Загрузка видео...

Не удалось загрузить видео

На главную

PoC to takeover Android using another Android by exploiting critical Bluetooth vulnerability to install #Metasploit payload without proper Bluetooth pairing (CVE-2023-45866) It still affects Android 10 and bellow #NetHunter

Комментарии: 11

Фото профиля Mobile Hacker
Mobile Hacker2 лет назад

In a different 0-click exploit scenario: It is also possible to lock-out user from its smartphone by brute-forcing a lock-screen passcodes in a loop to trigger 30 seconds and then 60 seconds timeout. Injected key-presses are typed way faster then user taps to unlock the device.

Фото профиля Mobile Hacker
Mobile Hacker2 лет назад

How to prevent becoming a victim: 1) For Android 10 and below, the security patch is not available - so, turn off Bluetooth if not used 2) Android 11 and above, install 2023-12-05 security patch (if OEM already pushed it) 3) Don't start Discoverable Mode to disclose MAC address

Фото профиля Youssef (s3c)
Youssef (s3c)2 лет назад

Is victim interaction required for accept the bluetooth connect with the attacker device?

Фото профиля Mobile Hacker
Mobile Hacker2 лет назад

No. The exploit enforces the Bluetooth pairing without any victim interaction

Фото профиля Hackhunting
Hackhunting2 лет назад

Keep up the good work! Hope to see a new PoC video on macOS, iOS and Windows ;)

Фото профиля oufi
oufi2 лет назад

can you share the script to inject the metasploit payload? thanks

Фото профиля Mobile Hacker
Mobile Hacker2 лет назад

Since many of Android devices are still vulnerable without option to patch this issue, I decided not to share the PoC script to inject the metasploit payload. I hope you understand my concerns.

Фото профиля Rubayet Hassan - MR_Prey3r
Rubayet Hassan - MR_Prey3r2 лет назад

🔥

Фото профиля Rumato Estorsky
Rumato Estorsky2 лет назад

How to detect is metasplpot was installed or not?

Фото профиля moreese
moreese2 лет назад

🔥 But Target device rooted ?

Фото профиля Mobile Hacker
Mobile Hacker2 лет назад

It doesn't matter if target is rooted or not. It affects Bluetooth protocol of devices running Android version 10 and below

Похожие видео