Resource / Blogs /

“Find – Bluetooth Tracker” Responsible Vulnerability Disclosure

A security assessment of a smart Bluetooth beacon reveals directory indexing, insecure API authorization, sensitive user-data exposure, and unencrypted mobile communication.
By
Arun-Magesh
November 27, 2018
4 mins
Get Tested
Device, firmware and APIs scoped as one system.
Talk to an Expert
White arrow pointing diagonally upward to the right on a black square background.White arrow pointing diagonally upward to the right on a black square background.

Key Takeaways

  • Directory indexing can unintentionally expose sensitive server files and user-generated content.
  • APIs must verify that an authenticated user is authorized to access each requested resource.
  • Authentication tokens should have appropriate expiration and revocation controls.
  • Predictable user identifiers should not provide access to other users’ data.
  • Mobile applications should use HTTPS for all communication with backend services.
  • Sensitive information such as passwords, tokens, addresses, and GPS coordinates must never be transmitted in plaintext.
  • IoT vendors should incorporate security and privacy testing throughout the product-development lifecycle.
  • Responsible disclosure does not guarantee remediation, making transparent risk communication important.

Introduction:

With the advent of IoT, everything is getting connected to the internet. Bluetooth is one such protocol which is used to connect devices to the internet as the most mobile device has Bluetooth Capability, you can check this blog on how to reverse a Bluetooth communication.  There are devices called Bluetooth beacons which are used to track devices which are in close proximity, companies have started connecting these beacons to the internet with geolocation and this is one such example.

This is a case of my findings on a Smart Bluetooth Beacon from Sensegiz

The testing was done on their Android Mobile Application.

For User's privacy, the IP/End-Point is not disclosed. It will be replaced by xxx.

Findings 1: Directory indexing

It was identified on analysing the endpoint “xxx.xxxxxx.com/smspush”. The files in the location can be read by anyone and it leads to leakage of information like pem files, user image and device image of all the users

Steps:

  1. Open your browser and point to “http://xxx.xxxxxxxx.com/smspush”
  2. Traverse to /mobileapp/users/images/ to find all the user image and mobileapp/findapp/images/device_images/ points to device image.

Finding 2: User Database Download

From the API call endpoint is being identified by intercepting the android app. Since the token doesn’t have any expiry time attacker can brute force the user id to get device user information like name, address and GPS location

Steps:

  1. Open the app and log in to your account
  2. Intercept the request in burp suite for user_id
  3. Add intruder in it and select the user_id field and brute-force the field
  4. Which returns information about their devices like GPS location, Device address and other sensitive information.

Finding 3: No HTTPS for communicating with the mobile app/server.

The connection from the mobile app and the server is using HTTP and it is prone to sniffing and other trivial attacks

An attacker can reverse engineer the communication to exploit the server.

Steps:

  1. Connect the access point to the proxy of your burp suite
  2. Now login to the app and look at the proxy history

You can see the sensitive information like password and other requests were sent in plain text.

Responsible Disclosure:

Reported: May 1, 2018

Vendor Response: May 13, 2018

Reminder for public disclosure: June 19, 2018

Disclosure: Nov 27, 2018

Conclusion

This analysis is based on the technologies and known threats as of the date of this report. The vendor has not fixed the bugs and they are vulnerable.

With fast-moving startup culture, vendors need to look into security and not compromise on user’s privacy and safety.

Get Tested
Device, firmware and APIs scoped as one system.
Talk to an Expert
White arrow pointing diagonally upward to the right on a black square background.White arrow pointing diagonally upward to the right on a black square background.
Author
Arun-Magesh
Ex-Bandit
Red arrow pointing diagonally upward to the right.Red arrow pointing diagonally upward to the right.
FAQ

Questions Web Application teams ask us.

What security issues were discovered in the smart Bluetooth beacon ecosystem?
The assessment uncovered directory indexing, unauthorized access to user and device information, non-expiring authentication tokens, and unencrypted HTTP communication.
How did directory indexing expose sensitive information?
Directory indexing allowed unauthenticated visitors to browse server folders containing user images, device images, PEM files, and other potentially sensitive resources.
Why was the user ID parameter vulnerable?
The API did not appear to enforce adequate object-level authorization. An authenticated attacker could modify or enumerate user IDs to access information associated with other users and devices.
What information could be exposed through the vulnerable API?
The exposed information could include users’ names, addresses, device details, device addresses, and GPS locations.
Why is using HTTP dangerous for a mobile application?
HTTP transmits information without transport-layer encryption. An attacker positioned on the network may be able to intercept credentials, API requests, tokens, and other sensitive data.

Keep Reading

For Security Leaders
Agentic AI Security: The Hidden Attack Surface Beyond Prompt Injection
August 25, 2026
10 min
For Security Leaders
Research & disclosures
Binwalk Path Traversal Vulnerability: Turning Firmware Analysis into Code Execution
August 26, 2026
8 min
Guides & tutorials
For Security Leaders
An Introduction to Smali
August 26, 2026
8 min
Dark scene with vertical thin orange lines resembling distant illuminated bars or streaks against a black background and a faint horizontal red glow near the bottom.