๐ก BLE Researcher Path¶
Duration: ~6 weeks ยท Level: ๐ก Intermediate ยท Resources: 24
Goal: identify, sniff, and exploit a vulnerability in a consumer BLE device.
Prerequisites¶
- Comfortable on Linux command line
- Have read IoT Beginner path or equivalent
Curriculum¶
- Bluetooth Core Spec overview (devzone tutorial)
- GATT, services, characteristics
- Set up nRF52840 Dongle + Wireshark with nRF Sniffer plugin
- Reverse Engineering a Smart Band
- How I Hacked Xiaomi MiBand 3
- Capture & decode pairing of a real device
- Read BLUFFS disclosure
- Study BleedingTooth writeup
- Try BlueDucky against an unpatched Android
- Pick a target, hunt for bugs
Reference page¶
Full curated BLE resource list: Bluetooth & BLE Security โ