|This article needs additional or better citations for verification. (May 2014) (Learn how and when to remove this template message)|
Bluesnarfing is the unauthorized access of information from a wireless device through a Bluetooth connection, often between phones, desktops, laptops, and PDAs (personal digital assistant). This allows access to calendars, contact lists, emails and text messages, and on some phones, users can copy pictures and private videos. Both Bluesnarfing and Bluejacking exploit others' Bluetooth connections without their knowledge. While Bluejacking is essentially harmless as it only transmits data to the target device, Bluesnarfing is the theft of information from the target device.
Current mobile software generally must allow a connection using a temporary state initiated by the user in order to be 'paired' with another device to copy content. There seem to have been, in the past, available reports of phones being Bluesnarfed without pairing being explicitly allowed. After the disclosure of this vulnerability, vendors of mobile phone patched their Bluetooth implementations and, at the time of writing, no current phone models are known to be vulnerable to this attack.
Any device with its Bluetooth connection turned on and set to "discoverable" (able to be found by other Bluetooth devices in range) may be susceptible to Bluejacking and possibly to Bluesnarfing if there is a vulnerability in the vendor's software. By turning off this feature, the potential victim can be safer from the possibility of being Bluesnarfed; although a device that is set to "hidden" may be Bluesnarfable by guessing the device's MAC address via a brute force attack. As with all brute force attacks, the main obstacle to this approach is the sheer number of possible MAC addresses. Bluetooth uses a 48-bit unique MAC Address, of which the first 24 bits are common to a manufacturer. The remaining 24 bits have approximately 16.8 million possible combinations, requiring an average of 8.4 million attempts to guess by brute force.
Attacks on wireless systems have increased along with the popularity of wireless networks. Attackers often search for rogue access points, or unauthorized wireless devices installed in an organization's network and allow an attacker to circumvent network security. Rogue access points and unsecured wireless networks are often detected through war driving, which is using an automobile or other means of transportation to search for a wireless signal over a large area. Bluesnarfing is an attack to access information from wireless devices that transmit using the Bluetooth protocol. With mobile devices, this type of attack is often used to target the international mobile equipment identity (IMEI). Access to this unique piece of data enables the attackers to divert incoming calls and messages to another device without the user's knowledge.
Bluetooth vendors advise customers with vulnerable bluetooth devices to either turn them off in areas regarded as unsafe or set them to undiscoverable. This bluetooth setting allows users to keep their bluetooth on so that compatible bluetooth products can be used but other bluetooth devices cannot discover them.
Because Bluesnarfing is an invasion of privacy, it is illegal in many countries.
Bluesniping has emerged as a specific form of Bluesnarfing that is effective at longer ranges than normally possible. According to Wired magazine, this method surfaced at the Black Hat Briefings and DEF CON hacker conferences of 2004 where it was shown on the G4techTV show The Screen Savers.
In the article "'Rifle' Sniffs Out Vulnerabilities", the 'rifle' features a directional antenna, Linux-powered embedded PC, and Bluetooth module all mounted on a Ruger 10/22 folding stock. According to Flexilis, the rifle is capable of targeting Bluetooth at ranges over 1 mile (1.6 km). This type of Bluesniping has been utilized to demonstrate the increasing security vulnerability of Bluetooth devices.
According to the Bluetooth Special Interest Group, in order to break into a Bluetooth device, an attacker must "force two paired Bluetooth devices to break their connection", known as Blueballing. One should take away from this the caveat of never pairing with unknown devices or in public places. The connection between one's cellular phone and one's Bluetooth-enabled headset, for instance, could be broken and the cellular phone may be able to be highjacked by the remote "Bluesniper" for one purpose or another.
In popular culture
- In the TV series Person of Interest, bluesnarfing, often mistakenly referred to as bluejacking in the show and at other times forced pairing and phone cloning, is a common element in the show used to spy on and track the people the main characters are trying to save or stop.
- Bialoglowy, Marek, Bluetooth Security Review, Part 1, http://www.symantec.com/connect/articles/bluetooth-security-review-part-1
- Fuller, John, How Bluetooth Surveillance Works, http://electronics.howstuffworks.com/bluetooth-surveillance1.htm
Mark Ciampa (2009), Security+ Guide to Network Security Fundamentals Third Edition. Printed in Canada.
Roberto Martelloni's home page with Linux source code of released Bluesnarfer proof-of-concept.