Wi-FiÁ÷Á¿ÐÅϢй©·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-02-28

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-15126  £¬Î£ÏÕ¼¶±ð£ºÖÐΣ  £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


³§ÉÌ

É豸/оƬ/·ÓÉÆ÷Ãû³Æ

broadcom

bcm4356

broadcom

bcm4389

broadcom

bcm4375

broadcom

bcm43012

broadcom

bcm43013

broadcom

bcm43752

Amazon

Echo 2nd gen

Amazon

Kindle 8th gen

Apple

iPad mini 2 (ipad_os < 13.2)

Apple

iPhone 6, 6S, 8, XR (iphone_os < 13.2)

Apple

MacBook Air Retina 13-inch 2018 (mac_os < 10.15.1)

Google

Nexus 5

Google

Nexus 6

Google

Nexus 6S

Raspberry

Pi 3

Samsung

Galaxy S4 GT-I9505

Samsung

Galaxy S8

Xiaomi

Redmi 3S

Asus

RT-N12

Huawei

B612S-25d

Huawei

EchoLife HG8245H

Huawei

E5577Cs-321



·ì϶¸ÅÊö


ÍøÂ簲ȫ×êÑÐÔ±´ÓʹÓÃ¿í·ºµÄ²©Í¨ (Broadcom) ºÍ Cypress WiFi оƬÖз¢ÏÖÁËÒ»¸öÓ²¼þ·ì϶  £¬Ó°ÏìÊýÊ®ÒŲ́É豸  £¬ÈçÖÇÄÜÊÖ»ú¡¢Æ½°åµçÄÔ¡¢±Ê¼Ç±¾µçÄÔ¡¢Â·ÓÉÆ÷ºÍÎïÁªÍøÉ豸¡£


¸Ã·ì϶±»³ÆÎª ¡°Kr00k¡±  £¬±àºÅΪ CVE-2019-15126  £¬Ëü¿Éµ¼ÖÂÔ¶³Ì¹¥»÷ÕßÀ¹½Ø²¢½âÃÜÒ×Êܹ¥»÷É豸ͨ¹ýÎÞÏß´«ÊäµÄijЩÎÞÏßÍøÂçÊý¾Ý°ü¡£¸Ã·ì϶²úÉúµÄÔ­ÒòÔÚÓÚ²©Í¨ºÍ Cypress оƬʹÓÃÁËÒ»¸öÈ«Áã¼ÓÃÜÃÜÔ¿  £¬´Ó¶øµ¼ÖÂÊý¾Ý±»½âÃÜ  £¬·ÛËéÁË WPA2-Personal ºÍ WPA2-Enterprise °²È«ºÍ̸¡£¹¥»÷ÕßÎÞÐèÏνӵ½Êܺ¦ÕßµÄÎÞÏßÍøÂç¼´¿É·¢Æð¹¥»÷¡£Ê¹Óà WPA2-Personal »ò WPA2-Enterprise ºÍ̸¡¢Í¨¹ý AES-CCMP ¼ÓÃܱ£»¤ÍøÂçÁ÷Á¿µÄÉ豸Ò×Êܹ¥»÷¡£


·ì϶ÏêÇé


ÔÚÏêÊö Kr00k ¹¥»÷֮ǰ  £¬ÎÒÃDZØÒªÏàʶÈçϼ¸µã£º


1. ¸Ã·ì϶²¢²»´æÔÚÓÚÎÞÏß¼ÓÃܺÍ̸ÖÐ  £¬¶øÊÇÒòÒ×Êܹ¥»÷оƬʵÏָüÓÃܺÍ̸µÄ·½Ê½²»µ±µ¼ÖµÄ£»

2. ¹¥»÷ÕßÎÞ·¨Í¨¹ý¸Ã·ì϶ÏνÓÓû§ WiFiÍøÂç²¢½øÒ»²½·¢ÆðÖÐÑëÈ˹¥»÷»òÕß¹¥»÷ÆäËüÁªÍøÉ豸£»

3. ¹¥»÷ÕßÎÞ·¨ÀûÓø÷ì϶»ñϤÓû§µÄ WiFi ÃÜÂë  £¬Åú¸Ä WiFi ÃÜÂëÎÞÖúÓÚÎÊÌ⽨¸´£»

4. ËüÎÞ·¨Ó°ÏìʹÓÃ×îРWiFi °²È«³ß¶È WPA3 ºÍ̸µÄÏÖ´úÉ豸£»

5. È»¶ø  £¬Ëü¿Éµ¼Ö¹¥»÷Õßץȡ²¢½âÃÜijЩÎÞÏßÊý¾Ý°ü£¨Êýǧ×Ö½Ú£©  £¬µ«ÎÞ·¨Ô¤²âËü½«Ô̺¬ÄÄЩÊý¾Ý£»

6. ×î³ÁÒªµÄÊÇ  £¬¸ÃȱµãÍ»ÆÆÁËÎÞÏß²ãÉϵļÓÃÜ»úÔì  £¬µ«ºÍ TLS ¼ÓÃܺÍ̸ÎÞ¹Ø  £¬Òò¶øºóÕßÒÀÈ»Äܹ»±£»¤ HTTPS Õ¾µãÍøÂçÁ÷Á¿µÄ°²È«¡£


ÔÚ WiFi ÖÐ  £¬É豸Ïνӵ½½Ó¼ûµã (AP) ±»³ÆÎª¡°¹ØÁª¡±  £¬¶Ï¿ªÏνӣ¨ÈçÓÐÈË´ÓÒ»¸ö WiFi AP ÖÜÓε½Áí±íÒ»¸ö AP  £¬¾­ÀúÁËÐźÅ×ÌÈÅ»ò¹Ø¹ØÉ豸 WiFi£©±»³ÆÎª¡°È¡µÞ¹ØÁª¡±¡£


ͼ1ÌṩÁËоƬÃýÎóµÄʾÒâͼ¡£×êÑÐÈËÔ±Ö¸³ö  £¬¡°Kr00k ·ì϶ÔÚÈ¡µÞ¹ØÁªÊ±³öÏÖ¡£Ò»µ©²úÉúÈ¡µÞ¹ØÁªµÄÇé¿ö¢Ù  £¬ÄÚ´æ¾Í»á¶Ï¸ù´æ´¢ÔÚÎÞÏßÍøÂç½Ó¿Ú½ÚÔìÆ÷ (WNIC) WiFi оƬÖеĻỰÃÜÔ¿  £¬¼´ÉèÖÃΪ0¢Ú¡£ÕâÖÖÐÐΪÇкÏÔ¤ÆÚ  £¬ÓÉÓÚÈ¡µÞ¹ØÁªºóÊý¾ÝÓ¦¸Ã²»ÔÙ´«Ê䡣Ȼ¶ø  £¬ÎÒÃÇ·¢ÏÖ  £¬¼´±ãÔÚͨ¹ýÕâ¸öËùÓÐΪ0µÄÃÜÔ¿¼ÓÃܺó¢Û  £¬ÒÅÁôÔÚ¸ÃоƬ´«Ê仺³åÇøÖеÄÊý¾ÝÖ¡ÒÀÈ»»á±»´«Êä¢Ü¡£¡±ÓÉÓÚËüÓÃÁËËùÓеÄ0  £¬Òò¶øÕâÖÖ¡°¼ÓÃÜ¡±ÏÖʵÉϻᵼÖÂÊý¾Ý±»½âÃÜÇÒÒÔÃ÷ÎÄ´ó¾ÖÔâ¶³ö¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹¥»÷õè¾¶ºÜµ¥Ò»£ºÖÎÀí¿ò¼ÜÖÎÀí¹ØÁªºÍÈ¡µÞ¹ØÁª²Ù×÷  £¬µ«ÖÎÀí¿ò¼Ü×ÔÉíÊÇδÈÏÖ¤ºÍδ¼ÓÃܵÄ¡£¹¥»÷ÕßÖ»Óз¢ËÍÒ»¸öÌØÊâ»ú¹ØµÄÖÎÀíÊý¾Ý¿ò¼Ü¾Í¿É´¥·¢È¡µÞ¹ØÁª´Ó¶ø·¢Æð¹¥»÷  £¬Ö®ºó¾Í¿ÉÄܼìË÷ÒÅÁôÔÚ»º³åÇøÖеÄÃ÷ÎÄÐÅÏ¢¡£¼ûͼ2¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Òò¶ø  £¬µÐÊÖÄܹ»²¶»ñ¸ü¶àÔ̺¬Ç±ÔÚÃô¸ÐÊý¾ÝµÄÍøÂç°ü  £¬Ô̺¬DNS¡¢ARP¡¢ICMP¡¢HTTP¡¢TCPºÍTLSÊý¾Ý°ü  £¬¼ûͼ3.


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±°µÊ¾  £¬Kr00k ¹¥»÷Ò»´Î¿É¶³ö×î¶à32KB Êý¾Ý  £¬Ï൱ÓÚÔ¼2Íò¸ö´ÊÓï¡£¹¥»÷Õ߿ɷ¢ËÍһϵÁÐÖÎÀí¿ò¼Ü´¥·¢¹¥»÷²¢ÆðÍ·ÍøÂçÊý¾Ý  £¬ÈçÃÜÂë¡¢ÐÅÓþ¿¨ÐÅÏ¢»òÆäËüÓû§Í¨¹ýWiFi·¢Ë͵½»¥ÁªÍøÉϵÄÈÎºÎÆ÷²Ä¡£


½¨¸´½¨Òé


1.ÇëÖ±½ÓÓëоƬÔì×÷ÉÌÁªÏµÒÔ»ñÈ¡ÓйØKR00K·ì϶µÄ²¹¶¡£»

2.¶ÔÊÜÓ°ÏìµÄÉ豸½øÐÐÉý¼¶¡£

Òò¸Ã·ì϶ֻÊÇÕë¶Ô WI-FI Á÷Á¿½øÐнâÃÜ¡£½¨ÒéÓû§¾¡Á¿Ê¹Óà HTTPS/TLS ½øÐÐÍøÂçͨѶ¡£¸Ã·½Ê½Äܹ»¿Ï¶¨Ë®Æ½µØ¼õ»º·ì϶´øÀ´µÄÓ°Ïì¡£


²Î¿¼Á´½Ó


https://thehackernews.com/2020/02/kr00k-wifi-encryption-flaw.html

https://www.welivesecurity.com/wp-content/uploads/2020/02/ESET_Kr00k.pdf