FragAttacks·ì϶·ÖÎö

°ä²¼¹¦·ò 2021-05-18

²¼¾°


½üÈÕ £¬Å¦Ô¼´óѧ°¢²¼Ôú±È·ÖУµÄ°²È«×êÑÐÔ±Mathy Vanhoef·¢ÏÖÁËһϵÁÐÓ°Ïì¾Þ´óµÄWi-Fi·ì϶ £¬ÕâһϵÁзì϶±»Í³³ÆÎªFragAttacks £¬FragAttacksÓ°ÏìÁË1997ÄêWi-Fi¼¼Êõµ®ÉúÒÔÀ´µÄËùÓÐWi-FiÉ豸£¨Ô̺¬ÍÆËã»ú¡¢¡¢¡¢ÖÇÄÜÊÖ»ú¡¢¡¢¡¢Ô°ÇøÍøÂç¡¢¡¢¡¢¼Òͥ·ÓÉÆ÷¡¢¡¢¡¢ÖÇÄܼҾÓÉ豸¡¢¡¢¡¢ÖÇÄÜÆû³µ¡¢¡¢¡¢ÎïÁªÍøµÈµÈ£©¡£¡£¡£


ÆäÖÐÈý¸ö·ì϶ӰÏì´óÎÞÊýWiFiÉ豸 £¬ÊôÓÚWi-Fi 802.11³ß¶ÈÖ¡¾ÛºÏºÍÖ¡·ÖƬְÄÜÖеÄÉè¼ÆÈ±µã £¬¶øÆäËû·ì϶ÊÇWi-Fi²úÆ·Öеıà³ÌÃýÎ󡣡£¡£


ºÚ¿ÍÖ»ÓÐÔÚÖ¸±êÉ豸µÄWi-FiÁìÓòÄÚ £¬¾ÍÄÜÀûÓÃFragAttacks·ì϶ÇÔÈ¡Ãô¸ÐÓû§Êý¾Ý²¢Ö´ÐжñÒâ´úÂë £¬ÉõÖÁÄܹ»ÊÕÊÜÕû¸öÉ豸¡£¡£¡£


OG¶«·½ÌüADLabµÚÒ»¹¦·ò¶Ô·ì϶½øÐÐÁË·ÖÎö £¬²¢Ìá³öÁËÏàÓ¦µÄ»º½â½¨Òé¡£¡£¡£ÓÉÓÚWiFi²úÆ·µÄºÍ̸ջ £¬Ô̺¬ÁËSoft Mac¼°Full Mac¶àÖÖʵÏֹ滮¡£¡£¡£FragAttacksϵÁзì϶²»½ö´æÔÚÓ°Ïì²Ù×÷ϵͳÄںˡ¢¡¢¡¢WiFiÇý¶¯ £¬»¹Ó°ÏìWiFiµÄSOCоƬ £¬ËùÒÔ·ì϶µÄÓ°Ïì³Ö¾Ã´æÔÚ¡£¡£¡£Çëʵʱ¹Ø×¢²¢¸üÐÂÉ豸¹©¸øÉ̵ݲȫ¸üС£¡£¡£


ÐÞ¸´¼°»º½â½¨Òé


¡ñ ʵʱ¸üÐÂÉ豸¹©¸øḚ́䲼µÄFragAttacks·ì϶°²È«¸üС£¡£¡£

¡ñ È·±£Äú½Ó¼ûµÄËùÓÐÍøÕ¾ºÍÔÚÏß·þÎñ¶¼ÆôÓÃÁ˰²È«³¬Îı¾´«ÊäºÍ̸HTTPS(ºÃ±È×°ÖÃHTTPS Everywhere²å¼þ)¡£¡£¡£

¡ñ ÀýÈçÔÚWi-Fi 6£¨802.11ax£©É豸ÖнûÓÃ·ÖÆ¬ £¬½ûÓóɶÔÖØÐÂÌìÉúÃÜÔ¿ÒÔ¼°½ûÓö¯Ì¬·ÖƬ¡£¡£¡£


·ì϶ÁÐ±í¼°¾ßÌåÓ°Ïì


Wi-FiÉè¼ÆÈ±µãÓйصķì϶Ô̺¬£º


CVE񅧏
·ì϶½éÉÜ
·ì϶ӰÏì
CVE-2020-24588
Õë¶ÔA-MSDU¾ÛºÏµÄ×¢Èë¹¥»÷£¨ÎÞЧµÄSPP A-MSDU±£»£»¤»úÖÆ£©

¹¥»÷Õ߿ɲåÈë¶ñÒâÖ¡ £¬´Û¸ÄÊý¾Ý°ü

CVE-2020-24587
»ìºÏÃÜÔ¿¹¥»÷£¨ÖØ×éʱʹÓÃ·ÖÆçÃÜÔ¿¼ÓÃܵķ֯¬ÃÜÈ¡Óû§µÄÃô¸ÐÊý¾Ý
CVE-2020-24586
·ÖƬ»º´æ¹¥»÷£¨ÖØÐÂÏνӵ½ÍøÂçʱ²»¶Ï¸ù·ÖƬ»º´æ£©ÇÔÈ¡Óû§Ãô¸ÐÊý¾Ý»ò´Û¸ÄËÁÒâÊý¾Ý°ü


Wi-FiʵÏÖÓйصķì϶Ô̺¬£º


CVE±àºÅ·ì϶½éÉÜ·ì϶ӰÏì
CVE-2020-26145

ÔÚ¼ÓÃÜͨѶÖÐ £¬ÈÔ½ÓÊÜδ¼ÓÃܹ㲥·ÖƬ×÷ΪÆëȫ֡

¶ÀÁ¢ÓÚÍøÂçÅäÖà £¬²åÈëËÁÒâÖ¡ £¬´Ó¶ø´Û¸ÄÊý¾Ý°ü


CVE-2020-26144

ÔÚ¼ÓÃÜͨѶÖÐ £¬ÈÔ½ÓÊÜδ¼ÓÃܵÄA-MSDUÖ¡

CVE-2020-26140

ÔÚÊܱ£»£»¤µÄÍøÂçÖнÓÊÜδ¼ÓÃÜÊý¾ÝÖ¡

CVE-2020-26143

ÔÚÊܱ£»£»¤µÄÍøÂçÖнÓÊÜ·ÖÆ¬µÄδ¼ÓÃÜÊý¾ÝÖ¡

CVE-2020-26139

ת·¢EAPOL֡ʱδÑéÖ¤·¢ËͶ˵ÄÉí·Ý

ºÍCVE-2020-24588½áºÏÆðÀ´ £¬²åÈëÈι¥»÷Õ߿ɲåÈë¶ñÒâÖ¡ £¬´Û¸ÄÊý¾Ý°ü

CVE-2020-26146

¶ÔÓÚ·ÇÂ½ÐøÊý¾Ý°ü±àºÅµÄ¼ÓÃÜ·ÖÆ¬ÒÀÈ»½øÐÐÖØÐÂ×éºÏ

ÇÔÈ¡Óû§Ãô¸ÐÊý¾Ý

CVE-2020-26147


¶Ô·ÖƬ½øÐÐÖØÐÂ×éӦʱ²»·Ö±æ¼ÓÃÜ»òδ¼ÓÃÜ

¹¥»÷Õ߿ɲåÈë¶ñÒâÖ¡ £¬´Û¸ÄÊý¾Ý°ü


CVE-2020-26142

½«·ÖƬ֡×÷ΪÆëȫ֡½øÐд¦ÖÃ


CVE-2020-26141

²»ÑéÖ¤·ÖƬ֡µÄTKIP MIC


ͨ¹ýÕâһϵÁзì϶ £¬¹¥»÷Õ߯ëÈ«Äܹ»»ñµÃÓû§µÄÃô¸ÐÐÅÏ¢»òÖ±½Ó½ÚÖÆÖÇÄÜÉ豸 £¬Èç½ÚÖÆÖÇÄܵçÔ´²å×ù £¬ÉõÖÁÖ±½Ó¹ÜÊÜÍøÂçÖдæÔÚ·ì϶µÄÍÆËã»ú £¬°Ý¼ûÏÂÎIJο¼×ÊÁÏ[2]¡£¡£¡£


·ì϶·ÖÎö


ÎÒÃǰÎÈ¡ÁËÔÚËùÓÐÉ豸ÆÕ±é´æÔÚµÄCVE-2020-24586¡¢¡¢¡¢CVE-2020-24587¡¢¡¢¡¢CVE-2020-24588Èý¸öÉè¼Æ·ì϶½øÐзÖÎö¡£¡£¡£ÓÉÓÚCVE-2020-24588µÄ·ì϶ӰÏì½Ï´ó £¬ÎÒÃÇ×ÅÖØ½øÐнéÉÜCVE-2020-24588¡£¡£¡£ 


1¡¢¡¢¡¢¼¼Êõ²¼¾°

ÓÉÓÚ802.11MAC²ãºÍ̸ºÄ·ÑÁËÏ൱¶à¿ªÏúÓÃ×÷Á´Â·µÄÊØ»¤ £¬ÎªÁËÌá¸ßMAC²ãµÄЧÄÜ £¬802.11nÒýÈëÖ¡¾ÛºÏ¼¼Êõ £¬±¨ÎÄÖ¡¾ÛºÏ¼¼ÊõÔ̺¬£ºA-MSDU(MAC·þÎñÊý¾Ýµ¥Ôª¾ÛºÏ) ¼° A-MPDU(MACºÍ̸Êý¾Ýµ¥Ôª¾ÛºÏ)¡£¡£¡£


A-MSDUÔÊÐí¶ÔÖ÷Õŵؼ°ÀûÓö¼Ò»ÑùµÄ¶à¸öA-MSDU×ÓÖ¡½øÐÐ¾ÛºÏ £¬¾ÛºÏºóµÄ¶à¸ö×ÓÖ¡Ö»ÓÐÒ»¸ö¹²Í¬µÄMACÖ¡Í· £¬µ±¶à¸ö×ÓÖ¡¾ÛºÏµ½Ò»Â·ºó £¬´Ó¶øÏ÷¼õÁË·¢ËÍÿһ¸ö802.11±¨ÎÄËùÐèµÄPLCP Preamble¡¢¡¢¡¢PLCP HeaderºÍ802.11MACÍ·µÄ¿ªÏú £¬Í¬Ê±Ï÷¼õÁËÓ¦´ðÖ¡µÄÊýÁ¿ £¬´Ó¶øÌá¸ßÎÞÏß´«ÊäЧÄÜ¡£¡£¡£A-MSDU±¨ÎÄÖ¡¾ÛºÏ¼¼ÊõÊÇ802.11nºÍ̸µÄÇ¿ÖÆÒªÇó £¬ËùÓÐÖ§³Ö802.11nºÍ̸µÄÉ豸¶¼±ØÐëÖ§³Ö¡£¡£¡£


ÏÂͼʾÒâÁËÔÚ802.11ºÍ̸ջÖÐ £¬·¢ËͶ˺ͽӹܶËÊÇÈôºÎ´¦ÖÃA-MSDUÊý¾ÝµÄ¡£¡£¡£


1.png

ͼ1. 802.11ºÍ̸Êý¾Ý´¦ÖÃÁ÷³Ì 


ÔÚ802.11ºÍ̸ջÖÐ £¬·¢ËͶ˽«À´×Ô3-7²ãµÄÍøÂçÊý¾Ý¾­¹ýÊý¾ÝÁ´Â·²ãµÄLLC×Ó²ãÔö³¤LLC/SNAPÍ·ºó·â×°³ÉMSDU(MAC·þÎñÊý¾Ýµ¥Ôª£© £¬MSDU¾­¹ýÔö³¤DA¡¢¡¢¡¢SA¡¢¡¢¡¢³¤¶È¼°padingºó £¬·â×°³ÉA-MSDU×ÓÖ¡ £¬ÔÚMAC×Ó²ãµÄ¶¥²ã½«¶à¸öA-MSDU×ÓÖ¡·â×°³ÉA-MSDU £¬¾­MAC×Ó²ãºó £¬Ö¡Êý¾Ý±»Ôö³¤ÉÏMACÍ·¼°Ö¡Î²·â×°³É802.11Êý¾ÝÖ¡£¡£¡£¨MPDU£© £¬MPDU/PSDU¾­¹ýÎïÀí²ãÔö³¤PLCP Preamble£¨PLCPǰµ¼Â룩¼°PLCP Header£¨PHYÍ·£© £¬ÎÞÏß²à×îºóͨ¹ýÉ䯵¿Ú½«¶þ½øÖÆÁ÷·¢Ë͵½½Ó¹Ü¶Ë¡£¡£¡£


½Ó¹Ü¶Ëͨ¹ýÏà·´õè¾¶¶Ô802.11Êý¾ÝÖ¡½øÐвð½â £¬×îºó»ñµÃ·¢ËͶ˵Ä3-7²ãµÄÍøÂçÊý¾Ý¡£¡£¡£


A-MSDUµÄºÍ̸Êý¾Ý×é³ÉÈçͼ2Ëùʾ £¬ÎÒÃÇ´ÓÉϵ½Ï½øÐбðÀë×¢Ã÷£º

£¨1£©Ò»¸öMSDUÓÉLCC/SNAPÍ·¡¢¡¢¡¢IPÍ·¡¢¡¢¡¢TCP/UDPÍ·¼°ºÍ̸Êý¾ÝData×é³É¡£¡£¡£

£¨2£©MSDUÔö³¤DA(Ö÷ÕŵØÖ·) £¬SA(Ô´µØÖ·) £¬ºóÐøÊý¾Ý³¤¶È¼°Padding(ËÄ×Ö½Ú¶ÔÆë)×é³ÉÒ»¸öMSDU×ÓÖ¡¡£¡£¡£

£¨3£©¶à¸öMSDU×ÓÖ¡×é³ÉÒ»¸ö802.11Ö¡µÄA-MSDUÓò¡£¡£¡£

£¨4£©802.11Êý¾Ý֡ͨ¹ýQOS ControlµÄA-MSDU PresentλÀ´°µÊ¾ÕâÊÇÒ»¸öÔ̺¬A-MSDUÓòµÄÊý¾ÝÖ¡¡£¡£¡£


2.png

 Í¼2. A-MSDUÊý¾Ý×é³ÉʾÒâ


ÔÚ802.11ºÍ̸ÖÐ £¬Ò»¸öͨ³£µÄ802.11Êý¾ÝÖ¡ÓëA-MSDUÊý¾ÝÖ¡µÄ½á¹¹ÊÇÒ»ÑùµÄ £¬Ö»ÊÇQOS ControlÓòµÄA-MSDU Presetλ Ϊ1 £¬Ôò±êʾÁ˸ÃÊý¾ÝÖ¡ÊÇÒ»¸öA-MSDUÊý¾ÝÖ¡¡£¡£¡£A-MSDU PresetλΪ0 £¬Ôò±êʾÕâÊÇͨ³£802.11Êý¾ÝÖ¡¡£¡£¡£


ÔÚ802.11ºÍ̸ÖÐWEP¼°CCMPÖ»±£»£»¤802.11MACµÄÓÐÐ§ÔØºÉ £¬ÖÁÓÚ802.11Ö¡Í·ÒÔ¼°»ù²ãºÍ̸µÄ±êÍ·ÔòÔ­·â²»¶¯ £¬Ò²¾ÍÊÇ˵802.11ºÍ̸ÖÐÊý¾ÝÖ¡ÖÐQOS Control²¢Ã»ÓмÓÃÜ £¬ÕâΪ¹¥»÷ÕßÌṩÁ˹¥»÷Èë¿Ú¡£¡£¡£


3.png

ͼ3. CCMP¼ÓÃܵÄ802.11Êý¾ÝÖ¡Ìåʽ


ΪԤ·ÀÖÐÑëÈ˹¥»÷ £¬IEEEÔÚ2011ÄêÉè¼ÆÁËSPPA-MSDU»úÖÆÀ´±£»£»¤A-MSDU Presetλ¼°A-MSDUµÄPayload¡£¡£¡£SPP A-MSDUͨ¹ýÔÚRSN capabilities ÓòÖÐÔö³¤SPP A-MSDU Capable¼°SPP A-MSDU RequiredÀ´±êʾÊÇ·ñÖ§³ÖSPP A-MSDU»úÖÆ¼°ÊÇ·ñѡȡSPP A-MSDU»úÖÆ¡£¡£¡£


4.png

ͼ4. RSN Capabilities ÓòÊý¾ÝÌåʽ


2¡¢¡¢¡¢Õë¶ÔA-MSDU¾ÛºÏµÄÖ¡×¢Èë¹¥»÷(CVE-2020-24588)


¹ÌÈ»ÓÐSPP A-MSDU»úÖÆÀ´±£»£»¤A-MSDU Presetλ²»±»´Û¸Ä £¬µ«ÊÇÔÚÏÖʵµÄ²âÊÔÖÐ £¬ÏÕЩËùÓеÄÉ豸¶¼²»×ñÑ­SPP A-MSDU»úÖÆ £¬ÕâʹµÃÖÐÑëÈ˹¥»÷³ÉΪ¿ÉÄÜ¡£¡£¡£


ÎÒÃÇÈç¹û·¢ËͶ˷¢ËÍÁËÒ»¸öÕý³£µÄ802.11Êý¾ÝÖ¡ £¬ÕâÊÇÒ»¸öÀïÃæ·â×°µÄÊÇÒ»¸öͨ³£TCP°ü £¬Æädst=¡°192.168.1.2", src="1.2.3.4", id=34


5.png

ͼ5. ԭʼµÄ802.11Êý¾ÝÖ¡


ÓÉÓÚÆ«ÒÆ0x18µÄQOS Control(0200£©²»Êܱ£»£»¤ £¬¹¥»÷ÕßÄܹ»½« QOS ControlÓòÖеÄA-MSDU Preset·­×ªÎª1 £¬Ê¹µÃQOS ControlµÄֵΪ8200 £¬Í¬Ê±ÔÚ֡ĩβעÈë¶ñÒâµÄA-MSDU×ÓÖ¡2£¨ÈçÏÂͼµÄºìÉ«Ïß±êʾ£© £¬×îºó·¢Ë͸ø½Ó¹Ü¶Ë¡£¡£¡£


6.png

 Í¼6. ´Û¸ÄºóµÄ802.11A-MSDUÊý¾ÝÖ¡


ÓÉÓÚQOS ControlÓòÖеÄA-MSDU Preset·­×ªÎª1 £¬µ±½Ó¹Ü¶Ë½Ó¹Üµ½Êý¾ÝÖ¡ºó £¬»á°´A-MSDUÌåʽÀ´²ð½âÀïÃæµÄÊý¾Ý¡£¡£¡£Êý¾Ý±»¼ø±ð³ÉÁ½¸öA-MSDU×ÓÖ¡¡£¡£¡£A-MSDU×ÓÖ¡1ÖеÄÊý¾ÝÊÇԭʼµÄMSDUÊý¾Ý £¬ËùÒԻᱻºÍ̸ջÅׯú £¬µ«µÚ¶þ¸ö×ÓÖ¡»á±»ÕýÈ·½âÎö²¢´¦Öᣡ£¡£ÕâÉÏÃæµÄÀý×ÓÖеڶþ¸ö×ÓÖ¡»á±»¼ø±ð³ÉICMP ping°ü £¬½Ó¹Ü¶Ë»á»Ø¸´Ò»¸öICMP echo Reply¸ø·¢ËͶˡ£¡£¡£


ÊÓÆµ1. ·¢ËͶËÊÕµ½ICMP echo Reply


ÏÂͼʾÒâÁËÖÐÑëÈËÖ¡×¢ÈëÁ÷³Ì£º


7.png

 Í¼7. ÖÐÑëÈËÖ¡×¢ÈëÁ÷³Ì 


£¨1£©STA£¨ÖÕ¶Ë£©ºÍAP£¨Èȵã/ÎÞÏß·ÓÉÆ÷£©ÐŵÀA£¨ÈçÐŵÀ6£©, ³ÉÁ¢¹ØÁª

£¨2£©MITMÀûÓöàÐŵÀÖÐÑëÈ˼¼ÊõʹµÃSTAÒÔΪAPÒѾ­Çл»µ½ÐŵÀB£¨ÈçÐŵÀ11£©¡£¡£¡£

£¨3£©STAÔÚÐŵÀ11¸ø MITM·¢ËͼÓÃܵÄWifiÕý³£Êý¾ÝÖ¡¡£¡£¡£

£¨4£©MITM½« ½Ó¹Üµ½µÄWifiÖ¡QOSÓòµÄA-MSDU Preset±êʾÉèΪ1 £¬Í¬Ê±²åÈë´Û¸ÄµÄA-MSDUÊý¾Ý¡£¡£¡£°ÑÒ»¸öÕý³£µÄWifiÖ¡¸Ä³ÉÒ»¸öA-MSDUÖ¡ £¬²¢×¢ÈëÒ»¸öICMPÒªÇó°ü £¬²¢ÔÚͨµÀ6·¢¸øAP¡£¡£¡£

£¨5£©AP½Ó¹Üµ½A-MSDUÊý¾ÝÖ¡ £¬AP²ð½âA-MSDU £¬·Ö³É¶à¸öA-MSDU×ÓÖ¡ £¬ÆäÖеÚÒ»¸öA-MSDU×Ó֡Ϊ·¸·¨°ü £¬»á±»Åׯú £¬µ«ºóÐøµÄMSDU×ÓÖ¡»á±»ÏµÍ³Õý³£´¦Öᣡ£¡£AP»á»Ø¸´ÊÕµ½Ò»¸öICMP Echo Ó¦´ð¸øMITM¡£¡£¡£

£¨6£©MITMÊÕµ½APµÄ»Ø¸´ºó £¬½«½Ó¹Üµ½µÄWIFI֡ת·¢¸øSTA £¬ÕâÑùSTAÊÕµ½AP»Ø¸´µÄICMPÓ¦´ð¡£¡£¡£


CVE-2020-24588µÄÐÞ¸´


½ñÄê3ÔÂWindows°ä²¼ÁËÏàÓ¦µÄ²¹¶¡ £¬ÐÞ¸´ÁËFragAttacksϵÁзì϶ £¬5ÔÂ11ÈÕLinuxÒ²°ä²¼ÁËFragAttacksϵÁзì϶²¹¶¡[6] £¬LinuxÕë¶ÔCVE-2020-24588µÄÐÞ¸´ÈçÏ£º


---

 net/wireless/util.c | 3 +++

 1 file changed, 3 insertions(+)

 

diff --git a/net/wireless/util.c b/net/wireless/util.c

index 39966a873e40..7ec021a610ae 100644

--- a/net/wireless/util.c

+++ b/net/wireless/util.c

@@ -771,6 +771,9 @@ void ieee80211_amsdu_to_8023s(struct sk_buff *skb, struct sk_buff_head *list,

 remaining = skb->len - offset;

 if (subframe_len > remaining)

 goto purge;

+/* mitigate A-MSDU aggregation injection attacks */

+if (ether_addr_equal(eth.h_dest, rfc1042_header))

+goto purge;

 

 offset += sizeof(struct ethhdr);

 last = remaining <= subframe_len + padding;

--


ÓÉÓÚÔÚA-MSDU¾ÛºÏ×¢Èë¹¥»÷ÖÐ £¬±ØÒª½«Í¨³£¼ÓÃÜWi-Fi֡ת»»ÎªA-MSDUÖ¡¡£¡£¡£ÕâÒâζ×ŵÚÒ»¸öA-MSDU×ÓÖ¡µÄǰ6×Ö½Ú¶ÔÓ¦ÓÚRFC1042µÄÖ¡Í· £¬liunxÄÚºËͨ¹ýÔö³¤ÅжÏDA£¨Ö¸±êµØÖ·£©ÊÇ·ñºÍrfc1042_header(\xaa\xaa\x03\x00\x00\x00)Ò»Ö £¬ÈôÊÇÏà³ÆÔòÒÔΪÊǶñÒâ¹¥»÷ £¬Äܹ»°ÑÕâ¸öA-MSDUÖ¡Åׯú¡£¡£¡£


»ìºÏÃÜÔ¿¹¥»÷(CVE-2020-24587)


8.png

ͼ8.»ìºÏÃÜÔ¿¹¥»÷Á÷³Ì


ÔÚ²½Öè1°ø±ß £¬¹¥»÷ÕßÓÕµ¼Êܺ¦Õß½Ó¼ûÊܹ¥»÷Õß½ÚÖÆµÄ·þÎñÆ÷ £¬Í¨¹ýһЩ¼¿Á© £¬ºÃ±ÈÖ¸¶¨Ò»¸ö³¬³¤µÄURL £¬´Ó¶øÊ¹Êܺ¦Õß·¢Ë͵ÄÊý¾Ý°ü²»µÃ²»·Ö³ÉÁ½¶Î½øÐд«Êä £¬·ÖƬµÄÊý¾Ý°üÓÃÃØÔ¿k¼ÓÃÜ £¬ÕâÁ½¸öÊý¾Ý°üΪºÍ¡£¡£¡£¶ø¹¥»÷Õßͨ¹ý¶àÐŵÀµÄÖÐÑëÈ˽øÐÐÀ¹½Ø £¬Ò»µ©¼à²âµ½¹¥»÷ÕßÖ¸¶¨IPÊý¾Ý°ü £¬±ã½«´ËÊý¾Ý°üת·¢¸øAP £¬¼´APÒ»µ©ÊÕµ½´ËÊý¾Ý°üºó £¬¾Í½«Æä½âÃܺó´æÔÚÄÚ´æ°ø±ß¡£¡£¡£ 


ÔÚ²½Öè2½øÐÐ֮ǰ £¬Êܺ¦Õß±ØÒªÓëAPÖØÐ½øÐÐËÄ´ÎÎÕÊÖ²¢Ð­ÉÌеÄÃÜÔ¿¡£¡£¡£Ö®ºó¹¥»÷ÕßÆÚ´ýÊܺ¦Õß·¢ËÍÔ̺¬Ãô¸ÐÐÅÏ¢µÄÊý¾Ý°ü £¬¼´ºÍ¡£¡£¡£¹¥»÷Õß½«Êý¾Ý°üºÅÂëΪn+1µÄÊý¾Ý°üÀ¹½Ø £¬²¢½«ÆäÐòÁкÅÅú¸ÄΪs £¬¶øºóת·¢¸øAP £¬¼´Êý¾Ý°ü¡£¡£¡£¶øAPÖ±½Ó°ÑËûµ±×÷ÐòÁкÅsÊý¾Ý°üµÄµÚ¶þ¸ö·ÖƬÐÅÏ¢ £¬½«Ëû½âÃܺóÖØ×é³ÉеÄÊý¾Ý°ü £¬¶øÐµÄÊý¾Ý°üÖÐÔ̺¬Êܺ¦ÕßµÄÃô¸ÐÐÅÏ¢Óë¹¥»÷ÕßÖ¸¶¨µÄIP¡£¡£¡£Òò¶øÃô¸ÐÐÅÏ¢¾Í±»·¢Ë͵½Êܺ¦Õß½ÚÖÆµÄ·þÎñÆ÷ÉÏ £¬Ôì³ÉÐÅϢй¶¡£¡£¡£


·ÖƬ»º´æÍ¶¶¾¹¥»÷(CVE-2020-24586)


9.png

ͼ9.·ÖƬ»º´æÍ¶¶¾¹¥»÷Á÷³Ì


ÔÚ²½Öè1ÖÐ £¬¹¥»÷ÕßÐá̽µ½Êܺ¦ÕßµÄMACµØÖ·ºó £¬Î±ÔìÊܺ¦ÕßMACµØÖ·È¥ÏνÓAP¡£¡£¡£ÕâÑù¾ÍÄܹ»ºÏ·¨µÄÓÃÊܺ¦ÕßµÄÉí·ÝÔÚAPµÄÄÚ´æÖвåÈë·ÖƬ¡£¡£¡£


ÔÚ²½Öè2ÖÐ £¬Êܺ¦Õß½øÐÐÕý³£µÄÈÏÖ¤¹¤×÷ £¬´Ëʱ¹¥»÷Õß·¢ËÍÊý¾Ý°ü £¬Õâ¸öÊý¾Ý°üÖÐÔ̺¬¹¥»÷ÕßÖ¸¶¨µÄIPÊý¾Ý°ü¡£¡£¡£¶øºóAP½âÃÜ´ËÊý¾Ý°ü £¬²¢±£ÁôÔÚÄÚ´æÖÐ £¬ÒÔÊܺ¦ÕßµÄMACµØÖ·×÷Ϊ±êʶ¡£¡£¡£¶øºó¹¥»÷Õßͨ¹ý·¢Ëͽâ³ýÈÏÖ¤µÄÊý¾Ý°ü²¢¶Ï¿ªÏÎ½Ó £¬ËæºóÔÚÊܺ¦ÕߺÍAPÖ®¼ä³ÉÁ¢Ò»¸ö¶àÐŵÀµÄÖÐÑëÈË¡£¡£¡£°ÑÎÈ´ËʱAPÄÚ´æÖÐµÄ·ÖÆ¬²¢Ã»Óб»¶Ï¸ù¡£¡£¡£


Ö®ºóÊܺ¦ÕßÓëAPÖ®¼ä½øÐÐÕý³£µÄÏνӡ£¡£¡£´Ëʱ¹¥»÷ÕßÖ»±ØÒªÆÚ´ýÊܺ¦Õß·¢Ë͵ڶþ¸ö·ÖƬ £¬Êý¾Ý°üºÅÂëΪn+1 £¬¹¥»÷Õß½«´ËÊý¾Ý°üÀ¹½Øºó £¬²¢½«´ËÊý¾Ý°üµÄÐòÁкÅÅú¸ÄΪs £¬¶øºóÆäת·¢¸øAP £¬¼´Êý¾Ý°ü £¬Ò»µ©APÊÕµ½´ËÊý¾Ý°ü £¬ºÍ»ìºÏÃÜÔ¿·ì϶ÀàËÆ £¬AP»á½«´ËÊý¾Ý°ü½âÃÜ £¬²¢ºÍ֮ǰ±£ÁôÔÚ»º´æÖеÄÊý¾Ý°üÖØ×é³ÉеÄÊý¾Ý°ü £¬ÓÉÓÚÕâÁ½¸öÊý¾Ý°üÔ̺¬Ò»ÑùµÄMACµØÖ·ºÍÐòÁкš£¡£¡£×îºó £¬AP½«ÖØ×éºóµÄÊý¾Ý°ü·¢Ë͸ø¹¥»÷Õß½ÚÖÆµÄ·þÎñÆ÷ £¬´Ó¶øÔì³ÉÃô¸ÐÐÅϢй¶¡£¡£¡£


²Î¿¼Á´½Ó£º

¡¾1¡¿https://papers.mathyvanhoef.com/usenix2021.pdf

¡¾2¡¿https://www.youtube.com/embed/88YZ4061tYw

¡¾3¡¿https://www.fragattacks.com/#notpatched

¡¾4¡¿https://github.com/vanhoefm/fragattacks

¡¾5¡¿https://lore.kernel.org/linux-wireless/20210511180259.159598-1-johannes@sipsolutions.net/


OG¶«·½Ìü»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©


ADLab³ÉÁ¢ÓÚ1999Äê £¬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò» £¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ± £¬¡°ºÚȸ¹¥»÷¡±¸ÅÄîÊ×ÍÆÕß¡£¡£¡£½ØÖ¹Ä¿Ç° £¬ADLabÒÑͨ¹ýCVEÀۼư䲼°²È«·ì϶½ü1100¸ö £¬Í¨¹ý CNVD/CNNVDÀۼư䲼°²È«·ì϶1000Óà¸ö £¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£¡£¡£³¢ÊÔÊÒ×êÑз½Ïòº­¸Ç²Ù×÷ϵͳÓëÀûÓÃϵͳ°²È«×êÑС¢¡¢¡¢ÖÇÄÜÖն˰²È«×êÑС¢¡¢¡¢ÎïÁªÍøÖÇÄÜÉ豸°²È«×êÑС¢¡¢¡¢Web°²È«×êÑС¢¡¢¡¢¹¤¿ØÏµÍ³°²È«×êÑС¢¡¢¡¢Ôư²È«×êÑС£¡£¡£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑС¢¡¢¡¢¹ú¶ÈÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢¡¢¡¢×¨Òµ°²È«·þÎñµÈ¡£¡£¡£


adlab.jpg