nerdexam
CompTIA

PT0-002 · Question #174

During a penetration test, a tester is in close proximity to a corporate mobile device belonging to a network administrator that is broadcasting Bluetooth frames. Which of the following is an example

The correct answer is B. Dump the user address book on the device.. Bluesnarfing is the unauthorized access to and exfiltration of data stored on a Bluetooth-enabled device, most commonly contact lists, emails, calendar entries, and text messages, by exploiting weaknesses in the Object Exchange (OBEX) protocol. Dumping the user's address book (B)

Attacks and Exploits

Question

During a penetration test, a tester is in close proximity to a corporate mobile device belonging to a network administrator that is broadcasting Bluetooth frames. Which of the following is an example of a Bluesnarfing attack that the penetration tester can perform?

Options

  • ASniff and then crack the WPS PIN on an associated WiFi device.
  • BDump the user address book on the device.
  • CBreak a connection between two Bluetooth devices.
  • DTransmit text messages to the device.

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    89% (25)
  • D
    7% (2)

Explanation

Bluesnarfing is the unauthorized access to and exfiltration of data stored on a Bluetooth-enabled device, most commonly contact lists, emails, calendar entries, and text messages, by exploiting weaknesses in the Object Exchange (OBEX) protocol. Dumping the user's address book (B) is the textbook definition of a Bluesnarfing attack. Option A describes a Wi-Fi WPS attack, which is unrelated to Bluetooth. Option C (breaking a Bluetooth connection) is closer to a denial-of-service or Bluejacking variant. Option D (transmitting text messages to the device) describes Bluejacking - pushing unsolicited messages - not stealing data.

Topics

#Bluetooth attacks#Bluesnarfing#Mobile device security#Penetration testing techniques

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice