Hidden Bluetooth SDP services
BR/EDR
BLE
In Bluetooth, a service represents a specific functionality offered by a device, identified by a Universally Unique Identifier (UUID). Services can be discovered and used by other Bluetooth devices that support them.
Bluetooth provides multiple mechanisms to discover available services, one of which is the Service Discovery Protocol (SDP). SDP enables the identification of remote services, retrieval of their characteristics, and the determination of how to connect to them.
To identify hidden or undocumented services, an SDP discovery must be performed using standard Bluetooth tools. After obtaining the list of services advertised via SDP, additional service discovery techniques should be applied to verify that all detected services match those advertised. The presence of a service not listed in SDP indicates a hidden service but does not secure it, as access remains possible.
If a service is properly secured, hiding it is unnecessary. Maintaining accurate SDP listings improves device interoperability and aligns with Bluetooth specifications.
Description
In order to check if there are hidden services it is important to perform an SDP discovery. This is an standard Bluetooth procedure that can be performed with standard bluetooth tools.
After having a list of available SDP services, it is needed to perform alternative ways of discovering Bluetooth services. This can include the following procedures:
- Capturing Bluetooth communications while operating the device to discover communications with previously unknown services.
- Performing bruteforce scans of services in a device.
- Performing service scans using different service discovery protocols such as GATT if available.
If there are services hidden to the SDP service, it is not correctly configured.
Related resources
To check this control, the following resources may be useful:
| ID | Description |
|---|---|
| BSAM-RES-04 | Bluetooth connections sniffing |
| BSAM-RES-05 | Capture of a Bluetooth connection |
Example case
The existence of hidden SDP (Service Discovery Protocol) services on a BR/EDR-enabled device is verified. The tests are conducted using a computer. Wireshark with BTVS (btvs.exe -Mode wireshark) is used to capture packets for analysis.
To perform the check of available Service, the sdptool tool, which is part of the bluez package in GNU-Linux operating systems, is used. A request is made to list the system’s services with the command sdptool browse.
This procedure displays all the Service that the SDP server has recorded. However, the Service Discovery Protocol does not have a mechanism to notify SDP clients when Service are added or removed from the SDP server. Due to this, there might be services not listed with the sdptool browse XX:XX:XX:XX:XX:XX command.
To check for hidden services, Scapy, or a similar tool, is used to generate a request to read the attributes of SDP Service. All available possibilities in each field need to be checked:
- ServiceRecordHandle
- MaximumAttributeByteCount
- AttributeIDList
- ContinuationState
For each request, a response is obtained that allows verifying whether the request made is correct or not.
By comparing the correct responses to the request for service attributes with those listed by the SDP server, hidden Service can be identified.
The check control FAIL when different services are found in the read requests compared to the SDP server’s listing.