BrakTooth Bluetooth Vulnerabilities Give Rise to an Ultra-Low-Cost ESP32-Based Bluetooth Sniffer

Packet injection capabilities to follow, its creators claim — once the embargo lifts on the vulnerability proof-of-concept.

Gareth Halfacree
3 years agoSecurity / Communication

Security researcher Matheus Eduardo Garbelini, best known as part of the team responsible for disclosing the SweynTooth family of Bluetooth vulnerabilities, has published a design for an ultra-low-cost Bluetooth Classic sniffer based on an Espressif ESP32 — as his team discloses yet another family of vulnerabilities.

Released by Garbelini as part of the disclosure of BrakTooth, a family of 16 security vulnerabilities affecting Bluetooth Classic hardware from a variety of vendors including Espressif, Intel, Texas Instruments, and Qualcomm, the unnamed sniffing device is claimed to be "the cheapest BR/EDR active sniffer" around — running on an ESP32 board costing as little as $4.

This ESP32 Bluetooth Classic sniffer, seen here exploiting a BrakTooth vulnerability, costs as little as $4. (📹: ASSET Group)

As well as being able to sniff Bluetooth traffic when installed as part of the piconet, capturing baseband, FHS, and LMP frames, the tool is capable of injecting packets too — a key part of the team's proof-of-concept for BrakTooth attacks, which can result in anything from a crash or reset all the way up to arbitrary code execution.

This feature, however, isn't yet publicly available. "The sniffer cannot be used to inject packets at the moment due to the PoC [Proof of Concept] embargo," the team explains. "The embargo will be lifted at the end of October 2021 and our full PoC tool will be made available to the public for research and reproduction."

Firmware for the sniffer is available on Garbelini's GitHub repository, while full details on the parts affected by the BrakTooth vulnerabilities — and the status of patches to close the holes — can be found on the disclosure page.

Gareth Halfacree
Freelance journalist, technical author, hacker, tinkerer, erstwhile sysadmin. For hire: freelance@halfacree.co.uk.
Latest articles
Sponsored articles
Related articles
Latest articles
Read more
Related articles