Wi-FiÁ÷Á¿ÐÅÏ¢×ß©Îó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-02-28Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-15126£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
|
³§ÉÌ |
×°±¸/оƬ/·ÓÉÆ÷Ãû³Æ |
|
broadcom |
bcm4356 |
|
broadcom |
bcm4389 |
|
broadcom |
bcm4375 |
|
broadcom |
bcm43012 |
|
broadcom |
bcm43013 |
|
broadcom |
bcm43752 |
|
Amazon |
Echo 2nd gen |
|
Amazon |
Kindle 8th gen |
|
Apple |
iPad mini 2 (ipad_os < 13.2) |
|
Apple |
iPhone 6, 6S, 8, XR (iphone_os < 13.2) |
|
Apple |
MacBook Air Retina 13-inch 2018 (mac_os < 10.15.1) |
|
|
Nexus 5 |
|
|
Nexus 6 |
|
|
Nexus 6S |
|
Raspberry |
Pi 3 |
|
Samsung |
Galaxy S4 GT-I9505 |
|
Samsung |
Galaxy S8 |
|
Xiaomi |
Redmi 3S |
|
Asus |
RT-N12 |
|
Huawei |
B612S-25d |
|
Huawei |
EchoLife HG8245H |
|
Huawei |
E5577Cs-321 |
Îó²î¸ÅÊö
ÍøÂçÇå¾²Ñо¿Ô±´ÓʹÓÃÆÕ±éµÄ²©Í¨ (Broadcom) ºÍ Cypress WiFi оƬÖз¢Ã÷ÁËÒ»¸öÓ²¼þÎó²î£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÊýÊ®ÒŲ́װ±¸£¬£¬£¬£¬£¬£¬£¬ÈçÖÇÄÜÊÖ»ú¡¢Æ½°åµçÄÔ¡¢Ìõ¼Ç±¾µçÄÔ¡¢Â·ÓÉÆ÷ºÍÎïÁªÍø×°±¸¡£¡£¡£¡£¡£¡£
¸ÃÎó²î±»³ÆÎª ¡°Kr00k¡±£¬£¬£¬£¬£¬£¬£¬±àºÅΪ CVE-2019-15126£¬£¬£¬£¬£¬£¬£¬Ëü¿Éµ¼ÖÂÔ¶³Ì¹¥»÷Õß×èµ²²¢½âÃÜÒ×Êܹ¥»÷×°±¸Í¨¹ýÎÞÏß´«ÊäµÄijЩÎÞÏßÍøÂçÊý¾Ý°ü¡£¡£¡£¡£¡£¡£¸ÃÎó²î±¬·¢µÄÔµ¹ÊÔÓÉÔÚÓÚ²©Í¨ºÍ Cypress оƬʹÓÃÁËÒ»¸öÈ«Áã¼ÓÃÜÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÊý¾Ý±»½âÃÜ£¬£¬£¬£¬£¬£¬£¬ÆÆËðÁË WPA2-Personal ºÍ WPA2-Enterprise Çå¾²ÐÒé¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÎÞÐèÅþÁ¬µ½Êܺ¦ÕßµÄÎÞÏßÍøÂç¼´¿É·¢¶¯¹¥»÷¡£¡£¡£¡£¡£¡£Ê¹Óà WPA2-Personal »ò WPA2-Enterprise ÐÒ顢ͨ¹ý AES-CCMP ¼ÓÃܱ£»£»£»£»£»¤ÍøÂçÁ÷Á¿µÄ×°±¸Ò×Êܹ¥»÷¡£¡£¡£¡£¡£¡£
Îó²îÏêÇé
ÔÚÏêÊö Kr00k ¹¥»÷֮ǰ£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇÐèÒªÏàʶÈçϼ¸µã£º
1. ¸ÃÎó²î²¢²»±£´æÓÚÎÞÏß¼ÓÃÜÐÒéÖУ¬£¬£¬£¬£¬£¬£¬¶øÊÇÒòÒ×Êܹ¥»÷оƬʵÏָüÓÃÜÐÒéµÄ·½·¨²»µ±µ¼Öµģ»£»£»£»£»
2. ¹¥»÷ÕßÎÞ·¨Í¨¹ý¸ÃÎó²îÅþÁ¬Óû§ WiFiÍøÂç²¢½øÒ»²½·¢¶¯ÖÐÐÄÈ˹¥»÷»òÕß¹¥»÷ÆäËüÁªÍø×°±¸£»£»£»£»£»
3. ¹¥»÷ÕßÎÞ·¨Ê¹ÓøÃÎó²î»ñϤÓû§µÄ WiFi ÃÜÂ룬£¬£¬£¬£¬£¬£¬ÐÞ¸Ä WiFi ÃÜÂëÎÞÖúÓÚÎÊÌâÐÞ¸´£»£»£»£»£»
4. ËüÎÞ·¨Ó°ÏìʹÓÃ×îРWiFi Çå¾²±ê×¼ WPA3 ÐÒéµÄÏÖ´ú×°±¸£»£»£»£»£»
5. È»¶ø£¬£¬£¬£¬£¬£¬£¬Ëü¿Éµ¼Ö¹¥»÷Õßץȡ²¢½âÃÜijЩÎÞÏßÊý¾Ý°ü£¨Êýǧ×Ö½Ú£©£¬£¬£¬£¬£¬£¬£¬µ«ÎÞ·¨Õ¹ÍûËü½«°üÀ¨ÄÄЩÊý¾Ý£»£»£»£»£»
6. ×îÖ÷ÒªµÄÊÇ£¬£¬£¬£¬£¬£¬£¬¸ÃȱÏÝÍ»ÆÆÁËÎÞÏß²ãÉϵļÓÃÜ»úÖÆ£¬£¬£¬£¬£¬£¬£¬µ«ºÍ TLS ¼ÓÃÜÐÒéÎ޹أ¬£¬£¬£¬£¬£¬£¬ÒòÒÔºóÕßÈÔÈ»¿ÉÒÔ±£»£»£»£»£»¤ HTTPS Õ¾µãÍøÂçÁ÷Á¿µÄÇå¾²¡£¡£¡£¡£¡£¡£
ÔÚ WiFi ÖУ¬£¬£¬£¬£¬£¬£¬×°±¸ÅþÁ¬µ½»á¼ûµã (AP) ±»³ÆÎª¡°¹ØÁª¡±£¬£¬£¬£¬£¬£¬£¬¶Ï¿ªÅþÁ¬£¨ÈôÓÐÈË´ÓÒ»¸ö WiFi AP ÖÜÓε½ÁíÍâÒ»¸ö AP£¬£¬£¬£¬£¬£¬£¬ÂÄÀúÁËÐźÅ×ÌÈÅ»ò¹Ø±Õ×°±¸ WiFi£©±»³ÆÎª¡°×÷·Ï¹ØÁª¡±¡£¡£¡£¡£¡£¡£
ͼ1ÌṩÁËоƬ¹ýʧµÄʾÒâͼ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Ö¸³ö£¬£¬£¬£¬£¬£¬£¬¡°Kr00k Îó²îÔÚ×÷·Ï¹ØÁªÊ±·ºÆð¡£¡£¡£¡£¡£¡£Ò»µ©±¬·¢×÷·Ï¹ØÁªµÄÇéÐ΢٣¬£¬£¬£¬£¬£¬£¬ÄÚ´æ¾Í»áɨ³ý´æ´¢ÔÚÎÞÏßÍøÂç½Ó¿Ú¿ØÖÆÆ÷ (WNIC) WiFi оƬÖеĻỰÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬¼´ÉèÖÃΪ0¢Ú¡£¡£¡£¡£¡£¡£ÕâÖÖÐÐΪÇкÏÔ¤ÆÚ£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ×÷·Ï¹ØÁªºóÊý¾ÝÓ¦¸Ã²»ÔÙ´«Êä¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ·¢Ã÷£¬£¬£¬£¬£¬£¬£¬×ÝÈ»ÔÚͨ¹ýÕâ¸öËùÓÐΪ0µÄÃÜÔ¿¼ÓÃܺó¢Û£¬£¬£¬£¬£¬£¬£¬ÒÅÁôÔÚ¸ÃоƬ´«Ê仺³åÇøÖеÄÊý¾ÝÖ¡ÈÔÈ»»á±»´«Êä¢Ü¡£¡£¡£¡£¡£¡£¡±ÓÉÓÚËüÓÃÁËËùÓеÄ0£¬£¬£¬£¬£¬£¬£¬Òò´ËÕâÖÖ¡°¼ÓÃÜ¡±ÏÖʵÉϻᵼÖÂÊý¾Ý±»½âÃÜÇÒÒÔÃ÷ÎÄÐÎʽÔâ̻¶¡£¡£¡£¡£¡£¡£
¹¥»÷·¾¶ºÜ¼òÆÓ£ºÖÎÀí¿ò¼ÜÖÎÀí¹ØÁªºÍ×÷·Ï¹ØÁª²Ù×÷£¬£¬£¬£¬£¬£¬£¬µ«ÖÎÀí¿ò¼Ü×Ô¼ºÊÇδÈÏÖ¤ºÍδ¼ÓÃܵġ£¡£¡£¡£¡£¡£¹¥»÷ÕßÖ»Òª·¢ËÍÒ»¸öÌØÊâ½á¹¹µÄÖÎÀíÊý¾Ý¿ò¼Ü¾Í¿É´¥±¬·¢·Ï¹ØÁª´Ó¶ø·¢¶¯¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ö®ºó¾ÍÄܹ»¼ìË÷ÒÅÁôÔÚ»º³åÇøÖеÄÃ÷ÎÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¼ûͼ2¡£¡£¡£¡£¡£¡£
Òò´Ë£¬£¬£¬£¬£¬£¬£¬µÐÊÖ¿ÉÒÔ²¶»ñ¸ü¶à°üÀ¨Ç±ÔÚÃô¸ÐÊý¾ÝµÄÍøÂç°ü£¬£¬£¬£¬£¬£¬£¬°üÀ¨DNS¡¢ARP¡¢ICMP¡¢HTTP¡¢TCPºÍTLSÊý¾Ý°ü£¬£¬£¬£¬£¬£¬£¬¼ûͼ3.
Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬Kr00k ¹¥»÷Ò»´Î¿É̻¶×î¶à32KB Êý¾Ý£¬£¬£¬£¬£¬£¬£¬Ï൱ÓÚÔ¼2Íò¸ö´ÊÓï¡£¡£¡£¡£¡£¡£¹¥»÷Õ߿ɷ¢ËÍһϵÁÐÖÎÀí¿ò¼Ü´¥·¢¹¥»÷²¢×îÏÈÍøÂçÊý¾Ý£¬£¬£¬£¬£¬£¬£¬ÈçÃÜÂë¡¢ÐÅÓÿ¨ÐÅÏ¢»òÆäËüÓû§Í¨¹ýWiFi·¢Ë͵½»¥ÁªÍøÉϵÄÈκι¤¾ß¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
1.ÇëÖ±½ÓÓëÐ¾Æ¬ÖÆÔìÉÌÁªÏµÒÔ»ñÈ¡ÓйØKR00KÎó²îµÄ²¹¶¡£¡£¡£¡£¡£¡£»£»£»£»£»
2.¶ÔÊÜÓ°ÏìµÄ×°±¸¾ÙÐÐÉý¼¶¡£¡£¡£¡£¡£¡£
Òò¸ÃÎó²îÖ»ÊÇÕë¶Ô WI-FI Á÷Á¿¾ÙÐнâÃÜ¡£¡£¡£¡£¡£¡£½¨ÒéÓû§Ö»¹ÜʹÓà HTTPS/TLS ¾ÙÐÐÍøÂçͨѶ¡£¡£¡£¡£¡£¡£¸Ã·½·¨¿ÉÒÔÒ»¶¨Ë®Æ½µØ¼õ»ºÎó²î´øÀ´µÄÓ°Ïì¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://thehackernews.com/2020/02/kr00k-wifi-encryption-flaw.html
https://www.welivesecurity.com/wp-content/uploads/2020/02/ESET_Kr00k.pdf


¾©¹«Íø°²±¸11010802024551ºÅ