Wi-FiÁ÷Á¿ÐÅÏ¢×ß©Îó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-02-28

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-15126 £¬£¬£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ £¬£¬£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


³§ÉÌ

×°±¸/оƬ/·ÓÉÆ÷Ãû³Æ

broadcom

bcm4356

broadcom

bcm4389

broadcom

bcm4375

broadcom

bcm43012

broadcom

bcm43013

broadcom

bcm43752

Amazon

Echo 2nd gen

Amazon

Kindle 8th gen

Apple

iPad mini 2 (ipad_os < 13.2)

Apple

iPhone 6, 6S, 8, XR (iphone_os < 13.2)

Apple

MacBook Air Retina 13-inch 2018 (mac_os < 10.15.1)

Google

Nexus 5

Google

Nexus 6

Google

Nexus 6S

Raspberry

Pi 3

Samsung

Galaxy S4 GT-I9505

Samsung

Galaxy S8

Xiaomi

Redmi 3S

Asus

RT-N12

Huawei

B612S-25d

Huawei

EchoLife HG8245H

Huawei

E5577Cs-321



Îó²î¸ÅÊö


ÍøÂçÇå¾²Ñо¿Ô±´ÓʹÓÃÆÕ±éµÄ²©Í¨ (Broadcom) ºÍ Cypress WiFi оƬÖз¢Ã÷ÁËÒ»¸öÓ²¼þÎó²î £¬£¬£¬£¬£¬ £¬£¬Ó°ÏìÊýÊ®ÒŲ́װ±¸ £¬£¬£¬£¬£¬ £¬£¬ÈçÖÇÄÜÊÖ»ú¡¢Æ½°åµçÄÔ¡¢Ìõ¼Ç±¾µçÄÔ¡¢Â·ÓÉÆ÷ºÍÎïÁªÍø×°±¸¡£¡£¡£¡£¡£¡£


¸ÃÎó²î±»³ÆÎª ¡°Kr00k¡± £¬£¬£¬£¬£¬ £¬£¬±àºÅΪ CVE-2019-15126 £¬£¬£¬£¬£¬ £¬£¬Ëü¿Éµ¼ÖÂÔ¶³Ì¹¥»÷Õß×èµ²²¢½âÃÜÒ×Êܹ¥»÷×°±¸Í¨¹ýÎÞÏß´«ÊäµÄijЩÎÞÏßÍøÂçÊý¾Ý°ü¡£¡£¡£¡£¡£¡£¸ÃÎó²î±¬·¢µÄÔµ¹ÊÔ­ÓÉÔÚÓÚ²©Í¨ºÍ Cypress оƬʹÓÃÁËÒ»¸öÈ«Áã¼ÓÃÜÃÜÔ¿ £¬£¬£¬£¬£¬ £¬£¬´Ó¶øµ¼ÖÂÊý¾Ý±»½âÃÜ £¬£¬£¬£¬£¬ £¬£¬ÆÆËðÁË WPA2-Personal ºÍ WPA2-Enterprise Ç徲ЭÒé¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÎÞÐèÅþÁ¬µ½Êܺ¦ÕßµÄÎÞÏßÍøÂç¼´¿É·¢¶¯¹¥»÷¡£¡£¡£¡£¡£¡£Ê¹Óà WPA2-Personal »ò WPA2-Enterprise ЭÒ顢ͨ¹ý AES-CCMP ¼ÓÃܱ£»£»£»£»£»¤ÍøÂçÁ÷Á¿µÄ×°±¸Ò×Êܹ¥»÷¡£¡£¡£¡£¡£¡£


Îó²îÏêÇé


ÔÚÏêÊö Kr00k ¹¥»÷֮ǰ £¬£¬£¬£¬£¬ £¬£¬ÎÒÃÇÐèÒªÏàʶÈçϼ¸µã£º


1. ¸ÃÎó²î²¢²»±£´æÓÚÎÞÏß¼ÓÃÜЭÒéÖÐ £¬£¬£¬£¬£¬ £¬£¬¶øÊÇÒòÒ×Êܹ¥»÷оƬʵÏָüÓÃÜЭÒéµÄ·½·¨²»µ±µ¼ÖµÄ£»£»£»£»£»

2. ¹¥»÷ÕßÎÞ·¨Í¨¹ý¸ÃÎó²îÅþÁ¬Óû§ WiFiÍøÂç²¢½øÒ»²½·¢¶¯ÖÐÐÄÈ˹¥»÷»òÕß¹¥»÷ÆäËüÁªÍø×°±¸£»£»£»£»£»

3. ¹¥»÷ÕßÎÞ·¨Ê¹ÓøÃÎó²î»ñϤÓû§µÄ WiFi ÃÜÂë £¬£¬£¬£¬£¬ £¬£¬ÐÞ¸Ä WiFi ÃÜÂëÎÞÖúÓÚÎÊÌâÐÞ¸´£»£»£»£»£»

4. ËüÎÞ·¨Ó°ÏìʹÓÃ×îРWiFi Çå¾²±ê×¼ WPA3 ЭÒéµÄÏÖ´ú×°±¸£»£»£»£»£»

5. È»¶ø £¬£¬£¬£¬£¬ £¬£¬Ëü¿Éµ¼Ö¹¥»÷Õßץȡ²¢½âÃÜijЩÎÞÏßÊý¾Ý°ü£¨Êýǧ×Ö½Ú£© £¬£¬£¬£¬£¬ £¬£¬µ«ÎÞ·¨Õ¹ÍûËü½«°üÀ¨ÄÄЩÊý¾Ý£»£»£»£»£»

6. ×îÖ÷ÒªµÄÊÇ £¬£¬£¬£¬£¬ £¬£¬¸ÃȱÏÝÍ»ÆÆÁËÎÞÏß²ãÉϵļÓÃÜ»úÖÆ £¬£¬£¬£¬£¬ £¬£¬µ«ºÍ TLS ¼ÓÃÜЭÒéÎÞ¹Ø £¬£¬£¬£¬£¬ £¬£¬ÒòÒÔºóÕßÈÔÈ»¿ÉÒÔ±£»£»£»£»£»¤ HTTPS Õ¾µãÍøÂçÁ÷Á¿µÄÇå¾²¡£¡£¡£¡£¡£¡£


ÔÚ WiFi ÖÐ £¬£¬£¬£¬£¬ £¬£¬×°±¸ÅþÁ¬µ½»á¼ûµã (AP) ±»³ÆÎª¡°¹ØÁª¡± £¬£¬£¬£¬£¬ £¬£¬¶Ï¿ªÅþÁ¬£¨ÈôÓÐÈË´ÓÒ»¸ö WiFi AP ÖÜÓε½ÁíÍâÒ»¸ö AP £¬£¬£¬£¬£¬ £¬£¬ÂÄÀúÁËÐźÅ×ÌÈÅ»ò¹Ø±Õ×°±¸ WiFi£©±»³ÆÎª¡°×÷·Ï¹ØÁª¡±¡£¡£¡£¡£¡£¡£


ͼ1ÌṩÁËоƬ¹ýʧµÄʾÒâͼ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Ö¸³ö £¬£¬£¬£¬£¬ £¬£¬¡°Kr00k Îó²îÔÚ×÷·Ï¹ØÁªÊ±·ºÆð¡£¡£¡£¡£¡£¡£Ò»µ©±¬·¢×÷·Ï¹ØÁªµÄÇéÐ΢٠£¬£¬£¬£¬£¬ £¬£¬ÄÚ´æ¾Í»áɨ³ý´æ´¢ÔÚÎÞÏßÍøÂç½Ó¿Ú¿ØÖÆÆ÷ (WNIC) WiFi оƬÖеĻỰÃÜÔ¿ £¬£¬£¬£¬£¬ £¬£¬¼´ÉèÖÃΪ0¢Ú¡£¡£¡£¡£¡£¡£ÕâÖÖÐÐΪÇкÏÔ¤ÆÚ £¬£¬£¬£¬£¬ £¬£¬ÓÉÓÚ×÷·Ï¹ØÁªºóÊý¾ÝÓ¦¸Ã²»ÔÙ´«Êä¡£¡£¡£¡£¡£¡£È»¶ø £¬£¬£¬£¬£¬ £¬£¬ÎÒÃÇ·¢Ã÷ £¬£¬£¬£¬£¬ £¬£¬×ÝÈ»ÔÚͨ¹ýÕâ¸öËùÓÐΪ0µÄÃÜÔ¿¼ÓÃܺó¢Û £¬£¬£¬£¬£¬ £¬£¬ÒÅÁôÔÚ¸ÃоƬ´«Ê仺³åÇøÖеÄÊý¾ÝÖ¡ÈÔÈ»»á±»´«Êä¢Ü¡£¡£¡£¡£¡£¡£¡±ÓÉÓÚËüÓÃÁËËùÓеÄ0 £¬£¬£¬£¬£¬ £¬£¬Òò´ËÕâÖÖ¡°¼ÓÃÜ¡±ÏÖʵÉϻᵼÖÂÊý¾Ý±»½âÃÜÇÒÒÔÃ÷ÎÄÐÎʽÔâ̻¶¡£¡£¡£¡£¡£¡£


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


¹¥»÷·¾¶ºÜ¼òÆÓ£ºÖÎÀí¿ò¼ÜÖÎÀí¹ØÁªºÍ×÷·Ï¹ØÁª²Ù×÷ £¬£¬£¬£¬£¬ £¬£¬µ«ÖÎÀí¿ò¼Ü×Ô¼ºÊÇδÈÏÖ¤ºÍδ¼ÓÃܵÄ¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÖ»Òª·¢ËÍÒ»¸öÌØÊâ½á¹¹µÄÖÎÀíÊý¾Ý¿ò¼Ü¾Í¿É´¥±¬·¢·Ï¹ØÁª´Ó¶ø·¢¶¯¹¥»÷ £¬£¬£¬£¬£¬ £¬£¬Ö®ºó¾ÍÄܹ»¼ìË÷ÒÅÁôÔÚ»º³åÇøÖеÄÃ÷ÎÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¼ûͼ2¡£¡£¡£¡£¡£¡£


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Òò´Ë £¬£¬£¬£¬£¬ £¬£¬µÐÊÖ¿ÉÒÔ²¶»ñ¸ü¶à°üÀ¨Ç±ÔÚÃô¸ÐÊý¾ÝµÄÍøÂç°ü £¬£¬£¬£¬£¬ £¬£¬°üÀ¨DNS¡¢ARP¡¢ICMP¡¢HTTP¡¢TCPºÍTLSÊý¾Ý°ü £¬£¬£¬£¬£¬ £¬£¬¼ûͼ3.


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Ñо¿Ö°Ô±ÌåÏÖ £¬£¬£¬£¬£¬ £¬£¬Kr00k ¹¥»÷Ò»´Î¿É̻¶×î¶à32KB Êý¾Ý £¬£¬£¬£¬£¬ £¬£¬Ï൱ÓÚÔ¼2Íò¸ö´ÊÓï¡£¡£¡£¡£¡£¡£¹¥»÷Õ߿ɷ¢ËÍһϵÁÐÖÎÀí¿ò¼Ü´¥·¢¹¥»÷²¢×îÏÈÍøÂçÊý¾Ý £¬£¬£¬£¬£¬ £¬£¬ÈçÃÜÂë¡¢ÐÅÓÿ¨ÐÅÏ¢»òÆäËüÓû§Í¨¹ýWiFi·¢Ë͵½»¥ÁªÍøÉϵÄÈκι¤¾ß¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


1.ÇëÖ±½ÓÓëÐ¾Æ¬ÖÆÔìÉÌÁªÏµÒÔ»ñÈ¡ÓйØKR00KÎó²îµÄ²¹¶¡£¡£¡£¡£¡£¡£»£»£»£»£»

2.¶ÔÊÜÓ°ÏìµÄ×°±¸¾ÙÐÐÉý¼¶¡£¡£¡£¡£¡£¡£

Òò¸ÃÎó²îÖ»ÊÇÕë¶Ô WI-FI Á÷Á¿¾ÙÐнâÃÜ¡£¡£¡£¡£¡£¡£½¨ÒéÓû§Ö»¹ÜʹÓà HTTPS/TLS ¾ÙÐÐÍøÂçͨѶ¡£¡£¡£¡£¡£¡£¸Ã·½·¨¿ÉÒÔÒ»¶¨Ë®Æ½µØ¼õ»ºÎó²î´øÀ´µÄÓ°Ïì¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://thehackernews.com/2020/02/kr00k-wifi-encryption-flaw.html

https://www.welivesecurity.com/wp-content/uploads/2020/02/ESET_Kr00k.pdf