TsuNAM·ì϶£º¿ÉDDoS DNS·þÎñÆ÷
°ä²¼¹¦·ò 2021-05-080x00 ·ì϶¸ÅÊö
CVE ID | ʱ ¼ä | 2021-05-08 | |
Àà ÐÍ | DDoS | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | ·ñ |
0x01 ·ì϶ÏêÇé

2021Äê05ÔÂ06ÈÕ£¬SIDN Labs£¨.nl×¢²á£©¡¢InternetNZ£¨.nz×¢²á£© ºÍÄϼÓÖÝ´óѧÐÅÏ¢¿ÆÑ§×êÑÐËùµÄ×êÑÐÈËÔ±¹«¿ªÅû¶ÁËÔÚDNS½âÎöÆ÷Öз¢ÏÖµÄÒ»¸ö¿Éµ¼ÖÂÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷µÄ·ì϶£¬¸Ã·ì϶±»³ÆÎªTsuNAME¡£
ÏÖ½ñ»¥ÁªÍøÉÏ´óÎÞÊýʹÓõÄDNS·þÎñÆ÷¶¼Êǵݹé·þÎñÆ÷£¬ËüÃǽÓÊÜÓû§µÄDNS²éÎʲ¢½«Æäת·¢µ½È¨ÍþDNS·þÎñÆ÷£¬ÕâÖÖ¹¤×÷·½Ê½¾ÍÏñµç»°²¾Ò»Ñù£¬Äܹ»·µ»ØÌض¨ÓòÃûµÄDNSÏìÓ¦¡£
ÔÚÕý³£Çé¿öÏ£¬ÊýÒÔ°ÙÍò¼ÆµÄµÝ¹éDNS·þÎñÆ÷ÿÌì»áÏòȨÍþÐÔDNS·þÎñÆ÷·¢ËÍÊýÊ®ÒÚ´ÎDNS²éÎÊ¡£ÕâЩȨÍþÐÔDNS·þÎñÆ÷ͨ³£ÓÉ´óÐ͹«Ë¾ºÍ×éÖ¯ÍйܺÍÖÎÀí£¨ÄÚÈݽ»¸¶ÍøÂç¡¢´óÐͿƼ¼¾ÞÍ·¡¢»¥ÁªÍø·þÎñÌṩÉÌ¡¢ÓòÃû×¢²áÉÌ»òµ±¾Ö×éÖ¯£©£¬ºÃ±ÈGoogleºÍCisco¡£
×êÑÐÈËÔ±°µÊ¾£¬¹¥»÷ÕßÄܹ»Ôì×÷¶ñÒâµÄDNS²éÎÊ£¬ÀûÓõݹéDNSÈí¼þµÄ·ì϶£¬ÏòÆäȨÍþDNS·þÎñÆ÷Ò»ÏòµØ·¢ËͶñÒâDNS²éÎÊ£¬µ«ÕâÖÖ¹¥»÷ÒÀÀµÓÚÊÜÓ°ÏìµÄµÝ¹éDNSÈí¼þºÍȨÍþDNS·þÎñÆ÷ÉϵÄÃýÎóÅäÖá£ÈôÊǹ¥»÷ÖÐ×¢²áÁË×ã¹»¶àµÄµÝ¹éDNS·þÎñÆ÷£¬Ôò¹¥»÷ÕßÄܹ»ÌáÒéÖØ´óµÄDDoS¹¥»÷£¬´Ó¶ø·ÛË鹨¼üµÄInternet½Úµã¡£
×êÑÐÈËÔ±»¹·¢ÏÖ£¬Ä³Ð©DNS½âÎöÆ÷ÔÚÓöµ½±»ÃýÎóÅäÖÃΪѻ·ÒÀÀµNS¼Í¼µÄÓòÃûʱÆðÍ·Ñ»·£¬¶øÕâÖÖÑ»·Äܹ»ÓÃÀ´¹¥»÷ȨÍþ·þÎñÆ÷¡£

×êÑÐÈËÔ±Ôڻ㱨ÖÐÃèÊöÁË2020ÄêÔÚ.nz authroritative·þÎñÆ÷ÉϹ۲쵽µÄÒ»¸öÓëtsuNAMEÓйصÄÊÂÎñ£¬ÆäʱÓÐÁ½¸öÓòÃû±»ÃýÎóµØÅäÖÃΪѻ·ÒÀÀµ¹ØÏµ£¬Ëüµ¼ÖÂ×ÜÁ÷Á¿Ôö³¤ÁË50%¡£Ôڻ㱨ÖУ¬×êÑÐÈËԹعʾÁËÒ»¸ö»ùÓÚÅ·Ã˵Ĺú¶È´úÂë¶¥¼¶ÓòÃûÈôºÎÒòÑ»·ÒÀÀµµÄÃýÎóÅäÖöøµ¼ÖÂÁ÷Á¿Ôö³¤ÁË10±¶¡£
×êÑÐÈËÔ±»¹°ä²¼ÁËÒ»ÖÖ³ÆÎªCycleHunterµÄ¹¤¾ß £¬È¨ÍþDNS·þÎñÆ÷µÄÔËÓªÉÌÄܹ»Ê¹Óøù¤¾ßÔÚÆäDNSÇøÓòÎļþÖвéÕÒ²¢½â³ýÑ»·ÒÀÀµÐÔ¡£½â³ýÕâЩѻ·ÒÀÀµÐÔ¿ÉÔÚδÀûÓò¹¶¡µÄÇé¿öÏÂÔ¤·À¹¥»÷ÕßÀûÓÃtsuNAME½øÐÐDDoS¹¥»÷¡£
´Ë±í£¬×êÑÐÈËԱʹÓÃCycleHunterÔÚÆß¸ö¶¥¼¶Óò£¨TLD£©ÖÐÆÀ¹ÀÁËÔ¼1.84ÒÚ¸öÓòÃû£¬²¢·¢ÏÖÁËÔ¼1400¸öÓòÃûʹÓõÄ44¸öÑ»·ÒÀÀµµÄNS¼Í¼£¨¿ÉÄÜÊÇÅäÖÃÃýÎ󣩣¬ÕâЩ¼Í¼¿ÉÄܻᱻÀÄÓÃÓÚÖ®ºóµÄ¹¥»÷¡£
Ó°ÏìÁìÓò
Google Public DNS£¨GDNS£©
Cisco OpenDNS
ÆäËüDNS½âÎöÆ÷
£¨×¢£ºUnbound¡¢BINDºÍKnotDNS²»ÊÜtsuNAMEÓ°Ï죩
0x02 ´ëÖý¨Òé
ĿǰGoogleºÍCiscoÒѾ½¨¸´ÁË´Ë·ì϶£¬½¨ÒéÓйØDNSÔËÓªÉ̾¡¿ìʹÓÃCycleHunter¹¤¾ß¼ì²â²¢½â³ýDNSÇøÓòÖеÄÑ»·ÒÀÀµ¹ØÏµ»òʵʱ½¨¸´¸Ã·ì϶¡£
ÏÂÔØÁ´½Ó£º
https://github.com/SIDN/CycleHunter
0x03 ²Î¿¼Á´½Ó
https://therecord.media/new-tsuname-bug-can-be-used-to-ddos-key-dns-servers/?
https://tsuname.io/
https://tsuname.io/tech_report.pdf
https://tsuname.io/advisory.pdf
0x04 ¹¦·òÏß
2021-05-06 ×êÑÐÈËÔ±¹«¿ªÅû¶·ì϶
2021-05-08 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ