A Survey of Bluetooth Vulnerabilities Trends (2023 Edition), (Tue, Feb 7th)

The use of Bluetooth-enabled devices remains popular. New products (such as mobile phones, laptops and fitness trackers) still support this protocol and have even launched with more recent versions (e.g. Samsung S23 family of phones, iPhone 14 and 14 Pro, Apple Watch Series 8/SE/Ultra all shipped with Bluetooth 5.3). I had previously written about surveying the trend of Bluetooth vulnerabilities back in 2021 [1]. As roughly a year or so has passed, it was a timely moment to review how things may have evolved with respect to the vulnerabilities discovered. Compared to the previous diary, the current Bluetooth core specification has been bumped up to 5.3 (from 5.2 as compared to the previous diary) [2].

Continue reading A Survey of Bluetooth Vulnerabilities Trends (2023 Edition), (Tue, Feb 7th)→

Posted in Uncategorized

Earthquake in Turkey and Syria: Be Aware of Possible Donation Scams, (Mon, Feb 6th)

Last night, Turkey and Syria were affected by a significant earthquake. Sadly, experience teaches us that disasters like this will often be abused. The most common scam involves fake donation websites. But you may also see malware disguised as a video or images from the affected region.

Continue reading Earthquake in Turkey and Syria: Be Aware of Possible Donation Scams, (Mon, Feb 6th)→

Posted in Uncategorized

APIs Used by Bots to Detect Public IP address, (Mon, Feb 6th)

Many of the bots I am observing attempt to detect the infected system&#;x26;#;39;s public (“WAN”) IP address. Most of these systems are assumed to be behind NAT. To detect the external IP address, these bots use various public APIs. It may be helpful to detect these requests. Many use unique host names. This will make detecting the request in DNS logs easy even if TLS is not intercepted.

Continue reading APIs Used by Bots to Detect Public IP address, (Mon, Feb 6th)→

Posted in Uncategorized