Deutsch | English
n.runs AG - Das Unternehmen Sicherheit
 
 
The Company
LEISTUNGSSPEKTRUM
IT INFRASTRUKTUR
IT SICHERHEIT SECURITY
IT BUSINESS CONSULTING
IT SOFTWARE

n.runs AG
Nassauer Straße 60
61440 Oberursel
Telefon: +49 (0) 6171/699-0
Telefax: +49 (0) 6171/699-199
E-mail: contact@nruns.com
Newsletter anfordern
Impressum

.Security Tools - BTcrack 1.1

Introduction
BTCrack is the worlds first Bluetooth Pass phrase (PIN) Brute force tool, BTCrack will bruteforce the Passkey and the Link key from captured Pairing* exchanges.

To capture the pairing data it is necessary to have a Professional Bluetooth Analyzer : FTE (BPA 100, BPA 105, others), Merlin OR to know how to flash a CSR based consumer USB dongle with special firmware.

Example of an aAttack scenario :

  1. Attacker reconstructs BD_ADDR of both Master and Slave through passive (reconstructing through a preamble sniff, even when the device is in hidden mode) or active means (redfang)
  2. Attacker changes his BD_ADDR to the one of the Slave device
  3. Attacker asks to pair with the Master indicating it has no key, the Master will more then often trash the old pairing data and request a new link key from the genuine slave
  4. Attacker now captures the key (pairing) exchange taking place between the two devices as the users try to re-establish a connection
  5. Attacker exports data to CSV format and imports into BTCrack
  6. Attacker can now compromise Master and Slave Bluetooth device through usage of the cracked Linkkey and is able to decrypt the data transmitted between the bluetooth devices


Why the PIN is not so important
An Attacker will focus on recovering the Linkkey and not the PIN, here's why :

  • The Link-key allows remote connections without the victim noticing
  • The Link-key allows and attacker to connect to devices in non-pairing mode and non discoverable mode
  • The Link-key allows decryption of the data

History :

  • Olly Whitehouse - 2003
    Presented theoretic weaknesses in the Implementation of the Pairing exchange
  • Shaked and Wool - 2005
    Present their logic to break pairing exchanges and implement it in Private
  • Thierry Zoller - 2006
    First public release of a complete optimized Implementation of the Shaked and Wool logic. Optimisation done by Erik Sesterhenn.
  • David Hulton / Thierry Zoller - 2007
    Worlds first FPGA based Implementation

Screenshots :

btcrack

Speed Comparison :
P4 2Ghz - Dual Core     200.000 keys/sec
FPGA E12 @ 50Mhz  7.600.000 keys/sec
FPGA E12 @ 75Mhz 10.000.000 keys/sec
FPGA E14 30.000.000 keys/sec

Known issues :
[+] Frontline 6.0 mixes Master & Slave Addresses

Changes :
1.0 First release
1.1 Intermediate Release
    »  E12 + E14 FPGA Support ( http://www.picocomputing.com)
    »  Splash Screen
    »  Process Priority
    »  Speed increase (+15%)

Downloads :

 Download BTCrack 1.1

bluetooth security flash
 Heisec 2007 - Scheunentor Bluetooth - DE
 23C3 - Bluetooth Hacking revisited - All your Bluetooth is belong to us - EN
more tools
 more n.runs tools from n.runs

Penetration Test



26 Juni 2008:
Corporate News:
Jahreszahlen 2007 und Ausblick 2008

+++ Umsatzerlöse von EUR 5,48 Millionen
+++ EBITDA von EUR -0,93 Millionen
+++ Sonderbelastung durch Softwareentwicklung i.H.v. EUR 0,82 Millionen
sowie Umstrukturierungs-maßnahmen
+++ Auftragseingang im Mai 2008 + 47,6 Prozent auf EUR 6,2 Millionen
+++ 2008 als bestes Jahr der Unternehmensgeschichte angestrebt

* * *

25 Juni 2008:
Advisory :
JSCAPE unsichere SSH Host key Validierung

* * *

24 Juni 2008:
PR-News:
+++ Virenscanner machen Angreifern den Weg ins Netzwerk frei +++

* * *
05 Mai 2008:
Corporate News:
+++ Kapitalerhöhung um weitere 75.000 Aktien beschlossen und platziert
+++ Weiterentwicklung Application Protection System – Anti Virus (aps-AV)

* * *
29 April 2008:
Corporate News:
+++ Auftragseingang steigt im ersten Quartal um +34,6 Prozent +++ Neue Unternehmensstruktur n.runs professionals +++ Weitere Produkte im Bereich IT-Applications geplant

* * *
27 Februar 2008:
Whitepaper :
Hacking jBoss using a Browser

* * *

19 Februar 2008:
        cebit
n.runs AG auf der CeBIT :
Halle 6, Stand J61/1
aps-AV zur Absicherung "offener" AntiViren-Strukturen

* * *
24 Januar 2008 :
Corporate News:
n.runs AG erschließt mit eigener Lösungsentwicklung weiteres Geschäftsfeld IT-Applications +++ aps-AV als erste Hochsicherheitslösung gelauncht

* * *

19 Dezember 2007:
Corporate News: Kapitalerhöhung beschlossen und platziert
+++ Bruttoemissionserlös dient der Finanzierung der Softwareeinführung


* * *

3 Dezember 2007:

Presse : Virenscanner öffnen Hacker die Türen

* * *
13 November 2007:
Conference / Talk : The Death of AV Defense in Depth ? - Revisiting Anti-Virus Software (Hack.lu 2007)

* * *

03 September 2007:
Advisory: Sophos Antivirus UPX parsing Code execution UPDATE

* * *

24 August 2007:
Advisory: ClamAV Remote Code Execution

* * *

24 August 2007:
Advisory: Sophos Antivirus Arbitrary Code Execution [UPX]

* * *

24 August 2007:
Advisory: Sophos Antivirus Infinite Loop DoS [BZIP]

* * *

25 Juli 2007:
Advisory: CA eTrust Antivirus Infinite Loop DoS [CHM]

* * *