Live data from Hacker News

Blueborne – A new attack vector endangering major operating systems

armis.com

21–30 of 34 posts

Re: Blueborne – A new attack vector endangering major operating systems

#21
post #16

Earlier quoted context omitted.

What you probably want is this combined with some privilege escalation technique. If you feel like doing the work, have at it.[1] 1: https://www.cvedetails.com/vendor/1224/Google.html

If I already had a working privilege escalation strategy, wouldn't I just be able to run that from a terminal emulator program on the phone? Or using an adb shell? My problem is exactly that there is no privilege escalation vulnerability in my version of the OS (that I know of)

I think DirtyCOW (CVE-2016-5195) had been dormant in the kernel for a long time. If I remember correctly the PoC demonstrated writing on root-owned files. Might be relevant.

https://github.com/dirtycow/dirtycow.github.io/wiki/Vulnerab...

Re: Blueborne – A new attack vector endangering major operating systems

#22
post #7
post #3

Am I missing something? The first line says: "Armis Labs revealed a new attack vector endangering major mobile, desktop, and IoT operating systems, including Android, iOS, Windows, and Linux, and the devices using them." Why is the title singling out Linux? Reading through the rest of it, it seems like this is on pretty much everything.

Windows was patched in July. Google has provided a patch for Android. Therefore, Linux is the only one left to make an announcement.

Microsoft is issuing security patches to all supported Windows versions at 10 AM, Tuesday, September 12.

Re: Blueborne – A new attack vector endangering major operating systems

#23
post #8

Earlier quoted context omitted.

Does keeping the BlueTooth radio turned off help here?

I have the same question -- I turned off the Bluetooth radio on my phone the day I got it, and I've never turned it back on. But does that mean the radio is actually powered down, or is the phone blocking Bluetooth at a higher level? Similarly, or possibly the same question, is an rfkill soft block adequate for a laptop with bluetooth?

On a laptop, if you want to be sure, you can at least do `sudo modprobe -r btusb` (or whatever your particular chipset's BT driver is called).

Re: Blueborne – A new attack vector endangering major operating systems

#24
post #4
post #2

This looks very scary, especially given how many Android devices are out there that receive few or no security updates.

Agreed. And just checked - my Samsung Galaxy S8 is vulnerable, no update available. Thanks Samsung! This one will get nasty...

I got the August security update yesterday - how do I check if I'm vulnerable?

Re: Blueborne – A new attack vector endangering major operating systems

#25
post #4

Earlier quoted context omitted.

Agreed. And just checked - my Samsung Galaxy S8 is vulnerable, no update available. Thanks Samsung! This one will get nasty...

I got the August security update yesterday - how do I check if I'm vulnerable?

For android: https://play.google.com/store/apps/details?id=com.armis.blue...

Re: Blueborne – A new attack vector endangering major operating systems

#26

Earlier quoted context omitted.

I got the August security update yesterday - how do I check if I'm vulnerable?

For android: https://play.google.com/store/apps/details?id=com.armis.blue...

Thanks. Yep, the S8+ updated yesterday is vulnerable.

Re: Blueborne – A new attack vector endangering major operating systems

#28
post #3

Am I missing something? The first line says: "Armis Labs revealed a new attack vector endangering major mobile, desktop, and IoT operating systems, including Android, iOS, Windows, and Linux, and the devices using them." Why is the title singling out Linux? Reading through the rest of it, it seems like this is on pretty much everything.

We've updated the title from “Blueborne – Stack buffer overflow in Linux kernel Bluetooth”.

Re: Blueborne – A new attack vector endangering major operating systems

#29
post #7
post #3

Am I missing something? The first line says: "Armis Labs revealed a new attack vector endangering major mobile, desktop, and IoT operating systems, including Android, iOS, Windows, and Linux, and the devices using them." Why is the title singling out Linux? Reading through the rest of it, it seems like this is on pretty much everything.

Windows was patched in July. Google has provided a patch for Android. Therefore, Linux is the only one left to make an announcement.

My 'flagship' OnePlus 5 is vulnerable today, according to their linked app.

While I totally believe that my device will receive a patch at some point in time, the majority of devices out there will probably never receive the patch Google provided. And even this recent phone is now vulnerable to a vulnerability that was just disclosed to the public at large..

I'd say Android is pretty much in deep (or rather: deeper than usual) shit as well, not just Linux

Re: Blueborne – A new attack vector endangering major operating systems

#30
Google has issued a patch and notified its partners. It will be available for:

    Nougat (7.0)
    Marshmallow (6.0)
Google has issued a security update patch and notified its partners. It was available to Android partners on August 7th, 2017, and made available as part of the September Security Update and Bulletin. We recommend that users check that Bulletin for the latest most accurate information. Android users should verify that they have the September 9, 2017 Security Patch Level

Take Nexus 5.

Opens Settings, Device information.

Android Version: 6.0.1. Great.

Android Security Level: 2016-10-5. A year old. Great.

Tap System update, force check... no update. Great.

Thank you Google.

Post reply on HN