目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2019-9506 PoC — Bluetooth BR/EDR 加密问题漏洞

来源
关联漏洞
标题: Bluetooth BR/EDR 加密问题漏洞 (CVE-2019-9506)
Description:Bluetooth BR/EDR是一种蓝牙BR/EDR(基本速率/增强数据速率)标准。 Bluetooth BR/EDR 5.1及之前版本中存在加密问题漏洞。该漏洞源于网络系统或产品未正确使用相关密码算法,导致内容未正确加密、弱加密、明文存储敏感信息等。
Description
Key Negotiation Of Bluetooth (KNOB) attacks on Bluetooth BR/EDR and BLE  [CVE-2019-9506]
介绍
# README

Repository about the [Key Negotiation Of Bluetooth (KNOB)](https://knobattack.com/) attacks on Bluetooth BR/EDR and Bluetooth Low Energy.

## Related Work

* [From the Bluetooth Standard to Standard-Compliant 0-days](https://francozappa.github.io/talk/hwio20/talk/) [HWIO20]
* [Key Negotiation Downgrade Attacks on Bluetooth and Bluetooth Low Energy](https://francozappa.github.io/publication/knob-ble/) [TOPS20]
* [Bluetooth blues: KNOB attack explained](https://francozappa.github.io/talk/cyberwire-knob/talk/) [CyberWire19]
* [The KNOB is Broken: Exploiting Low Entropy in the Encryption Key Negotiation of Bluetooth BR/EDR](https://francozappa.github.io/publication/knob/) [SEC19]
* [BIAS: Bluetooth Impersonatoin AttackS](https://francozappa.github.io/publication/bias/) [S&P20]

## Links

* [CVE-2019-9506](https://www.kb.cert.org/vuls/id/918987/).
* [PoC to perform the KNOB attack using internalblue v0.1](https://github.com/francozappa/knob/tree/master/poc-internalblue)
* [Code to validate and brute force E0 encryption keys](https://github.com/francozappa/knob/tree/master/e0)
* [How to patch the Linux kernel to perform the KNOB attack on BLE ](https://github.com/francozappa/knob/tree/master/ble)
* [Wireshark files](https://github.com/francozappa/knob/tree/master/wireshark)


文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →