Wi-Fi WPA2 ¡°Kr00k¡±Â©¶´·ÖÎöÓ븴ÏÖ

Ðû²¼Ê±¼ä 2020-03-26

1.Ñо¿Åä¾°


ÔÚ½ñÄê2Ô·ݵÄRSA´ó»áÉÏ£¬ESETµÄÑо¿ÈËÔ±¹ûÈ»Åû¶Wi-FiоƬ´æÔÚÑÏÖØÄþ¾²Â©¶´CVE-2019-15126£¬²¢½«ÆäÃüÃûΪ¡°Kr00k¡±¡£¹¥»÷Õß¿ÉÒÔÀûÓá°Kr00k¡±½âÃÜÎÞÏßÍøÂçÁ÷Á¿£¬»ñÈ¡´«Êä¹ý³ÌÖеÄÃô¸ÐÊý¾Ý¡£


Kr00k©¶´Ó°Ï첿ÃÅ°²×°BroadcomºÍCypress Wi-FiоƬµÄÉ豸£¬ÕâÁ½¼ÒоƬ²úÎï±»¹ã·ºÓ¦ÓÃÓÚÊÖ»ú¡¢Æ½°åµçÄÔ¼°IOTÉ豸ÖС£ÊؾÉÔ¤¼Æ£¬È«Çò×ܼÆÁè¼Ý10ÒÚµÄÉ豸Êܸ鶴µÄÓ°Ïì¡£


2.©¶´·ÖÎö


2.1 ©¶´Ô­Àí


ÔÚ½éÉÜKr00k©¶´Ö®Ç°£¬Ïȼòµ¥Á˽âÏÂWPA2ЭÒ顣Ŀǰ»ùÓÚAES-CCMPµÄWPA2ЭÒéÊÇWi-FiÍøÂçÖÐ×îÆÕ±éµÄ³ß¶È¡£ÏÂͼÊÇ¿Í»§¶Ë£¨Station, STA£©Á¬½Ó½ÓÈëµã£¨Access Point, AP£©µÄÏûÏ¢½»»¥¹ý³Ì¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


STAºÍAPÔÚËÄ´ÎÎÕÊÖÖУ¬Ð­É̻ỰÃÜÔ¿PTK£¨Pairwise Transient Key£©£¬PTKÊÇÓÉPMKºÍPKE¼ÆËãÉú³É£¬¶øPMKÓÉANonce¡¢SNonceºÍË«·½MACµØÖ·µÈ¼ÆËãÉú³É¡£PTK·ÖΪKCK¡¢KEKºÍTKÈý²¿ÃÅ£¬ÆäÖУ¬KCKÓÃÓÚMICУÑ飬KEKÓÃÓÚ¼ÓÃÜGTK£¬TKΪÊý¾Ý¼ÓÃÜÃÜÔ¿¡£ËÄ´ÎÎÕÊÖÍê³Éºó£¬´«ÊäÊý¾ÝʹÓÃTK½øÐмÓÃÜ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚWPA2ЭÒéÖУ¬½â³ý¹ØÁª²Ù×÷¿ÉÒÔÓÉδ¾­Éí·ÝÑéÖ¤ºÍδ¼ÓÃܵĹÜÀíÖ¡´¥·¢£¬Kr00k©¶´Óë½â³ý¹ØÁª²Ù×÷ÃÜÇÐÏà¹Ø¡£ÔÚÏÂͼËùʾÖУ¬µ±Õ¾µãµÄÁ¬½Ó»á»°½â³ý¹ØÁªºó£¬Éú´æÔÚWi-FiоƬÖеĻỰÃÜÔ¿(TK)±»ÖÃÁ㣬Èç¹ûʹÓÃÒÑÖÃÁãµÄTKÃÜÔ¿¶ÔоƬ»º´æÖеÄÊý¾Ý½øÐмÓÃܲ¢´«Ê䣬½«µ¼Ö©¶´·¢Éú¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹¥»÷ÕßÀûÓÃÎÞÏßÍø¿¨¼´¿ÉÍê³ÉÈëÇÖ£¬Í¨¹ý²»Í£´¥·¢½â³ý¹ØÁª¡¢ÖØйØÁª£¬È»ºóʹÓÃÈ«ÁãTK¶Ô²¶×½µÄÊý¾ÝÖ¡½øÐнâÃÜ£¬´Ó¶ø»ñÈ¡Ãô¸ÐÐÅÏ¢¡£


2.2 ¹Ì¼þ·ÖÎö


±¾ÎÄÑ¡È¡Nexus5ÖеÄBCM4339оƬ¹Ì¼þ½øÐзÖÎö¡£Ê×ÏÈ£¬¶¨Î»¹Ì¼þÖмÆËãptkµÄλÖã¬ÈçÏÂͼËùʾ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


È»ºó£¬¶ÔÆäÉϲ㺯Êýwlc_wpa_sup_eapol½øÐзÖÎö¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


wlc_wpa_sup_eapolµ÷ÓÃwpa_pmk_to_ptkʱ£¬´«ÈëµÄ²ÎÊý·Ö±ðΪmac1¡¢mac2¡¢Nonce1¡¢Nonce2¡¢pmk¡¢pmk_len¡¢ptk¡¢ptk_len¡£ptk¼ÆËã½á¹û±»Éú´æÔÚwpa_ptk½á¹¹ÌåÆ«ÒÆ0x8cλÖÃÖС£


wlc_sup_attachº¯ÊýÓÃÓÚ´¦ÖÃSTAµÄ³õʼ»¯Á¬½Ó£¬¸Ãº¯Êý¶Ôwpa_ptk½á¹¹Ìå½øÐÐÄÚ´æ·ÖÅäºÍ³õʼ»¯£¬wpa_ptk½á¹¹Ìå¾ÞϸΪ0x13C¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


µ±³õʼ»¯Ê§°Ü¡¢Á¬½Ó³¬Ê±»ò½â³ýÁ¬½ÓµÄʱºò£¬Ôò»áµ÷ÓÃwlc_sup_detachº¯Êý¶Ôwpa_ptk½á¹¹Ìå½øÐÐÖÃÁã²Ù×÷¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


3.©¶´ÑéÖ¤


3.1 ²âÊÔ»·¾³



É豸Ãû³Æ

ÊýÁ¿

ÊÜÓ°ÏìµÄÉ豸

Nexus5

1

iphone6sÊÖ»ú

1

Attacker

NETGEARÍø¿¨

2

3.2 ²âÊÔ²½Öè


£¨1£©¶Ôwireshark½âÃÜÊý¾Ý°üµÄÏà¹Ø¹¦Ð§½øÐÐpatch£¬Ê¹ÆäÄܹ»ÀֳɽâÃÜÈ«ÁãTK¼ÓÃܵÄÊý¾Ý¡£

£¨2£©Ê¹ÓÃpatchºóµÄwireshark¼àÌýÄ¿±êÉ豸ºÍAPͨÐŵÄÊý¾Ý°ü¡£

£¨3£©Ê¹ÓÃÄ¿±êÉ豸Á¬½ÓAP²¢ÈÎÒâ·ÃÎÊÍøÒ³¡£

£¨4£©¶ÔAPºÍ²âÊÔÄ¿±ê·¢ËÍDisassocation°ü¡£

£¨5£©Öظ´Ö´Ðв½Ö裨3£©ºÍ£¨4£©£¬ÊÓ²ìwiresharkÖÐÊý¾Ý°üÊÇ·ñ½âÃÜ¡£


3.3 ²âÊÔ½á¹û


Nexus 5£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


iphone 6s£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿ÉÒÔ¿´³ö£¬Nexus 5ºÍiphone 6s²¿ÃÅÊý¾Ý±»ÀֳɽâÃÜ¡£


4.Ó°Ï췶Χ


Ä¿Ç°ÒÑÖªÊÜÓ°ÏìµÄÉ豸ÓУº

Amazon Echo 2nd gen

Amazon Kindle 8th gen

Apple iPad mini 2

Apple iPhone 6, 6S, 8, XR

Apple MacBook Air Retina 13-inch 2018

Google Nexus 5

Google Nexus 6

Google Nexus 6P

Raspberry Pi 3

Samsung Galaxy S4 GT-I9505

Samsung Galaxy S8

Xiaomi Redmi 3S

Asus RT-N12

Huawei B612S-25d

Huawei EchoLife HG8245H

Huawei E5577Cs-321


5.Äþ¾²½¨Òé


É豸ÖÆÔìÉÌÒÑÐû²¼µÄÄþ¾²½¨ÒéÈçÏ£º

?https://support.apple.com/en-us/HT210721

?https://support.apple.com/en-us/HT210722

?https://support.apple.com/en-us/HT210788

?https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-003.txt

?https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200226-wi-fi-info-disclosure

?https://www.huawei.com/en/psirt/security-notices/huawei-sn-20200228-01-kr00k-en

?https://www.microchip.com/design-centers/wireless-connectivity/embedded-wi-fi/kr00k-vulnerability

?https://www.mist.com/documentation/mist-security-advisory-kr00k-attack-faq/

?https://www.zebra.com/us/en/support-downloads/lifeguard-security/kr00k-vulnerability.html