
모듈식 Bluetooth Classic(BR/EDR) 취약성 테스트 프레임워크로, 정찰 기능과 43개의 공개 공격/CVE용 익스플로잇 모듈, 구조화된 JSON 보고를 제공합니다.
문서 • 설치 • 사용법 • 익스플로잇 • 하드웨어 • 할 일 • 자동차 평가 • Bluetooth 리소스 • 라이선스
BlueToolkit은 Bluetooth Classic(BR/EDR) 및 Bluetooth Low Energy(BLE)를 위한 모듈식 블랙박스 Bluetooth 보안 테스트 프레임워크입니다. 반자동 테스트를 지원하며 세 가지 주요 모듈이 있습니다:
우리는 BlueToolkit을 다양한 제조사의 22개 차량(Audi, BMW, Chevrolet, Honda, Hyundai, Mercedes-Benz, Mini, Opel, Polestar, Renault, Skoda, Toyota, VW, Tesla)에서 평가했으며 128개의 취약점을 발견했습니다.
또한 이미 수립된 연결 또는 MitM 위치에서 MAP을 통한 온라인 계정 하이재킹 방법을 보여줍니다.
이 연구는 WOOT 25'에 채택된 연구 논문으로 이어졌습니다: 링크가 생기면 추가 예정
BlueToolkit은 베어메탈 Ubuntu/Debian 시스템(권장) 또는 가상 머신을 사용하여 설치할 수 있습니다. 두 경우 모두 설치 프로그램은 특정 하드웨어 장치가 연결되어 있어야 하는 Braktooth 및 BluetoothAssistant용 특정 모듈 설치를 요청합니다. 독립형 모듈 설치는 설치 프로그램을 다시 실행하여 별도로 수행할 수도 있습니다.
전제 조건:
설치 후:
* 가상 머신이 USB를 통해 Bluetooth 모듈 또는 추가 하드웨어에 액세스할 수 있도록 허용하려면 다음을 수행해야 합니다:
* USB 지원은 이미 켜져 있으므로 VirtualBox를 여세요
* 실행 중인 가상 머신을 찾아 "Show"를 클릭하세요
* "Devices" -> "USB"를 클릭하세요
* 가상 머신에 대해 활성화할 수 있는 여러 장치가 표시됩니다
* 필요한 장치(Bluetooth 모듈, 하드웨어, 휴대폰)를 체크하거나 확실히 하려면 모든 장치를 체크하세요.
</details>
### 사용법
`bluekit -h`를 실행하여 BlueToolkit 사용 정보를 표시하세요:```console
usage: bluekit [-h] [-t TARGET] [-l] [-c] [-ct] [-ch] [-v VERBOSITY] [-ex EXCLUDEEXPLOITS [EXCLUDEEXPLOITS ...]] [-e EXPLOITS [EXPLOITS ...]] [-r] [-re] [-rej] [-hh HARDWARE [HARDWARE ...]] ...
positional arguments:
rest
options:
-h, --help show this help message and exit
-t TARGET, --target TARGET
target MAC address
-l, --listexploits List exploits or not
-c, --checksetup Check whether Braktooth is available and setup
-ct, --checktarget Check connectivity and availability of the target
-ch, --checkpoint Start from a checkpoint
-v VERBOSITY, --verbosity VERBOSITY
Verbosity level
-ex EXCLUDEEXPLOITS [EXCLUDEEXPLOITS ...], --excludeexploits EXCLUDEEXPLOITS [EXCLUDEEXPLOITS ...]
Exclude exploits, example --exclude exploit1, exploit2
-e EXPLOITS [EXPLOITS ...], --exploits EXPLOITS [EXPLOITS ...]
Scan only for provided --exploits exploit1, exploit2; --exclude is not taken into account
-r, --recon Run a recon script
-re, --report Create a report for a target device
-rej, --reportjson Create a report for a target device
-hh HARDWARE [HARDWARE ...], --hardware HARDWARE [HARDWARE ...]
Scan only for provided exploits based on hardware --hardware hardware1 hardware2; --exclude and --exploit are not taken into account
Some usage examples are:
사용 가능한 모든 익스플로잇 나열(루트 불필요):
bluekit -l
정찰(recon) 실행:
sudo bluekit -t AA:BB:CC:DD:EE:FF -r
연결 테스트:
sudo bluekit -t AA:BB:CC:DD:EE:FF -ct
하나 이상의 익스플로잇 테스트(공백으로 구분):
sudo bluekit -t AA:BB:CC:DD:EE:FF -e invalid_max_slot au_rand_flooding internalblue_knob
더 많은 문서는 위키에서 확인할 수 있습니다.
일부 공격에는 특정 하드웨어가 필요합니다:
BlueToolkit은 모든 취약점 및 하드웨어 템플릿을 자동으로 다운로드합니다. BlueToolkit 템플릿 저장소에는 바로 사용할 수 있는 템플릿의 전체 목록이 있습니다. 또한 BlueToolkit의 템플릿 가이드를 따라 자신만의 템플릿과 검사를 작성하고 새 하드웨어를 추가할 수 있습니다. YAML 참조 구문은 여기에서 확인할 수 있습니다.
우리는 "Awesome Bluetooth Security" 방식으로 블루투스 취약점을 수집하고 분류했습니다. 다음 출처를 사용했습니다 - ACM, IEEE SP, Blackhat, DEFCON, Car Hacking Village, NDSS, Google Scholars. Google, Baidu, Yandex, Bing과 같은 검색 엔진에서 다음 키워드를 검색했습니다 - Bluetooth security toolkit, Bluetooth exploits github, Bluetooth security framework, bluetooth pentesting toolkit. 또한 다음 매개변수를 기준으로 모든 Github 저장소를 파싱했습니다 - topic:bluetooth topic:exploit, topic:bluetooth topic:security.
수동 공격은 문서를 참조하세요.