Some slides from Hack.lu Conference about attacking bluetooth. Blutooth autentication scheme (relying on link key - kind of session hijacking but also you know that you can sniff!)
Slides : http://secdev.zoller.lu/research/hack_lu_2006.pdf
Demo of BTCrack : http://secdev.zoller.lu/research/bluetoothcracker.htm