Facebook WhatsApp TLSÁîÅÆÐ¹Â©·ì϶¸´ÏÖ£¨CVE-2021-24027£©
°ä²¼¹¦·ò 2021-04-30²¼¾°
WhatsAppÊÇÃÀ¹úFacebookµÄ¼´Ê±Í¨Ñ¶ÀûÓã¬ÔÚº£±íÕ¼ÓÐÖØ´óµÄÓû§»ùÊý¡£4ÔÂ14ÈÕ£¬°²È«×êÑÐÔ±Chariton KaramitasÅû¶Android WhatsApp´æÔÚÁîÅÆÐ¹Â¶·ì϶£¬½áºÏÆäËû·ì϶¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¸Ã·ì϶ӰÏìWhatsApp v2.21.4.18ºÍWhatsApp Business v2.21.4.18֮ǰµÄ°æ±¾£¬½¨ÒéÓû§ÊµÊ±¸üе½2.21.4.18»ò¸ü¸ß°æ±¾£¬ÒÔ¶ã±Ü¸Ã·ì϶´æÔڵĹ¥»÷·çÏÕ¡£
·ì϶·ÖÎö
1¡¢ÁîÅÆÐ¹Â¶·ì϶£¨CVE-2021-24027£©
¸Ã·ì϶´æÔÚµÄÔÒò£¬ÊÇÓÉÓÚWhatsApp½«TLS»á»°µÇ½ºóµÄÐòÁл¯ÁîÅÆÎļþ·ÅÔÚÁËsdcardĿ¼Ï£¬¸ÃĿ¼²¢Î´ÉèÖýӼûȨÏÞ¡£
WhatsAppѡȡTLS1.3/TLS1.2À´½øÐпͻ§¶Ëµ½·þÎñÆ÷µÄͨѶ£¬ÔÚTLSÎÕÊֵĹý³ÌÖУ¬Í¨Ñ¶Ë«·½½øÐÐÏ໥ÈÏÖ¤ºÍÃÜÔ¿ÐÉÌ£¬·þÎñÆ÷Éí·ÝÑé֤ʹÓ÷ǶԳƼÓÃÜ·½Ê½£¬¶ÔÓÚ½ÏÓ׳ߴçµÄǶÈëʽÉ豸£¬ÕâÊÇÒ»¸öÍÆËãÁ¿¼«¶È´óµÄ¹ý³Ì¡£ÎªÁËÏ÷¼õ¹¦ºÄ£¬½Ú¼óCPUÖÜÆÚ£¬Ìá³öÁ˻Ự¸´Ô¹ý³Ì£¬µ±³ÁгÉÁ¢ÎÕÊÖʱ£¬¸´ÓÃ֮ǰµÄ»á»°ÐÅÏ¢¡£
ÏÂͼÖÐΪÉèÖûỰ»º´æÎļþ¼ÐµÄ·´±àÒë´úÂë½ØÍ¼¼°ÏÖʵÎļþõè¾¶½ØÍ¼£¬WhatsApp½«µÇ½»á»°»º´æTLS1.2ºÍTLS1.3±ðÀë·ÅÔÚÎļþ¼ÐSSLSessionCacheºÍwatls-sessionsÖС£ÕâЩĿ¼ÔÚ²»Êܱ£»¤µÄ±í²¿´æ´¢Ï¡£¹¥»÷ÕßÄܹ»Í¨¹ýÎïÀí½Ó´¥ÊÖ»ú»ñµÃÕâЩÎļþ£¬Ôì³ÉÁîÅÆÐ¹Â©¡£



2¡¢Ä¿Â¼´©Ô½·ì϶
WhatsAppÓÐEmojiºÍÕÕÆ¬Â˾µÈȸüÐÂÖ°ÄÜ£¬ÎÒÃÇÄܹ»ÀûÓÃÖÐÑëÈËÀ´´Û¸ÄEmoji»òÕÕÆ¬Â˾µÈȸüÐÂʱµÄzip°ü¡£zipÎļþ½âѹ·´±àÒë´úÂë½ØÍ¼ÈçÏ£º


WhatsApp½øÐÐEmoji»òÕÕÆ¬Â˾µÈȸüÐÂʱ£¬Ã»ÓйýÂË¡±.//¡±£¬¿Éµ¼ÖÂĿ¼´©Ô½¡£ÈôÊÇÊܺ¦Õß±»ÖÐÑëÈ˽ٳ֣¬²¢ÇÒ¹¥»÷Õß´Û¸ÄÁËÈȸüÐÂzip°ü£¬ÆäÖÐÔ̺¬ÓÉ¡±.//¡±Ä¿Â¼×é³ÉµÄsoÎļþ£¬Ê¹Æä¸²¸ÇWhatsApp¶¯Ì¬Á´½Ó¿âsoÎļþ£¬½«µ¼ÖÂËÁÒâ´úÂëÖ´ÐС£
·ì϶ÀûÓÃ
Ç°ÃæÌáµ½±ØÒªÍ¨¹ýÎïÀí½Ó´¥»ñÈ¡ÁîÅÆ£¬¾ÖÏÞÐԽϴó¡£ÈôÊǹ¥»÷Õß¹²Í¬ÍøÂç´¹µö£¬·¢ËÍÒ»¸ö¼Ù×°µÄhtmlÎļþ¸øÊܺ¦Õߣ¬µ±Êܺ¦ÕßʹÓÃChrome£¨´æÔÚ·ì϶CVE-2020-6516£©´ò¿ª´Ëhtmlʱ£¬Ö´ÐÐhtmlÖеÄjs´úÂ룬±éÀúsdcardÎļþ¼Ð²éÕÒTLS»º´æÎļþ£¬²¢°ÑÎļþ·¢Ë͵½¹¥»÷ÕßÖ¸¶¨µÄ·þÎñÆ÷ÉÏ¡£´óÌå¹ý³ÌÈçÏ£º
£¨1£©ÔÚ·¢ËÍÒ»ÌõÐÂÎÅʱ£¬Ô̺¬ÐÂÎŵÄÀàÐÍ¡¢ÐÂÎŵÄÔ¤ÀÀͼƬ¡¢ÐÂÎŵıêÌâºÍÐÂÎŵÄÏÖʵÄÚÈÝÎļþËIJ¿ÃÅ¡£Ààõè¾¶X/041µÄA0l×Ö¶ÎÅúʾ·¢ËÍÐÂÎŵÄÀàÐÍ£¬Ààõè¾¶X/0QeµÄA03×Ö¶ÎÅúʾÐÂÎŵÄÔ¤ÀÀͼƬµÄbyteÊý×飬Ààõè¾¶X/0NdµÄA04×Ö¶ÎÅúʾ·¢ËÍÐÂÎŵıêÌ⣬Ààõè¾¶X/0M6µÄA05(Ljava/util/List;Landroid/net/Uri;Ljava/lang/String;LX/041;LX/02l;Z)²½ÖèΪ×îÖÕ·¢ËÍÐÂÎÅÏÖʵÄÚÈÝÎļþµÄº¯Êý¡£ÓйؽØÍ¼ÈçÏ£º




£¨2£©¹¥»÷ÕßѡȡfridaµÄRPCÔ¶³ÌŲÓÃÖ°ÄÜ´´½¨Ò»¸öº¯Êý£¬²¢ÔÚhookº¯ÊýÖÐÅú¸ÄµÚÒ»²½Öдý·¢Ë͵ÄÐÂÎÅ£¬½«ÐÂÎŵÄÔ¤ÀÀͼƬ¸ü»»³ÉÓµÓÐÎüÒýÁ¦µÄͼƬ£¬²¢Å²ÓÃX/0M6µÄA05(Ljava/util/List;Landroid/net/Uri;Ljava/lang/String;LX/041;LX/02l;Z)²½Ö轫ÐÂÎÅ·¢Ë͸øÊܺ¦Õߣ¨µÚÒ»¸ö²ÎÊýΪÓÉÊܺ¦ÕßµÄWhatsAppµØÖ·×é³ÉµÄList£¬WhatAppµØÖ·ÌåʽΪmobile_number@s.whatsapp.net£©£¬ÈôÊÇÊܺ¦Õßµã»÷ͼƬ£¬Å²ÓÃChrome´ò¿ª¶ñÒâhtmlÎļþ£¬TLS»º´æÁîÅÆ¿ÉÄܱ»·¢Ë͵½¹¥»÷Õß·þÎñÆ÷¡£
£¨3£©htmlÎļþ¹Ø¼ü²¿ÃŽØÍ¼ÈçÏ¡£Ôڳɹ¦»ñÈ¡µ½TLS»º´æÎļþºó£¬ÎÒÃǼ´¿É½øÐÐÖÐÑëÈ˹¥»÷¡£


£¨4£©ÀûÓÃEmoji»òÕÕÆ¬Â˾µÈȸüÐÂÖ°ÄÜ£¬Í¨¹ýÖÐÑëÈËÀ´´Û¸ÄEmoji»òÕÕÆ¬Â˾µÈȸüÐÂÏìÓ¦zip°ü£¬´Ó¶øµ¼ÖÂÔ¶³ÌËÁÒâ´úÂëÖ´ÐУ¨ÑÝʾÊÓÆµÎªÁË·½±ã£¬Ö±½ÓʹÓÃCharlesÀ´·ÂÕÕÈȸüи²¸ÇWhatsApp¶¯Ì¬Á´½Ó¿âsoÎļþ£¬À´´ïµ½RCEµÄ¹ý³Ì£©¡£
·ì϶¸´ÏÖ
1¡¢ÁîÅÆÐ¹Â¶·ì϶¸´ÏÖ
2¡¢RCE·ì϶¸´ÏÖ
²Î¿¼Á´½Ó£º
[1]https://www.census-labs.com/news/2021/04/14/whatsapp-mitd-remote-exploitation-CVE-2021-24027/
[2] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24027
[3] https://github.com/CENSUS/whatsapp-mitd-mitm
[4] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6516
[5]https://bugs.chromium.org/p/chromium/issues/detail?id=1092449
[6] https://youtu.be/sdVqTEXHxxY
[7] https://youtu.be/KO_K0F4W36I
GA»Æ½ð¼×»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©
ADLab³ÉÁ¢ÓÚ1999Ä꣬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò»£¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¸ÅÏëÊ×ÍÆÕß¡£½ØÖ¹Ä¿Ç°£¬ADLabÒÑͨ¹ýCVEÀۼư䲼°²È«·ì϶½ü1100¸ö£¬Í¨¹ý CNVD/CNNVDÀۼư䲼°²È«·ì϶1000Óà¸ö£¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£³¢ÊÔÊÒ×êÑз½Ïòº¸Ç²Ù×÷ϵͳÓëÀûÓÃϵͳ°²È«×êÑÓ×¢ÖÇÄÜÖն˰²È«×êÑÓ×¢ÎïÁªÍøÖÇÄÜÉ豸°²È«×êÑÓ×¢Web°²È«×êÑÓ×¢¹¤¿ØÏµÍ³°²È«×êÑÓ×¢ÔÆ°²È«×êÑС£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑÓ×¢¹ú¶È³Áµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨Òµ°²È«·þÎñµÈ¡£



¾©¹«Íø°²±¸11010802024551ºÅ