Android Bluetooth Hacking with Python

Sdílet
Vložit
  • čas přidán 13. 09. 2024
  • Make sure you patch your phone (unfortunately older devices cannot be patched). See CVE here: nvd.nist.gov/v...
    How to stop / mitigate this attack:
    1) Upgrade your phone / install security patches on Android for versions 11 and later. Unfortunately earlier versions cannot be patched (Android 10 and earlier)
    2) Note: For the script to discover the MAC address of the phone, the phone needs to be in pairing mode.
    3) Turn off Bluetooth if not being used
    Learn more here: • Android Bluetooth Hacking
    #android #bluetooth #iphone

Komentáře • 759

  • @davidbombal
    @davidbombal  Před 4 měsíci +446

    Full video explaining this here: czcams.com/video/IevVEUzXA30/video.html
    Make sure you patch your phone (unfortunately older devices cannot be patched). See CVE here: nvd.nist.gov/vuln/detail/CVE-2023-45866
    How to stop / mitigate this attack:
    1) Upgrade your phone / install security patches on Android for versions 11 and later. Unfortunately earlier versions cannot be patched (Android 10 and earlier)
    2) Note: For the script to discover the MAC address of the phone, the phone needs to be in pairing mode.
    3) Turn off Bluetooth if not being used

    • @User-mm3uy
      @User-mm3uy Před 4 měsíci +3

      Can you suggest a blutooth adaptor for pentest?

    • @Priyabrat_Swain
      @Priyabrat_Swain Před 4 měsíci

      ​@@User-mm3uyyes recommend something that is chep in price?

    • @bhuvan1036
      @bhuvan1036 Před 4 měsíci +2

      Dude your mac address is exposed in the confirmation message

    • @bhuvan1036
      @bhuvan1036 Před 4 měsíci +1

      Timestamp 00:34

    • @JamieGillespieOnline
      @JamieGillespieOnline Před 4 měsíci +12

      It doesn't matter because MAC addresses are only used on the local network. There's literally nothing you can do with one over the Internet.

  • @GoofyLizard163
    @GoofyLizard163 Před 4 měsíci +2318

    Yeah I just got rick rolled by a raspberry Pi 😂

    • @davidbombal
      @davidbombal  Před 4 měsíci +157

      I had to do it 😂

    • @Mr.forgettable_wastaken
      @Mr.forgettable_wastaken Před 4 měsíci +38

      ​@@davidbombaldo you realise HOW MUCH POWER YOU HAVE!!! You can rick roll anyone at anytime.no man should have this much power

    • @KrisinaCrossing2011
      @KrisinaCrossing2011 Před 4 měsíci +2

      @@Mr.forgettable_wastaken not anytime they gotta be close to you

    • @backupjester3520
      @backupjester3520 Před 4 měsíci +6

      ​@@KrisinaCrossing2011r/whoosh

    • @Hypernoid.
      @Hypernoid. Před měsícem +1

      R/wooooshwith4os

  • @TweakMDS
    @TweakMDS Před 3 měsíci +459

    "the phone needs to be in pairing mode" is kind of a big if.

    • @miss_sapphire
      @miss_sapphire Před 2 měsíci +24

      Ty. That's what I was curious about

    • @emetsalt7965
      @emetsalt7965 Před měsícem +46

      ​@miss_sapphire This man just emulating a wireless keyboard😬😬

    • @Severartery
      @Severartery Před měsícem +19

      Look up blueborne vulnerability doesn't need to be in pairing mode for that

    • @SantinoDeluxe
      @SantinoDeluxe Před měsícem

      @@Severartery that was 7 years ago, if the device is a decade old you might be vulnerable but google provides a scan tool made by Armis, the people who reported the bugs.

    • @psudhani6991
      @psudhani6991 Před měsícem +10

      Another big if "the bluetooth need to be ON'

  • @_xQw7
    @_xQw7 Před 4 měsíci +847

    Bro rickrolls himself so we can learn something, huge respect

  • @kenn6110
    @kenn6110 Před 4 měsíci +329

    Blurring mac addresses on list but not blurring after selecting device is genius

  • @RayaRaj
    @RayaRaj Před 3 měsíci +484

    "im not gonna touch it"
    2 sec later: he touched the phone

  • @venb
    @venb Před 4 měsíci +340

    This vulnerability affects Android ~4.2.2 and later.
    > Android 4.2.2 - 10 will not be patched
    > Android 11 - 14 have patches available (2023-12-05 security patch level)
    Pretty much just old ass phones

    • @Hhhh22222-w
      @Hhhh22222-w Před 4 měsíci +22

      Bro forgot most android phones have 2-3 years of OS, if you bought an older Android... RIP

    • @SuperS05
      @SuperS05 Před 4 měsíci

      ​@@Hhhh22222-wif you're buying an old phone, get one that supports lineageos at least

    • @Bravin_Joshua
      @Bravin_Joshua Před 4 měsíci +11

      The phone demonstrated ran on android 12

    • @shadmansudipto7287
      @shadmansudipto7287 Před 4 měsíci +9

      ​@@Bravin_Joshuathen it did not get the security update.

    • @GamerBoy705_yt
      @GamerBoy705_yt Před 4 měsíci +16

      ​@@Bravin_JoshuaOnePlus 7T originally came with Android 10, the guy probably hasn't updated it.

  • @xenopholis47
    @xenopholis47 Před 4 měsíci +105

    The fact that he Rick Rolls all of us with a straight face is just hilarious.

  • @deim3
    @deim3 Před 4 měsíci +611

    > I'm not gonna touch it.
    > Touches it in less than a second

    • @nandorholozsnyak7799
      @nandorholozsnyak7799 Před 4 měsíci +24

      I was laughing so hard on it 😂

    • @tdrg_
      @tdrg_ Před 4 měsíci +31

      He had to enable the sound for the rickroll to count 😂

    • @MrSoso1212
      @MrSoso1212 Před 4 měsíci +1

      🤣🤣

    • @zamamadikizela8025
      @zamamadikizela8025 Před 4 měsíci +4

      I thought l was the only one who noticed 😂😂😂

    • @davidbombal
      @davidbombal  Před 4 měsíci +147

      Only after the attack was run 😂

  • @khartarnakbhaiyaPUBG
    @khartarnakbhaiyaPUBG Před 13 dny +3

    "No officer wait listen ...
    It was just educationaaaaal!!"

  • @siddharthchhetry4218
    @siddharthchhetry4218 Před 4 měsíci +17

    Respect for the person who wrote that python code

  • @milind_kulkarni
    @milind_kulkarni Před 4 měsíci +19

    ffs it's 2024 and I'm still getting rickrolled😭

  • @0CipherX
    @0CipherX Před 3 dny +1

    Bro just rick rolled the entire cyber security community 🎉

  • @Link-channel
    @Link-channel Před 3 měsíci +8

    This protocol was compromised so many times it should get an award for the less secure technology

  • @zertoil
    @zertoil Před 3 měsíci +17

    Honestly, I want to do this in a public setting like a comicon and rick roll everyone all at once. It would be epic hearing that every where, all at once 🤣

  • @SahitDagani
    @SahitDagani Před 4 měsíci +20

    Me sweating bricks as I always have Bluetooth on 😰

    • @emetsalt7965
      @emetsalt7965 Před měsícem +1

      U all good G most modern android distributions make you accept the connection b4 you connect to his wireless keyboard

    • @71lucid-kid
      @71lucid-kid Před měsícem

      @@emetsalt7965 could it do it to a iPhone 😅

  • @burgek1
    @burgek1 Před 4 měsíci +15

    This isn't the first time you've Rock Rolled me!

  • @jacksenic
    @jacksenic Před 4 měsíci +9

    Why go through the trouble of blurring the 7T MAC address, when 3 seconds later it's fully shown (after 4 is selected)

    • @thomeralgo
      @thomeralgo Před 4 měsíci +2

      Exactly what I thought ^^

  • @Mirage-on-the-beat
    @Mirage-on-the-beat Před měsícem +1

    Imagine doing this at school. Everyone just pulled out their phones and gets Rick rolled 😂😂😂

  • @ashakumawat4610
    @ashakumawat4610 Před 4 měsíci +63

    WE ARE GOING TO RICKROLL EVERYONE WITH THIS ONE 🔥🔥🗣️🗣️🗣️

  • @blender_wiki
    @blender_wiki Před 4 měsíci +2

    Even if is patched after android version 11 is a good security practice keep your bluetooth off when you are in public spaces.

  • @atikattar1104
    @atikattar1104 Před 3 měsíci +2

    That's Why I Keep My Bluetooth, Wifi, Etc. Types Of Wireless Communications Turned Off When Not Needed. Sometimes, Even Cellular Connection.

  • @eio1971
    @eio1971 Před měsícem +1

    David been getting me paranoid about blue tooth lately

  • @soumyadeepsarkar3808
    @soumyadeepsarkar3808 Před 4 měsíci +9

    Why did I get Rick rolled in a Dvid Bombal video ? 😢

  • @colin0516
    @colin0516 Před 3 měsíci +1

    this man single handedly keeping kali alive to date

    • @AminHoseiniMoghadam
      @AminHoseiniMoghadam Před dnem

      Just curious what are the better operating systems than kali except parrot

  • @griffindragon3562
    @griffindragon3562 Před 2 měsíci +1

    Smoothest rickroll ever. 😭

  • @hirananand1332
    @hirananand1332 Před 4 měsíci +7

    Bro got that hacking rizz

  • @Demon_playz7169
    @Demon_playz7169 Před 4 měsíci +9

    Imagine you're chilling and some hacker hacked you're phone and rick rolled you 😂

  • @cbb3062
    @cbb3062 Před 4 měsíci +20

    Is there going to be a how to video? The rick roll 😂😂😂

    • @davidbombal
      @davidbombal  Před 4 měsíci +20

      Yes. Coming soon!

    • @davidbombal
      @davidbombal  Před 4 měsíci +3

      Full video here: czcams.com/video/IevVEUzXA30/video.html

    • @klopf_
      @klopf_ Před 4 měsíci

      @@davidbombal If this link is gonna sent me to a Rick Astley video....

    • @-Cocell
      @-Cocell Před 4 měsíci

      ​@@klopf_Did it?

    • @AverageJoe46549
      @AverageJoe46549 Před 4 měsíci

      ​@@davidbombalyay!

  • @vaibhavmishra5327
    @vaibhavmishra5327 Před 4 měsíci +35

    Don't worry guys this vurniablity has been fix after A11

    • @Hhhh22222-w
      @Hhhh22222-w Před 4 měsíci +4

      Basically most android phone older than 2018 will most likely be vulnerable, since most Androids only get 1-2 extra year of security update, meanwhile iPhone 6 from 2014 still gets security updates lol.

    • @thevoiddemon6778
      @thevoiddemon6778 Před 4 měsíci

      ​@@Hhhh22222-w androids in the same price range as an iphone mostly get 5 years of security updates and the google is on another level so yea .

    • @HomayoonVafamehr
      @HomayoonVafamehr Před 4 měsíci

      ​@@Hhhh22222-wWhile Apple is doing a great job on updating its phones, there are some miss leading in your comment. First you are comparing a flagship phone (iphone 6) to budget phones out there. It's been a long time since Android flagships are getting 4 or 5 years of security updates(like pixels), and recently they offer 7 years of update. If any one wants to be picky and go for an iPhone, they should be picky in choosing Android phones too and not buying every crappy phone as Android phones and complaining.

    • @nvduk3
      @nvduk3 Před 4 měsíci +5

      No iPhone 6 cant be updated beyond iOS 12.5 as it doesnt meet the hardware requirement for the latest iOS. So unfortunately no latest security patches. Need to get a new phone for that. Tech simply cant backtrack to 10 year old devices.

    • @notch_àpple_op
      @notch_àpple_op Před 4 měsíci

      ​@@Hhhh22222-w yea with every update, they reduce the battery and performance 😂😂
      *mee eh eh apple Sheep detected*

  • @m_sitso
    @m_sitso Před 24 dny +1

    bro, just Rick rolled me

  • @hakdog-t1d
    @hakdog-t1d Před 4 hodinami

    "not gonna touch it" then proceeds to unmute the thing

    • @hakdog-t1d
      @hakdog-t1d Před 4 hodinami

      Also... I don't know if it's ok showing your MAC address like that... you censored the four... but when you entered 4.. it asked you if you like to enter the device with 22:22:1B:10:52:A5... why not censor it as well?
      p.s.: please don't answer my question like it's a matter of course... I know close to nothing when it comes to networking...

  • @KNIGHT.2809
    @KNIGHT.2809 Před měsícem

    never thought i would get rick rolled by a computer

  • @abeyroy007
    @abeyroy007 Před 4 měsíci

    Most technologically advanced RickRoll ever 😂

  • @HyperBeamXYT
    @HyperBeamXYT Před 19 dny

    That was a serious rick roll

  • @erik-fisher
    @erik-fisher Před 17 dny +1

    That phone was already unlocked.

  • @Mayhem-OS
    @Mayhem-OS Před měsícem

    I love how he went to press the 'unmute' button as its muted by default.

  • @ZoomMan2
    @ZoomMan2 Před měsícem

    Bro just did all of this for rickroll us, what a legend.

  • @michael040990
    @michael040990 Před 4 měsíci +5

    Calling this, a hack is a little bit of a reach. You already have the phone paired with the device so you have to have physical access and then you’re just emulating a USB keyboard to open a browser. Now it’ll be one thing if you were able to allow the raspberry pie to connect to the phone without previously being paired.

    • @daruiraikage
      @daruiraikage Před 3 měsíci

      thanks, I was wondering the same thing. can it be possible to mimic a paired device?

    • @prophetzarquon1922
      @prophetzarquon1922 Před 3 měsíci

      Mimicking a paired device is exactly how vulnerabilities like this (which doesn't affect newer OSes) go from minor to extreme.

  • @WhatAmIDoingHereOnYoutube

    “The bluetooth device is ready to pair”

  • @Snoper_real
    @Snoper_real Před měsícem

    “I’m not gonna touch it”
    Proceeds to touch it 💀

  • @michaelkingy355
    @michaelkingy355 Před 11 dny

    I constantly have this happen to me when I’m driving around at the moment

  • @abeyroy007
    @abeyroy007 Před 4 měsíci

    Technology have advanced so much but people still gets rickrolled 😂

    • @prophetzarquon1922
      @prophetzarquon1922 Před 3 měsíci

      In the year 2525,
      if man is still alive
      there will be RickRolling

    • @abeyroy007
      @abeyroy007 Před 3 měsíci

      @@prophetzarquon1922 fr ☠️

  • @phatomphreak5965
    @phatomphreak5965 Před měsícem

    ricky roll has been
    going around since 2011

  • @jenshansenhavde
    @jenshansenhavde Před 4 měsíci +1

    This is why you disable your phone being visible to other devices after being done pairing your phone with your stuff.
    You never know when a new or custom hack is out.

    • @prophetzarquon1922
      @prophetzarquon1922 Před 3 měsíci +1

      +1
      There's really no reason to leave all the wireless on when devices aren't connected; Bluetooth, NFC, UWB, WiFi, & even Location services, are best kept off when not in use.

    • @wildyato3737
      @wildyato3737 Před 3 měsíci

      Seriously everything is.possible besides using just for Internet..
      it's like it is accepting unauthorized things or commands from other source even it is not connected !
      I wonder if It does work on WiFi?😅

  • @Leroy0070
    @Leroy0070 Před měsícem

    The good old hacking days. When LOIC and IRCs were the thing.

  • @randomgameplayvid
    @randomgameplayvid Před 11 dny

    Expectation: Hackers steal stuff from our phone and put viruses in it
    Reality: Hackers rickroll us from our own phone

  • @erikstorm14
    @erikstorm14 Před 19 dny

    "I wont touch it"
    Proceds with touching

  • @LeViIain
    @LeViIain Před 27 dny

    They call him the father of hacking, he used bluetooth to wirelessly play a song on another device.

  • @CatCread16
    @CatCread16 Před 28 dny

    I see a lot of trolling capabilities in this

  • @StarfilmerOne
    @StarfilmerOne Před 4 měsíci +1

    Instructions unclear, rickrolled myself

  • @H4FI2
    @H4FI2 Před 4 měsíci +2

    its been a while with no rickrolls.

  • @pheapkim978
    @pheapkim978 Před 4 měsíci

    I never thought I would get Rick rolled again 😂

  • @bamstian
    @bamstian Před 3 měsíci

    "I am not gonna touch it" touches it.

  • @3pm-on-yt
    @3pm-on-yt Před měsícem

    thank u now i can wirelessly rickroll my friends

  • @jacklegminercanada3866

    Using a dummy phone as an example always wins.
    I used to have a seperate windows box that i practiced exploits on but in real world, alot less likely

  • @Accelerator974
    @Accelerator974 Před 24 dny

    „I am not gonna touch it“

  • @StijnHommes
    @StijnHommes Před 3 měsíci +1

    And that is why you turn bluetooth off.

  • @segfault4568
    @segfault4568 Před 4 měsíci

    Didn't see that coming, Good one David Good one.
    I will not forget this.

  • @yashwanthc1642
    @yashwanthc1642 Před 4 měsíci

    A very professional way to get Rick rolled... 😄😄😄

  • @williamyeong69
    @williamyeong69 Před 4 měsíci

    I remembered back in the days I installed a Java programme in my old phone that can “hack” into other phone by Bluetooth pairing. And it works, I can see their messages, contacts, even photos and videos that are saved in their devices. I can even make calls and send messages with their phones from mine.

  • @yusriamilkassim4795
    @yusriamilkassim4795 Před 4 měsíci

    Imagine you in party house attacking all you homies phone and start raving to the songs… that is best party trick

  • @davidblaze8847
    @davidblaze8847 Před 12 dny

    now I may be wrong, but I'm pretty sure it doesn't need to be in pairing mode to get the Mac, as long as you can scan the area, or your own network with a wifi adapter with monitor mode. considering devices are usually always trying to connect to a wifi source anyway.

  • @ACID1337xx
    @ACID1337xx Před 4 měsíci +3

    Im not gonna touch it - touches it

    • @davidbombal
      @davidbombal  Před 4 měsíci +1

      Only after the attack was run 😂

    • @davidbombal
      @davidbombal  Před 4 měsíci

      Only after the attack was run 😂

  • @LJ-zt6lf
    @LJ-zt6lf Před 3 měsíci +1

    Best way to Rick roll

  • @marekdedik3306
    @marekdedik3306 Před 4 měsíci

    same technology used by a phone to a television when you want to share a screen

  • @nitintalreja1615
    @nitintalreja1615 Před 3 měsíci

    Meanwhile android always push you to keep ur phone's Bluetooth on

  • @DonaldDuvall
    @DonaldDuvall Před 28 dny

    Can you make a longer video, where you explain what the vulnerability is in bluetooth or how an attacker is gaining access to perform remote code execution?

  • @planktonfun1
    @planktonfun1 Před 3 měsíci

    yes, you can also hack a desktop/laptop using bluetooth, its called bluetooth rubber ducky. you don't even need a raspberry pi your laptop is enough to do the trick. You can also use a usb directly, basically any device that can act as a keyboard

  • @taher9358
    @taher9358 Před 4 měsíci

    I feel like I need get back at you for the Rick Roll 😂

  • @agents_of_hydra1859
    @agents_of_hydra1859 Před měsícem

    Great tutorial sir

  • @harrisra4944
    @harrisra4944 Před 2 měsíci

    "Im not going to touch it". He touches it😮

  • @nishantkr5759
    @nishantkr5759 Před 4 měsíci

    You know your phone is hacked when it starts playing "Never gonna give you up" 😂

  • @sabre_code
    @sabre_code Před 4 měsíci +10

    Moral . Keep Bluetooth and wifi off when not needed

    • @semiruu
      @semiruu Před 4 měsíci

      I feel like that was missing as context, that if you are out on public lets say and still have Bluetooth on one could get rick rolled like that 😂

    • @wildyato3737
      @wildyato3737 Před 3 měsíci

      I wonder every thing has a weakness..even the USB😅

  • @Hanzakhan23
    @Hanzakhan23 Před 4 měsíci

    we got rickrolling from bluetooth before GTA6

  • @gamerab466
    @gamerab466 Před měsícem

    Sir, I want to learn some basic Hacking Methods usually used in games.❤

  • @Living1980s
    @Living1980s Před 4 měsíci

    Legend is "Rick is still Rollin' to this day"

  • @elektron2kim666
    @elektron2kim666 Před 3 měsíci

    It was not meant for computing at first. It was hands-free and audio as far as I remember. Laissez faire digital lines to a computer is madness. (Phone = computer at this point in time).

  • @Weeklong_Seagull
    @Weeklong_Seagull Před 25 dny

    You can also get people's credit cards off their phones really easy most people walk around with NFC turned on. On your phone and go close to them and you can scan the NFC and take their card

  • @mike22273
    @mike22273 Před 23 dny

    I’d accidentally hack the phone in my pocket instead of my intended target

  • @erichkaanikin3555
    @erichkaanikin3555 Před 2 měsíci

    Haha. “Rick rolled” wins the internet today!

  • @charliemedia5111
    @charliemedia5111 Před 3 měsíci

    Best Channel On You-Tube Love Learning New Ways Of Useing A Online Way Of Some Good Tacticks,Thanks Very Much Sir Sheer GOLD 🥇

  • @realityinred
    @realityinred Před 3 měsíci

    bluethout pairing security gonna prevent you from hacking the phone

  • @jerome436
    @jerome436 Před 25 dny

    Maybe try a newer phone that still receives security updates? It is expected that an older phone which no longer receives security updates ispre vulnerable to attacks.

  • @bigbuckoramma
    @bigbuckoramma Před 4 měsíci +1

    Gotta love that you censor thr MAC in the device list, but as soon as you select the device and execute the script, it ahows the full uncensored MAC. Whoops. 😂

  • @HensonKwong
    @HensonKwong Před 4 měsíci +1

    Let me just set this up in a starbucks coffee table

  • @rrrrrr9308
    @rrrrrr9308 Před měsícem

    It is a Bluetooth Rubberducky!

  • @tigerchills2079
    @tigerchills2079 Před 2 měsíci

    "I'm not gonna touch it"
    *touch touch touch touch*

  • @ArpaRec
    @ArpaRec Před 3 měsíci

    It probably acts as a bluetooth keyboard

  • @eckee
    @eckee Před 3 měsíci

    I can't believe how incompetent bluetooth developers are and how insecure it is. And how much we use it with no alternatives

  • @Khaled.003
    @Khaled.003 Před 3 měsíci

    Well its more dangerous for iOS cause in android when you turn off Bluetooth or wifi its off. But in ios it just disconnects the connected devices and don't turn it off. If you want to turn off you have to fo it in settings that most people don't do most of the time

  • @miicha84
    @miicha84 Před 4 měsíci

    He looks like Zed, the Android from the Future😂

  • @fatihyilmaz-Gtr
    @fatihyilmaz-Gtr Před 3 měsíci

    Never gonna touch your devices🕺

  • @setoman1
    @setoman1 Před 4 měsíci +1

    Don’t broadcast your BT and you’ll be fine 😂

  • @Kelvin.Ramoso
    @Kelvin.Ramoso Před 2 měsíci

    Noooo! You touch it! You said you're not going to touch it!!!

  • @L337Haxorz
    @L337Haxorz Před měsícem

    Damn like it’s 2007 all over again, I always loved getting rolled’ hats off to you sir

  • @FocusDarb
    @FocusDarb Před 3 měsíci

    Not going to touch he said , continues to unmute and skip the video 😂

  • @OneAndOnlyZekePolaris
    @OneAndOnlyZekePolaris Před 3 měsíci

    "I'm not going to touch it"
    Touches it

  • @motorsport5787
    @motorsport5787 Před 4 měsíci

    Bro casually rick rolled us😂

  • @tanvinrayhan
    @tanvinrayhan Před 2 měsíci

    I'm not gonna touch it, Touches the phone!