청에 응답해야 합니다. 이는 사용자 의도를 보장하므로, 상대방이 착용 중인 이어버드에 페어링할 수 없습니다.

문제점: 많은 제조사가 이 검사를 완전히 건너뜁니다. 페어링 모드 상태와 관계없이 페어링 요청을 처리하여 다음과 같은 문제를 가능하게 합니다:

  • 사용자 상호작용 없는 무음 페어링
  • 근접 공격에서의 액세서리 하이재킹
  • 피해자 기기에 연결하여 발생하는 개인정보 침해

Find Hub 계정 키 노출

Google의 Find My Device 네트워크(FMDN)는 크라우드소싱된 Android 기기 네트워크를 통해 Bluetooth 액세서리를 추적할 수 있게 해줍니다. 이를 위해서는 기기를 Google 계정에 연결하는 16바이트 대칭 키인 **계정 키(Account Key)**가 필요합니다.

문제점: Account Key 특성(characteristic)은 인증 없이 쓰기를 허용하는 경우가 많습니다:

  • 공격자가 기존 Account Key를 덮어쓸 수 있음
  • 피해자의 Find My Device 통합이 중단됨
  • 공격자가 자신의 키를 사용하여 기기를 추적할 수 있음
  • 공장 초기화 전까지 지속됨

Fast Pair 프로토콜 입문

악용에 대해 자세히 살펴보기 전에, 정상적인 Fast Pair 흐름을 이해해 봅시다:

광고 단계

┌─────────────────────────────────────────────────────────────┐
│                    BLE Advertisement                         │
├─────────────────────────────────────────────────────────────┤
│  Service UUID: 0xFE2C (Fast Pair)                           │
│  Service Data:                                               │
│    [Pairing Mode]   → 3 bytes: Model ID only                │
│    [Not Pairing]    → 4+ bytes: 0x00 + Account Key Filter   │
└─────────────────────────────────────────────────────────────┘

광고 형식은 페어링 상태를 드러냅니다:

  • 3바이트 = Model ID만 = 기기 검색 가능(페어링 모드)
  • 4바이트 이상 = 버전 바이트 + Account Key 데이터 = 페어링 모드 아님

키 기반 페어링 핸드셰이크

Seeker (Phone)                              Provider (Accessory)
      │                                              │
      │───── GATT Connect ──────────────────────────>│
      │                                              │
      │───── Discover Services ─────────────────────>│
      │<──── Service: 0xFE2C ────────────────────────│
      │                                              │
      │───── Enable Notifications (0xFE2C1234) ─────>│
      │                                              │
      │───── Write Key-Based Pairing Request ───────>│
      │      [16-byte encrypted block]               │
      │      [64-byte ECDH Public Key] (optional)    │
      │                                              │
      │      ┌────────────────────────────────────┐  │
      │      │ SECURITY CHECK:                    │  │
      │      │ If Public Key present AND          │  │
      │      │ device NOT in pairing mode:        │  │
      │      │   → IGNORE and EXIT                │  │
      │      │ Else:                              │  │
      │      │   → Process request                │  │
      │      └────────────────────────────────────┘  │
      │                                              │
      │<──── Notification: Encrypted Response ───────│
      │      [Provider's BR/EDR Address]             │
      │                                              │
      │═══════ Bluetooth Classic Pairing ═══════════>│

취약점은 기기가 'SECURITY CHECK' 상자를 완전히 건너뛸 때 발생합니다.


WhisperPair-PoC-Tool 작동 방식

WhisperPair-PoC-Tool은 Bleak BLE 라이브러리 기반의 Python 기반 보안 연구 도구입니다. 여러 단계로 작동합니다:

아키텍처 개요

┌────────────────────────────────────────────────────────────────┐
│                        WhisperPair-PoC-Tool                          │
├────────────────────────────────────────────────────────────────┤
│  CLI Layer                                                      │
│  ├── Argument parsing (--target-name, --scan-duration)         │
│  ├── TargetPolicy construction                                  │
│  └── REPL initialization                                        │
├────────────────────────────────────────────────────────────────┤
│  Discovery Engine                                               │
│  ├── BLE scanning via Bleak                                    │
│  ├── Advertisement parsing                                      │
│  ├── Protocol detection (Fast Pair, FMDN, Swift Pair)          │
│  └── Device fingerprinting (Model ID, OUI lookup)              │
├────────────────────────────────────────────────────────────────┤
│  Check Engines                                                  │
│  ├── FastPairCheckEngine (passive advertisement analysis)      │
│  ├── FastPairBypass (active CVE-2025-36911 testing)           │
│  ├── FindHubCheckEngine (Account Key status detection)         │
│  └── RiskScorer (composite vulnerability assessment)           │
├────────────────────────────────────────────────────────────────┤
│  Connection Manager                                             │
│  ├── GATT connect with MTU negotiation                         │
│  ├── Service/characteristic discovery                          │
│  ├── Read/Write/Notify operations                              │
│  └── Error handling and retry logic                            │
├────────────────────────────────────────────────────────────────┤
│  Exploitation Modules                                           │
│  ├── ring_device() - Trigger locator sound                     │
│  ├── set_account_key() - Write Account Key                     │
│  └── Response parsing (BR/EDR address extraction)              │
└────────────────────────────────────────────────────────────────┘

핵심 구성 요소

1. 검색 엔진 (discovery.py)

스캐너는 Bleak의 탐지 콜백을 사용하여 BLE 광고를 캡처합니다:

async def _detection_callback(
    self, device: BLEDevice, advertisement_data: AdvertisementData
) -> None:
    """Process each detected BLE advertisement."""
    discovered = DiscoveredDevice(
        address=device.address,
        name=device.name or advertisement_data.local_name,
        rssi=advertisement_data.rssi,
        advertisement=self._convert_advertisement(advertisement_data),
        first_seen=datetime.now(UTC),
        last_seen=datetime.now(UTC),
    )
    self._devices[device.address] = discovered

각 기기에 대해 도구는 다음을 추출합니다:

  • 서비스 UUID (Fast Pair 0xFE2C, FMDN 0xFD44 등 탐지)
  • 제조업체 데이터 (Google 0x00E0, Apple 0x004C)
  • 서비스 데이터 (Model ID 및 페어링 상태 파싱)

2. 페어링 모드 추론 (fastpair.py)

기기의 광고를 분석하여 페어링 모드를 결정합니다:

도구 다운로드