Wi-Fi WPA2 ¡°Kr00k¡±·ì϶·ÖÎöÓ븴ÏÖ

°ä²¼¹¦·ò 2020-03-26

1.×êÑв¼¾°


ÔÚ½ñÄê2Ô·ݵÄRSA´ó»áÉÏ£¬£¬ESETµÄ×êÑÐÈËÔ±¹«¿ªÅû¶Wi-FiоƬ´æÔÚÑÏÖØ°²È«·ì϶CVE-2019-15126£¬£¬²¢½«Æä¶¨ÃûΪ¡°Kr00k¡±¡£¹¥»÷ÕßÄܹ»ÀûÓá°Kr00k¡±½âÃÜÎÞÏßÍøÂçÁ÷Á¿£¬£¬»ñÈ¡´«Êä¹ý³ÌÖеÄÃô¸ÐÊý¾Ý¡£


Kr00k·ì϶ӰÏ첿ÃÅ×°ÖÃBroadcomºÍCypress Wi-FiоƬµÄÉ豸£¬£¬ÕâÁ½¼ÒоƬ²úÆ·±»¿í·ºÀûÓÃÓÚÊÖ»ú¡¢¡¢Æ½°åµçÄÔ¼°IOTÉ豸ÖС£ÊؾɹÀ¼Æ£¬£¬È«Çò×ܼƳ¬¹ý10ÒÚµÄÉ豸Êܸ÷ì϶µÄÓ°Ïì¡£


2.·ì϶·ÖÎö


2.1 ·ì϶µÀÀí


ÔÚ½éÉÜKr00k·ì϶֮ǰ£¬£¬Ïȵ¥Ò»ÏàʶÏÂWPA2ºÍ̸¡£Ä¿Ç°»ùÓÚAES-CCMPµÄWPA2ºÍ̸ÊÇWi-FiÍøÂçÖÐ×îÆÕ±éµÄ³ß¶È¡£ÏÂͼÊǿͻ§¶Ë£¨Station, STA£©ÏνӽÓÈëµã£¨Access Point, AP£©µÄÐÂÎŽ»»¥¹ý³Ì¡£


OG¶«·½Ìü¡¤(Öйú´ó½)


STAºÍAPÔÚËÄ´ÎÎÕÊÖÖУ¬£¬Ð­É̻ỰÃÜÔ¿PTK£¨Pairwise Transient Key£©£¬£¬PTKÊÇÓÉPMKºÍPKEÍÆËãÌìÉú£¬£¬¶øPMKÓÉANonce¡¢¡¢SNonceºÍË«·½MACµØÖ·µÈÍÆËãÌìÉú¡£PTK·ÖΪKCK¡¢¡¢KEKºÍTKÈý²¿ÃÅ£¬£¬ÆäÖУ¬£¬KCKÓÃÓÚMICУÑ飬£¬KEKÓÃÓÚ¼ÓÃÜGTK£¬£¬TKΪÊý¾Ý¼ÓÃÜÃÜÔ¿¡£ËÄ´ÎÎÕÊÖʵÏֺ󣬣¬´«ÊäÊý¾ÝʹÓÃTK½øÐмÓÃÜ¡£


OG¶«·½Ìü¡¤(Öйú´ó½)


ÔÚWPA2ºÍ̸ÖУ¬£¬½â³ý¹ØÁª²Ù×÷Äܹ»ÓÉδ¾­Éí·ÝÑéÖ¤ºÍδ¼ÓÃܵÄÖÎÀíÖ¡´¥·¢£¬£¬Kr00k·ì϶Óë½â³ý¹ØÁª²Ù×÷Ç×êÇÓйØ¡£±ÉÈËͼËùʾÖУ¬£¬µ±Õ¾µãµÄÏνӻỰ½â³ý¹ØÁªºó£¬£¬±£ÁôÔÚWi-FiоƬÖеĻỰÃÜÔ¿(TK)±»ÖÃÁ㣬£¬ÈôÊÇʹÓÃÒÑÖÃÁãµÄTKÃÜÔ¿¶ÔоƬ»º´æÖеÄÊý¾Ý½øÐмÓÃܲ¢´«Ê䣬£¬½«µ¼Ö·ì϶²úÉú¡£


OG¶«·½Ìü¡¤(Öйú´ó½)


¹¥»÷ÕßÀûÓÃÎÞÏßÍø¿¨¼´¿ÉʵÏÖÈëÇÖ£¬£¬Í¨¹ý²»ÐÝ´¥·¢½â³ý¹ØÁª¡¢¡¢ÖØÐ¹ØÁª£¬£¬¶øºóʹÓÃÈ«ÁãTK¶Ô²¶»ñµÄÊý¾ÝÖ¡½øÐнâÃÜ£¬£¬´Ó¶ø»ñÈ¡Ãô¸ÐÐÅÏ¢¡£


2.2 ¹Ì¼þ·ÖÎö


±¾ÎİÎÈ¡Nexus5ÖеÄBCM4339оƬ¹Ì¼þ½øÐзÖÎö¡£Ê×ÏÈ£¬£¬¶¨Î»¹Ì¼þÖÐÍÆËãptkµÄµØÎ»£¬£¬ÈçÏÂͼËùʾ¡£


OG¶«·½Ìü¡¤(Öйú´ó½)


¶øºó£¬£¬¶ÔÆäÉϲ㺯Êýwlc_wpa_sup_eapol½øÐзÖÎö¡£


OG¶«·½Ìü¡¤(Öйú´ó½)

OG¶«·½Ìü¡¤(Öйú´ó½)


wlc_wpa_sup_eapolŲÓÃwpa_pmk_to_ptkʱ£¬£¬´«ÈëµÄ²ÎÊý±ðÀëΪmac1¡¢¡¢mac2¡¢¡¢Nonce1¡¢¡¢Nonce2¡¢¡¢pmk¡¢¡¢pmk_len¡¢¡¢ptk¡¢¡¢ptk_len¡£ptkÍÆËãÁ˾ֱ»±£ÁôÔÚwpa_ptk½á¹¹ÌåÆ«ÒÆ0x8cµØÎ»ÖС£


wlc_sup_attachº¯ÊýÓÃÓÚ´¦ÖÃSTAµÄ³õʼ»¯ÏνÓ£¬£¬¸Ãº¯Êý¶Ôwpa_ptk½á¹¹Ìå½øÐÐÄÚ´æ·ÖÅäºÍ³õʼ»¯£¬£¬wpa_ptk½á¹¹Ìå¾ÞϸΪ0x13C¡£


OG¶«·½Ìü¡¤(Öйú´ó½)


µ±³õʼ»¯Ê§°Ü¡¢¡¢Ïνӳ¬Ê±»ò½â³ýÏνӵÄʱ³½£¬£¬Ôò»áŲÓÃwlc_sup_detachº¯Êý¶Ôwpa_ptk½á¹¹Ìå½øÐÐÖÃÁã²Ù×÷¡£


OG¶«·½Ìü¡¤(Öйú´ó½)

OG¶«·½Ìü¡¤(Öйú´ó½)


3.·ì϶ÑéÖ¤


3.1 ²âÊÔ»·¾³



É豸Ãû³Æ

ÊýÁ¿

ÊÜÓ°ÏìµÄÉ豸

Nexus5

1

iphone6sÊÖ»ú

1

Attacker

NETGEARÍø¿¨

2

3.2 ²âÊÔ²½Öè


£¨1£©¶Ôwireshark½âÃÜÊý¾Ý°üµÄÓйØÖ°ÄܽøÐÐpatch£¬£¬Ê¹Æä¿ÉÄܳɹ¦½âÃÜÈ«ÁãTK¼ÓÃܵÄÊý¾Ý¡£

£¨2£©Ê¹ÓÃpatchºóµÄwireshark¼àÌýÖ¸±êÉ豸ºÍAPͨѶµÄÊý¾Ý°ü¡£

£¨3£©Ê¹ÓÃÖ¸±êÉ豸ÏνÓAP²¢ËÁÒâ½Ó¼ûÍøÒ³¡£

£¨4£©¶ÔAPºÍ²âÊÔÖ¸±ê·¢ËÍDisassocation°ü¡£

£¨5£©·´¸´Ö´Ðв½Ö裨3£©ºÍ£¨4£©£¬£¬¹Û²ìwiresharkÖÐÊý¾Ý°üÊÇ·ñ½âÃÜ¡£


3.3 ²âÊÔÁ˾Ö


Nexus 5£º£º


OG¶«·½Ìü¡¤(Öйú´ó½)


iphone 6s£º£º


OG¶«·½Ìü¡¤(Öйú´ó½)


Äܹ»¿´³ö£¬£¬Nexus 5ºÍiphone 6s²¿ÃÅÊý¾Ý±»³É¹¦½âÃÜ¡£


4.Ó°ÏìÁìÓò


ĿǰÒÑÖªÊÜÓ°ÏìµÄÉ豸ÓУº£º

Amazon Echo 2nd gen

Amazon Kindle 8th gen

Apple iPad mini 2

Apple iPhone 6, 6S, 8, XR

Apple MacBook Air Retina 13-inch 2018

Google Nexus 5

Google Nexus 6

Google Nexus 6P

Raspberry Pi 3

Samsung Galaxy S4 GT-I9505

Samsung Galaxy S8

Xiaomi Redmi 3S

Asus RT-N12

Huawei B612S-25d

Huawei EchoLife HG8245H

Huawei E5577Cs-321


5.°²È«½¨Òé


Éè±¸ÖÆ×÷ÉÌÒѰ䲼µÄ°²È«½¨ÒéÈçÏ£º£º

?https://support.apple.com/en-us/HT210721

?https://support.apple.com/en-us/HT210722

?https://support.apple.com/en-us/HT210788

?https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-003.txt

?https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200226-wi-fi-info-disclosure

?https://www.huawei.com/en/psirt/security-notices/huawei-sn-20200228-01-kr00k-en

?https://www.microchip.com/design-centers/wireless-connectivity/embedded-wi-fi/kr00k-vulnerability

?https://www.mist.com/documentation/mist-security-advisory-kr00k-attack-faq/

?https://www.zebra.com/us/en/support-downloads/lifeguard-security/kr00k-vulnerability.html