TCP/IP Èí¼þ¿âRipple20Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-06-180x00 Îó²î¸ÅÊö
ÒÔÉ«ÁÐÍøÂçÇå¾²¹«Ë¾JSOFµÄÑо¿Ö°Ô±ÔÚTreck£¬£¬£¬£¬£¬£¬£¬£¬Inc.¿ª·¢µÄTCP/IPÈí¼þ¿âÖз¢Ã÷ÁË19¸ö0dayÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÕâһϵÁÐÎó²îͳ³ÆÎª¡°Ripple20¡±¡£¡£¡£¡£È«ÇòÊýÒŲ́£¨ÉõÖÁ¸ü¶à£©IoT×°±¸¿ÉÄÜ»áÊܵ½Ô¶³Ì¹¥»÷¡£¡£¡£¡£
0x01 Îó²îÏêÇé
Ripple20Ó°ÏìÁËÀ´×ÔÆÕ±éÁìÓòµÄÒªº¦ÎïÁªÍø×°±¸£¬£¬£¬£¬£¬£¬£¬£¬Éæ¼°ÁËÖڶ๩ӦÉÌ¡£¡£¡£¡£ÊÜÓ°ÏìµÄ¹©Ó¦É̹æÄ£ºÜ¹ã£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨HP¡¢Schneider Electric¡¢Intel¡¢Rockwell Automation¡¢Caterpillar¡¢BaxterÒÔ¼°Ðí¶àÆäËûÔÚÒ½ÁÆ¡¢ÔËÊä¡¢¹¤Òµ¿ØÖÆ·½ÃæµÄÖ÷Òª¹ú¼Ê¹©Ó¦ÉÌ¡¢ÆóÒµ¡¢ÄÜÔ´£¨Ê¯ÓÍ/×ÔÈ»Æø£©¡¢µçÐÅ¡¢ÁãÊÛºÍÉÌÒµÒÔ¼°ÆäËûÐÐÒµ¡£¡£¡£¡£
19¸öÎó²î¶¼ÊÇÄÚ´æËð»µÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬Ô´ÓÚʹÓòî±ðÐÒ飨°üÀ¨IPv4£¬£¬£¬£¬£¬£¬£¬£¬ICMPv4£¬£¬£¬£¬£¬£¬£¬£¬IPv6£¬£¬£¬£¬£¬£¬£¬£¬IPv6OverIPv4£¬£¬£¬£¬£¬£¬£¬£¬TCP£¬£¬£¬£¬£¬£¬£¬£¬UDP£¬£¬£¬£¬£¬£¬£¬£¬ARP£¬£¬£¬£¬£¬£¬£¬£¬DHCP£¬£¬£¬£¬£¬£¬£¬£¬DNS»òÒÔÌ«ÍøÁ´Â·²ã£©ÔÚÍøÂçÉÏ·¢Ë͵ÄÊý¾Ý°üµÄ´¦Öóͷ£¹ýʧ¡£¡£¡£¡£
ÆäÖаüÀ¨ËĸöÑÏÖØÎó²î£ºÓÐÁ½¸öÎó²îCVSSÆÀ·Ö10·Ö£¬£¬£¬£¬£¬£¬£¬£¬CVE-2020-11896¿ÉÄܵ¼ÖÂÔ¶³ÌÖ´ÐдúÂ룬£¬£¬£¬£¬£¬£¬£¬CVE-2020-11897¿ÉÄܵ¼ÖÂÔ½½çдÈë¡£¡£¡£¡£ÆäËûÁ½¸öÎó²îµÄCVSSÆÀ·Ö»®·ÖΪ9ºÍ9.1£¬£¬£¬£¬£¬£¬£¬£¬CVE-2020-11901¿ÉÄܵ¼ÖÂÔ¶³ÌÖ´ÐдúÂ룬£¬£¬£¬£¬£¬£¬£¬CVE-2020-11898¿ÉÄܵ¼ÖÂй¶Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£
¶øÆäËû15¸öÎó²îµÄÑÏÖØË®Æ½²î±ð£¬£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö´Ó3.1µ½8.2£¬£¬£¬£¬£¬£¬£¬£¬ÏêϸÐÅÏ¢ÈçÏ£º
|
CVE ID |
Îó²îÐÎò |
ÐÞ¸´°æ±¾ |
|
CVE-2020-11896 |
ÔÚ´¦Öóͷ£ÓÉδ¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬£¬£¬¶ÔIPv4 / UDP×é¼þÖеij¤¶È²ÎÊý·×ÆçÖµĴ¦Öóͷ£²»µ±¡£¡£¡£¡£¸ÃÎó²î¿ÉÄܵ¼ÖÂÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£ |
6.0.1.66 (release 30/03/2020) |
|
CVE-2020-11897 |
ÔÚ´¦Öóͷ£Î´¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬£¬£¬¶ÔIPv6×é¼þÖеij¤¶È²ÎÊý·×ÆçÖµĴ¦Öóͷ£²»µ±¡£¡£¡£¡£¸ÃÎó²î¿ÉÄܵ¼ÖÂÔ½½çдÈë¡£¡£¡£¡£ |
5.0.1.35 (release 04/06/2009) |
|
CVE-2020-11901 |
´¦Öóͷ£Î´¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬£¬£¬DNSÆÊÎöÆ÷×é¼þÖеÄÊäÈëÑéÖ¤²»×¼È·¡£¡£¡£¡£¸ÃÎó²î¿ÉÄܵ¼ÖÂÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/2020) |
|
CVE-2020-11898 |
´¦Öóͷ£Î´¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬£¬£¬¶ÔIPv4 / ICMPv4×é¼þÖеij¤¶È²ÎÊý·×ÆçÖµĴ¦Öóͷ£²»µ±¡£¡£¡£¡£¸ÃÎó²î¿ÉÄܵ¼ÖÂÃô¸ÐÐÅϢ̻¶¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/2020) |
|
CVE-2020-11900 |
´¦Öóͷ£ÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬£¬£¬IPv4ËíµÀ×é¼þÖпÉÄܱ£´æË«ÖØÊÍ·Å¡£¡£¡£¡£¸ÃÎó²î¿ÉÄܵ¼ÖÂUse After Free¡£¡£¡£¡£ |
6.0.1.41 (release 10/15/2014) |
|
CVE-2020-11902 |
´¦Öóͷ£Î´¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬£¬£¬IPv6OverIPv4ËíµÀ×é¼þÖеÄÊäÈëÑéÖ¤²»×¼È·¡£¡£¡£¡£¸ÃÎó²î¿ÉÄܵ¼ÖÂÔ½½ç¶ÁÈ¡¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/20) |
|
CVE-2020-11904 |
´¦Öóͷ£Î´¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬£¬£¬ÄÚ´æ·ÖÅÉ×é¼þÖпÉÄܱ£´æÕûÊýÒç³ö¡£¡£¡£¡£¸ÃÎó²î¿ÉÄܵ¼ÖÂÔ½½çдÈë¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/2020) |
|
CVE-2020-11899 |
´¦Öóͷ£Î´¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬£¬£¬IPv6×é¼þÖеÄÊäÈëÑéÖ¤²»×¼È·¡£¡£¡£¡£¸ÃÎó²î¿ÉÄܵ¼ÖÂÔ½½ç¶ÁÈ¡»ò¾Ü¾øÐ§ÀÍ¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/20) |
|
CVE-2020-11903 |
´¦Öóͷ£Î´¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬£¬£¬DHCP×é¼þÖб£´æÔ½½ç¶ÁÈ¡ÎÊÌâ¡£¡£¡£¡£¸ÃÎó²î¿ÉÄܵ¼ÖÂÃô¸ÐÐÅϢй¶¡£¡£¡£¡£ |
6.0.1.28 (release 10/10/12) |
|
CVE-2020-11905 |
´¦Öóͷ£Î´¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬£¬£¬DHCPv6×é¼þÖб£´æÔ½½ç¶ÁÈ¡ÎÊÌâ¡£¡£¡£¡£¸ÃÎó²î¿ÉÄܵ¼ÖÂÃô¸ÐÐÅϢй¶¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/20) |
|
CVE-2020-11906 |
ÔÚ´¦Öóͷ£Î´¾ÊÚȨÓû§·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÌ«ÍøÁ´Â·²ã×é¼þÖÐÊäÈëÑéÖ¤²»×¼È·¡£¡£¡£¡£¸ÃÎó²î¿ÉÄܵ¼ÖÂÕûÊýÒç³ö¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/20) |
|
CVE-2020-11907 |
´¦Öóͷ£Î´¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬£¬£¬TCP×é¼þÖжԲÎÊý³¤¶È·×ÆçÖµĴ¦Öóͷ£²»µ±¡£¡£¡£¡£¸ÃÎó²î¿ÉÄܵ¼ÖÂÕûÊýÒç³ö¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/20) |
|
CVE-2020-11909 |
´¦Öóͷ£Î´¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬£¬£¬IPv4×é¼þÖеÄÊäÈëÑéÖ¤²»×¼È·¡£¡£¡£¡£¸ÃÎó²î¿ÉÄܵ¼ÖÂÕûÊýÒç³ö¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/20) |
|
CVE-2020-11910 |
´¦Öóͷ£Î´¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬£¬£¬ICMPv4×é¼þÖеÄÊäÈëÑéÖ¤²»×¼È·¡£¡£¡£¡£¸ÃÎó²î¿ÉÄܵ¼ÖÂÔ½½ç¶ÁÈ¡¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/20) |
|
CVE-2020-11911 |
´¦Öóͷ£Î´¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬£¬£¬ICMPv4×é¼þÖеĻá¼û¿ØÖƲ»×¼È·¡£¡£¡£¡£¸ÃÎó²î¿ÉÄܵ¼ÖÂÒªº¦×ÊÔ´µÄȨÏÞ·ÖÅɹýʧ¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/20) |
|
CVE-2020-11912 |
´¦Öóͷ£Î´¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬£¬£¬TCP×é¼þÖеÄÊäÈëÑéÖ¤²»×¼È·¡£¡£¡£¡£¸ÃÎó²î¿ÉÄܵ¼ÖÂÔ½½ç¶ÁÈ¡¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/20) |
|
CVE-2020-11913 |
´¦Öóͷ£Î´¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬£¬£¬IPv6×é¼þÖеÄÊäÈëÑéÖ¤²»×¼È·¡£¡£¡£¡£¸ÃÎó²î¿ÉÄܵ¼ÖÂÔ½½ç¶ÁÈ¡¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/20) |
|
CVE-2020-11914 |
´¦Öóͷ£Î´¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬£¬£¬ARP×é¼þÖеÄÊäÈëÑéÖ¤²»×¼È·¡£¡£¡£¡£¸ÃÎó²î¿ÉÄܵ¼ÖÂÔ½½ç¶ÁÈ¡¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/20) |
|
CVE-2020-11908 |
´¦Öóͷ£Î´¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬£¬£¬DHCP×é¼þÖеÄNull Termination²»×¼È·¡£¡£¡£¡£¸ÃÎó²î¿ÉÄܵ¼ÖÂÃô¸ÐÐÅϢй¶¡£¡£¡£¡£ |
4.7.1.27 (release 11/08/07) |
JSOFÒÑÓë¶à¼Ò×éÖ¯ÏàÖú£¬£¬£¬£¬£¬£¬£¬£¬Ðµ÷Îó²îÅû¶ºÍÐÞ²¹ÊÂÇ飬£¬£¬£¬£¬£¬£¬£¬°üÀ¨CERT / CC£¬£¬£¬£¬£¬£¬£¬£¬CISA£¬£¬£¬£¬£¬£¬£¬£¬FDA£¬£¬£¬£¬£¬£¬£¬£¬¹ú¼ÒCERT£¬£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ¹©Ó¦ÉÌºÍÆäËûÍøÂçÇå¾²¹«Ë¾¡£¡£¡£¡£
µ½ÏÖÔÚΪֹ£¬£¬£¬£¬£¬£¬£¬£¬ÒѾȷÈÏÀ´×Ô11¸ö¹©Ó¦É̵IJúÆ·Ò×Êܹ¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Éæ¼°´òÓ¡»ú¡¢UPSϵͳ¡¢ÍøÂç×°±¸¡¢IPÉãÏñ»ú¡¢ÊÓÆµ¾Û»áϵͳ¡¢Â¥Óî×Ô¶¯»¯×°±¸ºÍICS×°±¸µÈ¡£¡£¡£¡£µ«²»Ö¹ÓÚ´Ë£¬£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÒÔΪÕâЩÎó²î¿ÉÄÜ»áÓ°ÏìÀ´×Ô100¶à¼Ò¹©Ó¦É̵ÄÊýÒŲ́װ±¸¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÈÔÔÚʹÓÃ×°±¸Ê±£¬£¬£¬£¬£¬£¬£¬£¬Ripple20×é³ÉÖØ´óΣº¦¡£¡£¡£¡£Ç±ÔÚµÄΣº¦³¡¾°°üÀ¨£º
? ÈôÊÇÃæÏò»¥ÁªÍø£¬£¬£¬£¬£¬£¬£¬£¬ÔòÀ´×ÔÍøÂçÍⲿµÄ¹¥»÷Õß½«¿ØÖÆÍøÂçÖеÄ×°±¸£»£»£»£»£»£»
? ÒѾÏë·¨ÉøÍ¸µ½ÍøÂçµÄ¹¥»÷Õß¿ÉÒÔʹÓÿâÎó²îÀ´Õë¶ÔÍøÂçÖеÄÌØ¶¨×°±¸£»£»£»£»£»£»
? ¹¥»÷Õß¿ÉÒԹ㲥Äܹ»Í¬Ê±½ÓÊÜÍøÂçÖÐËùÓÐÊÜÓ°Ïì×°±¸µÄ¹¥»÷£»£»£»£»£»£»
? ¹¥»÷Õß¿ÉÄÜʹÓÃÊÜÓ°ÏìµÄ×°±¸Òþ²ØÔÚÄÚÍøÖУ»£»£»£»£»£»
? ÖØ´óµÄ¹¥»÷Õß¿ÉÄÜ»á´ÓÍøÂç½çÏßÍⲿ¶ÔÍøÂçÄÚµÄ×°±¸¾ÙÐй¥»÷£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÈƹýÈκÎNATÉèÖᣡ£¡£¡£Õâ¿ÉÒÔͨ¹ýÖ´ÐÐMITM¹¥»÷»òdns»º´æÖж¾À´Íê³É£»£»£»£»£»£»
? ÔÚijЩÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÄܹ»Í¨¹ýÏìÓ¦ÍÑÀëÍøÂç½çÏßµÄÊý¾Ý°ü£¬£¬£¬£¬£¬£¬£¬£¬ÈƹýNAT£¬£¬£¬£¬£¬£¬£¬£¬´ÓÍøÂçÍⲿִÐй¥»÷£»£»£»£»£»£»
? ÔÚËùÓÐÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¶¼¿ÉÒÔÔ¶³Ì¿ØÖÆÄ¿µÄ×°±¸£¬£¬£¬£¬£¬£¬£¬£¬¶øÎÞÐèÓû§¸ÉÔ¤¡£¡£¡£¡£
JSOF½¨Òé½ÓÄɲ½·¥ÒÔ×îС»¯»ò¼õÇá×°±¸¿ª·¢µÄΣº¦¡£¡£¡£¡£×°±¸¹©Ó¦É̽«½ÓÄÉÓëÍøÂçÔËÓªÉ̲î±ðµÄÒªÁì¡£¡£¡£¡£Í¨³££¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃǽ¨ÒéÖ´ÐÐÒÔϰ취£º
? ËùÓÐ×éÖ¯ÔÚ°²ÅÅ·ÀÓù²½·¥Ö®Ç°¶¼±ØÐè¾ÙÐÐÖÜÈ«µÄΣº¦ÆÀ¹À¡£¡£¡£¡£
? ½¨Òé°²ÅÅ·ÀÓù²½·¥¡£¡£¡£¡£
? ×°±¸¹©Ó¦É̵Ļº½â²½·¥£º
1. È·¶¨ÄúÊÇ·ñʹÓÃÁËÒ×Êܹ¥»÷µÄTreck¿ÍÕ»£»£»£»£»£»£»
2. ÁªÏµTreckÏàʶΣº¦£»£»£»£»£»£»
3. ¸üе½×îеÄTreck¿ÍÕ»°æ±¾£¨6.0.1.67»ò¸ü¸ß°æ±¾£©£»£»£»£»£»£»
4. ÈôÊÇÎÞ·¨¸üУ¬£¬£¬£¬£¬£¬£¬£¬Çë˼Á¿½ûÓÃÒ×Êܹ¥»÷µÄ¹¦Ð§¡£¡£¡£¡£
? ¶ÔÔËÓªÉ̺ÍÍøÂçµÄ»º½â£º£¨»ùÓÚCERT/CCºÍCISA ICS-CERT×Éѯ£©
1. ½«ËùÓÐ×°±¸¸üе½×îа汾£»£»£»£»£»£»
2. ÈôÊÇÎÞ·¨¸üÐÂ×°±¸£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÖ´ÐÐÒÔϰ취£º
1) ×î´óÏ޶ȵØïÔÌǶÈëʽºÍÒªº¦×°±¸µÄÍøÂç̻¶£¬£¬£¬£¬£¬£¬£¬£¬²¢È·±£ÎÞ·¨´ÓInternet»á¼û£»£»£»£»£»£»
2) ¶¨Î»·À»ðǽ·À»¤µÄOTÍøÂçºÍ×°±¸£¬£¬£¬£¬£¬£¬£¬£¬²¢½«ÆäÓëÓªÒµÍøÂç¸ôÀ룻£»£»£»£»£»
3) ½öÆôÓÃÇå¾²µÄÔ¶³Ì»á¼ûÒªÁ죬£¬£¬£¬£¬£¬£¬£¬½¨ÒéʹÓÃÐéÄâרÓÃÍøÂ磨VPN£©¡£¡£¡£¡£
3. ×èÖ¹Òì³£IPÁ÷Á¿£»£»£»£»£»£»
4. ͨ¹ýÉî¶ÈÊý¾Ý°ü¼ì²éÀ´×èÖ¹ÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ½µµÍTreckǶÈëʽÆôÓÃTCP/ IPµÄ×°±¸µÄΣº¦¡£¡£¡£¡£
ÇÀռʽÁ÷Á¿¹ýÂËÊÇÒ»ÖÖÓÐÓõÄÊÖÒÕ£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÊÊÍâµØÓ¦ÓÃÓÚÄúµÄÍøÂçÇéÐΡ£¡£¡£¡£¹ýÂËÑ¡Ïî°üÀ¨£º
? ÈôÊÇÄúµÄÇéÐβ»Ö§³Ö£¬£¬£¬£¬£¬£¬£¬£¬Ôò¹æ·¶»¯»ò×èÖ¹IP¶Î£»£»£»£»£»£»
? ÈôÊDz»ÐèÒª£¬£¬£¬£¬£¬£¬£¬£¬Çë½ûÓûò×èÖ¹IPËíµÀ£¨IPv6-in-IPv4»òIP-in-IPËíµÀ£©£»£»£»£»£»£»
? ×èÖ¹IPԴ·ÓÉÒÔ¼°ËùÓв»ÔÞ³ÉʹÓÃIPv6µÄ¹¦Ð§£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈç·ÓɱêÍ·VU££267289£»£»£»£»£»£»
? Ç¿ÖÆÖ´ÐÐTCP¼ì²é£¬£¬£¬£¬£¬£¬£¬£¬¾Ü¾øÃûÌùýʧµÄTCPÊý¾Ý°ü£»£»£»£»£»£»
? ×èֹδʹÓõÄICMP¿ØÖÆÐÂÎÅ£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈçMTU¸üк͵صãÑÚÂë¸üУ»£»£»£»£»£»
? ͨ¹ýÇå¾²µÄµÝ¹éЧÀÍÆ÷»òDNS¼ì²é·À»ðǽ¹æ·¶DNS£»£»£»£»£»£»
? ÌṩDHCP/DHCPv6Çå¾²ÐÔ£¬£¬£¬£¬£¬£¬£¬£¬²¢¾ßÓÐDHCP¼àÌýµÈ¹¦Ð§£»£»£»£»£»£»
? ÈôÊÇδÔÚ½»Á÷»ù´¡¼Ü¹¹ÖÐʹÓ㬣¬£¬£¬£¬£¬£¬£¬Çë½ûÓÃ/×èÖ¹IPv6¶à²¥¹¦Ð§£»£»£»£»£»£»
? ÔÚ¿ÉÒÔʹÓþ²Ì¬IPµÄµØ·½½ûÓÃDHCP£»£»£»£»£»£»
? ʹÓÃÍøÂçIDSºÍIPSÊðÃû£»£»£»£»£»£»
? ÈôÊÇ¿ÉÓ㬣¬£¬£¬£¬£¬£¬£¬Çë»®·ÖÍøÂç¡£¡£¡£¡£
0x03 Ïà¹ØÐÂÎÅ
https://www.zdnet.com/article/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come/#ftag=RSSbaffb68
0x04 ²Î¿¼Á´½Ó
https://www.jsof-tech.com/ripple20/
0x05 ʱ¼äÏß
2020-06-16 JSOFÅû¶Îó²î
2020-06-17 VSRCÐû²¼Îó²îͨ¸æ


¾©¹«Íø°²±¸11010802024551ºÅ