OBEX - "Object Exchange: a set of high-level protocols allowing objects such as vCard contact information and vCalendar schedule entries to be exchanged using either IrDA (IrOBEX) or Bluetooth. Symbian OS implements IrOBEX".
A flaw in the OBEX implementation of Nokia 7610 and other models, allows attackers to disable the OBEX service by sending archives that contain the name ":" or "\".
Credit:
The information has been provided by A. Ramos..
# Error pushing other file after send ":" filename:
jim:~# obexftp -b 00:13:70:5E:1F:01 -p /etc/hosts
Browsing 00:13:70:5E:1F:01 ...
Channel: 10
No custom transport
obexftp_cli_open()
obexftp_cli_connect_uuid()
Connecting...obexftp_cli_connect_uuid() BT -1
failed: connect
Still trying to connect
obexftp_cli_connect_uuid()
Connecting...obexftp_cli_connect_uuid() BT -1
failed: connect
Still trying to connect
obexftp_cli_connect_uuid()
Connecting...obexftp_cli_connect_uuid() BT -1
failed: connect
Still trying to connect
Disclosure Timeline:
20.09.2005 - Bug found
21.09.2005 - Nokia security contacted
24.09.2005 - Disclosure in NCN - V congress (http://www.noconname.org)
26.09.2005 - Full disclosure