¡¾Â©¶´Í¨¸æ¡¿À¶ÑÀ & WiFi оƬ12Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2021-12-14


0x00 ©¶´¸ÅÊö

2021Äê12ÔÂ13ÈÕ £¬¶à¸öÑо¿»ú¹¹ÁªºÏÐû²¼ÁËÀ¶ÑÀ¼°WiFi¼Ü¹¹ºÍЭÒéÖеĶà¸öÄþ¾²Â©¶´ £¬ÕâЩ©¶´Ó°ÏìÁËÊýÊ®ÒÚWiFiºÍÀ¶ÑÀоƬ £¬¹¥»÷ÕßÄܹ»ÀûÓ鶴Õë¶ÔÉ豸µÄÀ¶ÑÀ×é¼þÌáÈ¡ÃÜÂë²¢¼à¿ØWiFiоƬÉϵÄÁ÷Á¿¡£

 

0x01 ©¶´ÏêÇé

image.png

ÏÖ´úÏû·ÑÀàµç×ÓÉ豸£¨ÈçÖÇÄÜÊÖ»ú£©µÄSoC¾ßÓжÀÁ¢µÄÀ¶ÑÀ¡¢WiFiºÍLTE×é¼þ £¬Ã¿¸ö×é¼þ¶¼ÓÐ×Ô¼ºµÄרÓÃÄþ¾²ÊµÏÖ £¬µ«ÕâЩ×é¼þͨ³£¹²ÏíÏàͬµÄ×ÊÔ´ £¬¿ÉÒÔ½«ÕâЩ¹²Ïí×ÊÔ´ÓÃ×÷¿çÎÞÏßоƬ½çÏÞÌᳫºáÏòȨÏÞÌáÉý¹¥»÷µÄÇÅÁº £¬ÒÔʵÏÖ´úÂëÖ´ÐС¢ÄÚ´æ¶ÁÈ¡ºÍ¾Ü¾ø·þÎñµÈ¡£

image.png

ΪÁËÀûÓÃÕâЩ©¶´ £¬Ê×ÏÈÐèÒªÔÚÀ¶ÑÀ»ò WiFi оƬÉÏÖ´ÐдúÂë £¬Ò»µ©ÊµÏÖ £¬¾Í¿ÉÒÔʹÓù²ÏíÄÚ´æ×ÊÔ´¶ÔÉ豸µÄÆäËûоƬ½øÐкáÏò¹¥»÷¡£ÕâЩ©¶´°üÂÞ£º

l  CVE-2020-10368£ºWiFi δ¼ÓÃÜÊý¾Ýй¶£¨¼Ü¹¹£©

l  CVE-2020-10367£ºWi-Fi ´úÂëÖ´ÐУ¨¼Ü¹¹£©

l  CVE-2019-15063£ºWi-Fi ¾Ü¾ø·þÎñ£¨Ð­Ò飩

l  CVE-2020-10370£ºÀ¶ÑÀ¾Ü¾ø·þÎñ£¨Ð­Ò飩

l  CVE-2020-10369£ºÀ¶ÑÀÊý¾Ýй¶£¨Ð­Ò飩

l  CVE-2020-29531£ºWiFi ¾Ü¾ø·þÎñ£¨Ð­Ò飩

l  CVE-2020-29533£ºWiFi Êý¾Ýй©£¨Ð­Ò飩

l  CVE-2020-29532£ºÀ¶ÑÀ¾Ü¾ø·þÎñ£¨Ð­Ò飩

l  CVE-2020-29530£ºÀ¶ÑÀÊý¾Ýй¶£¨Ð­Ò飩

ÕâЩ©¶´´æÔÚÓÚBroadcom¡¢Silicon Labs ºÍ Cypress µÈÖÆÔìÉÌÉú²úµÄоƬÖÐ £¬¶øÕâЩоƬӦÓÃÓÚÊýÊ®ÒÚµç×ÓÉ豸ÖС£Ñо¿ÈËÔ±Õë¶Ô CVE-2020-10368 ºÍ CVE-2020-10367 ²âÊÔµÄÉ豸ÈçÏ£º

image.png

 

0x02 ´¦Öý¨Òé

Ä¿Ç°ÕâЩ©¶´ÔÝδÍêÈ«ÐÞ¸´¡£½¨ÒéʹÓÃÈçϱ £»¤´ëÊ©£º

l  ɾ³ý²»ÐëÒªµÄÀ¶ÑÀÉ豸Åä¶Ô £»

l  ´ÓÉèÖÃÖÐɾ³ý²»Ê¹ÓÃµÄ WiFi ÍøÂç £»

l  ÔÚ¹«¹²³¡ËùʹÓÃÊÖ»ú·ÃÎÊ»¥ÁªÍø¶ø²»ÊÇ WiFi¡£

²Î¿¼Á´½Ó£º

https://arxiv.org/pdf/2112.05719.pdf

 

0x03 ²Î¿¼Á´½Ó

https://www.bleepingcomputer.com/news/security/bugs-in-billions-of-wifi-bluetooth-chips-allow-password-data-theft/

https://securityaffairs.co/wordpress/125585/hacking/wifi-chip-coexistence-attacks.html?utm_source=rss&utm_medium=rss&utm_campaign=wifi-chip-coexistence-attacks

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-12-14

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

¶¶È¦Îª¶Ä¶øÉú¼ò½é

¶¶È¦Îª¶Ä¶øÉú¹«Ë¾½¨Á¢ÓÚ1996Äê £¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊÐ £¬ÊǹúÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÄþ¾²²úÎï¡¢¿ÉÐÅÄþ¾²¹ÜÀíƽ̨¡¢Äþ¾²·þÎñÓë½â¾ö·½°¸µÄ×ÛºÏÌṩÉÌ¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ° £¬ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹ £¬ÓµÓÐÁýÕÖÈ«¹úµÄÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÖÐÐÄ £¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖݵȶàµØÉèÓÐÑз¢ÖÐÐÄ¡£

¶àÄêÀ´ £¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ £¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ £¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Å¬Á¦¡£


¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú

¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£

¹Ø×¢ÒÔϹ«ÖںŠ£¬»ñÈ¡È«Çò×îÐÂÄþ¾²×ÊѶ£º

image.png