Bluesnarfing

Introductionto address the device by its unique 48-bit
Bluetooth a short range wireless communicationBluetooth device name. For example, uncovering
technology developed for use at home, office andthe device name is possible using software
Personal Area Networks. Over the yearsapplications such as RedFang. This application uses
Bluetooth integration has been achieved in mobilea brute-force approach to discover device
phones, Personal Digital Assistants (PDAs) andaddresses by systematically generating every
other consumer devices. When blue tooth waspossible combination of characters and recording
conceived, an essential element of the technologythose combinations which get a response.
was its requirement for a low expectation of endFortunately this approach is time consuming,
user technical ability and minimum levels of userpotentially taking hours of computation.
setup and configuration for ease of use. This wasCurrent scenario
adopted to ensure that widespread adoption andThe subsequent release of the Bluetooth
utilization of Bluetooth technology by the generalspecification 1.2 has addressed this problem by
public could be achievedadding an anonymity mode that masks a device's
A direct consequence of this requirement someBluetooth physical address. In addition a major
users are not aware of the functionality Bluetoothprivacy concern related to this type of attack is
offers and its potential for exploitation and inthe possibility of obtaining the IMEI of a device
many cases leave the default settings on theirwhich can then be utilized to uniquely identify a
devices unchanged. Bluetooth enabled devices arephone on a mobile network and could also be
vulnerable to exploitation using a range ofused in illegal phone cloning. This could give
methods including Bluesnarf, Backdoor andsomeone the ability to use a cloned subscriber
Bluebug.identity module (SIM) card to track a mobile
Bluetooth vulnerabilitiesdevice and by inference the user carrier without
The use of Bluetooth technology to accesstheir knowledge. Recent firmware upgrades have
restricted areas of a users' device without theircorrected this problem but many phone owners
knowledge or approval for the purpose ofhave not installed them
capturing data e.g. contacts, images, lists of calledNokia the World leading Mobile phone
missed, received or dialed, calendars, businessmanufacturer recently made this announcement
cards and the device's International Mobile"Nokia is aware of claims that there are security
Equipment Identity (IMEI) is known as Bluesnarf.issues relating to malicious attempts by hackers
Bluesnarfing works by using the push profile ofto access another user's mobile device featuring
the Object Exchange protocol (OBEX) which is aBluetooth technology, an act currently referred to
built-in Bluetooth functionality for exchangingas "Bluesnarfing". Affected models include the
electronic business cards.Nokia 6310, 6310i, 8910, 8910i mobile phones. "
Instead of pushing a business card the BluesnarfNokia recommends the following in order to
attack pulls using a "get" request looking for filesprevent "Bluesnarfing". In public places, where
with known names e.g. phonebook file (telecomphones with Bluetooth technology might
pb.vcf) or calendar file (telecom/cal.vcs). Thistheoretically be targets of malicious attacks,
vulnerability exists due to the manner in which thereliable ways to foil potential hackers are:
OBEX push profile was implemented in some ofTo set the device to "hidden" mode using the
the early Bluetooth enabled phones, which did notBluetooth menu. Personal devices like headsets
require authentication from other Bluetoothcan still connect to the phone, but intrusion is
devices attempting to communicate with it.much more difficult since the hacker will have to
Accessing information by Bluesnarfing wasknow or guess the Bluetooth address before
thought to only be possible if the users device isestablishing a connection.
in "discoverable" or "visible" mode, but BluesnarfIf a user wants absolute security, they can simply
attacks have being carried out on devices set to"switch off" the Bluetooth functionality of their
"non-discoverable" mode.mobile phone. This will not affect other
To achieve this the Bluesnarfing software needsfunctionalities of the phone.