A security analyst reviews device logs following reports of abnormal wireless activity on an executive's smartphone during an off-site conference. The logs indicate that the smartphone first accepted an unsolicited vCard contact file over an unauthenticated Bluetooth Object Exchange (OBEX) connection. Immediately after, an unauthorized background process queried and exfiltrated the device's internal calendar entries and contact lists over Bluetooth without requesting user pairing approval. Based on these technical indicators, which of the following wireless attacks occurred? (Select TWO).
- Bluejacking, indicated by the unsolicited transmission of messages or contact cards to a Bluetooth-enabled device.Answer
- Bluesnarfing, indicated by the unauthorized access and exfiltration of sensitive information from a Bluetooth device.Answer
- CEvil Twin attack, indicated by an unauthorized access point broadcasting a spoofed Service Set Identifier (SSID).
- DRadio Frequency (RF) Jamming, indicated by intentionally flooding the wireless spectrum to cause massive frame loss.
Answer
The scenario demonstrates both Bluejacking (receipt of unsolicited vCard data over Bluetooth OBEX) and Bluesnarfing (unauthorized access and exfiltration of device contacts and calendar schedules).
The scenario describes two distinct Bluetooth exploits. Bluejacking is characterized by sending unsolicited messages or contact files (vCards) to a recipient device over Bluetooth. Bluesnarfing occurs when an attacker gains unauthorized access to steal private device data, such as calendars, emails, and contact lists, without user consent.
Step-by-Step Solution
Key Concept
Bluetooth Wireless Attack Indicators (Bluejacking vs. Bluesnarfing)
Estimated Time:1m 30s