Knowledge

Bluetooth Low Energy denial of service attacks

Source 📝

101:
2023 tweeted that the Android device they used to control their insulin pump had been crashed by a BLE attack and that if they hadn't been able to fix it they would have had to go to a hospital.
52:, a Bluetooth adapter and a couple of antennas. This attack used Bluetooth advertising packets, hence did not require pairing. The demonstration version claimed to be an Apple TV and affected 661: 595: 515: 439: 485: 365: 546: 696: 218: 651: 480: 465: 641: 646: 470: 300: 164: 429: 857: 475: 1033: 561: 391: 358: 245: 327: 907: 266: 671: 194: 424: 1038: 571: 386: 351: 110: 64:
This attack also uses Bluetooth advertising packets to repeatedly send notification signals to iPhones and iPads running
753: 556: 495: 620: 743: 615: 500: 490: 130: 852: 536: 691: 24: 798: 733: 605: 919: 803: 520: 86:
The release of iOS 17.2 made devices more resistant to the attack, reducing the flood of popup messages.
895: 713: 541: 505: 449: 28: 1003: 576: 510: 444: 1028: 982: 763: 434: 195:"Flipper Zero can be used to crash iPhones running iOS 17, but there's a way to foil the attack" 836: 831: 718: 636: 600: 305: 134: 118: 728: 656: 77: 925: 758: 703: 610: 98: 877: 748: 1022: 998: 841: 813: 73: 808: 708: 666: 223: 69: 49: 188: 186: 883: 551: 871: 788: 778: 72:
running third-party Xtreme firmware. It functions even when the device is in
937: 889: 723: 419: 219:"This tiny device is sending updated iPhones into a never-ending DoS loop" 966: 913: 901: 865: 566: 773: 961: 931: 783: 768: 343: 45: 328:"Now Android and Windows devices aren't safe from Flipper Zero either" 246:"iOS 17.1 update still no defense against Flipper Zero iPhone crashes" 823: 738: 169: 65: 53: 83:
The attack can cause the device to crash. It also affects iOS 17.1.
76:, and can only be avoided by disabling Bluetooth from the device's 793: 332: 271: 267:"iOS 17.2 update puts an end to Flipper Zero's iPhone shenanigans" 250: 199: 129:
The Flipper Zero version of the attack has been adapted to attack
114: 48:
31 in 2023, a demonstration was given using equipment made with a
301:"'Wall of Flippers' detects Flipper Zero Bluetooth spam attacks" 347: 212: 210: 294: 292: 290: 288: 89:
An app to perform these attacks was written for Android.
165:"New iPhone iOS 16 Bluetooth Hack Attack—How To Stop It" 158: 156: 154: 152: 150: 113:
script that can scan for BTLE attacks. It can run on
991: 975: 954: 947: 850: 822: 684: 629: 588: 529: 458: 412: 405: 596:Munster Technological University ransomware attack 486:Waikato District Health Board ransomware attack 21:Bluetooth Low Energy denial of service attacks 547:Anonymous and the Russian invasion of Ukraine 359: 8: 516:National Rifle Association ransomware attack 440:United States federal government data breach 109:The Wall of Flippers project has written a 951: 481:Health Service Executive ransomware attack 409: 366: 352: 344: 326:Kingsley-Williams, Adrian (2023-10-24). 31:that can make it difficult to use them. 471:Ivanti Pulse Connect Secure data breach 146: 265:Kingsley-Hughes, Adrian (2023-12-15). 244:Kingsley-Hughes, Adrian (2023-10-30). 193:Kingsley-Hughes, Adrian (2023-10-16). 652:Ukrainian cyberattacks against Russia 430:European Medicines Agency data breach 7: 27:against mobile phones and iPads via 647:Change Healthcare ransomware attack 476:Colonial Pipeline ransomware attack 93:Interference with a medical device 14: 466:Microsoft Exchange Server breach 16:Set of denial-of-service attacks 672:IRLeaks attack on Iranian banks 40:DEFCON proof of concept attack 1: 667:Fur Affinity domain hijacking 572:Shanghai police database leak 562:Costa Rican ransomware attack 496:Kaseya VSA ransomware attack 163:Winder, Davey (2023-09-06). 621:British Library cyberattack 611:Insomniac Games data breach 299:Toulas, Bill (2023-12-23). 1055: 616:Polish railway cyberattack 501:Transnet ransomware attack 491:JBS S.A. ransomware attack 217:Goodin, Dan (2023-11-02). 1034:Denial-of-service attacks 425:Twitter account hijacking 379: 25:denial-of-service attacks 557:DDoS attacks on Romania 35:iPhone and iPad attacks 896:Account pre-hijacking 642:Kadokawa and Niconico 542:Red Cross data breach 1039:Hacking in the 2020s 567:LastPass vault theft 537:Ukraine cyberattacks 450:Vastaamo data breach 374:Hacking in the 2020s 29:Bluetooth Low Energy 662:Trump campaign hack 578:Grand Theft Auto VI 445:EasyJet data breach 60:Flipper Zero attack 764:IT Army of Ukraine 606:MOVEit data breach 435:Nintendo data leak 396:2030s → 1016: 1015: 1012: 1011: 837:maia arson crimew 832:Graham Ivan Clark 697:associated events 680: 679: 637:XZ Utils backdoor 601:Evide data breach 521:Banco de Oro hack 400: 399: 306:Bleeping Computer 135:Microsoft Windows 119:Microsoft Windows 1046: 952: 657:2024 WazirX hack 506:Epik data breach 410: 382: 381: 368: 361: 354: 345: 338: 337: 323: 317: 316: 314: 313: 296: 283: 282: 280: 279: 262: 256: 255: 241: 235: 234: 232: 231: 214: 205: 204: 190: 181: 180: 178: 177: 160: 105:Wall of Flippers 23:are a series of 1054: 1053: 1049: 1048: 1047: 1045: 1044: 1043: 1019: 1018: 1017: 1008: 987: 971: 943: 855: 853:vulnerabilities 846: 818: 704:Anonymous Sudan 676: 625: 584: 525: 454: 406:Major incidents 401: 375: 372: 342: 341: 325: 324: 320: 311: 309: 298: 297: 286: 277: 275: 264: 263: 259: 243: 242: 238: 229: 227: 216: 215: 208: 192: 191: 184: 175: 173: 162: 161: 148: 143: 127: 107: 99:Midwest FurFest 97:An attendee of 95: 62: 42: 37: 17: 12: 11: 5: 1052: 1050: 1042: 1041: 1036: 1031: 1021: 1020: 1014: 1013: 1010: 1009: 1007: 1006: 1001: 995: 993: 989: 988: 986: 985: 979: 977: 973: 972: 970: 969: 964: 958: 956: 949: 945: 944: 942: 941: 935: 929: 923: 917: 911: 905: 899: 893: 887: 881: 878:PrintNightmare 875: 869: 862: 860: 848: 847: 845: 844: 839: 834: 828: 826: 820: 819: 817: 816: 811: 806: 804:Sakura Samurai 801: 796: 791: 786: 781: 776: 771: 766: 761: 756: 751: 749:GnosticPlayers 746: 741: 736: 731: 726: 721: 716: 711: 706: 701: 700: 699: 688: 686: 682: 681: 678: 677: 675: 674: 669: 664: 659: 654: 649: 644: 639: 633: 631: 627: 626: 624: 623: 618: 613: 608: 603: 598: 592: 590: 586: 585: 583: 582: 574: 569: 564: 559: 554: 549: 544: 539: 533: 531: 527: 526: 524: 523: 518: 513: 511:FBI email hack 508: 503: 498: 493: 488: 483: 478: 473: 468: 462: 460: 456: 455: 453: 452: 447: 442: 437: 432: 427: 422: 416: 414: 407: 403: 402: 398: 397: 394: 389: 380: 377: 376: 373: 371: 370: 363: 356: 348: 340: 339: 318: 284: 257: 236: 206: 182: 145: 144: 142: 139: 126: 125:Android attack 123: 106: 103: 94: 91: 61: 58: 41: 38: 36: 33: 15: 13: 10: 9: 6: 4: 3: 2: 1051: 1040: 1037: 1035: 1032: 1030: 1027: 1026: 1024: 1005: 1002: 1000: 999:Cyclops Blink 997: 996: 994: 990: 984: 981: 980: 978: 974: 968: 965: 963: 960: 959: 957: 953: 950: 946: 939: 936: 933: 930: 927: 924: 921: 918: 915: 912: 909: 906: 903: 900: 897: 894: 891: 888: 885: 882: 879: 876: 873: 870: 867: 864: 863: 861: 859: 854: 849: 843: 840: 838: 835: 833: 830: 829: 827: 825: 821: 815: 814:Wizard Spider 812: 810: 807: 805: 802: 800: 797: 795: 792: 790: 787: 785: 782: 780: 777: 775: 772: 770: 767: 765: 762: 760: 757: 755: 752: 750: 747: 745: 742: 740: 737: 735: 732: 730: 727: 725: 722: 720: 717: 715: 712: 710: 707: 705: 702: 698: 695: 694: 693: 690: 689: 687: 683: 673: 670: 668: 665: 663: 660: 658: 655: 653: 650: 648: 645: 643: 640: 638: 635: 634: 632: 628: 622: 619: 617: 614: 612: 609: 607: 604: 602: 599: 597: 594: 593: 591: 587: 581: 579: 575: 573: 570: 568: 565: 563: 560: 558: 555: 553: 550: 548: 545: 543: 540: 538: 535: 534: 532: 528: 522: 519: 517: 514: 512: 509: 507: 504: 502: 499: 497: 494: 492: 489: 487: 484: 482: 479: 477: 474: 472: 469: 467: 464: 463: 461: 457: 451: 448: 446: 443: 441: 438: 436: 433: 431: 428: 426: 423: 421: 418: 417: 415: 411: 408: 404: 395: 393: 390: 388: 385:←  384: 383: 378: 369: 364: 362: 357: 355: 350: 349: 346: 335: 334: 329: 322: 319: 308: 307: 302: 295: 293: 291: 289: 285: 274: 273: 268: 261: 258: 253: 252: 247: 240: 237: 226: 225: 220: 213: 211: 207: 202: 201: 196: 189: 187: 183: 172: 171: 166: 159: 157: 155: 153: 151: 147: 140: 138: 136: 132: 124: 122: 120: 116: 112: 104: 102: 100: 92: 90: 87: 84: 81: 79: 75: 74:airplane mode 71: 67: 59: 57: 55: 51: 47: 39: 34: 32: 30: 26: 22: 809:ShinyHunters 709:Berserk Bear 580:content leak 577: 331: 321: 310:. Retrieved 304: 276:. Retrieved 270: 260: 249: 239: 228:. Retrieved 224:Ars Technica 222: 198: 174:. Retrieved 168: 128: 108: 96: 88: 85: 82: 78:Settings app 70:Flipper Zero 68:. It uses a 63: 50:Raspberry Pi 43: 20: 18: 884:FORCEDENTRY 824:Individuals 744:Ghostwriter 552:Viasat hack 1023:Categories 872:Thunderspy 789:OceanLotus 779:LightBasin 729:DarkMatter 312:2024-01-05 278:2023-12-16 230:2023-11-13 176:2023-11-13 141:References 1029:Bluetooth 1004:Pipedream 938:Sinkclose 890:Log4Shell 858:disclosed 856:publicly 754:Guacamaya 724:Cozy Bear 692:Anonymous 420:BlueLeaks 137:systems. 983:Predator 967:Drovorub 926:Terrapin 914:LogoFAIL 908:Downfall 902:Retbleed 866:SMBGhost 842:Kirtaner 799:Sandworm 774:Lapsus$ 734:DarkSide 714:BlackCat 392:Timeline 962:Adrozek 948:Malware 932:GoFetch 784:LockBit 769:Killnet 759:Hafnium 131:Android 46:DEF CON 940:(2024) 934:(2024) 928:(2023) 922:(2023) 920:Reptar 916:(2023) 910:(2023) 904:(2022) 898:(2022) 892:(2021) 886:(2021) 880:(2021) 874:(2020) 868:(2020) 851:Major 739:Dridex 685:Groups 170:Forbes 111:Python 66:iOS 17 54:iOS 16 794:REvil 387:2010s 333:ZDNET 272:ZDnet 251:ZDNET 200:ZDNET 115:Linux 992:2022 976:2021 955:2020 719:Clop 630:2024 589:2023 530:2022 459:2021 413:2020 133:and 19:The 117:or 44:At 1025:: 330:. 303:. 287:^ 269:. 248:. 221:. 209:^ 197:. 185:^ 167:. 149:^ 121:. 80:. 56:. 367:e 360:t 353:v 336:. 315:. 281:. 254:. 233:. 203:. 179:.

Index

denial-of-service attacks
Bluetooth Low Energy
DEF CON
Raspberry Pi
iOS 16
iOS 17
Flipper Zero
airplane mode
Settings app
Midwest FurFest
Python
Linux
Microsoft Windows
Android
Microsoft Windows





"New iPhone iOS 16 Bluetooth Hack Attack—How To Stop It"
Forbes


"Flipper Zero can be used to crash iPhones running iOS 17, but there's a way to foil the attack"
ZDNET


"This tiny device is sending updated iPhones into a never-ending DoS loop"
Ars Technica

Text is available under the Creative Commons Attribution-ShareAlike License. Additional terms may apply.