Join now - be part of our community!

Temp Fix Bluetooth Connectivity (File TX, Tether, Stream): Vulnerability found CVE-2017-0781 -0785

SOLVED
NeoBeum
Enthusiast

Temp Fix Bluetooth Connectivity (File TX, Tether, Stream): Vulnerability found CVE-2017-0781 -0785

UPDATED: 12OCT2017

I'm sure google will change things again if they haven't already. But if the latest patch 32.4.A.1.54 did not include the Bluetooth Security Patches - there will be another change to the BT API no doubt.

There's a security Vulnerability to do with Bluetooth discovered in Sept. It's probably the junk I ran in to ... anyhoo... I'm busy compiling the new changes for 32.4.A.1.54  on the Z5C for a rebuild of the TWRP Recovery.

Adios.

CVE-2017-0781 to 0785

edit wow... i been out of action for a while... just looking at the last date there...

Spoiler
trolling microsoft by shrinking windows 10 pro, home and education on to 1 dvd and down to 3.9GB and posting screenshots on the MSDN forums hurrrrrr hueheu
Spoiler
lelele.PNG

UPDATED: 20JULY2017

Spoiler

one of my devices stored the correct names, the other didn't
the (W)hite device had never been paired to the pc before, while my main Black device had been previously

http://i.imgur.com/xiVkZvu.jpg
http://i.imgur.com/xiVkZvum.jpg


http://i.imgur.com/avyWCNFm.jpg http://i.imgur.com/QnPkCmZm.jpg

Standard Users having Bluetooth Problems:

  1. Remove All Paired Devices: Done via Bluetooth Settings Menu Page.
  2. Clear Android Bluetooth Data: Done via Apps Menu in Main Settings:
    - Settings >> Apps >> Vertical Triple Dot Menu and "Show System"
    - Find "Bluetooth Share" and select "Storage"
    - "Clear Data" and "Clear Cache"
  3. Turn Off Bluetooth.
  4. Reboot Device with Cache Clear: Done by pressing "Power Button" and "Volume Up" until Device display turns off and device vibrates once.
  5. Turn on device.
  6. Reset Bluetooth Notifications: Done by accessing Bluetooth Share in Apps Menu
    - Settings >> Apps >> Vertical Triple Dot Menu and "Show System"
    - Go to "Notifications"
    - Toggle all settings again, by turning it off and then back to the setting desired
    - Ensure "On the lock screen remains as "Show all notification content" & "Interupts in Priority Only" is left on for next test.
  7. Before pairing new devices, launch the Bluetooth App Menu, and turn on Bluetooth.
  8. Wait in the Bluetooth Menu Page, and select the Vertical Triple Dot Menu and select "Show Received Files"
    - If the "Show Received Files" page does not appear immediately, do not attempt to load other applications. If you are using a 3rd party "Home" launcher app, temporarily go back to the Sony Default Home App.
    - At the "Show Received Files" - if there are any files here, clear all by long press and clear.

    IF THERE WAS A DELAY FOR "SHOW RECEIVED FILES", WAIT UNTIL THERE IS NO DELAY WHEN LAUNCHING OR REPEAT STEP 1 TO 8

    DO NOT REPEATEDLY SELECT "SHOW RECEIVED FILES" AS THIS WILL CAUSE A BACKLOG OF PAGES TO APPEAR

    ONLY ONCE SELECT ONCE, AND WAIT OR REPEAT STEP 1 TO 8

    Screenshot_20170612-140801.png

  9. Pair a computer or another device capable of file transfer.
    - Ensure pairing code matches & that both devices display a successful pairing.
  10. Use Android Storage to access files: Done via Settings Menu >> Storage
    Select a file for transfer with your problem device set to receive the file:
    - Use Bluetooth Share via the "Share" Icon from the Storage app.
    Screenshot_20170612-140627.png  Screenshot_20170612-135552.png  Screenshot_20170612-141127.png
    - Test using a capture taken by the device, but make sure the image file extension is LOWER CASE: <filename>.jpg <filename>.jpeg <filename>.png
    - Test using a text file: ensure that extension is not <filename>.TXT but lower case.

    A POPUP DIALOG SHOULD APPEAR TO ACCEPT ANY FILE TRANSFER.
    IF IT DOES NOT: REPEAT STEP 8


  11. Test transfer with Sending files from the problem device.
    If a file transfer encounters a problem, select the notification from the Notification bar, and repeat the process for "Outbound transfer" menu page - (Step 8 Received File Page)

    Screenshot_20170612-140941.png


    Before Proceeding with Other Bluetooth Connectivity: Ensure that "Outbound Transfer" and "Bluetooth Received" pages are clear.


    Screenshot_20170612-140924.png  Screenshot_20170612-140807.png  Screenshot_20170612aaa-140924.jpg
    ACCESSING THESE PAGES SHOULD BE ALMOST INSTANTANEOUS, IF THERE IS A DELAY, THEN REPEAT THE CACHE CLEAR OR WAIT UNTIL THERE IS NO DELAY


  12. Pair audio device.
    - Test pairing with music stream.
  •   OPTIONAL:
    Test with Bluetooth Tether
    Test with Mirror Link, Miracast, or other Bluetooth services (3rd Party Apps)

Root Users Having Bluetooth Problems:

  • Clear Dalvik and ART Cache. Reboot using Power + Volume Up. Clear Cache in Recovery.
  • Repeat Process Above

 ____________

09 June 2017

Found the cause for some of the problems.

Shared Pref in User_De is missing pretty much all the configurations it needs.

 ____________

05 June 17

Included btopps database corruption examples - view last post

/t5/Xperia-Z5-Z5-Compact-Z5-Premium/Bluetooth-Android-API-Changes-and-Permissions-causing-port/m-p/1...

=========================================================

ORIGINAL POST

=========================================================

I've been doing some trawling through my log, as I've finally been able to recreate the Nougat issues on my phone that everyone else seems to have that I didn't.

From what I read ( could have misunderstood) the bluetooth and wireless api have had changes from Google to do with security. The result of this means that older hardware does not send the device sufficient parameters for a handshake or data transfer.

Older written apps will cause the system to check for things that it won't find because of permissions, so it loops causing battery drain.

I blame Google for a large part of this

15 REPLIES 15
NeoBeum
Enthusiast

Bumpity Bump.

Found the cause for the problems. /data/user_de/0/com.android.bluetooth/shared_pref

is missing bluetooth profile configurations.

Now all I need to do is find where in the framework the code is and submit a patch to Sony or Google

NeoBeum
Enthusiast

Bump to add temporary solution for Non-Root and Root Users

Jimmy_121
Visitor

There is a workaround, but you have to be sure not to turn off your bluetooth on your phone...or you will have to do the procedure again.

First, open smart connect app on your phone. you will find the bluetooth accessory in the list.

keep pressing on it, then remove.

Second, clear all your apps in memory (I use fast reboot app) then close all apps.

Third, open smart connect one more time, press on the plus to add accessory..this will open bluetooth settings...pair your device.

The accessory will work now....hopefully....until you turn off bluetooth....it will be corrupted...again. It works for me..(I use wireless headset pro mw1 and RM-X7bt car accessory).

NeoBeum
Enthusiast

this one's not really related but..

in Microsoft we trust

http://i.imgur.com/mMuBPZk.jpg

http://i.imgur.com/gumtZVM.jpg

http://i.imgur.com/afwUuxB.jpg

...and asus... because laptop isnt made for Server 2016...

but at least bluetooth is working..... pfff

now there's another vendor to add to confusion... yay windows

NeoBeum
Enthusiast

heres something interesting ...

one of my devices stored the correct names, the other didn't
the (W)hite device had never been paired to the pc before, while my main Black device had been previously

http://i.imgur.com/xiVkZvu.jpg
http://i.imgur.com/xiVkZvum.jpg


http://i.imgur.com/avyWCNFm.jpg http://i.imgur.com/QnPkCmZm.jpg

NeoBeum
Enthusiast

UPDATED: 12OCT2017

I'm sure google will change things again if they haven't already. But if the latest patch 32.4.A.1.54 did not include the Bluetooth Security Patches - there will be another change to the BT API no doubt.

There's a security Vulnerability to do with Bluetooth discovered in Sept. It's probably the junk I ran in to ... anyhoo... I'm busy compiling the new changes for 32.4.A.1.54  on the Z5C for a rebuild of the TWRP Recovery.

Adios.

CVE-2017-0781 to 0785