模块化蓝牙经典(BR/EDR)漏洞测试框架,具备侦察、针对 43 个公开攻击/CVE 的利用模块,以及结构化 JSON 报告。
文档 • 安装 • 使用 • 漏洞利用 • 硬件 • 待办事项 • 汽车评估 • 蓝牙资源 • 许可证
BlueToolkit 是一个模块化的黑盒蓝牙安全测试框架,适用于经典蓝牙(BR/EDR)和低功耗蓝牙(BLE)。它支持半自动化测试,并包含三个主要模块:
我们在来自不同厂商(奥迪、宝马、雪佛兰、本田、现代、奔驰、Mini、欧宝、极星、雷诺、斯柯达、丰田、大众、特斯拉)的 22 辆汽车上评估了 BlueToolkit,并发现了 128 个漏洞。
此外,我们展示了如何在已建立的连接或处于中间人(MitM)位置时,通过 MAP 劫持在线账户。
这项工作促成了一篇被 WOOT 25' 接收的研究论文:当我们有链接时再补充
BlueToolkit 可以安装在裸机 Ubuntu/Debian 系统(推荐)上,或使用虚拟机安装。两种情况下,安装程序都会提示安装 Braktooth 和 BluetoothAssistant 的特定模块,这些模块需要特定硬件设备可用并已插入。也可以重新运行安装程序来单独安装独立模块。
先决条件:
安装后:
* 你需要允许虚拟机通过 USB 访问蓝牙模块或额外硬件,为此你需要执行以下操作:
* USB 支持已开启,因此打开 VirtualBox
* 找到正在运行的虚拟机,然后点击“显示”
* 点击“设备”->“USB”
* 你将会看到多个可以为虚拟机开启的设备
* 勾选你需要的任何设备(蓝牙模块、硬件、手机),或者勾选所有设备以确保万无一失。
</details>
### 用法
运行 `bluekit -h` 以显示 BlueToolkit 的使用信息:```console
usage: bluekit [-h] [-t TARGET] [-l] [-c] [-ct] [-ch] [-v VERBOSITY] [-ex EXCLUDEEXPLOITS [EXCLUDEEXPLOITS ...]] [-e EXPLOITS [EXPLOITS ...]] [-r] [-re] [-rej] [-hh HARDWARE [HARDWARE ...]] ...
positional arguments:
rest
options:
-h, --help show this help message and exit
-t TARGET, --target TARGET
target MAC address
-l, --listexploits List exploits or not
-c, --checksetup Check whether Braktooth is available and setup
-ct, --checktarget Check connectivity and availability of the target
-ch, --checkpoint Start from a checkpoint
-v VERBOSITY, --verbosity VERBOSITY
Verbosity level
-ex EXCLUDEEXPLOITS [EXCLUDEEXPLOITS ...], --excludeexploits EXCLUDEEXPLOITS [EXCLUDEEXPLOITS ...]
Exclude exploits, example --exclude exploit1, exploit2
-e EXPLOITS [EXPLOITS ...], --exploits EXPLOITS [EXPLOITS ...]
Scan only for provided --exploits exploit1, exploit2; --exclude is not taken into account
-r, --recon Run a recon script
-re, --report Create a report for a target device
-rej, --reportjson Create a report for a target device
-hh HARDWARE [HARDWARE ...], --hardware HARDWARE [HARDWARE ...]
Scan only for provided exploits based on hardware --hardware hardware1 hardware2; --exclude and --exploit are not taken into account
一些用法示例:
列出所有可用漏洞利用(无需 root 权限):
bluekit -l
运行侦察:
sudo bluekit -t AA:BB:CC:DD:EE:FF -r
测试连接:
sudo bluekit -t AA:BB:CC:DD:EE:FF -ct
测试一个或多个漏洞利用(以空格分隔):
sudo bluekit -t AA:BB:CC:DD:EE:FF -e invalid_max_slot au_rand_flooding internalblue_knob
更多文档可在我们的 wiki中查看
某些攻击需要特定硬件:
BlueToolkit 会自动下载所有漏洞和硬件模板。BlueToolkit templates 仓库提供了可直接使用的模板完整列表。 此外,您可以按照 BlueToolkit 的模板编写指南编写自己的模板和检查项,并添加新硬件。 YAML 参考语法可在此处获取。
我们以 “Awesome Bluetooth Security” 的方式收集并分类了蓝牙漏洞。我们使用了以下来源——ACM、IEEE SP、Blackhat、DEFCON、Car Hacking Village、NDSS 和 Google Scholars。在 Google、Baidu、Yandex、Bing 等搜索引擎中搜索了以下关键词——Bluetooth security toolkit、Bluetooth exploits github、Bluetooth security framework、bluetooth pentesting toolkit。我们还根据以下参数解析了所有 GitHub 仓库——topic:bluetooth topic:exploit、topic:bluetooth topic:security。
如需手动攻击,请参阅文档。