Skip to content
KitploitKITPLOIT
FerramentasBlog
Enviar
FerramentasBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
Ferramentas/GitHubGitHub/fo-000/bluing
Segurança AndroidReconhecimentoSegurança BluetoothSegurança IoTColeta de InformaçõesSegurança Sem Fio
GitHubfo-000/bluing

bluing

Uma ferramenta de coleta de inteligência para hackear Bluetooth

Ver Repositório
1.0k130há 3 anosRevisado pelo Kitploit

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar

Bluing

Uma ferramenta de coleta de inteligência para hackear Bluetooth

English · 简体中文

Bluing (anteriormente bluescan) é uma ferramenta de coleta de inteligência (Bluetooth Intelligence Gathering) escrita principalmente em Python. Pode nos ajudar a espionar a estrutura interna do Bluetooth, que é um protocolo complexo, ou hackear dispositivos Bluetooth. Aqui estão as principais funcionalidades da ferramenta:

Instalação

Bluing depende parcialmente do BlueZ, a pilha oficial de protocolos Bluetooth do Linux. Portanto, só suporta execução no Linux. O comando a seguir é usado para instalar as dependências:```sh sudo apt install python3-pip python3-dev libcairo2-dev libgirepository1.0-dev
libbluetooth-dev libdbus-1-dev bluez-tools python3-cairo-dev
rfkill meson patchelf bluez ubertooth adb python-is-python3

root@kitploit:~
Atualmente, o bluing é distribuído via [PyPI](https://pypi.org/project/bluing/) e **suporta apenas Python 3.10**. O seguinte é um comando de instalação:```sh
sudo pip3.10 install bluing

Uso

  • Deus disse: "Haja colorido", e houve colorido.
  • Talvez queira uma breve visão geral do hardware recomendado.
$ bluing --help
root@kitploit:~
An intelligence gathering tool for hacking Bluetooth

Usage:
    bluing [-h | --help]
    bluing (-v | --version)
    bluing [-i <hci>] --clean BD_ADDR
    bluing --flash-micro-bit
    bluing <command> [<args>...]

Arguments:
    BD_ADDR    Bluetooth device address

Options:
    -h, --help           Print this help and quit
    -v, --version        Print version information and quit
    -i <hci>             HCI device
    --clean              Clean cached data of a remote device
    --flash-micro-bit    Download the dedicated firmware to micro:bit(s)

Commands:
    br         Basic Rate system, includes an optional Enhanced Data Rate (EDR) extension
    le         Low Energy system
    android    Android Bluetooth stack
    spoof      Spoof with new local device information
    plugin     Manage plugins

Run `bluing <command> --help` for more information on a command.

Comando br: sistema Basic Rate

$ bluing br --help
root@kitploit:~
Usage:
    bluing br [-h | --help]
    bluing br [-i <hci>] [--inquiry-len=<n>] --inquiry
    bluing br [-i <hci>] --sdp BD_ADDR
    bluing br [-i <hci>] --local --sdp
    bluing br [-i <hci>] --lmp-features BD_ADDR
    bluing br [-i <hci>] --local --lmp-features
    bluing br [-i <hci>] --stack BD_ADDR
    bluing br [-i <hci>] --local --stack
    bluing br [-i <hci>] [--inquiry-scan] --mon-incoming-conn
    bluing br --org=<name> --timeout=<sec> --sniff-and-guess-bd-addr

Arguments:
    BD_ADDR    BR/EDR Bluetooth device address

Options:
    -h, --help                   Print this help and quit
    -i <hci>                     HCI device
    --local                      Target a local BR/EDR device instead of a remote one
    --inquiry                    Discover other nearby BR/EDR controllers
    --inquiry-len=<n>            Maximum amount of time (added to --ext-inquiry-len=<n>) 
                                 specified before the Inquiry is halted.
                                     Time = n * 1.28 s
                                     Time range: 1.28 to 61.44 s
                                     Range of n: 0x01 to 0x30 [default: 8]
    --ext-inquiry-len=<n>        Extended_Inquiry_Length measured in number of 
                                 Baseband slots.
                                     Interval Length = n * 0.625 ms (1 Baseband slot)
                                     Time Range: 0 to 40.9 s
                                     Range of n: 0x0000 to 0xFFFF [default: 0]
    --sdp                        Retrieve information from the SDP database of a 
                                 remote BR/EDR device
    --lmp-features               Read LMP features of a remote BR/EDR device
    --stack                      Determine the Bluetooth stack type of a remote BR/EDR device
    --mon-incoming-conn          Print incoming connection from other nearby BR/EDR devices
    --inquiry-scan               Enable the Inquiry Scan
    --sniff-and-guess-bd-addr    Sniff SAPs of BD_ADDRs over the air, then guess the 
                                 address based on the organization name. Need at 
                                 least one Ubertooth device
    --org=<name>                 An organization name in the OUI.txt
    --timeout=<sec>              Timeout in second(s)

--inquiry: Descobrir outros controladores BR/EDR próximos

$ sudo bluing br --inquiry
root@kitploit:~
[INFO] Discovering other nearby BR/EDR Controllers on hci0 for 10.24 sec

BD_ADDR: B0:C9:52:45:33:13 (GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP.,LTD)
Page scan repetition mode: 1 (R1)
Reserved: 0x02
CoD: 0x5a020c
    Service Class: 0b1011010000
        Telephony
        Object Transfer
        Capturing
        Networking
    Major Device Class: 0b00010, Phone
Clock offset: 0x50D5
RSSI: -61
Extended inquiry response: 
    Complete Local Name: old man phone
    Complete List of 16-bit Service Class UUIDs
        0x1105 OBEXObjectPush
        0x110a AudioSource
        0x110c A/V_RemoteControlTarget
        0x110e A/V_RemoteControl
        0x1112 Headset - Audio Gateway (AG)
        0x1115 PANU
        0x1116 NAP
        0x111f HandsfreeAudioGateway
        0x112d SIM_Access
        0x112f Phonebook Access - PSE
        0x1200 PnPInformation
        0x1132 Message Access Server
    Complete List of 32-bit Service Class UUIDs
        None
    Complete List of 128-bit Service Class UUIDs
        A49EAA15-CB06-495C-9F4F-BB80A90CDF00
        00000000-0000-0000-0000-000000000000
... ...


[INFO] Requesting the names of all discovered devices...
B0:C9:52:45:33:13 : old man phone
... ...

--sdp: Recuperar informações da base de dados SDP de um dispositivo BR/EDR remoto

$ sudo bluing br --sdp 34:13:46:23:6A:4D
root@kitploit:~
Scanning ⠋
Number of service records: 18 

Service Record
0x0000: ServiceRecordHandle (uint32)
    0x0001000d
0x0001: ServiceClassIDList (sequence)
    0x1105: OBEXObjectPush
0x0004: ProtocolDescriptorList (sequence)
    0x0100: L2CAP
    0x0003: RFCOMM
        channel: 0x0c
    0x0008: OBEX
0x0005: BrowseGroupList (sequence)
    0x1002: PublicBrowseRoot
0x0009: BluetoothProfileDescriptorList (sequence)
    0x1105: OBEXObjectPush v1.2
0x0100: ServiceName (guess) (text)
    OBEX Object Push 
0x0200: GoepL2CapPsm (guess) (uint16)
	0x1023
0x0303: SupportedFormatsList (guess) (sequence)
    0x01: vCard 2.1
    0x02: vCard 3.0
    0x03: vCal 1.0
    0x04: iCal 2.0
    0xff: Any type of object
... ...

--lmp-features: Ler características LMP de um dispositivo BR/EDR remoto

$ sudo bluing br --lmp-features 6A:8D:99:33:56:AE
root@kitploit:~
Version
    Version:
        Bluetooth Core Specification 5.2 (LMP)
        Bluetooth Core Specification 5.2 (LL)
    Manufacturer name: HiSilicon Technologies CO., LIMITED
    Subversion: 33561 

LMP features
    3 slot packets: True
    5 slot packets: True
    Encryption: True
    Slot offset: True
    Timing accuracy: True
    Role switch: True
    Hold mode: False
    Sniff mode: True
    Previously used: False
    Power control requests: True
    Channel quality driven data rate (CQDDR): True
    ... ...

Extended LMP features
Page 1
    Secure Simple Pairing (Host Support): True
    LE Supported (Host): True
    Simultaneous LE and BR/EDR to Same Device Capable (Host): True
    Secure Connections (Host Support): True
Page 2
    Connectionless Slave Broadcast - Master Operation: False
    Connectionless Slave Broadcast - Slave Operation: False
    Synchronization Train: False
    Synchronization Scan: False
    HCI_Inquiry_Response_Notification event:  True
    ... ...

--mon-incoming-conn: Mostrar conexões recebidas de outros dispositivos BR/EDR próximos

$ sudo bluing br --inquiry-scan --mon-incoming-conn
root@kitploit:~
[INFO] Inquiry_Scan_Interval: 4096, 2560.0 ms
       Inquiry_Scan_Window:   4096, 2560.0 ms
[INFO] Inquiry Scan and Page Scan enabled

A0:DE:0F:99:EF:78 incoming
    CoD: 0x5a020c
        Service Class: 0b1011010000
            Telephony
            Object Transfer
            Capturing
            Networking
        Major Device Class: 0b00010, Phone
    link type: 0x01 - ACL
... ...

--sniff-and-guess-bd-addr: Farejar e adivinhar BD_ADDRs próximos pelo ar

$ bluing br --org='Huawei Device Co., Ltd.' --timeout=600 --sniff-and-guess-bd-addr
root@kitploit:~
[INFO] Possible BD_ADDR for ??:??:99:4C:45:C3
        24:A7:99:4C:45:C3

[INFO] Possible BD_ADDR for ??:??:E4:2D:69:EE
        BC:1A:E4:2D:69:EE
        D0:05:E4:2D:69:EE
        30:AA:E4:2D:69:EE

[INFO] Possible BD_ADDR for ??:??:15:60:81:7F
        64:23:15:60:81:7F
        D4:74:15:60:81:7F
... ...

Comando le: sistema Low Energy

$ bluing le --help
root@kitploit:~
Usage:
    bluing le [-h | --help]
    bluing le [-i <hci>] [--scan-type=<type>] [--timeout=<sec>] [--sort=<key>] --scan
    bluing le [-i <hci>] --pairing-feature [--timeout=<sec>] [--addr-type=<type>] PEER_ADDR
    bluing le [-i <hci>] --ll-feature-set [--timeout=<sec>] [--addr-type=<type>] PEER_ADDR
    bluing le [-i <hci>] --gatt [--io-cap=<name>] [--addr-type=<type>] PEER_ADDR
    bluing le [-i <hci>] --local --gatt
    bluing le [-i <hci>] --mon-incoming-conn
    bluing le [--device=</dev/tty>] [--channel=<num>] --sniff-adv

Arguments:
    PEER_ADDR    LE Bluetooth device address

Options:
    -h, --help            Print this help and quit
    -i <hci>              HCI device
    --scan                Discover advertising devices nearby
    --scan-type=<type>    The type of scan to perform. active or passive [default: active]
    --sort=<key>          Sort the discovered devices by key, only support RSSI 
                          now [default: rssi]
    --ll-feature-set      Read LL FeatureSet of a remote LE device
    --pairing-feature     Request the pairing feature of a remote LE device
    --timeout=<sec>       Duration of the LE scanning, but may not be precise [default: 10]
    --gatt                Discover GATT Profile hierarchy of a remote LE device
    --io-cap=<name>       Set IO capability of the agent. Available value: 
                              DisplayOnly, DisplayYesNo, KeyboardOnly, NoInputNoOutput, 
                              KeyboardDisplay (KeyboardOnly) [default: NoInputNoOutput]
    --addr-type=<type>    Type of the LE address, public or random
    --sniff-adv           Sniff advertising physical channel PDU. Need at least 
                          one micro:bit (or other supported NRF51 device specified with --device)
    --channel=<num>       LE advertising physical channel, 37, 38 or 39 [default: 37,38,39]
    --device=</dev/tty>   Device to use, comma separated (e.g., /dev/ttyUSB0,/dev/ttyUSB1,/dev/ttyUSB2)
                          Only needed if using NRF51 devices other than micro:bit (e.g., Bluefruit)

--scan: Descobrir dispositivos a anunciar próximos

$ sudo bluing le --scan
root@kitploit:~
[WARNING] You might want to spoof your LE address before doing an active scan
[INFO] LE active scanning on hci0 for 10 sec
Scanning ⠴

----------------LE Devices Scan Result----------------
Addr:        74:A3:4A:D4:78:55 (ZIMI CORPORATION)
Addr type:   public
Connectable: True
RSSI:        -68 dBm
General Access Profile:
    Flags: 
        LE General Discoverable Mode
        BR/EDR Not Supported
    Service Data - 16-bit UUID: 
        UUID: 0x95FE
        Data: 9055990701b743e34aa3740e00
    Appearance: 0000
    Tx Power Level: 0 dBm (pathloss 68 dBm)
    Complete Local Name: Mesh Mi Switch
... ...

--ll-feature-set: Ler o FeatureSet LL de um dispositivo LE remoto

$ sudo bluing le --ll-feature-set --addr-type=public 18:D9:8F:77:24:F1
root@kitploit:~
[INFO] Reading LL FeatureSet of 18:D9:8F:77:24:F1 on hci0
Reading ⠼
LE LL Features:
    LE Encryption: True
    Connection Parameters Request Procedure: False
    Extended Reject Indication: False
    Slave-initiated Features Exchange: False
    LE Ping: False
    LE Data Packet Length Extension: True
    LL Privacy: False
    Extended Scanner Filter Policies: False
    LE 2M PHY: False
    Stable Modulation Index - Transmitter: False
    Stable Modulation Index - Receiver: False
    ... ...

--pairing-feature: Solicitar a funcionalidade de emparelhamento de um dispositivo LE remoto

$ sudo bluing le --pairing-feature --addr-type=public 18:D9:8F:77:24:F1
root@kitploit:~
[INFO] Requesting pairing feature of 18:D9:8F:77:24:F1 on hci0
Requesting ⠧
Pairing Response
    IO Capability: 0x03 - NoInputNoOutput
    OOB data flag: 0x00 - Not Present
    AuthReq: 0x01
    Maximum Encryption Key Size: 16
Initiator Key Distribution: 0x00
        EncKey:  False
        IdKey:   False
        SignKey: False
        LinkKey: False
        RFU:     0b0000
Responder Key Distribution: 0x01
        EncKey:  True
        IdKey:   False
        SignKey: False
        LinkKey: False
        RFU:     0b0000

--gatt: Descobrir a hierarquia do perfil GATT de um dispositivo LE remoto

$ sudo bluing le --gatt --addr-type=public 18:D9:8F:77:24:F1Conectando ⠋ Descobrindo todos os serviços primários ⠏ Descobrindo todas as características do serviço 0x0001 ⠹ ... ... Descobrindo todos os descritores da característica 0x0002 ⠼ ... ... Lendo valor do descritor 0x0013 ⠴ ... ...

----------------Resultado da Verificação GATT---------------- Número de serviços: 6

Serviço (0x0100 - 0x0112, 7 características) Declaração Handle: 0x0100 Tipo: 2800 (Declaração de serviço primário) Valor: 1812 (Dispositivo de Interface Humana) Permissões: Leitura (sem autenticação/autorização)

root@kitploit:~
<span style="font-weight: bold; color: #ecc179">Característica</span> (2 descritores)
    <span style="font-weight: bold; color: #ecc179">Declaração</span>
        Handle: 0x010d
        Tipo:   2803 (Declaração de característica)
        Valor:
            Propriedades: <span style="font-weight: bold; color: #9fab76">Leitura, Escrita sem Resposta, Escrita, Notificação</span>
            Handle:     <span style="font-weight: bold; color: #9fab76">0x010e</span>
            UUID:       <span style="font-weight: bold; color: #9fab76">2A4D</span> (<span style="font-weight: bold; color: #9fab76">Relatório</span>)
        Permissões: Leitura (sem autenticação/autorização)

    <span style="font-weight: bold; color: #ecc179">Valor</span>
        Handle: 0x0302
        Tipo:   4A02 (Desconhecido)
        Valor:  <span style="font-weight: bold; color: #c35956">Leitura não Permitida</span>
        Permissões: Específico da camada superior

    <span style="font-weight: bold; color: #ecc179">Descritor</span>
        Handle: <span style="font-weight: bold; color: #9fab76">0x010f</span>
        Tipo:   <span style="font-weight: bold; color: #9fab76">2902</span> (<span style="font-weight: bold; color: #ecc179">Declaração de Configuração de Característica do Cliente</span>)
        Valor:  <span style="font-weight: bold; color: #9fab76">b'\x00\x00'</span>
        Permissões: Leitura (sem autenticação/autorização), Escrita (camada superior especifica autenticação/autorização)

--sniff-adv: Farejar PDU do canal físico de propaganda

$ sudo bluing le --sniff-adv
root@kitploit:~
[INFO] Usando micro:bit /dev/ttyACM2 no canal 37
[INFO] Usando micro:bit /dev/ttyACM1 no canal 38
[INFO] Usando micro:bit /dev/ttyACM0 no canal 39
[INFO] micro:bit 38 < Pronto -> Iniciar
[INFO] micro:bit 37 < Pronto -> Iniciar
[INFO] micro:bit 39 < Pronto -> Iniciar
[38] [ADV_NONCONN_IND]
AdvA aleatório: 28:7A:88:B2:35:0B
[39] [ADV_IND]
AdvA público: A4:E4:72:B1:CB:8D
[37] [SCAN_REQ]
ScanA aleatório: 6A:90:0C:07:3E:14
AdvA aleatório: 7D:9B:A8:5A:F2:81
... ...

Comando android: Pilha Bluetooth Android

$ bluing android --help
root@kitploit:~
Uso:
    bluing android [-h | --help]
    bluing android [-t <id>] --collect-btsnoop-log [-o <arquivo>]

Opções:
    -h, --help               Exibe esta ajuda e sai
    -t <id>                  Usa dispositivo Android com o id de transporte fornecido. Esta opção 
                             será ignorada quando apenas um dispositivo estiver disponível
    --collect-btsnoop-log    Coleta o log btsnoop sendo gerado para um arquivo local, 
                             padrão ./btsnoop_hci.log
    -o <arquivo>              Coloca a saída em <arquivo> [padrão: ./btsnoop_hci.log]

--collect-btsnoop-log: Coleta o log btsnoop sendo gerado

$ bluing android -t 3 --collect-btsnoop-log -o btsnoop_hci.log; file btsnoop_hci.log
root@kitploit:~
btsnoop_hci.log: BTSnoop versão 1, HCI UART (H4)

Comando spoof: Spoof com novas informações do dispositivo local

$ bluing spoof --help
root@kitploit:~
Uso:
    bluing spoof [-h | --help]
    bluing spoof [-i <hci>] --bd-addr=<BD_ADDR>
    bluing spoof [-i <hci>] --cls-of-dev=<num>
    bluing spoof --host-name=<nome>
    bluing spoof [-i <hci>] --alias=<alias>

Opções:
    -h, --help             Imprime esta ajuda e sai
    -i <hci>               Dispositivo HCI
    --bd-addr=<BD_ADDR>    Spoof com um novo endereço BD_ADDR
    --cls-of-dev=<num>     Spoof com uma nova Classe de Dispositivo
    --host-name=<nome>     Spoof com um novo nome de host
    --alias=<alias>        Spoof com um novo alias

--bd-addr=<BD_ADDR>: Spoof com um novo endereço BD_ADDR

Este recurso atualmente é baseado no spooftooph, que pode ser instalado executando sudo apt install spooftooph se você estiver usando no Kali Linux. No entanto, se você estiver usando este recurso no Ubuntu, precisará compilar e instalar manualmente o spooftooph.

$ sudo bluing spoof --bd-addr=AA:BB:CC:DD:EE:FF
root@kitploit:~
[AVISO] O número original do dispositivo HCI pode ter sido alterado
[INFO] BD_ADDR alterado: 11:22:33:44:55:66 -> AA:BB:CC:DD:EE:FF

--cls-of-dev=<num>: Spoof com uma nova Classe de Dispositivo

$ sudo bluing spoof --cls-of-dev=0x6c0100
root@kitploit:~
Nenhuma saída quando bem-sucedido

--host-name=<name>: Spoof com um novo nome de host

$ sudo bluing spoof --host-name=Bluing
root@kitploit:~
Nenhuma saída quando bem-sucedido

--alias=<alias>: Spoof com um novo alias de controlador

$ sudo bluing spoof --alias='Bluing Alias'
root@kitploit:~
Nenhuma saída quando bem-sucedido

Comando plugin: Gerenciar plugins

$ bluing plugin --help
root@kitploit:~
Uso:
    bluing plugin [-h | --help]
    bluing plugin <comando> [<args>...]

Opções:
    -h, --help    Exibe esta ajuda e sai

Comandos:
    list         Lista plugins instalados
    install      Instala um plugin
    uninstall    Desinstala um plugin
    run          Executa um plugin

Hardware Recomendado

Adaptador Bluetooth

Muitos recursos do bluing exigem acesso a pelo menos 1 adaptador Bluetooth. Embora seja possível usar o adaptador que vem com a máquina física Linux ou tornar a máquina virtual Linux exclusiva para um adaptador da máquina host, ainda é recomendado usar um adaptador Bluetooth USB externo para mais estabilidade, como o Parani UD100-G03.

micro:bit original (opcional)

O Bluing requer pelo menos 1 micro:bit original ao farejar PDUs do canal físico de propaganda (le --sniff-adv), e é recomendado usar 3 deles ao mesmo tempo. Esses micro:bits precisam executar o firmware dedicado fornecido pelo bluing. Após conectar os micro:bits ao Linux, o firmware pré-construído pode ser gravado executando o seguinte comando:

root@kitploit:~
bluing --flash-micro-bit

Embora menos conveniente de usar do que o micro:bit, porém mais acessível para compra, adaptadores NRF51 mais genéricos também podem ser suportados. Foi adicionado suporte para as placas Adafruit Bluefruit LE Friend e BLE400. Para usá-los, eles precisarão ser gravados usando SWD. Esta ferramenta não suporta a gravação desses dispositivos. Além disso, a ferramenta não pode identificar automaticamente esses dispositivos. Em vez disso, a opção --devices precisa identificar as portas conectadas ao computador.

Ubertooth One (opcional)

Ao farejar e adivinhar BD_ADDRs próximos (br --sniff-and-guess-bd-addr), o bluing requer um Ubertooth One.

FAQ

rfkill não consegue encontrar hci0

A seguir está a mensagem de exceção:```txt Exception: Can't find the ID of hci0 in rfkill

root@kitploit:~
Essa exceção pode ser causada pela falta de suporte para as opções `-r` e `-n` na versão antiga do rfkill, por exemplo:
  
<pre>
$ <span style="font-weight: bold; color: #9fab76">cat</span> /etc/os-release | <span style="font-weight: bold; color: #9fab76">head</span> -n 2
NAME="Ubuntu"
VERSION="16.10 (Yakkety Yak)"

$ <span style="font-weight: bold; color: #9fab76">rfkill</span> --version
rfkill 0.5-1ubuntu3 (Ubuntu)
</pre>

Neste momento, atualizar o rfkill para uma versão mais recente pode resolver o problema, como:

<pre>
$ <span style="font-weight: bold; color: #9fab76">cat</span> /etc/os-release | <span style="font-weight: bold; color: #9fab76">head</span> -n 2
PRETTY_NAME="Kali GNU/Linux Rolling"
NAME="Kali GNU/Linux"

$ <span style="font-weight: bold; color: #9fab76">rfkill</span> --version
rfkill from util-linux 2.38.1
</pre>

### Comando de gerenciamento `scanend` falhou ao executar

A seguir está uma mensagem de erro:```txt
ERROR: Failed to execute management command 'scanend' (code: 11, error: Rejected)

Tente reiniciar o serviço Bluetooth para solucionar o problema:

root@kitploit:~
sudo systemctl restart bluetooth.service
Baixar ferramenta

... ...