CompTIA PenTest+ (PT0-003)Attacks and ExploitsEasy

During a physical security assessment, an attacker walks past an employee's unlocked phone and exploits a vulnerable OBEX Push service to silently copy the contact list, photos, and text messages from the paired Bluetooth device without the owner's knowledge. Which attack is being performed?

  1. AWar driving
  2. BBluebugging
  3. CBluesnarfing
  4. DBluejacking
Show answer & explanation

Correct answer: C. Bluesnarfing

Bluesnarfing is the unauthorized access and theft of data (contacts, messages, files) from a Bluetooth-enabled device, typically by exploiting vulnerable OBEX file-transfer services.

Why the other options are wrong

  • A. War driving refers to searching for open Wi-Fi networks while driving, unrelated to Bluetooth.
  • B. Bluebugging goes further by taking full remote control of the device's functions, not just copying data.
  • D. Bluejacking only sends unsolicited messages/data to a device; it does not steal information.

Bluesnarfing

A Bluetooth attack that steals data such as contacts, calendar entries, and messages from a target device by exploiting insecure Bluetooth services like OBEX Push.

  • Requires the device to be discoverable/pairable and vulnerable
  • Distinct from bluejacking (sends data) and bluebugging (full device control)
  • Mitigated by disabling Bluetooth discoverability when not in use

Memory trick: Snarf = to steal food quietly; bluesnarfing quietly steals your data

More Attacks and Exploits questions