Devices exposed to MITM attacks as hackers exploit BLURtooth vulnerability
The attacks that exploit the vulnerability are termed as BLUR attacks by security researchers.
Bluetooth has been a widely used technology in various devices and as technology advances the use of Bluetooth is becoming more profound. Just like every protocol, it is important to remember that it can be vulnerable as well.
Keeping the vulnerabilities in mind, recently researchers have discovered that the Cross-Transport Key Derivation (CTKD) which can be found in both versions 4.2 and 5.0 of Bluetooth’s core specifications is vulnerable to a Man in the Middle Attack (MITM).
The vulnerability targets the fact that CTKD is used for the authentication that occurs when multiple devices connect to each other. It does so by allowing the user to choose 1 out of 2 standards, namely Low Energy (BLE) and Basic Rate/Enhanced Data Rate (BR/EDR) for the authentication to occur.
BLE is mostly used in IoT devices and wearable tech, while BR/EDR is a digital mobile phone technology that allows improved data transmission rates. Mostly, the technology is used in apps like wireless headphones and speakers, etc.
Their are various methods by which the vulnerability can be patched. One of these is that no overwriting of keys is allowed by default in the vulnerable versions mentioned above and ” restrictions on CTKD” be also placed.
NPAV recommends users to always monitor their bluetooth devices and keep a proper password protection over the pairing mechanism. Bluetooth can be exploited by hackers to launch various cyber attacks on your devices.
Install NPAV to keep your devices protected from all kinds of cyber attacks. Use NPAV and join us on a mission to secure the cyber world.
- Other (42)
- Ransomware (123)
- Events and News (26)
- Features (44)
- Security (422)
- Tips (79)
- Google (22)
- Achievements (8)
- Products (33)
- Activation (7)
- Dealers (1)
- Bank Phishing (42)
- Malware Alerts (187)
- Cyber Attack (219)
- Data Backup (11)
- Data Breach (75)
- Phishing (138)
- Securty Tips (1)
- Browser Hijack (16)
- Adware (15)
- Email And Password (67)
- Android Security (55)
- Knoweldgebase (38)
- Botnet (15)
- Updates (3)
- Alert (70)
- Hacking (57)
- Social Media (7)
- vulnerability (53)
- Hacker (31)
- Spyware (8)
- Windows (6)
- Microsoft (21)
- Uber (1)
- YouTube (1)
- Trojan (2)
- Website hacks (3)
- Paytm (1)
- Credit card scam (1)
- Telegram (3)
- RAT (5)
- Bug (3)
- Twitter (2)
- Facebook (7)
- Banking Trojan (5)
- Mozilla (2)
- COVID-19 (5)
- Instagram (2)
- NPAV Announcement (5)
- IoT Security (1)
- Deals and Offers (1)
- Cloud Security (8)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (2)
- WhatsApp (4)
- Amazon (1)
- DMart (1)
- Payment Risk (4)
- Occasion (2)
- firewall (1)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (4)
- Impersonation phishing (1)
- DDoS (4)
- Smishing (2)
- Whale (0)
- Whale phishing (3)
- WINRAR (2)
- ZIP (2)