AMNESIA33£º¿ªÔ´TCP/IPЭÒéջϵÁЩ¶´·ÖÎöÓëÑéÖ¤

Ðû²¼Ê±¼ä 2020-12-14

Ç°ÑÔ


½üÆÚ£¬¹úÍâÄþ¾²Ñо¿ÈËÔ±ÔÚ¶à¸ö±»¹ã·ºÊ¹ÓõĿªÔ´TCP/IPЭÒéÕ»·¢ÏÖÁ˶à¸ö©¶´£¬ÕâһϵÁЩ¶´Í³³ÆΪAMNESIA33¡£ÕâЩ©¶´¹ã·º´æÔÚÓÚǶÈëʽºÍÎïÁªÍøÉ豸ÖУ¬Ó°ÏìÁ˶à¸öÐÐÒµÁìÓò£¨°üÂÞÒ½ÁÆ¡¢ÔËÊä¡¢ÄÜÔ´¡¢µçÐÅ¡¢¹¤Òµ¿ØÖÆ¡¢ÁãÊÛºÍÉÌÒµµÈ£©£¬Ä¿Ç°ÒÑÖª·¶Î§ÄÚÉæ¼°Á˳¬150¼Ò¹©Ó¦ÉÌÒÔ¼°ÊýÒÔ°ÙÍò¼ÆµÄÉ豸¡£ÓëURGEN11ºÍRipple20²îÒìµÄÊÇ£¬AMNESIA33Ó°ÏìµÄÊǶà¸ö¿ªÔ´TCP/IPЭÒéÕ»£¬Òò´ËÕâЩ©¶´¿ÉÒÔÇÄÎÞÉùÏ¢µØÓ°Ïìµ½ÎÞÊý¸ö´úÂë¿â¡¢¿ª·¢ÍŶÓÓë¸÷¸ö¹«Ë¾µÄ²úÎĿǰÒÑÖªµÄ©¶´Éæ¼°µ½ÁËÖÇÄܼҾӡ¢¹¤³§PLC¡¢SCADAÉ豸Ó빤¿Ø½»»»»ú£¬µçÁ¦¼à¿ØµÈÉ豸¡£


ÕâЩ©¶´´æÔÚÓÚuIP¡¢FNET¡¢picoTCPºÍNut/NetµÈ¿ªÔ´Ð­ÒéÕ»ÉÏ£¬Ó°ÏìTCP/IPЭÒéÕ»µÄ¶à¸ö×é¼þ£¬°üÂÞDNS¡¢IPv6¡¢IPv4¡¢TCP¡¢ICMP¡¢LLMNRºÍmDNSµÈ¡£ÆäÖаüÂÞ¶à¸öÑÏÖØ©¶´£¬ËüÃǵÄCVE±àºÅ·Ö±ðΪCVE-2020-17437¡¢CVE-2020-17443¡¢CVE-2020-24338¡¢CVE-2020-24336¡¢CVE-2020-25111¡£


CVE-2020-17437£¨CVSSÆÀ·Ö8.2£©¡¢CVE-2020-17443£¨CVSSÆÀ·Ö8.2£©¿Éµ¼ÖÂÉ豸¾Ü¾ø·þÎñ¡£CVE-2020-24338¡¢CVE-2020-24336¡¢CVE-2020-25111£¨ÕâÈý¸öCVSSÆÀ·Ö¾ùΪ9.8£©¶¼¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ(RCE)¡£ÆäËü28¸ö©¶´µÄÑÏÖØˮƽ¸÷Ò죬CVSSÆÀ·Ö·Ö±ð´Ó4µ½8.2¡£


ÓÉÓÚIoT¡¢OT¡¢ITÉ豸¹©Ó¦Á´µÄÌØÐÔ£¬Â©¶´Ó°ÏìµÄÉ豸Öڶ࣬ӰÏ췶Χ¹ãÇÒÁ¬Ðøʱ¼ä³¤£¬Â©¶´ÐÞ¸´µÄʵʩ½ÏÀ§ÄÑ¡£Í¬Ê±£¬ÓÉÓÚuIP¡¢picoTCP¿ªÔ´Ð­ÒéÕ»ÒѾ­²»ÔÙά»¤£¬ËùÒÔ²¿ÃÅ©¶´Ã»Óв¹¶¡£¬ºÜ¶à²úÎïÖ»ÄÜÑ°ÕÒÌæ´ú¼¼Êõ·½°¸»òÕßÊÇÔö¼Ó·À·¶´ëÊ©¡£


Òò´Ë£¬¶«É­Æ½Ì¨ADLab¶ÔÏà¹Ø©¶´½øÐÐÁË·ÖÎö£¬²¢Àֳɸ´ÏÖÁ˶à¸ö©¶´£¬¿ª·¢ÁËAMNESIA33Ïà¹Ø©¶´¼ì²â¼¼Êõ£¬²¢ÌáÈ¡ÁËÁ÷Á¿¼à¿ØÌØÕ÷£¬ÕâЩ¼¼ÊõÕýÔÚÓ¦Óõ½ÎÒÃǵÄÄþ¾²²úÎïÖС£ÎªÁË»º½â©¶´µÄÓ°Ï죬ÎÒÃÇÌá³öÏÂÁзÀ·¶½¨Òé¡£

·À·¶½¨Òé 


¶ÔÓÚÕâЩ©¶´µÄ·À·¶»º½â´ëÊ©£¬ÎÒÃǽ¨Òé½ÓÄÉÈçϼ¸¸ö´ëÊ©£º 


¡ñ ÅäÖÃÄÚÍøÉ豸µÄDNS·þÎñÆ÷ΪÄÚÍøDNS·þÎñÆ÷¡£

¡ñ Èç²»ÐëÒª£¬Çë¹Ø±ÕIPv6ÉèÖá£

¡ñ ÀûÓéɨ²úÎïʶ±ð³ö½ÓÄÉÎÊÌâЭÒéÕ»µÄÉ豸×ʲú£¬¶Ô×éÖ¯ÄÚ¿ÉÄÜ´æÔÚÎÊÌâµÄIoT¡¢OTºÍITÉ豸½øÐзçÏÕÆÀ¹À¡£

¡ñ ·À»ðǽ¼°IPS²úÎï¼ÓÈëAMNESIA33©¶´¹¥»÷ʶ±ðÌØÕ÷£¬¼à¿Ø¶ñÒâÁ÷Á¿¡£

¡ñ Èç²»ÐëÒª£¬É豸²»ÒªÌ»Â¶ÔÚ¹«Íø¡£

¡ñ ¾¡¿ÉÄܸüÐÂÏà¹ØÊÜÓ°ÏìЭÒéÕ»µ½×îа汾¡£


ϱíÊDz¿ÃÅÒѾ­ÐÞ¸´µÄЭÒéÕ»¼°°æ±¾£º


TCP/IPЭÒéÕ»

ÐÞ¸´°æ±¾

FNET

4.70¼°ÒÔÉÏ

uIP-Contiki-NG

4.6.0¼°ÒÔÉÏ

Nut/Net

5.1¼°ÒÔÉÏ



CISAÁªÃË·ÖÏíÁË13¸öÉæ¼°µ½AMNESIA33©¶´µÄ¹«Ë¾µÄ²úÎïÐÞ¸´½¨Ò飬°üÂÞÁËMicrochip¡¢SiemensµÈ¹«Ë¾µÄ²úÎÏê¼û²Î¿¼Á´½Ó[5]¡£


Ïà¹Ø¿´·¨½éÉÜ 


1¡¢DNSЭÒé½âÎö


DNSµÄÇëÇóºÍÏìÓ¦µÄ»ù±¾µ¥ÔªÊÇDNS±¨ÎÄ£¨Message£©¡£ÇëÇóºÍÏìÓ¦µÄDNS±¨ÎĽṹÊÇÍêÈ«ÏàͬµÄ£¬Ã¿¸ö±¨ÎĶ¼ÓÉÒÔÏÂÎå¶Î£¨Section£©×é³É£º


ͼƬ


DNS HeaderÊÇÿ¸öDNS±¨ÎĶ¼±ØÐëÓµÓеÄÒ»²¿ÃÅ£¬ËüµÄ³¤¶ÈÀιÌΪ12¸ö×Ö½Ú¡£Question²¿ÃÅ´æ·ÅµÄÊÇÏò·þÎñÆ÷²éѯµÄÓòÃûÊý¾Ý£¬Ò»°ãÇé¿öÏÂËüÖ»ÓÐÒ»ÌõEntry¡£Ã¿¸öEntryµÄ¸ñʽÊÇÏàͬµÄ£¬ÈçÏÂËùʾ£º


ͼƬ


QNAMEÊÇÓÉlabelsÐòÁÐ×é³ÉµÄÓòÃû¡£QNAMEµÄ¸ñʽʹÓÃDNS³ß¶ÈÃû³ÆÌåÏÖ·¨¡£Õâ¸ö×Ö¶ÎÊDZ䳤µÄ£¬Òò´ËÓпÉÄÜ·ºÆðÆæÊý¸ö×Ö½Ú£¬µ«²»½øÐв¹Æë¡£DNSʹÓÃÒ»Öֳ߶ȸñʽ¶ÔÓòÃû½øÐбàÂë¡£ËüÓÉһϵÁеÄlabel£¨ºÍÓòÃûÖÐÓÃ.Ö§½âµÄlabel²îÒ죩×é³É¡£Ã¿¸ölabelÊ××ֽڵĸßÁ½Î»ÓÃÓÚÌåÏÖlabelµÄÀàÐÍ¡£RFC1035ÖзÖÅäÁËËĸöÀïÃæµÄÁ½¸ö£¬·Ö±ðÊÇ£º00ÌåÏÖµÄÆÕͨlabel£¬11£¨0xC0£©ÌåÏÖµÄѹËõlabel¡£


Answer¡¢AuthorityºÍAdditionalÈý¸ö¶ÎµÄ¸ñʽÊÇÍêÈ«ÏàͬµÄ£¬¶¼ÊÇÓÉÁãÖÁ¶àÌõResource Record£¨×ÊÔ´¼Ç¼£©×é³É¡£ÕâЩ×ÊÔ´¼Ç¼ÒòΪ²îÒìµÄÓÃ;¶ø±»À뿪´æ·Å¡£Answer¶ÔÓ¦²éѯÇëÇóÖеÄQuestion£¬QuestionÖеÄÇëÇó²éѯ½á¹û»áÔÚAnswerÖиø³ö£¬Èç¹ûÒ»¸öÏìÓ¦±¨ÎĵÄAnswerΪ¿Õ£¬ËµÃ÷Õâ´Î²éѯûÓÐÖ±½Ó»ñµÃ½á¹û¡£


RR(Resource Record)×ÊÔ´¼Ç¼ÊÇDNSϵͳÖзdz£ÖØÒªµÄÒ»²¿ÃÅ£¬ËüÓµÓÐÒ»¸ö±ä³¤µÄ½á¹¹£¬¾ßÌå¸ñʽÈçÏ£º


ͼƬ


¡ñ NAME£ºËüÖ¸¶¨¸ÃÌõ¼Ç¼¶ÔÓ¦µÄÊÇÄĸöÓòÃû£¬¸ñʽʹÓÃDNS³ß¶ÈÃû³ÆÌåÏÖ·¨

¡ñ TYPE£º×ÊÔ´¼Ç¼µÄÀàÐÍ¡£

¡ñ CLASS£º¶ÔÓ¦QuestionµÄQCLASS£¬Ö¸¶¨ÇëÇóµÄÀàÐÍ£¬³£ÓÃֵΪIN£¬ÖµÎª0x001¡£

¡ñ TTL(Time To Live)×ÊÔ´µÄÓÐЧÆÚ£ºÌåÏÖÄã¿ÉÒÔ½«¸ÃÌõRR»º´æTLLÃ룬TTLΪ0ÌåÏÖ¸ÃRR²»Äܱ»»º´æ¡£TTLÊÇÒ»¸ö4×Ö½ÚÓзûºÅÊý£¬µ«ÊÇֻʹÓÃËü´óÓÚ¼´ÊÇ0µÄ²¿ÃÅ¡£

¡ñ RDLENGTH£ºÒ»¸öÁ½×ֽڷǸºÕûÊý£¬ÓÃÓÚÖ¸¶¨RDATA²¿Ãŵij¤¶È£¨×Ö½ÚÊý£©¡£

¡ñ RDATA£ºÌåÏÖÒ»¸ö³¤¶ÈºÍ½á¹¹¶¼¿É±äµÄ×ֶΣ¬ËüµÄ¾ßÌå½á¹¹È¡¾öÓÚTYPE×Ö¶ÎÖ¸¶¨µÄ×ÊÔ´ÀàÐÍ¡£

DNSÏìÓ¦°üÈçÏÂͼËùʾ£º


ͼƬ


´ÓÉÏͼÖпÉÖª£¬¸ÃAnswersÇø¶ÎÖдæÔÚ9¸ö×ÊÔ´¼Ç¼£¬ºì¿òÖÐÌåÏÖµÄÊÇÖ÷»úµØÖ·£¨AÀàÐÍ£©×ÊÔ´¼Ç¼¡£


Óò±êÇ©labelÔÚDNSÊý¾Ý°üÀï±»±àÂ룬ÿ¸öÆÕͨ±êÇ©µÄµÚÒ»¸ö×Ö½Ú´ú±íÕâ¸ö±êÇ©µÄ³¤¶È£¬Ê£ÏµÄ×ÖĸÊý×Ö×Ö·ûΪ±êÇ©×Ô¼º(һЩÌØÊâ×Ö·ûÒ²ÊÇ¿ÉÒÔµÄ)£¬µ«ÊÇ×îÖÕ½áβµÄ×Ö·ûÒ»¶¨ÊÇÒÔ¿Õ×Ö½Ú½áβ(¼´0x00)£¬ÓÃÀ´ÌåÏÖÓòÃûµÄ½áÊø¡£¾Ù¸öÀý×Ó£¬ÈçÏÂͼËùʾ£¬Óò±êÇ©µÚÒ»¸ö×Ö·ûÊÇ0x03£¬Õâ´ú±íµÚÒ»¸ö±êÇ©³¤¶ÈΪ3(¼´0x77 0x77 0x77 == ¡°www¡±)£¬Í¬Àí£¬0x62 0x61 0x690x64 0x75 == ¡°baidu¡±£¬×îºó¿ÉÒÔ¿´µ½ÒÔ0x00½áβ¡£


ͼƬ


2¡¢TCP½ô¼±Ä£Ê½


ΪÁË·¢ËÍÖØҪЭÒéÊý¾Ý,TCPÌṩÁËÒ»ÖÖ³ÆΪ½ô¼±Ä£Ê½(urgentmode)µÄ»úÖÆ£¬TCPЭÒéÔÚÊý¾Ý¶ÎÖÐÉèÖÃURGλ,ÌåÏÖ½øÈë½ô¼±Ä£Ê½¡£Í¨¹ýÉèÖýô¼±Ä£Ê½£¬·¢ËÍ·½¿ÉÒÔÔÚ·¢ËÍÐÐÁÐÖÐÓÅÏÈ·¢ËÍÕⲿÃŵÄÊý¾Ý£¬¶øÇÒ²»ÓÃÔÚ·¢ËÍÐÐÁÐÖÐÅŶÓ£¬¶ø½ÓÊÕ·½¿ÉÒÔ¶Ô½ô¼±Ä£Ê½½ÓÄÉÌØÊâµÄ´¦Öá£ÕâÖÖ·½Ê½Êý¾Ý²»ÈÝÒ×½ÓÊܱ»×èÈû,·þÎñÆ÷¶Ë·¨Ê½»áÓÅÏȽÓÊÜÕâЩ½ô¼±µÄÊý¾Ý£¬¶ø²»ÓýøÐÐÅŶӴ¦Öá£ÔÚTCP±¨ÎÄÖнç˵ÁËÁ½¸ö×Ö¶ÎÀ´±êʾ½ô¼±Ä£Ê½£¬Ò»¸öURG±êÖ¾£¬¸Ã±êÖ¾ÌåÏÖ±¨ÎÄÖÐÓнô¼±Êý¾Ý£¬ÁíÒ»¸ö±êÖ¾Êǽô¼±Ö¸Õ룬Ëü±êʾ½ô¼±Êý¾ÝÔÚ´«ÊäÊý¾ÝÖÐÆ«ÒÆλÖá£ÈçÏÂͼËùʾ£º


ͼƬ


©¶´·ÖÎö 


ÏÂÃæÎÒÃǶԼ¸¸öCVSSÆÀ·Ö½Ï¸ßµÄ©¶´½øÐзÖÎö£º


1¡¢CVE-2020-17437


CVE-2020-17437´æÔÚÓÚuIPЭÒéÕ»µÄuip.cÎļþµÄuip_processº¯ÊýÖУ¬¸Ãº¯ÊýÖ÷ÒªÊÇ´¦ÖÃip/tcp±¨ÎÄ£¬ÏÂͼÊÇuIPЭÒéÕ»¶ÔTCP±¨ÎÄÖдøÓÐTCP_URG½ô¼±Ö¸Õë±êʶʱµÄ´¦ÖôúÂ룬Èç¹û±àÒëʱÅäÖÃÁËUIP_URGDATA£¬Ôò·¨Ê½»á×ßµ½ÏÂÃæµÄif·ÖÖ§£¬¶Ô½ô¼±Ö¸ÕëÊý¾Ý½øÐÐרÃÅ´¦Öá£


µ«ÊÇÔÚĬÈÏÇé¿öÏ£¬UIP_URGDATA²¢Ã»ÓÐÅäÖᣴúÂë»á½øÈëµ½else·ÖÖ§£¬·¨Ê½»áÌø¹ý´¦Öýô¼±Ö¸ÕëÊý¾Ý£¬²¢ÐÞ¸Äuip_lenµÄÊýÖµ¡£·¨Ê½ÔÚÐÞ¸Äuip_lenµÄʱºò²¢Ã»ÓÐÅжϽô¼±Ö¸ÕëµÄÖµ£¬µ±uip_lenµÄÖµÌرðС£¬¶ø½ô¼±Ö¸ÕëµÄÖµurgpÌرð´óʱ£¬¾Í»áÒýÆðÕûÊýÒç³ö£¬µ¼ÖÂÉ豸ÖØÆô»òÕßÊÇÔ½½ç¶Áд¡£


ͼƬ


2¡¢CVE-2020-24338


¸Ã©¶´·ºÆðÔÚpicoTCP/IPЭÒéÕ»ÖнâÎöÓòÃûlabelµÄpico_dns_decompress_name()º¯ÊýÖУ¬¸Ãº¯Êý¾ßÌåʵÏÖÈçÏ´úÂëËùʾ£º


ͼƬ


µÚ95¡¢96Ðгõʼ»¯iterator£¬nameÖ¸Ïò´ý½âѹËõµÄlabels£¬dest_iteratorÖ¸Ïò´æ·Å½âѹ³öÀ´µÄlabelsµÄ»º³åÇø£¬¾ÞϸΪ256×Ö½Ú¡£µÚ97ÐпªÊ¼ÎªwhileÑ­»·£¬¶ÁÈ¡µ½×Ö·û´®½áβ¿Õ×Ö½ÚÍ˳ö¡£µÚ98ÐУ¬Í¨¹ýiterator&0xC0ÅжÏlabelÀàÐÍ£¬Èç¹ûΪѹËõlabel£¬Ôòͨ¹ýpacket¶¨Î»µ½ÆÕͨlabelËùÔÚµÄλÖã¬Èç¹ûΪÆÕͨlabelÖ±½Ó½øÈëelse´úÂë¿éÖУ¬µÚ107ÐУ¬µ÷ÓÃmemcpy½«ÆÕͨlabel¿½±´µ½dest_iteratorÖС£ÎÒÃÇÖªµÀdest_iterator»º³åÇø¾ÞϸֻÓÐ256×Ö½Ú£¬¶øwhileÑ­»·Í˳öÌõ¼þΪ¶Áµ½×Ö·û´®½áβ¿Õ×Ö½Ú£¬Òò´Ëµ±name³¤¶ÈÁè¼Ý256×Ö½Úʱ£¬µ¼ÖÂdest_iterator»º³åÇøÒç³ö¡£


3¡¢CVE-2020-24336


¸Ã©¶´·ºÆðÔÚcontikiЭÒéÕ»ÖеÄip64_dns64_4to6()ÖУ¬¸Ãº¯Êý¹¦Ð§Êǽ«ipv4ÀàÐ͵ÄDNSÊý¾Ý°üת»»³Éipv6ÀàÐ͵ÄDNSÊý¾Ý°ü£¬Òªº¦´úÂëÈçÏ£º


ͼƬ


±éÀúAnswerÇø¶Î²¢¸üе½ipv6ÀàÐ͵ÄAnswerÇø¶ÎÖС£´ÓµÚ209ÐпªÊ¼×ª»»×ÊÔ´¼Ç¼£¬¾ßÌåʵÏÖ´úÂëÈçÏÂËùʾ£º


ͼƬ


Ê×ÏÈÅжÏTYPEÊÇ·ñÊÇDNS_TYPE_A£¬DNS_TYPE_AÌåÏÖ¸Ã×ÊÔ´¼Ç¼Ϊipv4Ö÷»úµØÖ·£¬È»ºó½«¶ÔÓ¦Çø¶Î¿½±´µ½acopyÖС£µÚ220ÐУ¬´Ó×ÊÔ´¼Ç¼ÖÐÖ±½ÓÈ¡RDLENGTH£¬Ç°ÎÄÒѽéÉÜ£¬¸ÃÇø¶Î±íÕ÷RDATAµÄ³¤¶È¡£µÚ227ÐУ¬ÅжÏlen³¤¶ÈÊÇ·ñ¼´ÊÇ4£¬ÕâÀïÕý³£Çé¿ö£¬lenÓ¦¸ÃΪ4£¬ÒòΪipv4µØÖ·³¤¶ÈΪ4¸ö×Ö½Ú¡£Èç¹ûlen²»¼´ÊÇ4£¬Ôò½øÈëelseÓï¾äÖУ¬Ö±½Óµ÷ÓÃmemcpy½øÐÐRDATAÊý¾Ý¿½±´¡£ÕâÀïÊÇ´æÔÚÎÊÌâµÄ£¬Ipv4Ö÷»úµØÖ·³¤¶È²»¼´ÊÇ4£¬²¢Ã»ÓÐÑéÖ¤Ö÷»úµØÖ·µÄºÏÀíÐÔ¶øÇÒlen×î´óΪ0xFFFF£¬Ö±½Ó¿½±´¿ÉÄܵ¼Ö»º³åÇøÒç³ö¡£


4¡¢CVE-2020-25111


ÔÚʹÓÃNut/NetЭÒéÕ»µÄÉ豸ÖУ¬NutDnsGetResourceAll()ÊÇ´¦ÖÃDNSÇëÇóµÄº¯Êý£¬ÆäÖд¦ÖÃDNS»Ø¸´µÄº¯ÊýÊÇDecodeDnsQuestion()£¬´¦ÖÃÓò±êÇ©µÄº¯ÊýÊÇScanName()£¬Â©¶´¾Í·ºÆðÔÚScanName()º¯ÊýÖС£ÈçÏÂͼËùʾ£¬cpΪָÏòÓòÃûµÚÒ»¸ö×Ö½ÚµÄÖ¸Õë(¼´µÚÒ»¸öÓò±êÇ©µÄ³¤¶È×Ö½Ú)£¬*nppΪ¼´½«±»½âÎöµÄÓòÃûbuffer£¬Í¨¹ýstrlen()½«Õû¸öÓòÃû³¤¶È¸³Öµ¸ørc,È»ºó»ùÓÚrc·ÖÅä*npp buffer£¬Ö®ºóͨ¹ýÒ»¸öwhile£¬Ñ­»·´¦ÖÃÿһ¸ölabel¡£ÎÊÌâÏÔ¶øÒ×¼û£¬cpÊǹ¥»÷Õ߿ɿصÄ£¬ÓÉ´Ë¿ÉÒÔ¿ØÖÆ*nppµÄ¾Þϸ¡£¶ø¶ÔÓÚ±êÇ©µÄ³¤¶È£¬¼´len±äÁ¿£¬Ö±½Ó´ÓÊý¾Ý°üÖеõ½£¬²¢Ã»ÓÐ×öÈκνçÏÞ¼ì²é£¬È»ºóͨ¹ýwhileÑ­»·´¦Öá£Òò´Ë¿ÉÒÔ¶ÔlenÉèÖÃÈÎÒâµÄÖµ£¬¼´¹¥»÷Õ߶Ô*npp buffer¿É¿ØµÄ³¤¶È¡£ÓÉ´Ë¿ÉÒÔÔÚ¶ÑÖÐÔì³ÉÔ½½çд£¬Õâ¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ(RCE)¡£


ͼƬ


5¡¢CVE-2020-17443


CVE-2020-17443´æÔÚÓÚPicoTCPЭÒéÕ»pico_icmp6.cÎļþÖС£ÎÊÌâ´úÂëλÓÚpico_icmp6_send_echoreply£¨£©º¯ÊýÖУ¬¸Ãº¯ÊýµÄÖ÷Òª¹¦Ð§Êǻظ´ICMPv6Ó¦´ðÊý¾Ý°üÒÔÏìÓ¦¶Ô¶ËµÄICMPv6Echo(ping)ÇëÇó¡£


ͼƬ


ÎÒÃÇ¿ÉÒÔ¿´µ½£¬µÚ68ÐУ¬replay½á¹¹µÄ»º³å¾Þϸ»ùÓÚechoµÄ±¨ÎÄÖÐtransport_len±äÁ¿¡£ÔÚµÚ84ÐУ¬·¨Ê½´Óecho->payloadÏòreply->payloadµØÖ·¸´ÖÆÁ˳¤¶ÈΪecho->transport_len- 8¾ÞϸµÄÊý¾Ý¡£


×¢Ò⣬Èç¹ûecho->transport_lenСÓÚ 8£¬echo->transport_len - 8»áµ¼ÖÂÕûÊýÒç³ö£¬memcpy²Ù×÷»áµ¼Ö»º³åÇøÒç³ö¡£


ÔÚPicoTCPЭÒéÕ»¹¥»÷Õßͨ¹ý½á¹¹¶ñÒâµÄICMPv6Êý¾Ý°ü£¬Õâ¸ö¶ñÒâµÄÊý¾Ý°üICMP±¨Í·Ð¡ÓÚ8£¬»áµ¼ÖÂÉ豸ÖØÆô»ò¾Ü¾ø·þÎñ¡£


©¶´ÑéÖ¤


©¶´ÑéÖ¤ÊÓƵÇë¼ì²ìADLab¹«ÖÚºÅ


²Î¿¼Á´½Ó£º


[1] https://www.forescout.com/research-labs/amnesia33/[2]https://www.securityweek.com/amnesia33-vulnerabilities-tcpip-stacks-expose-millions-devices-attacks

[3] https://www.zdnet.com/article/amnesia33-vulnerabilities-impact-millions-of-smart-and-industrial-devices/

[4] https://tools.ietf.org/html/rfc1035

[5] https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01


¶«É­Æ½Ì¨»ý¼«·ÀÓùʵÑéÊÒ£¨ADLab£©


ADLab½¨Á¢ÓÚ1999Ä꣬ÊÇÖйúÄþ¾²ÐÐÒµ×îÔ罨Á¢µÄ¹¥·À¼¼ÊõÑо¿ÊµÑéÊÒÖ®Ò»£¬Î¢ÈíMAPP¼Æ»®ºËÐijÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£½ØֹĿǰ£¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Äþ¾²Â©¶´½ü1100¸ö£¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Äþ¾²Â©¶´900Óà¸ö£¬Á¬Ðø±£³Ö¹ú¼ÊÍøÂçÄþ¾²ÁìÓòÒ»Á÷Ë®×¼¡£ÊµÑéÊÒÑо¿Æ«Ïòº­¸Ç²Ù×÷ϵͳÓëÓ¦ÓÃϵͳÄþ¾²Ñо¿¡¢Òƶ¯ÖÇÄÜÖÕ¶ËÄþ¾²Ñо¿¡¢ÎïÁªÍøÖÇÄÜÉ豸Äþ¾²Ñо¿¡¢WebÄþ¾²Ñо¿¡¢¹¤¿ØϵͳÄþ¾²Ñо¿¡¢ÔÆÄþ¾²Ñо¿¡£Ñо¿½á¹ûÓ¦ÓÃÓÚ²úÎïºËÐļ¼ÊõÑо¿¡¢¹ú¼ÒÖصã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÄþ¾²·þÎñµÈ¡£


adlab.jpg