TCP/IP¶ÑÕ»£ºNAME£ºWRECK DNSÐÒé©¶´
Ðû²¼Ê±¼ä 2021-04-130x00 ©¶´¸ÅÊö
2021Äê04ÔÂ13ÈÕ£¬Äþ¾²ÈËÔ±Åû¶ÁËTCP/IP¶ÑÕ»ÖÐDNSÐÒéÖÐͳ³ÆÎªNAME£ºWRECKµÄ9¸öÄþ¾²Â©¶´£¬ÕâЩ©¶´ÖÁÉÙÓ°ÏìÁË1ÒÚ¸öInternetÉÏÔËÐеÄÉ豸£¬¹¥»÷Õß¿ÉÒÔÀûÓÃÕâЩ©¶´Ê¹ÊÜÓ°ÏìµÄÉ豸ÍÑ»ú»ò¶ÔÉ豸½øÐпØÖÆ¡£
0x01 ©¶´ÏêÇé
NAME£ºWRECKÊÇÎïÁªÍøÆóÒµÄþ¾²¹«Ë¾ForescoutºÍÒÔÉ«ÁÐÄþ¾²Ñо¿Ð¡×éJSOFµÄÅäºÏ·¢Ïֵģ¬ÕâЩ©¶´Ó°ÏìµÄTCP/IP¶ÑÕ»°üÂÞµ«²»ÏÞÓÚ£º
FreeBSD£¨Ó°Ïì°æ±¾£º12.1£©-BSDϵÁÐÖÐ×îÁ÷ÐеIJÙ×÷ϵͳ֮һ¡£
IPnet£¨Ó°Ïì°æ±¾£ºVxWorks 6.6£©-×î³õÓÉInterpeak¿ª·¢£¬ÏÖÔÚÓÉWindRiverά»¤£¬²¢ÓÉVxWorksʵʱ²Ù×÷ϵͳ£¨RTOS£©Ê¹Óá£
NetX£¨Ó°Ïì°æ±¾£º6.0.1£©-ThreadX RTOSµÄÒ»²¿ÃÅ£¬ÏÖÔÚÊÇMicrosoftά»¤µÄÒ»¸ö¿ªÔ´ÏîÄ¿£¬Ãû³ÆÎªAzure RTOS NetX¡£
Nucleus NET£¨Ó°Ïì°æ±¾£º4.3£©-ÓÉÎ÷ÃÅ×ÓÒµÎñMentor Graphicsά»¤µÄNucleus RTOSµÄÒ»²¿ÃÅ£¬ÓÃÓÚÒ½ÁÆ¡¢¹¤Òµ¡¢Ïû·ÑÀà¡¢º½¿Õº½ÌìºÍÎïÁªÍøÉ豸¡£
¹¥»÷Õß¿ÉÒÔÀûÓÃNAME£ºWRECK©¶´ÇÔÈ¡Ãô¸ÐÊý¾Ý¡¢Ð޸ĻòʹÉ豸ÍÑ»úÒÔ¶ÔÖÆÔìÐÐÒµÖеÄÕþ¸®»òÆóÒµ·þÎñÆ÷¡¢Ò½ÁÆ»ú¹¹¡¢ÁãÊÛÉÌ»ò¹«Ë¾Ôì³ÉÖØ´óÄþ¾²Ê¹ʡ£
¹¥»÷Õß»¹¿ÉÒÔÀûÓÃÕâЩ©¶´¸Ä¶¯×¡Õ¬»òÉÌÒµ³¡ËùµÄÖÇÄÜÉ豸£¬ÒÔ¿ØÖƹ©Å¯ºÍͨ·ç¡¢½ûÓÃÄþ¾²ÏµÍ³»ò¸Ä¶¯×Ô¶¯ÕÕÃ÷ϵͳ¡£
Ñо¿ÈËÔ±ÔÚ·ÖÎöÉÏÊöTCP/IP¶ÑÕ»ÖеÄDNSʱ£¬·ÖÎöÁ˸ÃÐÒéµÄÏûϢѹËõ¹¦Ð§¡£DNSÏìÓ¦Êý¾Ý°üÖаüÂÞÏàͬµÄÓòÃû»ò²¿ÃÅÓòÃûµÄÇé¿ö²¢²»ÉÙ¼û£¬Òò´ËËüʹÓÃÒ»ÖÖѹËõ»úÖÆÀ´¼õСDNSÏûÏ¢µÄ¾Þϸ£¬ÕâÖÖ±àÂë²»½öÓ¦ÓÃÔÚDNS½âÎöÆ÷ÖУ¬Ëü»¹Ó¦ÓÃÔڶಥDNS£¨mDNS£©¡¢DHCP¿Í»§¶ËºÍIPv6·ÓÉÆ÷ͨ¸æÖС£
ForescoutÔÚÆä³ÂËßÖнâÊÍ˵£¬¾¡¹ÜijЩÐÒ鲢δÕýʽ֧³ÖѹËõ£¬µ«¸Ã¹¦Ð§»¹´æÔÚÓÚÐí¶àÓ¦ÓÃÖС£ÖµµÃ×¢ÒâµÄÊÇ£¬²¢·ÇNAME£ºWRECKÖеÄËùÓЩ¶´¶¼¿ÉÒÔ±»ÀûÓÃÀ´»ñµÃÏàͬµÄ½á¹û¡£ÆäÖÐ×îÑÏÖØµÄÊÇÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬Æä×î¸ßÆÀ·ÖΪ9.8£¨Âú·Ö10·Ö£©£¬9¸ö©¶´ÈçϱíËùʾ£¬²¢·ÇËùÓЩ¶´¶¼ÓëÏûϢѹËõÓйأº
CVE ID | Stack | ÃèÊö | ÊÜÓ°Ï칦Ч | DZÔÚÓ°Ïì | ÆÀ·Ö |
CVE-2020-7461 | FreeBSD |
-ÍøÂçÉϵĹ¥»÷Õß¿ÉÒÔ½«¶ñÒâÖÆ×÷µÄÊý¾Ý·¢Ë͵½DHCP¿Í»§¶Ë | Message compression | RCE | 7.7 |
CVE-2016-20009 | IPnet | -ÏûÏ¢½âѹËõ¹¦Ð§»ùÓÚ¶ÑÕ»µÄÒç³ö | Message compression | RCE | 9.8 |
CVE-2020-15795 | Nucleus NET | -DNSÓòÃû±êÇ©½âÎö¹¦Ð§ÎÞ·¨ÕýÈ·ÑéÖ¤DNSÏìÓ¦ÖеÄÃû³Æ -½âÎö¸ñʽ´íÎóµÄÏìÓ¦¿ÉÄܵ¼ÖÂд²Ù×÷³¬³ö·ÖÅäµÄ½á¹¹µÄĩβ | Domain name label parsing | RCE | 8.1 |
CVE-2020-27009 | Nucleus NET | -DNSÓòÃû¼Ç¼½âѹËõ¹¦Ð§ÎÞ·¨ÕýÈ·ÑéÖ¤Ö¸ÕëÆ«ÒÆÖµ -½âÎö¸ñʽ´íÎóµÄÏìÓ¦¿ÉÄܵ¼ÖÂд²Ù×÷³¬³ö·ÖÅäµÄ½á¹¹µÄĩβ | Message compression | RCE | 8.1 |
CVE-2020-27736 | Nucleus NET | -DNSÓòÃû±êÇ©½âÎö¹¦Ð§ÎÞ·¨ÕýÈ·ÑéÖ¤DNSÏìÓ¦ÖеÄÃû³Æ -½âÎö¸ñʽ´íÎóµÄÏìÓ¦¿ÉÄܵ¼ÖÂд²Ù×÷³¬³ö·ÖÅäµÄ½á¹¹µÄĩβ | Domain name label parsing | ¾Ü¾ø·þÎñ | 6.5 |
CVE-2020-27737 | Nucleus NET | -DNSÏìÓ¦½âÎö¹¦Ð§ÎÞ·¨ÕýÈ·ÑéÖ¤ÖÖÖÖ³¤¶ÈºÍ¼Ç¼Êý -½âÎö¸ñʽ´íÎóµÄÏìÓ¦¿ÉÄܻᵼÖ¶ÁÈ¡³¬³öÒÑ·ÖÅä½á¹¹µÄĩβ | Domain name label parsing | ¾Ü¾ø·þÎñ | 6.5 |
CVE-2020-27738 | Nucleus NET | -DNSÓòÃû¼Ç¼½âѹËõ¹¦Ð§ÎÞ·¨ÕýÈ·ÑéÖ¤Ö¸ÕëÆ«ÒÆÖµ -½âÎö¸ñʽ´íÎóµÄÏìÓ¦¿ÉÄܵ¼Ö³¬³ö·ÖÅä½á¹¹Ä©Î²µÄ¶ÁÈ¡·ÃÎÊ | Message compression | ¾Ü¾ø·þÎñ | 6.5 |
CVE-2021-25677 | Nucleus NET | -DNS¿Í»§¶ËÎÞ·¨ÕýÈ·Ëæ»ú»¯DNSÊÂÎñID£¨TXID£©ºÍUDP¶Ë¿ÚºÅ | Transaction ID | DNS»º´æÖж¾/ÆÛÆ | 5.3 |
* | NetX | -DNS½âÎöÆ÷ÖеÄÁ½¸ö¹¦Ð§ÎÞ·¨¼ì²éѹËõÖ¸ÕëÊÇ·ñ²»¼´Êǵ±Ç°ÕýÔÚ½âÎöµÄÏàÍ¬Æ«ÒÆÁ¿£¬´Ó¶ø¿ÉÄܵ¼ÖÂÎÞÏÞÑ»· | Message compression | ¾Ü¾ø·þÎñ | 6.5 |
ÀûÓõ¥¸ö©¶´¿ÉÄܲ»»áÔì³ÉÌ«´óÓ°Ï죬µ«Èç¹û¹¥»÷Õß½«ËüÃÇ×éºÏÔÚÒ»ÆðÀ´ÀûÓ㬾ͿÉÄÜ»áÔì³ÉÑÏÖØÆÆ»µ¡£ÀýÈ磬¹¥»÷Õß¿ÉÒÔÀûÓÃÒ»¸ö©¶´½«ÈÎÒâÊý¾ÝдÈëÒ×Êܹ¥»÷É豸µÄÃô¸ÐÄÚ´æÎ»Öã¬ÀûÓÃÁíÒ»¸ö©¶´ÔÚÊý¾Ý°üÖÐ×¢Èë´úÂ룬ȻºóÔÙÀûÓõÚÈý¸ö©¶´½«Æäͨ±¨¸øÄ¿±ê¡£
Forescout¹«Ë¾µÄ³ÂËßÉîÈë̽ÌÖÁ˼¼Êõϸ½Ú£¬¼´ÀûÓÃÔÚ¿ªÔ´TCP/IP¶ÑÕ»Öз¢ÏÖµÄNAME:WRECK©¶´ÒÔ¼°AMNESIA:33ÖеÄ©¶´À´ÊµÏÖÔ¶³Ì´úÂëÖ´Ðй¥»÷¡£¸Ã¹«Ë¾»¹ÌÖÂÛÁ˶à¸öÔÚDNSÏûÏ¢½âÎöÆ÷Öв»Í£Öظ´µÄÖ´ÐÐÎÊÌ⣬ÕâЩÎÊÌâ±»³ÆÎªanti-patterns£¨·´Ä£Ê½£©£¬ËüÃÇÊÇÔì³ÉNAME:WRECK©¶´µÄÔÒò£º
ȱÉÙTXIDÑéÖ¤£¬Ëæ»úTXIDºÍÔ´UDP¶Ë¿Ú²»×㣻
ȱ·¦ÓòÃû×Ö·ûÑéÖ¤£»
ȱÉÙ±êÇ©ºÍÃû³Æ³¤¶ÈÑéÖ¤£»
ȱÉÙNULLÖÕÖ¹ÑéÖ¤£»
ȱÉټǼ¼ÆÊý×Ö¶ÎÑéÖ¤£»
ȱ·¦ÓòÃûѹËõÖ¸ÕëºÍÆ«ÒÆÁ¿ÑéÖ¤£»
´ËÍ⣬Forescout»¹ÌṩÁËÁ½¸ö¿ªÔ´¹¤¾ß£¬¿ÉÒÔ×ÊÖúÈ·¶¨Ä¿±êÍøÂçÉ豸ÊÇ·ñÔËÐÐÌØ¶¨µÄǶÈëʽTCP/IPÐÒéÕ»£¨Project Memoria Detector£©ºÍÓÃÓÚ¼ì²âÀàËÆÓÚNAME:WRECKµÄÎÊÌ⣨namewreck£¬ÓëJoernÒ»ÆðʹÓã©¡£
0x02 ´¦Öý¨Òé
NAME£ºWRECKµÄÐÞ¸´·¨Ê½ÊÊÓÃÓÚ FreeBSD¡¢Nucleus NETºÍ NetX£¬½¨ÒéÏÈʵʩÒÔÏÂÄþ¾²½¨Ò飬ÔÙ¼°Ê±Ó¦ÓÃÉ豸¹©Ó¦ÉÌÐû²¼µÄÄþ¾²¸üС£
Äþ¾²½¨Ò飺
ʹÓÃһЩ»º½âÐÅÏ¢À´¿ª·¢¼ì²âDNS©¶´µÄÇ©Ãû£»
·¢ÏÖ²¢ÇåµãÔËÐÐÒ×Êܹ¥»÷¶ÑÕ»µÄÉ豸£»
ʵʩ·Ö¶Î¿ØÖƺÍÊʵ±µÄnetwork hygiene£»
¼àÊÓÊÜÓ°ÏìµÄÉ豸¹©Ó¦ÉÌÐû²¼µÄ²¹¶¡£»
ÅäÖÃÉ豸ÒÀÀµÄÚ²¿DNS·þÎñÆ÷£»
¼à¿ØËùÓÐÍøÂçÁ÷Á¿ÖеĶñÒâÊý¾Ý°ü¡£
0x03 ²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/name-wreck-dns-vulnerabilities-affect-over-100-million-devices/
https://www.freebsd.org/security/advisories/FreeBSD-SA-20:26.dhclient.asc
https://github.com/Forescout/project-memoria-detector
https://github.com/Forescout/namewreck
0x04 ʱ¼äÏß
2021-04-13 bleepingcomputerÅû¶©¶´
2021-04-13 VSRCÐû²¼Äþ¾²Í¨¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/