FragAttacks©¶´·ÖÎö

Ðû²¼Ê±¼ä 2021-05-18

Åä¾°


½üÈÕ £¬Å¦Ô¼´óѧ°¢²¼Ôú±È·ÖУµÄÄþ¾²Ñо¿Ô±Mathy Vanhoef·¢ÏÖÁËһϵÁÐÓ°Ïì¾Þ´óµÄWi-Fi©¶´ £¬ÕâһϵÁЩ¶´±»Í³³ÆΪFragAttacks £¬FragAttacksÓ°ÏìÁË1997ÄêWi-Fi¼¼Êõµ®ÉúÒÔÀ´µÄËùÓÐWi-FiÉ豸£¨°üÂÞ¼ÆËã»ú¡¢ÖÇÄÜÊÖ»ú¡¢Ô°ÇøÍøÂç¡¢¼Òͥ·ÓÉÆ÷¡¢ÖÇÄܼҾÓÉ豸¡¢ÖÇÄÜÆû³µ¡¢ÎïÁªÍøµÈµÈ£©¡£


ÆäÖÐÈý¸ö©¶´Ó°Ïì´ó¶àÊýWiFiÉ豸 £¬ÊôÓÚWi-Fi 802.11³ß¶ÈÖ¡¾ÛºÏºÍÖ¡·ÖƬ¹¦Ð§ÖеÄÉè¼ÆȱÏÝ £¬¶øÆäËû©¶´ÊÇWi-Fi²úÎïÖеıà³Ì´íÎó¡£


ºÚ¿ÍÖ»ÒªÔÚÄ¿±êÉ豸µÄWi-Fi·¶Î§ÄÚ £¬¾ÍÄÜÀûÓÃFragAttacks©¶´ÇÔÈ¡Ãô¸ÐÓû§Êý¾Ý²¢Ö´ÐжñÒâ´úÂë £¬ÉõÖÁ¿ÉÒÔ½Ó¹ÜÕû¸öÉ豸¡£


¶¶È¦Îª¶Ä¶øÉúADLabµÚһʱ¼ä¶Ô©¶´½øÐÐÁË·ÖÎö £¬²¢Ìá³öÁËÏàÓ¦µÄ»º½â½¨Òé¡£ÓÉÓÚWiFi²úÎïµÄЭÒéÕ» £¬°üÂÞÁËSoft Mac¼°Full Mac¶àÖÖʵÏÖ·½°¸¡£FragAttacksϵÁЩ¶´²»½ö´æÔÚÓ°Ïì²Ù×÷ϵͳÄںˡ¢WiFiÇý¶¯ £¬»¹Ó°ÏìWiFiµÄSOCоƬ £¬ËùÒÔ©¶´µÄÓ°Ïìºã¾Ã´æÔÚ¡£Ç뼰ʱ¹Ø×¢²¢¸üÐÂÉ豸¹©Ó¦É̵ÄÄþ¾²¸üС£


ÐÞ¸´¼°»º½â½¨Òé


¡ñ ¼°Ê±¸üÐÂÉ豸¹©Ó¦ÉÌÐû²¼µÄFragAttacks©¶´Äþ¾²¸üС£

¡ñ È·±£Äú·ÃÎʵÄËùÓÐÍøÕ¾ºÍÔÚÏß·þÎñ¶¼ÆôÓÃÁËÄþ¾²³¬Îı¾´«ÊäЭÒéHTTPS(ºÃ±È°²×°HTTPS Everywhere²å¼þ)¡£

¡ñ ÀýÈçÔÚWi-Fi 6£¨802.11ax£©É豸ÖнûÓ÷ÖƬ £¬½ûÓóɶÔÖØÐÂÉú³ÉÃÜÔ¿ÒÔ¼°½ûÓö¯Ì¬·ÖƬ¡£


©¶´ÁÐ±í¼°¾ßÌåÓ°Ïì


Wi-FiÉè¼ÆȱÏÝÏà¹ØµÄ©¶´°üÂÞ£º


CVE񅧏
©¶´½éÉÜ
©¶´Ó°Ïì
CVE-2020-24588
Õë¶ÔA-MSDU¾ÛºÏµÄ×¢Èë¹¥»÷£¨ÎÞЧµÄSPP A-MSDU±£»¤»úÖÆ£©

¹¥»÷Õ߿ɲåÈë¶ñÒâÖ¡ £¬¸Ä¶¯Êý¾Ý°ü

CVE-2020-24587
»ìºÏÃÜÔ¿¹¥»÷£¨ÖØ×éʱʹÓòîÒìÃÜÔ¿¼ÓÃܵķÖƬÃÜÈ¡Óû§µÄÃô¸ÐÊý¾Ý
CVE-2020-24586
·ÖƬ»º´æ¹¥»÷£¨ÖØÐÂÁ¬½Óµ½ÍøÂçʱ²»Çå³ý·ÖƬ»º´æ£©ÇÔÈ¡Óû§Ãô¸ÐÊý¾Ý»ò¸Ä¶¯ÈÎÒâÊý¾Ý°ü


Wi-FiʵÏÖÏà¹ØµÄ©¶´°üÂÞ£º


CVE±àºÅ©¶´½éÉÜ©¶´Ó°Ïì
CVE-2020-26145

ÔÚ¼ÓÃÜͨѶÖÐ £¬ÈÔ½ÓÊÜδ¼ÓÃܹ㲥·ÖƬ×÷ΪÍêÕûÖ¡

¶ÀÁ¢ÓÚÍøÂçÅäÖà £¬²åÈëÈÎÒâÖ¡ £¬´Ó¶ø¸Ä¶¯Êý¾Ý°ü


CVE-2020-26144

ÔÚ¼ÓÃÜͨѶÖÐ £¬ÈÔ½ÓÊÜδ¼ÓÃܵÄA-MSDUÖ¡

CVE-2020-26140

ÔÚÊܱ£»¤µÄÍøÂçÖнÓÊÜδ¼ÓÃÜÊý¾ÝÖ¡

CVE-2020-26143

ÔÚÊܱ£»¤µÄÍøÂçÖнÓÊÜ·ÖƬµÄδ¼ÓÃÜÊý¾ÝÖ¡

CVE-2020-26139

ת·¢EAPOL֡ʱδÑéÖ¤·¢ËͶ˵ÄÉí·Ý

ºÍCVE-2020-24588½áºÏÆðÀ´ £¬²åÈëÈι¥»÷Õ߿ɲåÈë¶ñÒâÖ¡ £¬¸Ä¶¯Êý¾Ý°ü

CVE-2020-26146

¶ÔÓÚ·ÇÁ¬ÐøÊý¾Ý°ü±àºÅµÄ¼ÓÃÜ·ÖƬÒÀÈ»½øÐÐÖØÐÂ×éºÏ

ÇÔÈ¡Óû§Ãô¸ÐÊý¾Ý

CVE-2020-26147


¶Ô·ÖƬ½øÐÐÖØÐÂ×éºÏʱ²»Çø·Ö¼ÓÃÜ»òδ¼ÓÃÜ

¹¥»÷Õ߿ɲåÈë¶ñÒâÖ¡ £¬¸Ä¶¯Êý¾Ý°ü


CVE-2020-26142

½«·ÖƬ֡×÷ΪÍêÕûÖ¡½øÐд¦ÖÃ


CVE-2020-26141

²»ÑéÖ¤·ÖƬ֡µÄTKIP MIC


ͨ¹ýÕâһϵÁЩ¶´ £¬¹¥»÷ÕßÍêÈ«¿ÉÒÔ»ñµÃÓû§µÄÃô¸ÐÐÅÏ¢»òÖ±½Ó¿ØÖÆÖÇÄÜÉ豸 £¬Èç¿ØÖÆÖÇÄܵçÔ´²å×ù £¬ÉõÖÁÖ±½Ó½Ó¹ÜÍøÂçÖдæÔÚ©¶´µÄ¼ÆËã»ú £¬²Î¼ûÏÂÎIJο¼×ÊÁÏ[2]¡£


©¶´·ÖÎö


ÎÒÃÇÑ¡È¡ÁËÔÚËùÓÐÉ豸ÆÕ±é´æÔÚµÄCVE-2020-24586¡¢CVE-2020-24587¡¢CVE-2020-24588Èý¸öÉè¼Æ©¶´½øÐзÖÎö¡£ÓÉÓÚCVE-2020-24588µÄ©¶´Ó°Ïì½Ï´ó £¬ÎÒÃÇ×ÅÖؽøÐнéÉÜCVE-2020-24588¡£ 


1¡¢¼¼ÊõÅä¾°

ÓÉÓÚ802.11MAC²ãЭÒéºÄ·ÑÁËÏ൱¶à¿ªÏúÓÃ×÷Á´Â·µÄά»¤ £¬ÎªÁËÌá¸ßMAC²ãµÄЧÂÊ £¬802.11nÒýÈëÖ¡¾ÛºÏ¼¼Êõ £¬±¨ÎÄÖ¡¾ÛºÏ¼¼Êõ°üÂÞ£ºA-MSDU(MAC·þÎñÊý¾Ýµ¥Ôª¾ÛºÏ) ¼° A-MPDU(MACЭÒéÊý¾Ýµ¥Ôª¾ÛºÏ)¡£


A-MSDUÔÊÐí¶ÔÄ¿µÄµØ¼°Ó¦Óö¼ÏàͬµÄ¶à¸öA-MSDU×ÓÖ¡½øÐÐ¾ÛºÏ £¬¾ÛºÏºóµÄ¶à¸ö×ÓÖ¡Ö»ÓÐÒ»¸öÅäºÏµÄMACÖ¡Í· £¬µ±¶à¸ö×ÓÖ¡¾ÛºÏµ½Ò»Æðºó £¬´Ó¶ø¼õÉÙÁË·¢ËÍÿһ¸ö802.11±¨ÎÄËùÐèµÄPLCP Preamble¡¢PLCP HeaderºÍ802.11MACÍ·µÄ¿ªÏú £¬Í¬Ê±¼õÉÙÁËÓ¦´ðÖ¡µÄÊýÁ¿ £¬´Ó¶øÌá¸ßÎÞÏß´«ÊäЧÂÊ¡£A-MSDU±¨ÎÄÖ¡¾ÛºÏ¼¼ÊõÊÇ802.11nЭÒéµÄÇ¿ÖÆÒªÇó £¬ËùÓÐÖ§³Ö802.11nЭÒéµÄÉ豸¶¼±ØÐëÖ§³Ö¡£


ÏÂͼʾÒâÁËÔÚ802.11ЭÒéÕ»ÖÐ £¬·¢ËͶ˺ͽÓÊÕ¶ËÊÇÈçºÎ´¦ÖÃA-MSDUÊý¾ÝµÄ¡£


1.png

ͼ1. 802.11ЭÒéÊý¾Ý´¦ÖÃÁ÷³Ì 


ÔÚ802.11ЭÒéÕ»ÖÐ £¬·¢ËͶ˽«À´×Ô3-7²ãµÄÍøÂçÊý¾Ý¾­¹ýÊý¾ÝÁ´Â·²ãµÄLLC×Ó²ãÌí¼ÓLLC/SNAPÍ·ºó·â×°³ÉMSDU(MAC·þÎñÊý¾Ýµ¥Ôª£© £¬MSDU¾­¹ýÌí¼ÓDA¡¢SA¡¢³¤¶È¼°padingºó £¬·â×°³ÉA-MSDU×ÓÖ¡ £¬ÔÚMAC×Ó²ãµÄ¶¥²ã½«¶à¸öA-MSDU×ÓÖ¡·â×°³ÉA-MSDU £¬¾­MAC×Ó²ãºó £¬Ö¡Êý¾Ý±»Ìí¼ÓÉÏMACÍ·¼°Ö¡Î²·â×°³É802.11Êý¾ÝÖ¡£¨MPDU£© £¬MPDU/PSDU¾­¹ýÎïÀí²ãÌí¼ÓPLCP Preamble£¨PLCPÇ°µ¼Â룩¼°PLCP Header£¨PHYÍ·£© £¬ÎÞÏß²à×îºóͨ¹ýÉäƵ¿Ú½«¶þ½øÖÆÁ÷·¢Ë͵½½ÓÊնˡ£


½ÓÊÕ¶Ëͨ¹ýÏ෴·¾¶¶Ô802.11Êý¾ÝÖ¡½øÐвð½â £¬×îºó»ñµÃ·¢ËͶ˵Ä3-7²ãµÄÍøÂçÊý¾Ý¡£


A-MSDUµÄЭÒéÊý¾Ý×é³ÉÈçͼ2Ëùʾ £¬ÎÒÃÇ´ÓÉϵ½Ï½øÐзֱð˵Ã÷£º

£¨1£©Ò»¸öMSDUÓÉLCC/SNAPÍ·¡¢IPÍ·¡¢TCP/UDPÍ·¼°Ð­ÒéÊý¾ÝData×é³É¡£

£¨2£©MSDUÌí¼ÓDA(Ä¿µÄµØÖ·) £¬SA(Ô´µØÖ·) £¬ºóÐøÊý¾Ý³¤¶È¼°Padding(ËÄ×Ö½Ú¶ÔÆë)×é³ÉÒ»¸öMSDU×ÓÖ¡¡£

£¨3£©¶à¸öMSDU×ÓÖ¡×é³ÉÒ»¸ö802.11Ö¡µÄA-MSDUÓò¡£

£¨4£©802.11Êý¾Ý֡ͨ¹ýQOS ControlµÄA-MSDU PresentλÀ´ÌåÏÖÕâÊÇÒ»¸ö°üÂÞA-MSDUÓòµÄÊý¾ÝÖ¡¡£


2.png

 Í¼2. A-MSDUÊý¾Ý×é³ÉʾÒâ


ÔÚ802.11ЭÒéÖÐ £¬Ò»¸öÆÕͨµÄ802.11Êý¾ÝÖ¡ÓëA-MSDUÊý¾ÝÖ¡µÄ½á¹¹ÊÇÏàͬµÄ £¬Ö»ÊÇQOS ControlÓòµÄA-MSDU Presetλ Ϊ1 £¬Ôò±êʾÁ˸ÃÊý¾ÝÖ¡ÊÇÒ»¸öA-MSDUÊý¾ÝÖ¡¡£A-MSDU PresetλΪ0 £¬Ôò±êʾÕâÊÇÆÕͨ802.11Êý¾ÝÖ¡¡£


ÔÚ802.11ЭÒéÖÐWEP¼°CCMPÖ»±£»¤802.11MACµÄÓÐЧÔØºÉ £¬ÖÁÓÚ802.11Ö¡Í·ÒÔ¼°Ï²ãЭÒéµÄ±êÍ·ÔòÔ­·â²»¶¯ £¬Ò²¾ÍÊÇ˵802.11ЭÒéÖÐÊý¾ÝÖ¡ÖÐQOS Control²¢Ã»ÓмÓÃÜ £¬ÕâΪ¹¥»÷ÕßÌṩÁ˹¥»÷Èë¿Ú¡£


3.png

ͼ3. CCMP¼ÓÃܵÄ802.11Êý¾ÝÖ¡¸ñʽ


Ϊ·ÀÖ¹ÖмäÈ˹¥»÷ £¬IEEEÔÚ2011ÄêÉè¼ÆÁËSPPA-MSDU»úÖÆÀ´±£»¤A-MSDU Presetλ¼°A-MSDUµÄPayload¡£SPP A-MSDUͨ¹ýÔÚRSN capabilities ÓòÖÐÌí¼ÓSPP A-MSDU Capable¼°SPP A-MSDU RequiredÀ´±êʾÊÇ·ñÖ§³ÖSPP A-MSDU»úÖƼ°ÊÇ·ñ½ÓÄÉSPP A-MSDU»úÖÆ¡£


4.png

ͼ4. RSN Capabilities ÓòÊý¾Ý¸ñʽ


2¡¢Õë¶ÔA-MSDU¾ÛºÏµÄÖ¡×¢Èë¹¥»÷(CVE-2020-24588)


ËäÈ»ÓÐSPP A-MSDU»úÖÆÀ´±£»¤A-MSDU Presetλ²»±»¸Ä¶¯ £¬µ«ÊÇÔÚʵ¼ÊµÄ²âÊÔÖÐ £¬¼¸ºõËùÓеÄÉ豸¶¼²»×ñÑ­SPP A-MSDU»úÖÆ £¬ÕâʹµÃÖмäÈ˹¥»÷³ÉΪ¿ÉÄÜ¡£


ÎÒÃǼÙÉè·¢ËͶ˷¢ËÍÁËÒ»¸öÕý³£µÄ802.11Êý¾ÝÖ¡ £¬ÕâÊÇÒ»¸öÀïÃæ·â×°µÄÊÇÒ»¸öÆÕͨTCP°ü £¬Æädst=¡°192.168.1.2", src="1.2.3.4", id=34


5.png

ͼ5. ԭʼµÄ802.11Êý¾ÝÖ¡


ÓÉÓÚÆ«ÒÆ0x18µÄQOS Control(0200£©²»Êܱ£»¤ £¬¹¥»÷Õß¿ÉÒÔ½« QOS ControlÓòÖеÄA-MSDU Preset·­×ªÎª1 £¬Ê¹µÃQOS ControlµÄֵΪ8200 £¬Í¬Ê±ÔÚ֡ĩβעÈë¶ñÒâµÄA-MSDU×ÓÖ¡2£¨ÈçÏÂͼµÄºìÉ«Ïß±êʾ£© £¬×îºó·¢Ë͸ø½ÓÊնˡ£


6.png

 Í¼6. ¸Ä¶¯ºóµÄ802.11A-MSDUÊý¾ÝÖ¡


ÓÉÓÚQOS ControlÓòÖеÄA-MSDU Preset·­×ªÎª1 £¬µ±½ÓÊն˽ÓÊÕµ½Êý¾ÝÖ¡ºó £¬»á°´A-MSDU¸ñʽÀ´²ð½âÀïÃæµÄÊý¾Ý¡£Êý¾Ý±»Ê¶±ð³ÉÁ½¸öA-MSDU×ÓÖ¡¡£A-MSDU×ÓÖ¡1ÖеÄÊý¾ÝÊÇԭʼµÄMSDUÊý¾Ý £¬ËùÒԻᱻЭÒéÕ»Å×Æú £¬µ«µÚ¶þ¸ö×ÓÖ¡»á±»ÕýÈ·½âÎö²¢´¦Öá£ÕâÉÏÃæµÄÀý×ÓÖеڶþ¸ö×ÓÖ¡»á±»Ê¶±ð³ÉICMP ping°ü £¬½ÓÊն˻á»Ø¸´Ò»¸öICMP echo Reply¸ø·¢ËͶË¡£


ÊÓƵ1. ·¢ËͶËÊÕµ½ICMP echo Reply


ÏÂͼʾÒâÁËÖмäÈËÖ¡×¢ÈëÁ÷³Ì£º


7.png

 Í¼7. ÖмäÈËÖ¡×¢ÈëÁ÷³Ì 


£¨1£©STA£¨Öնˣ©ºÍAP£¨Èȵã/ÎÞÏß·ÓÉÆ÷£©ÐŵÀA£¨ÈçÐŵÀ6£©, ½¨Á¢¹ØÁª

£¨2£©MITMÀûÓöàÐŵÀÖмäÈ˼¼ÊõʹµÃSTAÈÏΪAPÒѾ­Çл»µ½ÐŵÀB£¨ÈçÐŵÀ11£©¡£

£¨3£©STAÔÚÐŵÀ11¸ø MITM·¢ËͼÓÃܵÄWifiÕý³£Êý¾ÝÖ¡¡£

£¨4£©MITM½« ½ÓÊÕµ½µÄWifiÖ¡QOSÓòµÄA-MSDU Preset±êʾÉèΪ1 £¬Í¬Ê±²åÈë¸Ä¶¯µÄA-MSDUÊý¾Ý¡£°ÑÒ»¸öÕý³£µÄWifiÖ¡¸Ä³ÉÒ»¸öA-MSDUÖ¡ £¬²¢×¢ÈëÒ»¸öICMPÇëÇó°ü £¬²¢ÔÚͨµÀ6·¢¸øAP¡£

£¨5£©AP½ÓÊÕµ½A-MSDUÊý¾ÝÖ¡ £¬AP²ð½âA-MSDU £¬·Ö³É¶à¸öA-MSDU×ÓÖ¡ £¬ÆäÖеÚÒ»¸öA-MSDU×Ó֡Ϊ·Ç·¨°ü £¬»á±»Å×Æú £¬µ«ºóÐøµÄMSDU×ÓÖ¡»á±»ÏµÍ³Õý³£´¦Öá£AP»á»Ø¸´ÊÕµ½Ò»¸öICMP Echo Ó¦´ð¸øMITM¡£

£¨6£©MITMÊÕµ½APµÄ»Ø¸´ºó £¬½«½ÓÊÕµ½µÄWIFI֡ת·¢¸øSTA £¬ÕâÑùSTAÊÕµ½AP»Ø¸´µÄICMPÓ¦´ð¡£


CVE-2020-24588µÄÐÞ¸´


½ñÄê3ÔÂWindowsÐû²¼ÁËÏàÓ¦µÄ²¹¶¡ £¬ÐÞ¸´ÁËFragAttacksϵÁЩ¶´ £¬5ÔÂ11ÈÕLinuxÒ²Ðû²¼ÁËFragAttacksϵÁЩ¶´²¹¶¡[6] £¬LinuxÕë¶ÔCVE-2020-24588µÄÐÞ¸´ÈçÏ£º


---

 net/wireless/util.c | 3 +++

 1 file changed, 3 insertions(+)

 

diff --git a/net/wireless/util.c b/net/wireless/util.c

index 39966a873e40..7ec021a610ae 100644

--- a/net/wireless/util.c

+++ b/net/wireless/util.c

@@ -771,6 +771,9 @@ void ieee80211_amsdu_to_8023s(struct sk_buff *skb, struct sk_buff_head *list,

 remaining = skb->len - offset;

 if (subframe_len > remaining)

 goto purge;

+/* mitigate A-MSDU aggregation injection attacks */

+if (ether_addr_equal(eth.h_dest, rfc1042_header))

+goto purge;

 

 offset += sizeof(struct ethhdr);

 last = remaining <= subframe_len + padding;

--


ÒòΪÔÚA-MSDU¾ÛºÏ×¢Èë¹¥»÷ÖÐ £¬ÐèÒª½«ÆÕͨ¼ÓÃÜWi-Fi֡ת»»ÎªA-MSDUÖ¡¡£ÕâÒâζ×ŵÚÒ»¸öA-MSDU×ÓÖ¡µÄÇ°6×Ö½Ú¶ÔÓ¦ÓÚRFC1042µÄÖ¡Í· £¬liunxÄÚºËͨ¹ýÔö¼ÓÅжÏDA£¨Ä¿±êµØÖ·£©ÊÇ·ñºÍrfc1042_header(\xaa\xaa\x03\x00\x00\x00)Ò»Ö £¬Èç¹ûÏàµÈÔòÈÏΪÊǶñÒâ¹¥»÷ £¬¿ÉÒÔ°ÑÕâ¸öA-MSDUÖ¡Å×Æú¡£


»ìºÏÃÜÔ¿¹¥»÷(CVE-2020-24587)


8.png

ͼ8.»ìºÏÃÜÔ¿¹¥»÷Á÷³Ì


ÔÚ²½Öè1µ±ÖÐ £¬¹¥»÷ÕßÓÕµ¼Êܺ¦Õß·ÃÎÊÊܹ¥»÷Õß¿ØÖƵķþÎñÆ÷ £¬Í¨¹ýһЩÊֶΠ£¬ºÃ±ÈÖ¸¶¨Ò»¸ö³¬³¤µÄURL £¬´Ó¶øʹÊܺ¦Õß·¢Ë͵ÄÊý¾Ý°ü²»µÃ²»·Ö³ÉÁ½¶Î½øÐд«Êä £¬·ÖƬµÄÊý¾Ý°üÓÃÃØÔ¿k¼ÓÃÜ £¬ÕâÁ½¸öÊý¾Ý°üΪºÍ¡£¶ø¹¥»÷Õßͨ¹ý¶àÐŵÀµÄÖмäÈ˽øÐÐÀ¹½Ø £¬Ò»µ©¼à²âµ½¹¥»÷ÕßÖ¸¶¨IPÊý¾Ý°ü £¬±ã½«´ËÊý¾Ý°üת·¢¸øAP £¬¼´APÒ»µ©ÊÕµ½´ËÊý¾Ý°üºó £¬¾Í½«Æä½âÃܺó´æÔÚÄÚ´æµ±ÖС£ 


ÔÚ²½Öè2½øÐÐ֮ǰ £¬Êܺ¦ÕßÐèÒªÓëAPÖØнøÐÐËÄ´ÎÎÕÊÖ²¢Ð­ÉÌеÄÃÜÔ¿¡£Ö®ºó¹¥»÷ÕßÆÚ´ýÊܺ¦Õß·¢ËÍ°üÂÞÃô¸ÐÐÅÏ¢µÄÊý¾Ý°ü £¬¼´ºÍ¡£¹¥»÷Õß½«Êý¾Ý°üºÅÂëΪn+1µÄÊý¾Ý°üÀ¹½Ø £¬²¢½«ÆäÐòÁкÅÐÞ¸ÄΪs £¬È»ºóת·¢¸øAP £¬¼´Êý¾Ý°ü¡£¶øAPÖ±½Ó°ÑËû¿´³ÉÐòÁкÅsÊý¾Ý°üµÄµÚ¶þ¸ö·ÖƬÐÅÏ¢ £¬½«Ëû½âÃܺóÖØ×é³ÉеÄÊý¾Ý°ü £¬¶øеÄÊý¾Ý°üÖаüÂÞÊܺ¦ÕßµÄÃô¸ÐÐÅÏ¢Óë¹¥»÷ÕßÖ¸¶¨µÄIP¡£ÓÚÊÇÃô¸ÐÐÅÏ¢¾Í±»·¢Ë͵½Êܺ¦Õß¿ØÖƵķþÎñÆ÷ÉÏ £¬Ôì³ÉÐÅϢй¶¡£


·ÖƬ»º´æͶ¶¾¹¥»÷(CVE-2020-24586)


9.png

ͼ9.·ÖƬ»º´æͶ¶¾¹¥»÷Á÷³Ì


ÔÚ²½Öè1ÖÐ £¬¹¥»÷ÕßÐá̽µ½Êܺ¦ÕßµÄMACµØÖ·ºó £¬Î±ÔìÊܺ¦ÕßMACµØÖ·È¥Á¬½ÓAP¡£ÕâÑù¾Í¿ÉÒԺϷ¨µÄÓÃÊܺ¦ÕßµÄÉí·ÝÔÚAPµÄÄÚ´æÖвåÈë·ÖƬ¡£


ÔÚ²½Öè2ÖÐ £¬Êܺ¦Õß½øÐÐÕý³£µÄÈÏÖ¤ÊÂÇé £¬´Ëʱ¹¥»÷Õß·¢ËÍÊý¾Ý°ü £¬Õâ¸öÊý¾Ý°üÖаüÂÞ¹¥»÷ÕßÖ¸¶¨µÄIPÊý¾Ý°ü¡£È»ºóAP½âÃÜ´ËÊý¾Ý°ü £¬²¢Éú´æÔÚÄÚ´æÖÐ £¬ÒÔÊܺ¦ÕßµÄMACµØÖ·×÷Ϊ±êʶ¡£È»ºó¹¥»÷Õßͨ¹ý·¢Ëͽâ³ýÈÏÖ¤µÄÊý¾Ý°ü²¢¶Ï¿ªÁ¬½Ó £¬ËæºóÔÚÊܺ¦ÕߺÍAPÖ®¼ä½¨Á¢Ò»¸ö¶àÐŵÀµÄÖмäÈË¡£×¢Òâ´ËʱAPÄÚ´æÖеķÖƬ²¢Ã»Óб»Çå³ý¡£


Ö®ºóÊܺ¦ÕßÓëAPÖ®¼ä½øÐÐÕý³£µÄÁ¬½Ó¡£´Ëʱ¹¥»÷ÕßÖ»ÐèÒªÆÚ´ýÊܺ¦Õß·¢Ë͵ڶþ¸ö·ÖƬ £¬Êý¾Ý°üºÅÂëΪn+1 £¬¹¥»÷Õß½«´ËÊý¾Ý°üÀ¹½Øºó £¬²¢½«´ËÊý¾Ý°üµÄÐòÁкÅÐÞ¸ÄΪs £¬È»ºóÆäת·¢¸øAP £¬¼´Êý¾Ý°ü £¬Ò»µ©APÊÕµ½´ËÊý¾Ý°ü £¬ºÍ»ìºÏÃÜԿ©¶´ÀàËÆ £¬AP»á½«´ËÊý¾Ý°ü½âÃÜ £¬²¢ºÍ֮ǰÉú´æÔÚ»º´æÖеÄÊý¾Ý°üÖØ×é³ÉеÄÊý¾Ý°ü £¬ÒòΪÕâÁ½¸öÊý¾Ý°ü°üÂÞÏàͬµÄMACµØÖ·ºÍÐòÁкÅ¡£×îºó £¬AP½«ÖØ×éºóµÄÊý¾Ý°ü·¢Ë͸ø¹¥»÷Õß¿ØÖƵķþÎñÆ÷ £¬´Ó¶øÔì³ÉÃô¸ÐÐÅϢй¶¡£


²Î¿¼Á´½Ó£º

¡¾1¡¿https://papers.mathyvanhoef.com/usenix2021.pdf

¡¾2¡¿https://www.youtube.com/embed/88YZ4061tYw

¡¾3¡¿https://www.fragattacks.com/#notpatched

¡¾4¡¿https://github.com/vanhoefm/fragattacks

¡¾5¡¿https://lore.kernel.org/linux-wireless/20210511180259.159598-1-johannes@sipsolutions.net/


¶¶È¦Îª¶Ä¶øÉú»ý¼«·ÀÓùʵÑéÊÒ£¨ADLab£©


ADLab½¨Á¢ÓÚ1999Äê £¬ÊÇÖйúÄþ¾²ÐÐÒµ×îÔ罨Á¢µÄ¹¥·À¼¼ÊõÑо¿ÊµÑéÊÒÖ®Ò» £¬Î¢ÈíMAPP¼Æ»®ºËÐijÉÔ± £¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£½ØֹĿǰ £¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Äþ¾²Â©¶´½ü1100¸ö £¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Äþ¾²Â©¶´1000Óà¸ö £¬Á¬Ðø±£³Ö¹ú¼ÊÍøÂçÄþ¾²ÁìÓòÒ»Á÷Ë®×¼¡£ÊµÑéÊÒÑо¿Æ«Ïòº­¸Ç²Ù×÷ϵͳÓëÓ¦ÓÃϵͳÄþ¾²Ñо¿¡¢ÖÇÄÜÖÕ¶ËÄþ¾²Ñо¿¡¢ÎïÁªÍøÖÇÄÜÉ豸Äþ¾²Ñо¿¡¢WebÄþ¾²Ñо¿¡¢¹¤¿ØϵͳÄþ¾²Ñо¿¡¢ÔÆÄþ¾²Ñо¿¡£Ñо¿½á¹ûÓ¦ÓÃÓÚ²úÎïºËÐļ¼ÊõÑо¿¡¢¹ú¼ÒÖصã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÄþ¾²·þÎñµÈ¡£


adlab.jpg