palowireless
          Bluetooth Resource Center


Advanced search


palowireless
Wireless
WPANs news tools hardware software


bluethoot blutooth bluetoth bluetoot blueteeth bleutooth





 
wireless

Members

Member:

Password:

Forgot your
password?


New Member
palowireless
[  Also see: Bluejacking   Wireless Security   WLAN Security  Java Security  Cathal's Corner  ]

 

Recent Security Headlines

FreshPatents.com Vehicle activity module
Systems and methods are disclosed for maintaining security and data gathering for a number of vehicles. The systems include a vehicle activity module for each of the vehicles. The vehicle activity module has a wireless transmitter, a storage device, at least one sensor for receiving event information from identification devices,...

FreshPatents.com Methods and devices for a multi-protocol wireless security controller
Methods and devices for a wireless security controller that is able to receive data transmissions over multiple frequency channels and decode security messages that use different data protocols is provided. The security controller monitors an incoming security message transmission from a security sensor. As the transmission is received, the security...

FreshPatents.com Vehicle security system and method of using the same
A vehicle security system includes a trigger module, an image acquisition module, a microprocessor and a database. The trigger module triggers the image acquisition module to capture a pupil image of a proximal party triggering the trigger module. The database is coupled with the microprocessor and stores at least one...

FreshPatents.com Dog bark door bell notification and personal protection system
A security system includes a warning notification module adapted to recognize at least one of a wireless or audible signal. A door bell ringer or emergency transmission signal from a wireless transmitter can provide a recognition signal to a microprocessor in the security system via the warning notification module. The...

Network World Cybersecurity help exists, focusing it is the trick
There are a ton of groups out there that offer cybersecurty help and guidance, the trick, it seems is finding he right one for you organization.

IEEE Touring DNS Open Houses for Trends and Configurations
The Domain Name System (DNS) is a critical component of the Internet. It maps domain names to IP addresses and serves as a distributed database for various other applications, including mail, Web, and spam filtering. This paper examines DNS zones in the Internet for diversity, adoption rates of new technologies, and prevalence of configuration issues. To gather data, we sweep 60% of the Internet's domains in June-August 2007 for zone transfers. Of them, 6.6% allow us to transfer their complete information....

Rootsecure.net Offensive Security: MS11-080 A Voyage into Ring Zero
 

Rootsecure.net Krebs On Security: Who Knows What Youhavedownloaded.com?
 

Rootsecure.net Acros Security: Google Chrome HTTPS Address Bar Spoofing
 

Rootsecure.net Net Security: BackTrack 5 Wireless Penetration Testing
 

About our headline feed



 

Research Reports

Mobile Device Security 2011-2016: Opportunities and Challenges
Visiongain, Aug 2011

WTRS Wireless Sensor Network Technology Trends Report Q4 2010; Single Issue
West Technology Research Solutions, LLC, Jan 2010

The WTRS Wireless Sensor Network Technology Trends Q2 2010, One year quarterly subscription
West Technology Research Solutions, LLC, Jan 2010

Non-Cellular Waveforms in Mobile Phones: Technologies and Global Markets
BCC Research, Jan 2011

More Research Reports
 



 

Bluetooth Security

Bluetooth security encryption pin connection Welcome to our summary of Bluetooth security information, tips, encryption, techniques, news and tools.



Featured Research Reports

IEEE 1902.1 (RuBee) Protocol

RuBee is a bidirectional protocol operating at low wavelengths designed to operate in harsh environments and high security applications. As a competitive technology to the more widely used Radio Frequency Identification (RFID) systems, RuBee, however, is not RFID. RuBee is an on demand peer-to-peer protocol that works like WiFi, except it uses magnetic waves not radio waves. RuBee tags have passed stringent security tests, and are in use within some of the most secure sites in the USA where other wireless technologies such as RFID, Wi-Fi, and Bluetooth are banned. RuBee is the only wireless technology that can dynamically manage range to prevent eavesdropping as well as the option to provide bit level data encryption.

Published By: Faulkner Information Services
Date Published: Jan 2010

* * * * * *

Mobile Content and Services (7th edition)

Mobile Content and Services (7th edition) answers key questions, illuminating case studies from around the globe and future roadmaps for players across the value chain - backed by detailed forecasts to 2013. The report provides you with critical information on which to base your strategy.

Key Coverage

The major industry analysis covered within the Mobile Content and Services report includes:
  • Mobile enterprise analysis: evaluation of the mobile applications and solutions employed in these sectors.
  • Business models: Coverage of key areas, including mobile messaging, music, games, Mobile TV and video, mobile web browsing and search, location based services, mobile advertising and social networking, and m-commerce and mobile financial services.
  • Strategic issues: analyses the impact of the evolving content value chain on all industry players. Evaluates high level business and marketing issues, and the critical considerations for addressing the mobile content and services market. Looks at the impact of disruptive technologies such as VoIP. Assesses the impact of the growth of the handset market including smartphones and the impact of devices like the iPhone on the industry.
Key Issues Addressed
The report details
Global industry forecasts
Value chain and competitive analysis
New services available
Revenue and business models
Pricing strategies
Technology launches
Major players’ strategies
Future roadmap scenarios

Please Note: Informa requires that clients sign a confidentiality agreement prior to fulfillment of all orders. Fulfillment may take 2-3 days after receipt of form.

Published By: Informa Media and Telecom
Date Published: Jan 2009

* * * * * *



Software Tools

n.runs BTCrack a Bluetooth PIN Recovery tool. Thierry Zoller, a security consultant, developed BTCrack, an implementation of a flaw disclosed in 2005 by Israeli security researchers. The tool takes advantage of weak PINs in Bluetooth devices, allowing an attacker to listen in on a pairing session and gain access to both paired devices.
WM-soft The Real Bluejack is software for smartphones and Pocket PCs, that use Bluetooth. It extends your device’s Bluetooth functions. This program can: send Bluetooth messages, browse target-device’s filesystem via OBEX protocol, send AT commands, get phonebook, send SMS via target-phone, send files up to 2x faster then file managers, receive files directly into the Storage Card and other features.
"THE REAL BLUEJACK" IS NOT INTENDED FOR GETTING UNAUTHORIZED ACCESS TO PERSONAL DATA! Authentication is required! (But after you can do everything that you want)

 

Useful Resources:

  • Bluetooth SIG

    • Bluetooth SIG Response to Recent Analysis of Pairing and Security (6/05) New Scientist reported a new security threat to Bluetooth technology in June 2005 (New hack cracks 'secure' Bluetooth devices) from two Israeli researchers who suggested a way to subvert one of the built-in Bluetooth security mechanisms. Bluetooth devices generate a secure connection by means of the initial pairing process. During this process one or both devices need a PIN code to be entered, which is used by internal algorithms to generate a secure key which is then used to authenticate the devices whenever they connect in the future. The new academic paper puts forward a theoretical process that could potentially “guess” the security settings on a pair of Bluetooth devices. To do this the attacking device would need to listen in to the initial one-time pairing process. From this point it can use an algorithm to guess the security key and masquerade as the other Bluetooth device. What is new in this paper is an approach that forces a new pairing sequence to be conducted between the two devices and an improved method of performing the guessing process, which brings the time down significantly from previous attacks.

  • Java Security Our new listing on Java-related security.
     

  • WAP Security Our listings of WAP security news, tips, tools and techniques.

  • The Bunker Serious flaws in bluetooth security lead to disclosure of personal data In November 2003, Adam Laurie of A.L. Digital Ltd. discovered that there are serious flaws in the authentication and/or data transfer mechanisms on some Bluetooth enabled devices. Specifically, three vulnerabilities have been found: Firstly, confidential data can be obtained, anonymously, and without the owner's knowledge or consent, from some Bluetooth enabled mobile phones. Secondly, it has been found that the complete memory contents of some mobile phones can be accessed by a previously trusted ("paired") device that has since been removed from the trusted list. Thirdly, access can be gained to the AT command set of the device, giving full access to the higher level commands and channels, such as data, voice and messaging.