An attack on Bluetooth 4, or Bluetooth Low Energy (LE), exposes millions of Bluetooth-enabled devices, leaving them vulnerable to malicious actors, according to a study called GATTacking Bluetooth Smart Devices, written by SecuRing security researcher Slawomir JASEK.
Due to its low energy consumption, Bluetooth LE has become one of the favorite methods for those who have an IoT device that talks to its paired device, usually a smartphone or tablet, running a specially built app.
At the Black Hat security conference last week, Jasek presented a new attack on the Bluetooth LE protocol that allows an attacker to spoof some of the lower layers of communication, which occur before the device is authenticated, in conjunction with an application through cryptographic functions.
This way, the attacker can gain a MITM (Man in the Middle) position between the Bluetooth LE device and the app. To prove that such a scenario can happen and help others test their products, Jasek created a tool for conducting such attacks, called GATTacker, which is open source on GitHub.
In section 4.1.1 of his research paper, Jasek details some real-world scenarios where a GATTack could be used.
For example, in a smart home, an attacker could tell a user's app that the IoT home automation system is down and disconnect the user's app from the home management functions, leaving the owner unable to control their home (Yes, like in that episode of “Mr Robot”!).
The same ability to disconnect apps from their devices can be used to turn off anti-theft systems, whether for homes or smart luggage locks.
Additionally, GATTacks can be used to insert and replace existing commands. Imagine a smart car locking system. The user sends a lock command, but the attacker intervenes and interrupts the unlocking, keeping the car open. Many other such attacks are possible.
Jasek says that for a GATTack to take place, the attacker needs to be near both devices they want to attack: the IoT device and the victim's smartphone. If the attacker uses malware to infect the smartphone, they may not need to be near the victim.
The researcher says that if manufacturers want to protect their devices from GATTacks, they should use BLE encryption, bonding, random MACs properly, watch out for configuration errors, and not implement static passwords.

