TCP/IP¶ÑÕ»£ºNAME£ºWRECK DNSЭÒé©¶´

Ðû²¼Ê±¼ä 2021-04-13

0x00 ©¶´¸ÅÊö

2021Äê04ÔÂ13ÈÕ£¬Äþ¾²ÈËÔ±Åû¶ÁËTCP/IP¶ÑÕ»ÖÐDNSЭÒéÖÐͳ³ÆÎªNAME£ºWRECKµÄ9¸öÄþ¾²Â©¶´£¬ÕâЩ©¶´ÖÁÉÙÓ°ÏìÁË1ÒÚ¸öInternetÉÏÔËÐеÄÉ豸£¬¹¥»÷Õß¿ÉÒÔÀûÓÃÕâЩ©¶´Ê¹ÊÜÓ°ÏìµÄÉ豸ÍÑ»ú»ò¶ÔÉ豸½øÐпØÖÆ¡£

 

0x01 ©¶´ÏêÇé

image.png


NAME£ºWRECKÊÇÎïÁªÍøÆóÒµÄþ¾²¹«Ë¾ForescoutºÍÒÔÉ«ÁÐÄþ¾²Ñо¿Ð¡×éJSOFµÄÅäºÏ·¢Ïֵģ¬ÕâЩ©¶´Ó°ÏìµÄTCP/IP¶ÑÕ»°üÂÞµ«²»ÏÞÓÚ£º

FreeBSD£¨Ó°Ïì°æ±¾£º12.1£©-BSDϵÁÐÖÐ×îÁ÷ÐеIJÙ×÷ϵͳ֮һ¡£

IPnet£¨Ó°Ïì°æ±¾£ºVxWorks 6.6£©-×î³õÓÉInterpeak¿ª·¢£¬ÏÖÔÚÓÉWindRiverά»¤£¬²¢ÓÉVxWorksʵʱ²Ù×÷ϵͳ£¨RTOS£©Ê¹Óá£

NetX£¨Ó°Ïì°æ±¾£º6.0.1£©-ThreadX RTOSµÄÒ»²¿ÃÅ£¬ÏÖÔÚÊÇMicrosoftά»¤µÄÒ»¸ö¿ªÔ´ÏîÄ¿£¬Ãû³ÆÎªAzure RTOS NetX¡£

Nucleus NET£¨Ó°Ïì°æ±¾£º4.3£©-ÓÉÎ÷ÃÅ×ÓÒµÎñMentor Graphicsά»¤µÄNucleus RTOSµÄÒ»²¿ÃÅ£¬ÓÃÓÚÒ½ÁÆ¡¢¹¤Òµ¡¢Ïû·ÑÀà¡¢º½¿Õº½ÌìºÍÎïÁªÍøÉ豸¡£

 

¹¥»÷Õß¿ÉÒÔÀûÓÃNAME£ºWRECK©¶´ÇÔÈ¡Ãô¸ÐÊý¾Ý¡¢Ð޸ĻòʹÉ豸ÍÑ»úÒÔ¶ÔÖÆÔìÐÐÒµÖеÄÕþ¸®»òÆóÒµ·þÎñÆ÷¡¢Ò½ÁÆ»ú¹¹¡¢ÁãÊÛÉÌ»ò¹«Ë¾Ôì³ÉÖØ´óÄþ¾²Ê¹Ê¡£

image.png

 

¹¥»÷Õß»¹¿ÉÒÔÀûÓÃÕâЩ©¶´¸Ä¶¯×¡Õ¬»òÉÌÒµ³¡ËùµÄÖÇÄÜÉ豸£¬ÒÔ¿ØÖƹ©Å¯ºÍͨ·ç¡¢½ûÓÃÄþ¾²ÏµÍ³»ò¸Ä¶¯×Ô¶¯ÕÕÃ÷ϵͳ¡£

image.png

 

Ñо¿ÈËÔ±ÔÚ·ÖÎöÉÏÊöTCP/IP¶ÑÕ»ÖеÄDNSʱ£¬·ÖÎöÁ˸ÃЭÒéµÄÏûϢѹËõ¹¦Ð§¡£DNSÏìÓ¦Êý¾Ý°üÖаüÂÞÏàͬµÄÓòÃû»ò²¿ÃÅÓòÃûµÄÇé¿ö²¢²»ÉÙ¼û£¬Òò´ËËüʹÓÃÒ»ÖÖѹËõ»úÖÆÀ´¼õСDNSÏûÏ¢µÄ¾Þϸ£¬ÕâÖÖ±àÂë²»½öÓ¦ÓÃÔÚDNS½âÎöÆ÷ÖУ¬Ëü»¹Ó¦ÓÃÔڶಥDNS£¨mDNS£©¡¢DHCP¿Í»§¶ËºÍIPv6·ÓÉÆ÷ͨ¸æÖС£

ForescoutÔÚÆä³ÂËßÖнâÊÍ˵£¬¾¡¹ÜijЩЭÒ鲢δÕýʽ֧³ÖѹËõ£¬µ«¸Ã¹¦Ð§»¹´æÔÚÓÚÐí¶àÓ¦ÓÃÖС£ÖµµÃ×¢ÒâµÄÊÇ£¬²¢·ÇNAME£ºWRECKÖеÄËùÓЩ¶´¶¼¿ÉÒÔ±»ÀûÓÃÀ´»ñµÃÏàͬµÄ½á¹û¡£ÆäÖÐ×îÑÏÖØµÄÊÇÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬Æä×î¸ßÆÀ·ÖΪ9.8£¨Âú·Ö10·Ö£©£¬9¸ö©¶´ÈçϱíËùʾ£¬²¢·ÇËùÓЩ¶´¶¼ÓëÏûϢѹËõÓйأº

CVE   ID

Stack

ÃèÊö

ÊÜÓ°Ï칦Ч

DZÔÚÓ°Ïì

ÆÀ·Ö

CVE-2020-7461

FreeBSD


  dhclient
£¨8£©µÄDHCPÊý¾Ý°üÖеÄÑ¡Ïî119Êý¾Ý½øÐнâÎöʱ·ºÆð½çÏÞ´íÎó

-ÍøÂçÉϵĹ¥»÷Õß¿ÉÒÔ½«¶ñÒâÖÆ×÷µÄÊý¾Ý·¢Ë͵½DHCP¿Í»§¶Ë

Message

compression   

RCE

7.7

CVE-2016-20009

IPnet

-ÏûÏ¢½âѹËõ¹¦Ð§»ùÓÚ¶ÑÕ»µÄÒç³ö

Message

compression   

RCE

9.8

CVE-2020-15795

Nucleus   NET

-DNSÓòÃû±êÇ©½âÎö¹¦Ð§ÎÞ·¨ÕýÈ·ÑéÖ¤DNSÏìÓ¦ÖеÄÃû³Æ

-½âÎö¸ñʽ´íÎóµÄÏìÓ¦¿ÉÄܵ¼ÖÂд²Ù×÷³¬³ö·ÖÅäµÄ½á¹¹µÄĩβ

Domain   name

label   parsing

RCE

8.1

CVE-2020-27009

Nucleus   NET

-DNSÓòÃû¼Ç¼½âѹËõ¹¦Ð§ÎÞ·¨ÕýÈ·ÑéÖ¤Ö¸ÕëÆ«ÒÆÖµ

-½âÎö¸ñʽ´íÎóµÄÏìÓ¦¿ÉÄܵ¼ÖÂд²Ù×÷³¬³ö·ÖÅäµÄ½á¹¹µÄĩβ

Message

compression

RCE

8.1

CVE-2020-27736

Nucleus   NET

-DNSÓòÃû±êÇ©½âÎö¹¦Ð§ÎÞ·¨ÕýÈ·ÑéÖ¤DNSÏìÓ¦ÖеÄÃû³Æ

-½âÎö¸ñʽ´íÎóµÄÏìÓ¦¿ÉÄܵ¼ÖÂд²Ù×÷³¬³ö·ÖÅäµÄ½á¹¹µÄĩβ

Domain

name   label

parsing

¾Ü¾ø·þÎñ

6.5

CVE-2020-27737

Nucleus   NET

-DNSÏìÓ¦½âÎö¹¦Ð§ÎÞ·¨ÕýÈ·ÑéÖ¤ÖÖÖÖ³¤¶ÈºÍ¼Ç¼Êý

-½âÎö¸ñʽ´íÎóµÄÏìÓ¦¿ÉÄܻᵼÖ¶ÁÈ¡³¬³öÒÑ·ÖÅä½á¹¹µÄĩβ

Domain   name

label   parsing

¾Ü¾ø·þÎñ

6.5

CVE-2020-27738

Nucleus   NET

-DNSÓòÃû¼Ç¼½âѹËõ¹¦Ð§ÎÞ·¨ÕýÈ·ÑéÖ¤Ö¸ÕëÆ«ÒÆÖµ

-½âÎö¸ñʽ´íÎóµÄÏìÓ¦¿ÉÄܵ¼Ö³¬³ö·ÖÅä½á¹¹Ä©Î²µÄ¶ÁÈ¡·ÃÎÊ

Message

compression

¾Ü¾ø·þÎñ

6.5

CVE-2021-25677

Nucleus   NET

-DNS¿Í»§¶ËÎÞ·¨ÕýÈ·Ëæ»ú»¯DNSÊÂÎñID£¨TXID£©ºÍUDP¶Ë¿ÚºÅ

Transaction   ID

DNS»º´æÖж¾/ÆÛÆ­

5.3

*

NetX

-DNS½âÎöÆ÷ÖеÄÁ½¸ö¹¦Ð§ÎÞ·¨¼ì²éѹËõÖ¸ÕëÊÇ·ñ²»¼´Êǵ±Ç°ÕýÔÚ½âÎöµÄÏàÍ¬Æ«ÒÆÁ¿£¬´Ó¶ø¿ÉÄܵ¼ÖÂÎÞÏÞÑ­»·

Message

compression

¾Ü¾ø·þÎñ

6.5

 

ÀûÓõ¥¸ö©¶´¿ÉÄܲ»»áÔì³ÉÌ«´óÓ°Ï죬µ«Èç¹û¹¥»÷Õß½«ËüÃÇ×éºÏÔÚÒ»ÆðÀ´ÀûÓ㬾ͿÉÄÜ»áÔì³ÉÑÏÖØÆÆ»µ¡£ÀýÈ磬¹¥»÷Õß¿ÉÒÔÀûÓÃÒ»¸ö©¶´½«ÈÎÒâÊý¾ÝдÈëÒ×Êܹ¥»÷É豸µÄÃô¸ÐÄÚ´æÎ»Öã¬ÀûÓÃÁíÒ»¸ö©¶´ÔÚÊý¾Ý°üÖÐ×¢Èë´úÂ룬ȻºóÔÙÀûÓõÚÈý¸ö©¶´½«Æäͨ±¨¸øÄ¿±ê¡£

Forescout¹«Ë¾µÄ³ÂËßÉîÈë̽ÌÖÁ˼¼Êõϸ½Ú£¬¼´ÀûÓÃÔÚ¿ªÔ´TCP/IP¶ÑÕ»Öз¢ÏÖµÄNAME:WRECK©¶´ÒÔ¼°AMNESIA:33ÖеÄ©¶´À´ÊµÏÖÔ¶³Ì´úÂëÖ´Ðй¥»÷¡£¸Ã¹«Ë¾»¹ÌÖÂÛÁ˶à¸öÔÚDNSÏûÏ¢½âÎöÆ÷Öв»Í£Öظ´µÄÖ´ÐÐÎÊÌ⣬ÕâЩÎÊÌâ±»³ÆÎªanti-patterns£¨·´Ä£Ê½£©£¬ËüÃÇÊÇÔì³ÉNAME:WRECK©¶´µÄÔ­Òò£º

ȱÉÙTXIDÑéÖ¤£¬Ëæ»úTXIDºÍÔ´UDP¶Ë¿Ú²»×ã £»

ȱ·¦ÓòÃû×Ö·ûÑéÖ¤ £»

ȱÉÙ±êÇ©ºÍÃû³Æ³¤¶ÈÑéÖ¤ £»

ȱÉÙNULLÖÕÖ¹ÑéÖ¤ £»

ȱÉټǼ¼ÆÊý×Ö¶ÎÑéÖ¤ £»

ȱ·¦ÓòÃûѹËõÖ¸ÕëºÍÆ«ÒÆÁ¿ÑéÖ¤ £»

´ËÍ⣬Forescout»¹ÌṩÁËÁ½¸ö¿ªÔ´¹¤¾ß£¬¿ÉÒÔ×ÊÖúÈ·¶¨Ä¿±êÍøÂçÉ豸ÊÇ·ñÔËÐÐÌØ¶¨µÄǶÈëʽTCP/IPЭÒéÕ»£¨Project Memoria Detector£©ºÍÓÃÓÚ¼ì²âÀàËÆÓÚNAME:WRECKµÄÎÊÌ⣨namewreck£¬ÓëJoernÒ»ÆðʹÓã©¡£


0x02 ´¦Öý¨Òé

NAME£ºWRECKµÄÐÞ¸´·¨Ê½ÊÊÓÃÓÚ FreeBSD¡¢Nucleus NETºÍ NetX£¬½¨ÒéÏÈʵʩÒÔÏÂÄþ¾²½¨Ò飬ÔÙ¼°Ê±Ó¦ÓÃÉ豸¹©Ó¦ÉÌÐû²¼µÄÄþ¾²¸üС£

Äþ¾²½¨Ò飺

ʹÓÃһЩ»º½âÐÅÏ¢À´¿ª·¢¼ì²âDNS©¶´µÄÇ©Ãû £»

·¢ÏÖ²¢ÇåµãÔËÐÐÒ×Êܹ¥»÷¶ÑÕ»µÄÉ豸 £»

ʵʩ·Ö¶Î¿ØÖƺÍÊʵ±µÄnetwork hygiene £»

¼àÊÓÊÜÓ°ÏìµÄÉ豸¹©Ó¦ÉÌÐû²¼µÄ²¹¶¡ £»

ÅäÖÃÉ豸ÒÀÀµÄÚ²¿DNS·þÎñÆ÷ £»

¼à¿ØËùÓÐÍøÂçÁ÷Á¿ÖеĶñÒâÊý¾Ý°ü¡£

 

 

0x03 ²Î¿¼Á´½Ó

https://www.bleepingcomputer.com/news/security/name-wreck-dns-vulnerabilities-affect-over-100-million-devices/

https://www.freebsd.org/security/advisories/FreeBSD-SA-20:26.dhclient.asc

https://github.com/Forescout/project-memoria-detector

https://github.com/Forescout/namewreck

 

0x04 ʱ¼äÏß

2021-04-13  bleepingcomputerÅû¶©¶´

2021-04-13  VSRCÐû²¼Äþ¾²Í¨¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png