Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2019-9506 PoC — Blutooth BR/EDR specification does not specify sufficient encryption key length and allows an attacker to influence key

Source
Associated Vulnerability
Title: Blutooth BR/EDR specification does not specify sufficient encryption key length and allows an attacker to influence key length negotiation (CVE-2019-9506)
Description:The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.
Description
Key Negotiation Of Bluetooth (KNOB) attacks on Bluetooth BR/EDR and BLE  [CVE-2019-9506]
Readme
# README

Repository about the [Key Negotiation Of Bluetooth (KNOB)](https://knobattack.com/) attacks on Bluetooth BR/EDR and Bluetooth Low Energy.

## Related Work

* [From the Bluetooth Standard to Standard-Compliant 0-days](https://francozappa.github.io/talk/hwio20/talk/) [HWIO20]
* [Key Negotiation Downgrade Attacks on Bluetooth and Bluetooth Low Energy](https://francozappa.github.io/publication/knob-ble/) [TOPS20]
* [Bluetooth blues: KNOB attack explained](https://francozappa.github.io/talk/cyberwire-knob/talk/) [CyberWire19]
* [The KNOB is Broken: Exploiting Low Entropy in the Encryption Key Negotiation of Bluetooth BR/EDR](https://francozappa.github.io/publication/knob/) [SEC19]
* [BIAS: Bluetooth Impersonatoin AttackS](https://francozappa.github.io/publication/bias/) [S&P20]

## Links

* [CVE-2019-9506](https://www.kb.cert.org/vuls/id/918987/).
* [PoC to perform the KNOB attack using internalblue v0.1](https://github.com/francozappa/knob/tree/master/poc-internalblue)
* [Code to validate and brute force E0 encryption keys](https://github.com/francozappa/knob/tree/master/e0)
* [How to patch the Linux kernel to perform the KNOB attack on BLE ](https://github.com/francozappa/knob/tree/master/ble)
* [Wireshark files](https://github.com/francozappa/knob/tree/master/wireshark)


File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →