Thursday, January 25, 2007

OBEX Push Bluetooth DoS

A vulnerability in the way Bluetooth enabled phones handle incoming file-push, allows remote attackers to cause the phone to stop working effectively causing a denial of service.

Using ussp-push, it is possible to send out files very quickly. By continuously trying to push a file, the target is flooded with prompts whether to accept the file or not, which disables any other usage on the phone, including the ability to turn off Bluetooth.

The information has been provided by Armin Hornung.

The original article can be found at: http://www.xmailserver.org/ussp-push.html

----------------------------------

You could just turn the phone off and walk away...but that just makes the remote DoS into a self-served DoS.

Yet another reason why I have not used Bluetooth on my RAZR. Bluetooth is just a drain on your battery anyways....

No comments:

Post a Comment