Wi-FiÁ÷Á¿ÐÅϢй©·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-02-28·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-15126£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
|
³§ÉÌ |
É豸/оƬ/·ÓÉÆ÷Ãû³Æ |
|
broadcom |
bcm4356 |
|
broadcom |
bcm4389 |
|
broadcom |
bcm4375 |
|
broadcom |
bcm43012 |
|
broadcom |
bcm43013 |
|
broadcom |
bcm43752 |
|
Amazon |
Echo 2nd gen |
|
Amazon |
Kindle 8th gen |
|
Apple |
iPad mini 2 (ipad_os < 13.2) |
|
Apple |
iPhone 6, 6S, 8, XR (iphone_os < 13.2) |
|
Apple |
MacBook Air Retina 13-inch 2018 (mac_os < 10.15.1) |
|
|
Nexus 5 |
|
|
Nexus 6 |
|
|
Nexus 6S |
|
Raspberry |
Pi 3 |
|
Samsung |
Galaxy S4 GT-I9505 |
|
Samsung |
Galaxy S8 |
|
Xiaomi |
Redmi 3S |
|
Asus |
RT-N12 |
|
Huawei |
B612S-25d |
|
Huawei |
EchoLife HG8245H |
|
Huawei |
E5577Cs-321 |
·ì϶¸ÅÊö
ÍøÂ簲ȫ×êÑÐÔ±´ÓʹÓÃ¿í·ºµÄ²©Í¨ (Broadcom) ºÍ Cypress WiFi оƬÖз¢ÏÖÁËÒ»¸öÓ²¼þ·ì϶£¬Ó°ÏìÊýÊ®ÒŲ́É豸£¬ÈçÖÇÄÜÊÖ»ú¡¢Æ½°åµçÄÔ¡¢±Ê¼Ç±¾µçÄÔ¡¢Â·ÓÉÆ÷ºÍÎïÁªÍøÉ豸¡£
¸Ã·ì϶±»³ÆÎª ¡°Kr00k¡±£¬±àºÅΪ CVE-2019-15126£¬Ëü¿Éµ¼ÖÂÔ¶³Ì¹¥»÷ÕßÀ¹½Ø²¢½âÃÜÒ×Êܹ¥»÷É豸ͨ¹ýÎÞÏß´«ÊäµÄijЩÎÞÏßÍøÂçÊý¾Ý°ü¡£¸Ã·ì϶²úÉúµÄÔÒòÔÚÓÚ²©Í¨ºÍ Cypress оƬʹÓÃÁËÒ»¸öÈ«Áã¼ÓÃÜÃÜÔ¿£¬´Ó¶øµ¼ÖÂÊý¾Ý±»½âÃÜ£¬·ÛËéÁË WPA2-Personal ºÍ WPA2-Enterprise °²È«ºÍ̸¡£¹¥»÷ÕßÎÞÐèÏνӵ½Êܺ¦ÕßµÄÎÞÏßÍøÂç¼´¿É·¢Æð¹¥»÷¡£Ê¹Óà WPA2-Personal »ò WPA2-Enterprise ºÍ̸¡¢Í¨¹ý AES-CCMP ¼ÓÃܱ£»¤ÍøÂçÁ÷Á¿µÄÉ豸Ò×Êܹ¥»÷¡£
·ì϶ÏêÇé
ÔÚÏêÊö Kr00k ¹¥»÷֮ǰ£¬ÎÒÃDZØÒªÏàʶÈçϼ¸µã£º
1. ¸Ã·ì϶²¢²»´æÔÚÓÚÎÞÏß¼ÓÃܺÍ̸ÖУ¬¶øÊÇÒòÒ×Êܹ¥»÷оƬʵÏָüÓÃܺÍ̸µÄ·½Ê½²»µ±µ¼Öµģ»
2. ¹¥»÷ÕßÎÞ·¨Í¨¹ý¸Ã·ì϶ÏνÓÓû§ WiFiÍøÂç²¢½øÒ»²½·¢ÆðÖÐÑëÈ˹¥»÷»òÕß¹¥»÷ÆäËüÁªÍøÉ豸£»
3. ¹¥»÷ÕßÎÞ·¨ÀûÓø÷ì϶»ñϤÓû§µÄ WiFi ÃÜÂ룬Åú¸Ä WiFi ÃÜÂëÎÞÖúÓÚÎÊÌ⽨¸´£»
4. ËüÎÞ·¨Ó°ÏìʹÓÃ×îРWiFi °²È«³ß¶È WPA3 ºÍ̸µÄÏÖ´úÉ豸£»
5. È»¶ø£¬Ëü¿Éµ¼Ö¹¥»÷Õßץȡ²¢½âÃÜijЩÎÞÏßÊý¾Ý°ü£¨Êýǧ×Ö½Ú£©£¬µ«ÎÞ·¨Ô¤²âËü½«Ô̺¬ÄÄЩÊý¾Ý£»
6. ×î³ÁÒªµÄÊÇ£¬¸ÃȱµãÍ»ÆÆÁËÎÞÏß²ãÉϵļÓÃÜ»úÔ죬µ«ºÍ TLS ¼ÓÃܺÍ̸Î޹أ¬Òò¶øºóÕßÒÀÈ»Äܹ»±£»¤ HTTPS Õ¾µãÍøÂçÁ÷Á¿µÄ°²È«¡£
ÔÚ WiFi ÖУ¬É豸Ïνӵ½½Ó¼ûµã (AP) ±»³ÆÎª¡°¹ØÁª¡±£¬¶Ï¿ªÏνӣ¨ÈçÓÐÈË´ÓÒ»¸ö WiFi AP ÖÜÓε½Áí±íÒ»¸ö AP£¬¾ÀúÁËÐźÅ×ÌÈÅ»ò¹Ø¹ØÉ豸 WiFi£©±»³ÆÎª¡°È¡µÞ¹ØÁª¡±¡£
ͼ1ÌṩÁËоƬÃýÎóµÄʾÒâͼ¡£×êÑÐÈËÔ±Ö¸³ö£¬¡°Kr00k ·ì϶ÔÚÈ¡µÞ¹ØÁªÊ±³öÏÖ¡£Ò»µ©²úÉúÈ¡µÞ¹ØÁªµÄÇé¿ö¢Ù£¬ÄÚ´æ¾Í»á¶Ï¸ù´æ´¢ÔÚÎÞÏßÍøÂç½Ó¿Ú½ÚÔìÆ÷ (WNIC) WiFi оƬÖеĻỰÃÜÔ¿£¬¼´ÉèÖÃΪ0¢Ú¡£ÕâÖÖÐÐΪÇкÏÔ¤ÆÚ£¬ÓÉÓÚÈ¡µÞ¹ØÁªºóÊý¾ÝÓ¦¸Ã²»ÔÙ´«Ê䡣Ȼ¶ø£¬ÎÒÃÇ·¢ÏÖ£¬¼´±ãÔÚͨ¹ýÕâ¸öËùÓÐΪ0µÄÃÜÔ¿¼ÓÃܺó¢Û£¬ÒÅÁôÔÚ¸ÃоƬ´«Ê仺³åÇøÖеÄÊý¾ÝÖ¡ÒÀÈ»»á±»´«Êä¢Ü¡£¡±ÓÉÓÚËüÓÃÁËËùÓеÄ0£¬Òò¶øÕâÖÖ¡°¼ÓÃÜ¡±ÏÖʵÉϻᵼÖÂÊý¾Ý±»½âÃÜÇÒÒÔÃ÷ÎÄ´ó¾ÖÔâ¶³ö¡£
¹¥»÷õè¾¶ºÜµ¥Ò»£ºÖÎÀí¿ò¼ÜÖÎÀí¹ØÁªºÍÈ¡µÞ¹ØÁª²Ù×÷£¬µ«ÖÎÀí¿ò¼Ü×ÔÉíÊÇδÈÏÖ¤ºÍδ¼ÓÃܵġ£¹¥»÷ÕßÖ»Óз¢ËÍÒ»¸öÌØÊâ»ú¹ØµÄÖÎÀíÊý¾Ý¿ò¼Ü¾Í¿É´¥·¢È¡µÞ¹ØÁª´Ó¶ø·¢Æð¹¥»÷£¬Ö®ºó¾Í¿ÉÄܼìË÷ÒÅÁôÔÚ»º³åÇøÖеÄÃ÷ÎÄÐÅÏ¢¡£¼ûͼ2¡£
Òò¶ø£¬µÐÊÖÄܹ»²¶»ñ¸ü¶àÔ̺¬Ç±ÔÚÃô¸ÐÊý¾ÝµÄÍøÂç°ü£¬Ô̺¬DNS¡¢ARP¡¢ICMP¡¢HTTP¡¢TCPºÍTLSÊý¾Ý°ü£¬¼ûͼ3.
×êÑÐÈËÔ±°µÊ¾£¬Kr00k ¹¥»÷Ò»´Î¿É¶³ö×î¶à32KB Êý¾Ý£¬Ï൱ÓÚÔ¼2Íò¸ö´ÊÓï¡£¹¥»÷Õ߿ɷ¢ËÍһϵÁÐÖÎÀí¿ò¼Ü´¥·¢¹¥»÷²¢ÆðÍ·ÍøÂçÊý¾Ý£¬ÈçÃÜÂë¡¢ÐÅÓþ¿¨ÐÅÏ¢»òÆäËüÓû§Í¨¹ýWiFi·¢Ë͵½»¥ÁªÍøÉϵÄÈÎºÎÆ÷²Ä¡£
½¨¸´½¨Òé
1.ÇëÖ±½ÓÓëоƬÔì×÷ÉÌÁªÏµÒÔ»ñÈ¡ÓйØKR00K·ì϶µÄ²¹¶¡£»
2.¶ÔÊÜÓ°ÏìµÄÉ豸½øÐÐÉý¼¶¡£
Òò¸Ã·ì϶ֻÊÇÕë¶Ô WI-FI Á÷Á¿½øÐнâÃÜ¡£½¨ÒéÓû§¾¡Á¿Ê¹Óà HTTPS/TLS ½øÐÐÍøÂçͨѶ¡£¸Ã·½Ê½Äܹ»¿Ï¶¨Ë®Æ½µØ¼õ»º·ì϶´øÀ´µÄÓ°Ïì¡£
²Î¿¼Á´½Ó
https://thehackernews.com/2020/02/kr00k-wifi-encryption-flaw.html
https://www.welivesecurity.com/wp-content/uploads/2020/02/ESET_Kr00k.pdf


¾©¹«Íø°²±¸11010802024551ºÅ