Wi-Fi WPA2 ¡°Kr00k¡±·ì϶·ÖÎöÓ븴ÏÖ

°ä²¼¹¦·ò 2020-03-26

1.×êÑв¼¾°


ÔÚ½ñÄê2Ô·ݵÄRSA´ó»áÉÏ£¬ESETµÄ×êÑÐÈËÔ±¹«¿ªÅû¶Wi-FiоƬ´æÔÚÑϳÁ°²È«·ì϶CVE-2019-15126£¬²¢½«Æä¶¨ÃûΪ¡°Kr00k¡±¡£¹¥»÷ÕßÄܹ»ÀûÓá°Kr00k¡±½âÃÜÎÞÏßÍøÂçÁ÷Á¿£¬»ñÈ¡´«Êä¹ý³ÌÖеÄÃô¸ÐÊý¾Ý¡£


Kr00k·ì϶ӰÏ첿ÃÅ×°ÖÃBroadcomºÍCypress Wi-FiоƬµÄÉ豸£¬ÕâÁ½¼ÒоƬ²úÆ·±»¿í·ºÀûÓÃÓÚÊÖ»ú¡¢Æ½°åµçÄÔ¼°IOTÉ豸ÖС£ÊؾɹÀ¼Æ£¬È«Çò×ܼƳ¬¹ý10ÒÚµÄÉ豸Êܸ÷ì϶µÄÓ°Ïì¡£


2.·ì϶·ÖÎö


2.1 ·ì϶µÀÀí


ÔÚ½éÉÜKr00k·ì϶֮ǰ£¬Ïȵ¥Ò»ÏàʶÏÂWPA2ºÍ̸¡£Ä¿Ç°»ùÓÚAES-CCMPµÄWPA2ºÍ̸ÊÇWi-FiÍøÂçÖÐ×îÆÕ±éµÄ³ß¶È¡£ÏÂͼÊǿͻ§¶Ë£¨Station, STA£©ÏνӽÓÈëµã£¨Access Point, AP£©µÄÐÂÎŽ»»¥¹ý³Ì¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


STAºÍAPÔÚËÄ´ÎÎÕÊÖÖУ¬Ð­É̻ỰÃÜÔ¿PTK£¨Pairwise Transient Key£©£¬PTKÊÇÓÉPMKºÍPKEÍÆËãÌìÉú£¬¶øPMKÓÉANonce¡¢SNonceºÍË«·½MACµØÖ·µÈÍÆËãÌìÉú¡£PTK·ÖΪKCK¡¢KEKºÍTKÈý²¿ÃÅ£¬ÆäÖУ¬KCKÓÃÓÚMICУÑ飬KEKÓÃÓÚ¼ÓÃÜGTK£¬TKΪÊý¾Ý¼ÓÃÜÃÜÔ¿¡£ËÄ´ÎÎÕÊÖʵÏֺ󣬴«ÊäÊý¾ÝʹÓÃTK½øÐмÓÃÜ¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚWPA2ºÍ̸ÖУ¬½â³ý¹ØÁª²Ù×÷Äܹ»ÓÉδ¾­Éí·ÝÑéÖ¤ºÍδ¼ÓÃܵÄÖÎÀíÖ¡´¥·¢£¬Kr00k·ì϶Óë½â³ý¹ØÁª²Ù×÷Ç×êÇÓйØ¡£±ÉÈËͼËùʾÖУ¬µ¹Ø¾µãµÄÏνӻỰ½â³ý¹ØÁªºó£¬±£ÁôÔÚWi-FiоƬÖеĻỰÃÜÔ¿(TK)±»ÖÃÁ㣬ÈôÊÇʹÓÃÒÑÖÃÁãµÄTKÃÜÔ¿¶ÔоƬ»º´æÖеÄÊý¾Ý½øÐмÓÃܲ¢´«Ê䣬½«µ¼Ö·ì϶²úÉú¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹¥»÷ÕßÀûÓÃÎÞÏßÍø¿¨¼´¿ÉʵÏÖÈëÇÖ£¬Í¨¹ý²»ÐÝ´¥·¢½â³ý¹ØÁª¡¢³ÁйØÁª£¬¶øºóʹÓÃÈ«ÁãTK¶Ô²¶»ñµÄÊý¾ÝÖ¡½øÐнâÃÜ£¬´Ó¶ø»ñÈ¡Ãô¸ÐÐÅÏ¢¡£


2.2 ¹Ì¼þ·ÖÎö


±¾ÎİÎÈ¡Nexus5ÖеÄBCM4339оƬ¹Ì¼þ½øÐзÖÎö¡£Ê×ÏÈ£¬¶¨Î»¹Ì¼þÖÐÍÆËãptkµÄµØÎ»£¬ÈçÏÂͼËùʾ¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¶øºó£¬¶ÔÆäÉϲ㺯Êýwlc_wpa_sup_eapol½øÐзÖÎö¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


wlc_wpa_sup_eapolŲÓÃwpa_pmk_to_ptkʱ£¬´«ÈëµÄ²ÎÊý±ðÀëΪmac1¡¢mac2¡¢Nonce1¡¢Nonce2¡¢pmk¡¢pmk_len¡¢ptk¡¢ptk_len¡£ptkÍÆËãÁ˾ֱ»±£ÁôÔÚwpa_ptk½á¹¹ÌåÆ«ÒÆ0x8cµØÎ»ÖС£


wlc_sup_attachº¯ÊýÓÃÓÚ´¦ÖÃSTAµÄ³õʼ»¯ÏνÓ£¬¸Ãº¯Êý¶Ôwpa_ptk½á¹¹Ìå½øÐÐÄÚ´æ·ÖÅäºÍ³õʼ»¯£¬wpa_ptk½á¹¹Ìå´óÓ×Ϊ0x13C¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


µ±³õʼ»¯Ê§°Ü¡¢Ïνӳ¬Ê±»ò½â³ýÏνӵÄʱ³½£¬Ôò»áŲÓÃwlc_sup_detachº¯Êý¶Ôwpa_ptk½á¹¹Ìå½øÐÐÖÃÁã²Ù×÷¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


3.·ì϶ÑéÖ¤


3.1 ²âÊÔ»·¾³



É豸Ãû³Æ

ÊýÁ¿

ÊÜÓ°ÏìµÄÉ豸

Nexus5

1

iphone6sÊÖ»ú

1

Attacker

NETGEARÍø¿¨

2

3.2 ²âÊÔ²½Öè


£¨1£©¶Ôwireshark½âÃÜÊý¾Ý°üµÄÓйØÖ°ÄܽøÐÐpatch£¬Ê¹Æä¿ÉÄܳɹ¦½âÃÜÈ«ÁãTK¼ÓÃܵÄÊý¾Ý¡£

£¨2£©Ê¹ÓÃpatchºóµÄwireshark¼àÌýÖ¸±êÉ豸ºÍAPͨѶµÄÊý¾Ý°ü¡£

£¨3£©Ê¹ÓÃÖ¸±êÉ豸ÏνÓAP²¢ËÁÒâ½Ó¼ûÍøÒ³¡£

£¨4£©¶ÔAPºÍ²âÊÔÖ¸±ê·¢ËÍDisassocation°ü¡£

£¨5£©³Á¸´Ö´Ðв½Ö裨3£©ºÍ£¨4£©£¬¹Û²ìwiresharkÖÐÊý¾Ý°üÊÇ·ñ½âÃÜ¡£


3.3 ²âÊÔÁ˾Ö


Nexus 5£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


iphone 6s£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Äܹ»¿´³ö£¬Nexus 5ºÍiphone 6s²¿ÃÅÊý¾Ý±»³É¹¦½âÃÜ¡£


4.Ó°ÏìÁìÓò


ĿǰÒÑÖªÊÜÓ°ÏìµÄÉ豸ÓУº

Amazon Echo 2nd gen

Amazon Kindle 8th gen

Apple iPad mini 2

Apple iPhone 6, 6S, 8, XR

Apple MacBook Air Retina 13-inch 2018

Google Nexus 5

Google Nexus 6

Google Nexus 6P

Raspberry Pi 3

Samsung Galaxy S4 GT-I9505

Samsung Galaxy S8

Xiaomi Redmi 3S

Asus RT-N12

Huawei B612S-25d

Huawei EchoLife HG8245H

Huawei E5577Cs-321


5.°²È«½¨Òé


É豸Ôì×÷ÉÌÒѰ䲼µÄ°²È«½¨ÒéÈçÏ£º

?https://support.apple.com/en-us/HT210721

?https://support.apple.com/en-us/HT210722

?https://support.apple.com/en-us/HT210788

?https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-003.txt

?https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200226-wi-fi-info-disclosure

?https://www.huawei.com/en/psirt/security-notices/huawei-sn-20200228-01-kr00k-en

?https://www.microchip.com/design-centers/wireless-connectivity/embedded-wi-fi/kr00k-vulnerability

?https://www.mist.com/documentation/mist-security-advisory-kr00k-attack-faq/

?https://www.zebra.com/us/en/support-downloads/lifeguard-security/kr00k-vulnerability.html