Eavesdropping on Bluetooth headsets

Here’s a short video in which Joshua Wright demonstrates how a Bluetooth headset can be hijacked, allowing audio to be captured or sent to the device:

Few users realize that Bluetooth headsets can be exploited granting a remote attacker the ability to record and inject audio through the headset while the device is not in an active call. SANS Institute author and senior instructor Joshua Wright demonstrates.

All that is necessary is knowing the device address, which can be easily sniffed, and the secret pin, which defaults to 0000. The headset audio is tapped while not in a call, so any room conversation the headset’s mic can pick up can potentially be listened to remotely.

18 Responses to Eavesdropping on Bluetooth headsets

  1. edisson calderon on said:

    thanks for the video, it is very good information.

  2. kidmidnight on said:

    holy crap, that dude is a freaking sissy

  3. fagmidnight on said:

    holy crap, that sissy just listened to you having phone sex with your gay boyfriend

  4. Nicely done, well presented.

  5. peter guszti on said:

    , Yeah I have a wireless blootooth headset, and its great. i think they started selling like 30% more the last year., I also posted it on my blog with extra coments,www.opentopix.com/topic/gadgets/bluetooth-wireless-headsets-boom

  6. All 3 of my bluetooth headsets will only pair when it is put in a special “pair mode” (typically by holding the power button for 10 seconds or more).

    I’d be interested if this attack will work on devices with this “feature”.

  7. umm, I call BS for a few reasons.

    1) The pin is used to associate two devices (the handshake) not for ongoing communication.
    2) Once the headset has been associated to the device, it cannot be re-associated to another device while the first device is still active. So I would have to turn my phone off.
    3) Even though you may be able to send a signal with that super nifty antenna, you most likely will not be able to receive the signal back unless they have a similar antenna.

    You’re more at risk with the FBI being able to remotely activate your mic.

  8. Brown University Baby!

  9. wow, brown university…

  10. did he get her number

  11. ghey is the correct terminology, kidmidnight.

  12. Didnt even watch the video because it sounds so retarded.

  13. very good blog :)

  14. Karl Moerder on said:

    This guy is more annoying and effeminate than me !

  15. Recently,we have tailored the unique wow gold

  16. ignore the other comments. good presentation. good info. those who think that this is lame are skr1pt k1dd1ez who just want it point-n-click so they can use it…

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s