1.打開(kāi)藍(lán)牙
輸入指令查看藍(lán)牙是否打開(kāi)
hciconfig
通過(guò)剛才的指令可以看到藍(lán)牙還未打開(kāi),接下來(lái)輸入指令打開(kāi)藍(lán)牙。
service bluetooth start
或者是輸入? systemctl start bluetooth.service
2.掃描藍(lán)牙
hcitool scan
?RedFang
如果我們希望對(duì)藍(lán)牙設(shè)備進(jìn)行暴力破解,那么將會(huì)用到該工具。它主要是為了識(shí)別不可發(fā)現(xiàn)的藍(lán)牙設(shè)備的概念性證明。僅僅因?yàn)椴樵?xún)掃描沒(méi)有返回任何結(jié)果并不意味著沒(méi)有藍(lán)牙設(shè)備。它會(huì)幫助我們識(shí)別所有這些設(shè)備。通過(guò)該程序我們可以讓它掃描出所有可能的地址,或者我們可以指定一個(gè)范圍。
fang -r B9D43EC9DBBE-B998F756550C -s
?3.服務(wù)識(shí)別
我們可以查看該設(shè)備支持的功能
hcitool info B8:98:F7:56:55:0C
?為了獲取配置文件,將使用服務(wù)發(fā)現(xiàn)協(xié)議使用sdptool 獲取支持的位置文件列表。
sdptool browse B8:98:F7:56:55:0C
┌──(root?Suanlunce)-[~]
└─# sdptool browse B8:98:F7:56:55:0C
Browsing B8:98:F7:56:55:0C ...
Service RecHandle: 0x10001
Service Class ID List:
"Generic Access" (0x1800)
Protocol Descriptor List:
"L2CAP" (0x0100)
PSM: 31
"ATT" (0x0007)
uint16: 0x0001
uint16: 0x0005
Service Name: Headset Audio Gateway
Service RecHandle: 0x10002
Service Class ID List:
"Headset Audio Gateway" (0x1112)
"Generic Audio" (0x1203)
Protocol Descriptor List:
"L2CAP" (0x0100)
"RFCOMM" (0x0003)
Channel: 1
Language Base Attr List:
code_ISO639: 0x656e
encoding: 0x6a
base_offset: 0x100
Profile Descriptor List:
"Headset" (0x1108)
Version: 0x0102
Service Name: Handsfree Audio Gateway
Service RecHandle: 0x10003
Service Class ID List:
"Handsfree Audio Gateway" (0x111f)
"Generic Audio" (0x1203)
Protocol Descriptor List:
"L2CAP" (0x0100)
"RFCOMM" (0x0003)
Channel: 2
Language Base Attr List:
code_ISO639: 0x656e
encoding: 0x6a
base_offset: 0x100
Profile Descriptor List:
"Handsfree" (0x111e)
Version: 0x0106
Service Name: Network Access Point Service
Service Description: Bluetooth NAP Service
Service RecHandle: 0x10004
Service Class ID List:
"Network Access Point" (0x1116)
Protocol Descriptor List:
"L2CAP" (0x0100)
PSM: 15
"BNEP" (0x000f)
Version: 0x0100
SEQ8: 0 6
Language Base Attr List:
code_ISO639: 0x656e
encoding: 0x6a
base_offset: 0x100
Profile Descriptor List:
"Network Access Point" (0x1116)
Version: 0x0100
Service RecHandle: 0x10006
Service Class ID List:
"AV Remote Target" (0x110c)
Protocol Descriptor List:
"L2CAP" (0x0100)
PSM: 23
"AVCTP" (0x0017)
uint16: 0x0100
Profile Descriptor List:
"AV Remote" (0x110e)
Version: 0x0103
Service RecHandle: 0x10007
Service Class ID List:
"AV Remote Controller" (0x110f)
Protocol Descriptor List:
"L2CAP" (0x0100)
PSM: 23
"AVCTP" (0x0017)
uint16: 0x0100
Profile Descriptor List:
"AV Remote" (0x110e)
Version: 0x0100
Service Name: Advanced Audio
Service RecHandle: 0x10008
Service Class ID List:
"Audio Source" (0x110a)
Protocol Descriptor List:
"L2CAP" (0x0100)
PSM: 25
"AVDTP" (0x0019)
uint16: 0x0102
Profile Descriptor List:
"Advanced Audio" (0x110d)
Version: 0x0102
Service Name: 000eSMS/MMS
Service RecHandle: 0x10009
Service Class ID List:
"Message Access - MAS" (0x1132)
Protocol Descriptor List:
"L2CAP" (0x0100)
"RFCOMM" (0x0003)
Channel: 21
"OBEX" (0x0008)
Profile Descriptor List:
"Message Access" (0x1134)
Version: 0x0101
Service Name: OBEX Phonebook Access Server
Service RecHandle: 0x1000a
Service Class ID List:
"Phonebook Access - PSE" (0x112f)
Protocol Descriptor List:
"L2CAP" (0x0100)
"RFCOMM" (0x0003)
Channel: 22
"OBEX" (0x0008)
Profile Descriptor List:
"Phonebook Access" (0x1130)
Version: 0x0101
Service Name: OBEX Object Push
Service RecHandle: 0x1000b
Service Class ID List:
"OBEX Object Push" (0x1105)
Protocol Descriptor List:
"L2CAP" (0x0100)
"RFCOMM" (0x0003)
Channel: 23
"OBEX" (0x0008)
Profile Descriptor List:
"OBEX Object Push" (0x1105)
Version: 0x0100
?4.其它
blueranger hci0 B8:98:F7:56:55:0C
?
bluelog 該命令可以用于掃描或者其它腳本此工具的主要特征是可以根據(jù)已經(jīng)找到的內(nèi)容生成一個(gè)日志文件。保存在當(dāng)前路徑下。
bluelog
?文章來(lái)源:http://www.zghlxwxcb.cn/news/detail-813551.html
?文章來(lái)源地址http://www.zghlxwxcb.cn/news/detail-813551.html
到了這里,關(guān)于kali 藍(lán)牙使用的文章就介紹完了。如果您還想了解更多內(nèi)容,請(qǐng)?jiān)谟疑辖撬阉鱐OY模板網(wǎng)以前的文章或繼續(xù)瀏覽下面的相關(guān)文章,希望大家以后多多支持TOY模板網(wǎng)!