|
Earlier than expected, the number of downloads of the phone auditing tool Blooover exceeded the number of 65000. This means that the average download rate of the application was about 500 per day. This really high number of downloads made me think of implementing a new, more comprehensive version of Blooover: 'Blooover II'
Most likely, Blooover II will do Blueprinting to help identifying vulnerable devices. Also, the HeloMoto attack (discovered by Adam) will be included, since it is very similar to the already implemented BlueBug attack and does not need a lot of extra implementation. Another attack I thought of adding to Blooover is the BlueSmack attack. Unfortunately, this attack relies on L2CAP frames of which the support by the Java Bluetooth API is optional. As far as I found out, the JSR-82 implementation on Symbian phones do support this.
Planned release for 'Blooover II' would be DEFCON-13 (in the end of July 2005 in Las Vegas). Since it is not clear yet how my trip to Vegas (from Austria) is financed, any financial help is highly appreciated. So if you feel like contributing, you may do so. Thanks.
|