TCP/IP²Ö¿â£ºNAME£ºWRECK DNSºÍ̸·ì϶
°ä²¼¹¦·ò 2021-04-130x00 ·ì϶¸ÅÊö
2021Äê04ÔÂ13ÈÕ£¬°²È«ÈËÔ±Åû¶ÁËTCP/IP²Ö¿âÖÐDNSºÍ̸ÖÐͳ³ÆÎªNAME£ºWRECKµÄ9¸ö°²È«·ì϶£¬ÕâЩ·ì϶ÖÁÉÙÓ°ÏìÁË1ÒÚ¸öInternetÉÏÔËÐеÄÉ豸£¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶ʹÊÜÓ°ÏìµÄÉ豸ÍÑ»ú»ò¶ÔÉ豸½øÐнÚÔì¡£
0x01 ·ì϶ÏêÇé

NAME£ºWRECKÊÇÎïÁªÍøÆóÒµ°²È«¹«Ë¾ForescoutºÍÒÔÉ«Áа²È«×êÑÐÓ××éJSOFµÄ¹²Í¬·¢Ïֵģ¬ÕâЩ·ì϶ӰÏìµÄTCP/IP²Ö¿âÔ̺¬µ«²»ÏÞÓÚ£º
FreeBSD£¨Ó°Ïì°æ±¾£º12.1£©-BSDϵÁÐÖÐ×îÊ¢ÐеIJÙ×÷ϵͳ֮һ¡£
IPnet£¨Ó°Ïì°æ±¾£ºVxWorks 6.6£©-×î³õÓÉInterpeak¿ª·¢£¬´Ë¿ÌÓÉWindRiverÊØ»¤£¬²¢ÓÉVxWorksʵʱ²Ù×÷ϵͳ£¨RTOS£©Ê¹Óá£
NetX£¨Ó°Ïì°æ±¾£º6.0.1£©-ThreadX RTOSµÄÒ»²¿ÃÅ£¬´Ë¿ÌÊÇMicrosoftÊØ»¤µÄÒ»¸ö¿ªÔ´ÏîÄ¿£¬Ãû³ÆÎªAzure RTOS NetX¡£
Nucleus NET£¨Ó°Ïì°æ±¾£º4.3£©-ÓÉÎ÷ÃÅ×ÓÒµÎñMentor GraphicsÊØ»¤µÄNucleus RTOSµÄÒ»²¿ÃÅ£¬ÓÃÓÚÒ½ÁÆ¡¢¹¤Òµ¡¢Ïû·ÑÀà¡¢º½¿Õº½ÌìºÍÎïÁªÍøÉ豸¡£
¹¥»÷ÕßÄܹ»ÀûÓÃNAME£ºWRECK·ì϶ÇÔÈ¡Ãô¸ÐÊý¾Ý¡¢Åú¸Ä»òʹÉ豸ÍÑ»úÒÔ¶ÔÔì×÷ÐÐÒµÖÐÈ·µ±¾Ö»òÆóÒµ·þÎñÆ÷¡¢Ò½ÁÆ»ú¹¹¡¢ÁãÊÛÉÌ»ò¹«Ë¾Ôì³É³Á´ó°²È«±äÂÒ¡£

¹¥»÷Õß»¹Äܹ»ÀûÓÃÕâЩ·ì϶´Û¸Äסլ»òóÒ׳¡ËùµÄÖÇÄÜÉ豸£¬ÒÔ½ÚÔ칩ÎÂů͸·ç¡¢½ûÓð²Õûϵͳ»ò´Û¸Ä×Ô¶¯ÕÕÃ÷ϵͳ¡£

×êÑÐÈËÔ±ÔÚ·ÖÎöÉÏÊöTCP/IP²Ö¿âÖеÄDNSʱ£¬·ÖÎöÁ˸úÍ̸µÄÐÂÎÅѹËõÖ°ÄÜ¡£DNSÏìÓ¦Êý¾Ý°üÖÐÔ̺¬Ò»ÑùµÄÓòÃû»ò²¿ÃÅÓòÃûµÄÇé¿ö²¢²»ÉÙ¼û£¬Òò¶øËüʹÓÃÒ»ÖÖѹËõ»úÔìÀ´¼õÓ×DNSÐÂÎŵĴóÓ×£¬ÕâÖÖ±àÂë²»½öÀûÓÃÔÚDNS½âÎöÆ÷ÖУ¬Ëü»¹ÀûÓÃÔڶಥDNS£¨mDNS£©¡¢DHCP¿Í»§¶ËºÍIPv6·ÓÉÆ÷¹«¸æÖС£
ForescoutÔÚÆä»ã±¨ÖÐÚ¹ÊÍ˵£¬Ö»¹ÜijЩºÍ̸²¢Î´Õýʽ֧³ÖѹËõ£¬µ«¸ÃÖ°ÄÜ»¹´æÔÚÓںܶàÀûÓÃÖС£ÖµÍ×ÌùÐĵÄÊÇ£¬²¢·ÇNAME£ºWRECKÖеÄËùÓзì϶¶¼Äܹ»±»ÀûÓÃÀ´»ñµÃÒ»ÑùµÄÁ˾֡£ÆäÖÐ×îÑϳÁµÄÊÇÔ¶³Ì´úÂëÖ´Ðзì϶£¬Æä×î¸ßÆÀ·ÖΪ9.8£¨Âú·Ö10·Ö£©£¬9¸ö·ì϶ÈçϱíËùʾ£¬²¢·ÇËùÓзì϶¶¼ÓëÐÂÎÅѹËõÓйأº
CVE ID | Stack | ÃèÊö | ÊÜÓ°ÏìÖ°ÄÜ | DZÔÚÓ°Ïì | ÆÀ·Ö |
CVE-2020-7461 | FreeBSD |
-ÍøÂçÉϵĹ¥»÷ÕßÄܹ»½«¶ñÒâÔì×÷µÄÊý¾Ý·¢Ë͵½DHCP¿Í»§¶Ë | Message compression | RCE | 7.7 |
CVE-2016-20009 | IPnet | -ÐÂÎŽâѹËõÖ°ÄÜ»ùÓÚ²Ö¿âµÄÒç³ö | Message compression | RCE | 9.8 |
CVE-2020-15795 | Nucleus NET | -DNSÓòÃû±êÇ©½âÎöÖ°ÄÜÎÞ·¨ÕýÈ·ÑéÖ¤DNSÏìÓ¦ÖеÄÃû³Æ -½âÎöÌåʽÃýÎóµÄÏìÓ¦¿ÉÄܵ¼ÖÂд²Ù×÷³¬³ö·ÖÅäµÄ½á¹¹µÄĩβ | Domain name label parsing | RCE | 8.1 |
CVE-2020-27009 | Nucleus NET | -DNSÓòÃû¼Í¼½âѹËõÖ°ÄÜÎÞ·¨ÕýÈ·ÑéÖ¤Ö¸ÕëÆ«ÒÆÖµ -½âÎöÌåʽÃýÎóµÄÏìÓ¦¿ÉÄܵ¼ÖÂд²Ù×÷³¬³ö·ÖÅäµÄ½á¹¹µÄĩβ | Message compression | RCE | 8.1 |
CVE-2020-27736 | Nucleus NET | -DNSÓòÃû±êÇ©½âÎöÖ°ÄÜÎÞ·¨ÕýÈ·ÑéÖ¤DNSÏìÓ¦ÖеÄÃû³Æ -½âÎöÌåʽÃýÎóµÄÏìÓ¦¿ÉÄܵ¼ÖÂд²Ù×÷³¬³ö·ÖÅäµÄ½á¹¹µÄĩβ | Domain name label parsing | »Ø¾ø·þÎñ | 6.5 |
CVE-2020-27737 | Nucleus NET | -DNSÏìÓ¦½âÎöÖ°ÄÜÎÞ·¨ÕýÈ·ÑéÖ¤¸÷À೤¶ÈºÍ¼Í¼Êý -½âÎöÌåʽÃýÎóµÄÏìÓ¦¿ÉÄܻᵼÖ¶ÁÈ¡³¬³öÒÑ·ÖÅä½á¹¹µÄĩβ | Domain name label parsing | »Ø¾ø·þÎñ | 6.5 |
CVE-2020-27738 | Nucleus NET | -DNSÓòÃû¼Í¼½âѹËõÖ°ÄÜÎÞ·¨ÕýÈ·ÑéÖ¤Ö¸ÕëÆ«ÒÆÖµ -½âÎöÌåʽÃýÎóµÄÏìÓ¦¿ÉÄܵ¼Ö³¬³ö·ÖÅä½á¹¹Ä©Î²µÄ¶ÁÈ¡½Ó¼û | Message compression | »Ø¾ø·þÎñ | 6.5 |
CVE-2021-25677 | Nucleus NET | -DNS¿Í»§¶ËÎÞ·¨ÕýÈ·Ëæ»ú»¯DNSÊÂÎñID£¨TXID£©ºÍUDP¶Ë±êÓï | Transaction ID | DNS»º´æÖж¾/ºýŪ | 5.3 |
* | NetX | -DNS½âÎöÆ÷ÖеÄÁ½¸öÖ°ÄÜÎÞ·¨²é³Ñ¹ËõÖ¸ÕëÊÇ·ñ²»µÅ×Úµ±Ç°ÔÚ½âÎöµÄÒ»ÑùÆ«ÒÆÁ¿£¬´Ó¶ø¿ÉÄܵ¼ÖÂÎÞÏÞÑ»· | Message compression | »Ø¾ø·þÎñ | 6.5 |
ÀûÓõ¥¸ö·ì϶¿ÉÄܲ»»áÔì³ÉÌ«´óÓ°Ï죬µ«ÈôÊǹ¥»÷Õß½«ËüÃÇ×éºÏÔÚһ·À´ÀûÓ㬾ͿÉÄÜ»áÔì³ÉÑϳÁ·ÛËé¡£ÀýÈ磬¹¥»÷ÕßÄܹ»ÀûÓÃÒ»¸ö·ì϶½«ËÁÒâÊý¾ÝдÈëÒ×Êܹ¥»÷É豸µÄÃô¸ÐÄÚ´æµØÎ»£¬ÀûÓÃÁíÒ»¸ö·ì϶ÔÚÊý¾Ý°üÖÐ×¢Èë´úÂ룬¶øºóÔÙÀûÓõÚÈý¸ö·ì϶½«Æä´«µÝ¸øÖ¸±ê¡£
Forescout¹«Ë¾µÄ»ã±¨Éî¿Ì̽ÇóÁ˼¼Êõϸ½Ú£¬¼´ÀûÓÃÔÚ¿ªÔ´TCP/IP²Ö¿âÖз¢ÏÖµÄNAME:WRECK·ì϶ÒÔ¼°AMNESIA:33Öеķì϶À´ÊµÏÖÔ¶³Ì´úÂëÖ´Ðй¥»÷¡£¸Ã¹«Ë¾»¹»áÉÌÁ˶à¸öÔÚDNSÐÂÎŽâÎöÆ÷Öв»ÐݳÁ¸´µÄÖ´ÐÐÎÊÌ⣬ÕâЩÎÊÌâ±»³ÆÎªanti-patterns£¨·´Ä£Ê½£©£¬ËüÃÇÊÇÔì³ÉNAME:WRECK·ì϶µÄÔÒò£º
¶ÌȱTXIDÑéÖ¤£¬Ëæ»úTXIDºÍÔ´UDP¶Ë¿Ú²»¼°£»
²»×ãÓòÃû×Ö·ûÑéÖ¤£»
¶Ìȱ±êÇ©ºÍÃû³Æ³¤¶ÈÑéÖ¤£»
¶ÌȱNULLÖÕÖ¹ÑéÖ¤£»
¶Ìȱ¼Í¼¼ÆÊý×Ö¶ÎÑéÖ¤£»
²»×ãÓòÃûѹËõÖ¸ÕëºÍÆ«ÒÆÁ¿ÑéÖ¤£»
´Ë±í£¬Forescout»¹ÌṩÁËÁ½¸ö¿ªÔ´¹¤¾ß£¬Äܹ»Ô®ÊÖÈ·¶¨Ö¸±êÍøÂçÉ豸ÊÇ·ñÔËÐÐÌØ¶¨µÄǶÈëʽTCP/IPºÍ̸ջ£¨Project Memoria Detector£©ºÍÓÃÓÚ¼ì²âÀàËÆÓÚNAME:WRECKµÄÎÊÌ⣨namewreck£¬ÓëJoernһ·ʹÓã©¡£
0x02 ´ëÖý¨Òé
NAME£ºWRECKµÄ½¨¸´·¨Ê½ºÏÓÃÓÚ FreeBSD¡¢Nucleus NETºÍ NetX£¬½¨ÒéÏÈÖ´ÐÐÒÔϰ²È«½¨Ò飬ÔÙʵʱÀûÓÃÉ豸¹©¸øḚ́䲼µÄ°²È«¸üС£
°²È«½¨Ò飺
ʹÓÃһЩ»º½âÐÅÏ¢À´¿ª·¢¼ì²âDNS·ì϶µÄÊðÃû£»
·¢ÏÖ²¢Å̵ãÔËÐÐÒ×Êܹ¥»÷²Ö¿âµÄÉ豸£»
Ö´ÐзֶνÚÔìºÍÊʵ±µÄnetwork hygiene£»
¼à¶½ÊÜÓ°ÏìµÄÉ豸¹©¸øḚ́䲼µÄ²¹¶¡£»
ÅäÖÃÉ豸ÒÀÀµÄÚ²¿DNS·þÎñÆ÷£»
¼à¿ØËùÓÐÍøÂçÁ÷Á¿ÖеĶñÒâÊý¾Ý°ü¡£
0x03 ²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/name-wreck-dns-vulnerabilities-affect-over-100-million-devices/
https://www.freebsd.org/security/advisories/FreeBSD-SA-20:26.dhclient.asc
https://github.com/Forescout/project-memoria-detector
https://github.com/Forescout/namewreck
0x04 ¹¦·òÏß
2021-04-13 bleepingcomputerÅû¶·ì϶
2021-04-13 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ