Wi-Fi WPA2 ¡°Kr00k¡±·ì϶·ÖÎöÓ븴ÏÖ
°ä²¼¹¦·ò 2020-03-261.×êÑв¼¾°
ÔÚ½ñÄê2Ô·ݵÄRSA´ó»áÉÏ£¬ESETµÄ×êÑÐÈËÔ±¹«¿ªÅû¶Wi-FiоƬ´æÔÚÑϳÁ°²È«·ì϶CVE-2019-15126£¬²¢½«Æä¶¨ÃûΪ¡°Kr00k¡±¡£¹¥»÷ÕßÄܹ»ÀûÓá°Kr00k¡±½âÃÜÎÞÏßÍøÂçÁ÷Á¿£¬»ñÈ¡´«Êä¹ý³ÌÖеÄÃô¸ÐÊý¾Ý¡£
Kr00k·ì϶ӰÏ첿ÃÅ×°ÖÃBroadcomºÍCypress Wi-FiоƬµÄÉ豸£¬ÕâÁ½¼ÒоƬ²úÆ·±»¿í·ºÀûÓÃÓÚÊÖ»ú¡¢Æ½°åµçÄÔ¼°IOTÉ豸ÖС£ÊؾɹÀ¼Æ£¬È«Çò×ܼƳ¬¹ý10ÒÚµÄÉ豸Êܸ÷ì϶µÄÓ°Ïì¡£
2.·ì϶·ÖÎö
2.1 ·ì϶µÀÀí
ÔÚ½éÉÜKr00k·ì϶֮ǰ£¬Ïȵ¥Ò»ÏàʶÏÂWPA2ºÍ̸¡£Ä¿Ç°»ùÓÚAES-CCMPµÄWPA2ºÍ̸ÊÇWi-FiÍøÂçÖÐ×îÆÕ±éµÄ³ß¶È¡£ÏÂͼÊǿͻ§¶Ë£¨Station, STA£©ÏνӽÓÈëµã£¨Access Point, AP£©µÄÐÂÎŽ»»¥¹ý³Ì¡£
STAºÍAPÔÚËÄ´ÎÎÕÊÖÖУ¬ÐÉ̻ỰÃÜÔ¿PTK£¨Pairwise Transient Key£©£¬PTKÊÇÓÉPMKºÍPKEÍÆËãÌìÉú£¬¶øPMKÓÉANonce¡¢SNonceºÍË«·½MACµØÖ·µÈÍÆËãÌìÉú¡£PTK·ÖΪKCK¡¢KEKºÍTKÈý²¿ÃÅ£¬ÆäÖУ¬KCKÓÃÓÚMICУÑ飬KEKÓÃÓÚ¼ÓÃÜGTK£¬TKΪÊý¾Ý¼ÓÃÜÃÜÔ¿¡£ËÄ´ÎÎÕÊÖʵÏֺ󣬴«ÊäÊý¾ÝʹÓÃTK½øÐмÓÃÜ¡£
ÔÚWPA2ºÍ̸ÖУ¬½â³ý¹ØÁª²Ù×÷Äܹ»ÓÉδ¾Éí·ÝÑéÖ¤ºÍδ¼ÓÃܵÄÖÎÀíÖ¡´¥·¢£¬Kr00k·ì϶Óë½â³ý¹ØÁª²Ù×÷Ç×êÇÓйء£±ÉÈËͼËùʾÖУ¬µ¹Ø¾µãµÄÏνӻỰ½â³ý¹ØÁªºó£¬±£ÁôÔÚWi-FiоƬÖеĻỰÃÜÔ¿(TK)±»ÖÃÁ㣬ÈôÊÇʹÓÃÒÑÖÃÁãµÄTKÃÜÔ¿¶ÔоƬ»º´æÖеÄÊý¾Ý½øÐмÓÃܲ¢´«Ê䣬½«µ¼Ö·ì϶²úÉú¡£
¹¥»÷ÕßÀûÓÃÎÞÏßÍø¿¨¼´¿ÉʵÏÖÈëÇÖ£¬Í¨¹ý²»ÐÝ´¥·¢½â³ý¹ØÁª¡¢³ÁйØÁª£¬¶øºóʹÓÃÈ«ÁãTK¶Ô²¶»ñµÄÊý¾ÝÖ¡½øÐнâÃÜ£¬´Ó¶ø»ñÈ¡Ãô¸ÐÐÅÏ¢¡£
2.2 ¹Ì¼þ·ÖÎö
±¾ÎİÎÈ¡Nexus5ÖеÄBCM4339оƬ¹Ì¼þ½øÐзÖÎö¡£Ê×ÏÈ£¬¶¨Î»¹Ì¼þÖÐÍÆËãptkµÄµØÎ»£¬ÈçÏÂͼËùʾ¡£
¶øºó£¬¶ÔÆäÉϲ㺯Êýwlc_wpa_sup_eapol½øÐзÖÎö¡£
wlc_wpa_sup_eapolŲÓÃwpa_pmk_to_ptkʱ£¬´«ÈëµÄ²ÎÊý±ðÀëΪmac1¡¢mac2¡¢Nonce1¡¢Nonce2¡¢pmk¡¢pmk_len¡¢ptk¡¢ptk_len¡£ptkÍÆËãÁ˾ֱ»±£ÁôÔÚwpa_ptk½á¹¹ÌåÆ«ÒÆ0x8cµØÎ»ÖС£
wlc_sup_attachº¯ÊýÓÃÓÚ´¦ÖÃSTAµÄ³õʼ»¯Ïνӣ¬¸Ãº¯Êý¶Ôwpa_ptk½á¹¹Ìå½øÐÐÄÚ´æ·ÖÅäºÍ³õʼ»¯£¬wpa_ptk½á¹¹Ìå´óÓ×Ϊ0x13C¡£
µ±³õʼ»¯Ê§°Ü¡¢Ïνӳ¬Ê±»ò½â³ýÏνӵÄʱ³½£¬Ôò»áŲÓÃwlc_sup_detachº¯Êý¶Ôwpa_ptk½á¹¹Ìå½øÐÐÖÃÁã²Ù×÷¡£
3.·ì϶ÑéÖ¤
3.1 ²âÊÔ»·¾³
|
|
É豸Ãû³Æ |
ÊýÁ¿ |
|
ÊÜÓ°ÏìµÄÉ豸 |
Nexus5 |
1 |
|
iphone6sÊÖ»ú |
1 |
|
|
Attacker |
NETGEARÍø¿¨ |
2 |
3.2 ²âÊÔ²½Öè
£¨1£©¶Ôwireshark½âÃÜÊý¾Ý°üµÄÓйØÖ°ÄܽøÐÐpatch£¬Ê¹Æä¿ÉÄܳɹ¦½âÃÜÈ«ÁãTK¼ÓÃܵÄÊý¾Ý¡£
£¨2£©Ê¹ÓÃpatchºóµÄwireshark¼àÌýÖ¸±êÉ豸ºÍAPͨѶµÄÊý¾Ý°ü¡£
£¨3£©Ê¹ÓÃÖ¸±êÉ豸ÏνÓAP²¢ËÁÒâ½Ó¼ûÍøÒ³¡£
£¨4£©¶ÔAPºÍ²âÊÔÖ¸±ê·¢ËÍDisassocation°ü¡£
£¨5£©³Á¸´Ö´Ðв½Ö裨3£©ºÍ£¨4£©£¬¹Û²ìwiresharkÖÐÊý¾Ý°üÊÇ·ñ½âÃÜ¡£
3.3 ²âÊÔÁ˾Ö
Nexus 5£º
iphone 6s£º
Äܹ»¿´³ö£¬Nexus 5ºÍiphone 6s²¿ÃÅÊý¾Ý±»³É¹¦½âÃÜ¡£
4.Ó°ÏìÁìÓò
ĿǰÒÑÖªÊÜÓ°ÏìµÄÉ豸ÓУº
Amazon Echo 2nd gen
Amazon Kindle 8th gen
Apple iPad mini 2
Apple iPhone 6, 6S, 8, XR
Apple MacBook Air Retina 13-inch 2018
Google Nexus 5
Google Nexus 6
Google Nexus 6P
Raspberry Pi 3
Samsung Galaxy S4 GT-I9505
Samsung Galaxy S8
Xiaomi Redmi 3S
Asus RT-N12
Huawei B612S-25d
Huawei EchoLife HG8245H
Huawei E5577Cs-321
5.°²È«½¨Òé
É豸Ôì×÷ÉÌÒѰ䲼µÄ°²È«½¨ÒéÈçÏ£º
?https://support.apple.com/en-us/HT210721
?https://support.apple.com/en-us/HT210722
?https://support.apple.com/en-us/HT210788
?https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-003.txt
?https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200226-wi-fi-info-disclosure
?https://www.huawei.com/en/psirt/security-notices/huawei-sn-20200228-01-kr00k-en
?https://www.microchip.com/design-centers/wireless-connectivity/embedded-wi-fi/kr00k-vulnerability
?https://www.mist.com/documentation/mist-security-advisory-kr00k-attack-faq/
?https://www.zebra.com/us/en/support-downloads/lifeguard-security/kr00k-vulnerability.html


¾©¹«Íø°²±¸11010802024551ºÅ