PT0-002 · Question #174
During a penetration test, a tester is in close proximity to a corporate mobile device belonging to a network administrator that is broadcasting Bluetooth frames. Which of the following is an example
The correct answer is B. Dump the user address book on the device.. Bluesnarfing is the unauthorized access to and exfiltration of data stored on a Bluetooth-enabled device, most commonly contact lists, emails, calendar entries, and text messages, by exploiting weaknesses in the Object Exchange (OBEX) protocol. Dumping the user's address book (B)
Question
During a penetration test, a tester is in close proximity to a corporate mobile device belonging to a network administrator that is broadcasting Bluetooth frames. Which of the following is an example of a Bluesnarfing attack that the penetration tester can perform?
Options
- ASniff and then crack the WPS PIN on an associated WiFi device.
- BDump the user address book on the device.
- CBreak a connection between two Bluetooth devices.
- DTransmit text messages to the device.
How the community answered
(28 responses)- A4% (1)
- B89% (25)
- D7% (2)
Explanation
Bluesnarfing is the unauthorized access to and exfiltration of data stored on a Bluetooth-enabled device, most commonly contact lists, emails, calendar entries, and text messages, by exploiting weaknesses in the Object Exchange (OBEX) protocol. Dumping the user's address book (B) is the textbook definition of a Bluesnarfing attack. Option A describes a Wi-Fi WPS attack, which is unrelated to Bluetooth. Option C (breaking a Bluetooth connection) is closer to a denial-of-service or Bluejacking variant. Option D (transmitting text messages to the device) describes Bluejacking - pushing unsolicited messages - not stealing data.
Topics
Community Discussion
No community discussion yet for this question.