Wi-FiÁ÷Á¿ÐÅϢй©·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-02-28

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-15126£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


³§ÉÌ

É豸/оƬ/·ÓÉÆ÷Ãû³Æ

broadcom

bcm4356

broadcom

bcm4389

broadcom

bcm4375

broadcom

bcm43012

broadcom

bcm43013

broadcom

bcm43752

Amazon

Echo 2nd gen

Amazon

Kindle 8th gen

Apple

iPad mini 2 (ipad_os < 13.2)

Apple

iPhone 6, 6S, 8, XR (iphone_os < 13.2)

Apple

MacBook Air Retina 13-inch 2018 (mac_os < 10.15.1)

Google

Nexus 5

Google

Nexus 6

Google

Nexus 6S

Raspberry

Pi 3

Samsung

Galaxy S4 GT-I9505

Samsung

Galaxy S8

Xiaomi

Redmi 3S

Asus

RT-N12

Huawei

B612S-25d

Huawei

EchoLife HG8245H

Huawei

E5577Cs-321



·ì϶¸ÅÊö


ÍøÂ簲ȫ×êÑÐÔ±´ÓʹÓÃ¿í·ºµÄ²©Í¨ (Broadcom) ºÍ Cypress WiFi оƬÖз¢ÏÖÁËÒ»¸öÓ²¼þ·ì϶£¬Ó°ÏìÊýÊ®ÒŲ́É豸£¬ÈçÖÇÄÜÊÖ»ú¡¢Æ½°åµçÄÔ¡¢±Ê¼Ç±¾µçÄÔ¡¢Â·ÓÉÆ÷ºÍÎïÁªÍøÉ豸¡£


¸Ã·ì϶±»³ÆÎª ¡°Kr00k¡±£¬±àºÅΪ CVE-2019-15126£¬Ëü¿Éµ¼ÖÂÔ¶³Ì¹¥»÷ÕßÀ¹½Ø²¢½âÃÜÒ×Êܹ¥»÷É豸ͨ¹ýÎÞÏß´«ÊäµÄijЩÎÞÏßÍøÂçÊý¾Ý°ü¡£¸Ã·ì϶²úÉúµÄÔ­ÒòÔÚÓÚ²©Í¨ºÍ Cypress оƬʹÓÃÁËÒ»¸öÈ«Áã¼ÓÃÜÃÜÔ¿£¬´Ó¶øµ¼ÖÂÊý¾Ý±»½âÃÜ£¬·ÛËéÁË WPA2-Personal ºÍ WPA2-Enterprise °²È«ºÍ̸¡£¹¥»÷ÕßÎÞÐèÏνӵ½Êܺ¦ÕßµÄÎÞÏßÍøÂç¼´¿É·¢Æð¹¥»÷¡£Ê¹Óà WPA2-Personal »ò WPA2-Enterprise ºÍ̸¡¢Í¨¹ý AES-CCMP ¼ÓÃܱ£»¤ÍøÂçÁ÷Á¿µÄÉ豸Ò×Êܹ¥»÷¡£


·ì϶ÏêÇé


ÔÚÏêÊö Kr00k ¹¥»÷֮ǰ£¬ÎÒÃDZØÒªÏàʶÈçϼ¸µã£º


1. ¸Ã·ì϶²¢²»´æÔÚÓÚÎÞÏß¼ÓÃܺÍ̸ÖУ¬¶øÊÇÒòÒ×Êܹ¥»÷оƬʵÏָüÓÃܺÍ̸µÄ·½Ê½²»µ±µ¼ÖµÄ£»

2. ¹¥»÷ÕßÎÞ·¨Í¨¹ý¸Ã·ì϶ÏνÓÓû§ WiFiÍøÂç²¢½øÒ»²½·¢ÆðÖÐÑëÈ˹¥»÷»òÕß¹¥»÷ÆäËüÁªÍøÉ豸£»

3. ¹¥»÷ÕßÎÞ·¨ÀûÓø÷ì϶»ñϤÓû§µÄ WiFi ÃÜÂ룬Åú¸Ä WiFi ÃÜÂëÎÞÖúÓÚÎÊÌ⽨¸´£»

4. ËüÎÞ·¨Ó°ÏìʹÓÃ×îРWiFi °²È«³ß¶È WPA3 ºÍ̸µÄÏÖ´úÉ豸£»

5. È»¶ø£¬Ëü¿Éµ¼Ö¹¥»÷Õßץȡ²¢½âÃÜijЩÎÞÏßÊý¾Ý°ü£¨Êýǧ×Ö½Ú£©£¬µ«ÎÞ·¨Ô¤²âËü½«Ô̺¬ÄÄЩÊý¾Ý£»

6. ×î³ÁÒªµÄÊÇ£¬¸ÃȱµãÍ»ÆÆÁËÎÞÏß²ãÉϵļÓÃÜ»úÔ죬µ«ºÍ TLS ¼ÓÃܺÍ̸Î޹أ¬Òò¶øºóÕßÒÀÈ»Äܹ»±£»¤ HTTPS Õ¾µãÍøÂçÁ÷Á¿µÄ°²È«¡£


ÔÚ WiFi ÖУ¬É豸Ïνӵ½½Ó¼ûµã (AP) ±»³ÆÎª¡°¹ØÁª¡±£¬¶Ï¿ªÏνӣ¨ÈçÓÐÈË´ÓÒ»¸ö WiFi AP ÖÜÓε½Áí±íÒ»¸ö AP£¬¾­ÀúÁËÐźÅ×ÌÈÅ»ò¹Ø¹ØÉ豸 WiFi£©±»³ÆÎª¡°È¡µÞ¹ØÁª¡±¡£


ͼ1ÌṩÁËоƬÃýÎóµÄʾÒâͼ¡£×êÑÐÈËÔ±Ö¸³ö£¬¡°Kr00k ·ì϶ÔÚÈ¡µÞ¹ØÁªÊ±³öÏÖ¡£Ò»µ©²úÉúÈ¡µÞ¹ØÁªµÄÇé¿ö¢Ù£¬ÄÚ´æ¾Í»á¶Ï¸ù´æ´¢ÔÚÎÞÏßÍøÂç½Ó¿Ú½ÚÔìÆ÷ (WNIC) WiFi оƬÖеĻỰÃÜÔ¿£¬¼´ÉèÖÃΪ0¢Ú¡£ÕâÖÖÐÐΪÇкÏÔ¤ÆÚ£¬ÓÉÓÚÈ¡µÞ¹ØÁªºóÊý¾ÝÓ¦¸Ã²»ÔÙ´«Ê䡣Ȼ¶ø£¬ÎÒÃÇ·¢ÏÖ£¬¼´±ãÔÚͨ¹ýÕâ¸öËùÓÐΪ0µÄÃÜÔ¿¼ÓÃܺó¢Û£¬ÒÅÁôÔÚ¸ÃоƬ´«Ê仺³åÇøÖеÄÊý¾ÝÖ¡ÒÀÈ»»á±»´«Êä¢Ü¡£¡±ÓÉÓÚËüÓÃÁËËùÓеÄ0£¬Òò¶øÕâÖÖ¡°¼ÓÃÜ¡±ÏÖʵÉϻᵼÖÂÊý¾Ý±»½âÃÜÇÒÒÔÃ÷ÎÄ´ó¾ÖÔâ¶³ö¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¹¥»÷õè¾¶ºÜµ¥Ò»£ºÖÎÀí¿ò¼ÜÖÎÀí¹ØÁªºÍÈ¡µÞ¹ØÁª²Ù×÷£¬µ«ÖÎÀí¿ò¼Ü×ÔÉíÊÇδÈÏÖ¤ºÍδ¼ÓÃܵÄ¡£¹¥»÷ÕßÖ»Óз¢ËÍÒ»¸öÌØÊâ»ú¹ØµÄÖÎÀíÊý¾Ý¿ò¼Ü¾Í¿É´¥·¢È¡µÞ¹ØÁª´Ó¶ø·¢Æð¹¥»÷£¬Ö®ºó¾Í¿ÉÄܼìË÷ÒÅÁôÔÚ»º³åÇøÖеÄÃ÷ÎÄÐÅÏ¢¡£¼ûͼ2¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Òò¶ø£¬µÐÊÖÄܹ»²¶»ñ¸ü¶àÔ̺¬Ç±ÔÚÃô¸ÐÊý¾ÝµÄÍøÂç°ü£¬Ô̺¬DNS¡¢ARP¡¢ICMP¡¢HTTP¡¢TCPºÍTLSÊý¾Ý°ü£¬¼ûͼ3.


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


×êÑÐÈËÔ±°µÊ¾£¬Kr00k ¹¥»÷Ò»´Î¿É¶³ö×î¶à32KB Êý¾Ý£¬Ï൱ÓÚÔ¼2Íò¸ö´ÊÓï¡£¹¥»÷Õ߿ɷ¢ËÍһϵÁÐÖÎÀí¿ò¼Ü´¥·¢¹¥»÷²¢ÆðÍ·ÍøÂçÊý¾Ý£¬ÈçÃÜÂë¡¢ÐÅÓþ¿¨ÐÅÏ¢»òÆäËüÓû§Í¨¹ýWiFi·¢Ë͵½»¥ÁªÍøÉϵÄÈÎºÎÆ÷²Ä¡£


½¨¸´½¨Òé


1.ÇëÖ±½ÓÓëоƬÔì×÷ÉÌÁªÏµÒÔ»ñÈ¡ÓйØKR00K·ì϶µÄ²¹¶¡£»

2.¶ÔÊÜÓ°ÏìµÄÉ豸½øÐÐÉý¼¶¡£

Òò¸Ã·ì϶ֻÊÇÕë¶Ô WI-FI Á÷Á¿½øÐнâÃÜ¡£½¨ÒéÓû§¾¡Á¿Ê¹Óà HTTPS/TLS ½øÐÐÍøÂçͨѶ¡£¸Ã·½Ê½Äܹ»¿Ï¶¨Ë®Æ½µØ¼õ»º·ì϶´øÀ´µÄÓ°Ïì¡£


²Î¿¼Á´½Ó


https://thehackernews.com/2020/02/kr00k-wifi-encryption-flaw.html

https://www.welivesecurity.com/wp-content/uploads/2020/02/ESET_Kr00k.pdf