
Bluetooth 해킹을 위한 정보 수집 도구
Bluing(이전 명칭 bluescan)은 주로 Python으로 작성된 블루투스 정보 수집(Bluetooth Intelligence Gathering) 도구입니다. 이 도구는 복잡한 프로토콜인 블루투스의 내부 구조를 염탐하거나 블루투스 장치를 해킹하는 데 도움을 줄 수 있습니다. 주요 기능은 다음과 같습니다:
Bluing은 부분적으로 Linux 공식 블루투스 프로토콜 스택인 BlueZ에 의존합니다. 따라서 Linux에서만 실행을 지원합니다. 다음 명령어는 의존성을 설치하는 데 사용됩니다:```sh
sudo apt install python3-pip python3-dev libcairo2-dev libgirepository1.0-dev
libbluetooth-dev libdbus-1-dev bluez-tools python3-cairo-dev
rfkill meson patchelf bluez ubertooth adb python-is-python3
현재, bluing은 [PyPI](https://pypi.org/project/bluing/)를 통해 배포되며 **Python 3.10만 지원합니다**. 다음은 설치 명령입니다:```sh
sudo pip3.10 install bluing
$ bluing --helpAn intelligence gathering tool for hacking Bluetooth
Usage:
bluing [-h | --help]
bluing (-v | --version)
bluing [-i <hci>] --clean BD_ADDR
bluing --flash-micro-bit
bluing <command> [<args>...]
Arguments:
BD_ADDR Bluetooth device address
Options:
-h, --help Print this help and quit
-v, --version Print version information and quit
-i <hci> HCI device
--clean Clean cached data of a remote device
--flash-micro-bit Download the dedicated firmware to micro:bit(s)
Commands:
br Basic Rate system, includes an optional Enhanced Data Rate (EDR) extension
le Low Energy system
android Android Bluetooth stack
spoof Spoof with new local device information
plugin Manage plugins
Run `bluing <command> --help` for more information on a command.
br 명령어: 기본 전송률 시스템$ bluing br --helpUsage:
bluing br [-h | --help]
bluing br [-i <hci>] [--inquiry-len=<n>] --inquiry
bluing br [-i <hci>] --sdp BD_ADDR
bluing br [-i <hci>] --local --sdp
bluing br [-i <hci>] --lmp-features BD_ADDR
bluing br [-i <hci>] --local --lmp-features
bluing br [-i <hci>] --stack BD_ADDR
bluing br [-i <hci>] --local --stack
bluing br [-i <hci>] [--inquiry-scan] --mon-incoming-conn
bluing br --org=<name> --timeout=<sec> --sniff-and-guess-bd-addr
Arguments:
BD_ADDR BR/EDR Bluetooth device address
Options:
-h, --help Print this help and quit
-i <hci> HCI device
--local Target a local BR/EDR device instead of a remote one
--inquiry Discover other nearby BR/EDR controllers
--inquiry-len=<n> Maximum amount of time (added to --ext-inquiry-len=<n>)
specified before the Inquiry is halted.
Time = n * 1.28 s
Time range: 1.28 to 61.44 s
Range of n: 0x01 to 0x30 [default: 8]
--ext-inquiry-len=<n> Extended_Inquiry_Length measured in number of
Baseband slots.
Interval Length = n * 0.625 ms (1 Baseband slot)
Time Range: 0 to 40.9 s
Range of n: 0x0000 to 0xFFFF [default: 0]
--sdp Retrieve information from the SDP database of a
remote BR/EDR device
--lmp-features Read LMP features of a remote BR/EDR device
--stack Determine the Bluetooth stack type of a remote BR/EDR device
--mon-incoming-conn Print incoming connection from other nearby BR/EDR devices
--inquiry-scan Enable the Inquiry Scan
--sniff-and-guess-bd-addr Sniff SAPs of BD_ADDRs over the air, then guess the
address based on the organization name. Need at
least one Ubertooth device
--org=<name> An organization name in the OUI.txt
--timeout=<sec> Timeout in second(s)
--inquiry: 주변 BR/EDR 컨트롤러 검색$ sudo bluing br --inquiry[INFO] Discovering other nearby BR/EDR Controllers on hci0 for 10.24 sec