palowireless
          Bluetooth Resource Center


Advanced search


palowireless
Wireless
WPANs news tools hardware software


bluethoot blutooth bluetoth bluetoot blueteeth bleutooth





 
wireless

Members

Member:

Password:

Forgot your
password?


New Member
palowireless
[  Also see: Bluejacking   Wireless Security   WLAN Security  Java Security  Cathal's Corner  ]

 

Recent Security Headlines

Network World HTML5 raises new security issues
As HTML5 enhances the Web, so too will it bring new vulnerabilities, security experts warn

IEEE DTRAB: Combating Against Attacks on Encrypted Protocols Through Traffic-Feature Analysis
The unbridled growth of the Internet and the network-based applications has contributed to enormous security leaks. Even the cryptographic protocols, which are used to provide secure communication, are often targeted by diverse attacks. Intrusion detection systems (IDSs) are often employed to monitor network traffic and host activities that may lead to unauthorized accesses and attacks against vulnerable services. Most of the conventional misuse-based and anomaly-based IDSs are ineffective against attacks ...

IEEE Aegis: Physical Space Security for Wireless Networks With Smart Antennas
In this paper, we focus on securing communication over wireless data networks from malicious eavesdroppers by using smart antennas. While conventional cryptography-based approaches focus on hiding the meaning of the information being communicated from the eavesdropper, we consider a complimentary class of strategies that limit knowledge of the existence of the information from the eavesdropper. We profile the performance achievable with simple beamforming strategies using a newly defined metric called expo...

Rootsecure.net Security-Shell: Ebay XSS
 

Rootsecure.net Net Security: 25% of new worms are designed to spread through USB devices
 

Rootsecure.net H Security: US Deputy Secretary of Defense confirms virus attack
 

Rootsecure.net Security-Shell: Verizon website vulnerable to XSS and SQL Injection
 

ITtoolbox How Xsigo Enhances VMware Deployments
XS International presents this whitepaper on how the virtual I/O capabilities of the Xsigo I/O Director enable a virtualized datacenter running VMware ESX to scale better, ensure security through traffic isolation, and guarantee performance through QoS. Together, these benefits allow a greater percentage of applications to run in virtual machines, further reducing the need for physical servers that consume power and real estate.

ITtoolbox Voice Network Security - Strategies for Control
With voice traffic now running across the data network, the burden of safeguarding voice systems now lies in the hands of the networking team. Read this white paper to learn to secure your voice network now.

Encryption News [New] Video Hider S60 - hide and encrypt your confidential videos
Video Hider from Aims Migital Technovations lets you quickly and easily hide video clips on your S60 phone. They become completely invisible, password protected, and an encryption option is also available for additional security.

About our headline feed



 

Research Reports

The WTRS Wireless Sensor Network Technology Trends Q2 2010,Single Issue
West Technology Research Solutions, LLC, Jan 2010

The WTRS Wireless Sensor Network Technology Trends Q2 2010, One year quarterly subscription
West Technology Research Solutions, LLC, Jan 2010

Wireless Personal Area Networks: Applications, Assessment Technologies and Markets
Practel, Inc., Jan 2009

Global Mobile Security Market 2009-2013
Infiniti Research Limited, May 2010

More Research Reports
 



 

Bluetooth Security

Bluetooth security encryption pin connection Welcome to our summary of Bluetooth security information, tips, encryption, techniques, news and tools.



Featured Research Reports

Mobile Content and Services (7th edition)

Mobile Content and Services (7th edition) answers key questions, illuminating case studies from around the globe and future roadmaps for players across the value chain - backed by detailed forecasts to 2013. The report provides you with critical information on which to base your strategy.

Key Coverage

The major industry analysis covered within the Mobile Content and Services report includes:
  • Mobile enterprise analysis: evaluation of the mobile applications and solutions employed in these sectors.
  • Business models: Coverage of key areas, including mobile messaging, music, games, Mobile TV and video, mobile web browsing and search, location based services, mobile advertising and social networking, and m-commerce and mobile financial services.
  • Strategic issues: analyses the impact of the evolving content value chain on all industry players. Evaluates high level business and marketing issues, and the critical considerations for addressing the mobile content and services market. Looks at the impact of disruptive technologies such as VoIP. Assesses the impact of the growth of the handset market including smartphones and the impact of devices like the iPhone on the industry.
Key Issues Addressed
The report details
Global industry forecasts
Value chain and competitive analysis
New services available
Revenue and business models
Pricing strategies
Technology launches
Major players’ strategies
Future roadmap scenarios

Please Note: Informa requires that clients sign a confidentiality agreement prior to fulfillment of all orders. Fulfillment may take 2-3 days after receipt of form.

Published By: Informa Media and Telecom
Date Published: Jan 2009

* * * * * *

RFID for Airports and Airlines 2008-2018

RFID is an extremely powerful enabling technology in airports and aircraft, serving to improve security against criminal attack, safety against general hazards, efficiency, error prevention and data capture and to remove tedious tasks. It can even create new earning streams where it makes tolling feasible without causing congestion and where new airport "touch and go" cards offer new paid services without delays.

Please note, the PDF Email From Publisher version of this report allows five users.

Published By: IDTechEx Ltd
Date Published: Jan 2008

* * * * * *



Software Tools

n.runs BTCrack a Bluetooth PIN Recovery tool. Thierry Zoller, a security consultant, developed BTCrack, an implementation of a flaw disclosed in 2005 by Israeli security researchers. The tool takes advantage of weak PINs in Bluetooth devices, allowing an attacker to listen in on a pairing session and gain access to both paired devices.
WM-soft The Real Bluejack is software for smartphones and Pocket PCs, that use Bluetooth. It extends your device’s Bluetooth functions. This program can: send Bluetooth messages, browse target-device’s filesystem via OBEX protocol, send AT commands, get phonebook, send SMS via target-phone, send files up to 2x faster then file managers, receive files directly into the Storage Card and other features.
"THE REAL BLUEJACK" IS NOT INTENDED FOR GETTING UNAUTHORIZED ACCESS TO PERSONAL DATA! Authentication is required! (But after you can do everything that you want)

 

Useful Resources:

  • Bluetooth SIG

    • Bluetooth SIG Response to Recent Analysis of Pairing and Security (6/05) New Scientist reported a new security threat to Bluetooth technology in June 2005 (New hack cracks 'secure' Bluetooth devices) from two Israeli researchers who suggested a way to subvert one of the built-in Bluetooth security mechanisms. Bluetooth devices generate a secure connection by means of the initial pairing process. During this process one or both devices need a PIN code to be entered, which is used by internal algorithms to generate a secure key which is then used to authenticate the devices whenever they connect in the future. The new academic paper puts forward a theoretical process that could potentially “guess” the security settings on a pair of Bluetooth devices. To do this the attacking device would need to listen in to the initial one-time pairing process. From this point it can use an algorithm to guess the security key and masquerade as the other Bluetooth device. What is new in this paper is an approach that forces a new pairing sequence to be conducted between the two devices and an improved method of performing the guessing process, which brings the time down significantly from previous attacks.

  • Java Security Our new listing on Java-related security.
     

  • WAP Security Our listings of WAP security news, tips, tools and techniques.

  • The Bunker Serious flaws in bluetooth security lead to disclosure of personal data In November 2003, Adam Laurie of A.L. Digital Ltd. discovered that there are serious flaws in the authentication and/or data transfer mechanisms on some Bluetooth enabled devices. Specifically, three vulnerabilities have been found: Firstly, confidential data can be obtained, anonymously, and without the owner's knowledge or consent, from some Bluetooth enabled mobile phones. Secondly, it has been found that the complete memory contents of some mobile phones can be accessed by a previously trusted ("paired") device that has since been removed from the trusted list. Thirdly, access can be gained to the AT command set of the device, giving full access to the higher level commands and channels, such as data, voice and messaging.