Facebook WhatsApp TLSÁîÅÆй©©¶´¸´ÏÖ£¨CVE-2021-24027£©
Ðû²¼Ê±¼ä 2021-04-30Åä¾°
WhatsAppÊÇÃÀ¹úFacebookµÄ¼´Ê±Í¨Ñ¶Ó¦Óã¬ÔÚº£ÍâÓµÓÐÅÓ´óµÄÓû§»ùÊý¡£4ÔÂ14ÈÕ£¬Äþ¾²Ñо¿Ô±Chariton KaramitasÅû¶Android WhatsApp´æÔÚÁîÅÆ鶩¶´£¬½áºÏÆäËû©¶´¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¸Ã©¶´Ó°ÏìWhatsApp v2.21.4.18ºÍWhatsApp Business v2.21.4.18֮ǰµÄ°æ±¾£¬½¨ÒéÓû§¼°Ê±¸üе½2.21.4.18»ò¸ü¸ß°æ±¾£¬ÒÔ¹æ±Ü¸Ã©¶´´æÔڵĹ¥»÷·çÏÕ¡£
©¶´·ÖÎö
1¡¢ÁîÅÆ鶩¶´£¨CVE-2021-24027£©
¸Ã©¶´´æÔÚµÄÔÒò£¬ÊÇÓÉÓÚWhatsApp½«TLS»á»°µÇ½ºóµÄÐòÁл¯ÁîÅÆÎļþ·ÅÔÚÁËsdcardĿ¼Ï£¬¸ÃĿ¼²¢Î´ÉèÖ÷ÃÎÊȨÏÞ¡£
WhatsApp½ÓÄÉTLS1.3/TLS1.2À´½øÐпͻ§¶Ëµ½·þÎñÆ÷µÄͨÐÅ£¬ÔÚTLSÎÕÊֵĹý³ÌÖУ¬Í¨ÐÅË«·½½øÐÐÏ໥ÈÏÖ¤ºÍÃÜÔ¿ÐÉÌ£¬·þÎñÆ÷Éí·ÝÑé֤ʹÓ÷ǶԳƼÓÃÜ·½Ê½£¬¶ÔÓÚ½ÏС³ß´çµÄǶÈëʽÉ豸£¬ÕâÊÇÒ»¸ö¼ÆËãÁ¿·Ç³£´óµÄ¹ý³Ì¡£ÎªÁ˼õÉÙ¹¦ºÄ£¬½ÚÊ¡CPUÖÜÆÚ£¬Ìá³öÁ˻Ự»Ö¸´¹ý³Ì£¬µ±ÖØн¨Á¢ÎÕÊÖʱ£¬¸´ÓÃ֮ǰµÄ»á»°ÐÅÏ¢¡£
ÏÂͼÖÐΪÉèÖûỰ»º´æÎļþ¼ÐµÄ·´±àÒë´úÂë½Øͼ¼°Êµ¼ÊÎļþ·¾¶½Øͼ£¬WhatsApp½«µÇ½»á»°»º´æTLS1.2ºÍTLS1.3·Ö±ð·ÅÔÚÎļþ¼ÐSSLSessionCacheºÍwatls-sessionsÖС£ÕâЩĿ¼ÔÚ²»Êܱ£»¤µÄÍⲿ´æ´¢Ï¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÎïÀí½Ó´¥ÊÖ»ú»ñµÃÕâЩÎļþ£¬Ôì³ÉÁîÅÆй©¡£
2¡¢Ä¿Â¼´©Ô½Â©¶´
WhatsAppÓÐEmojiºÍÕÕƬÂ˾µÈȸüй¦Ð§£¬ÎÒÃÇ¿ÉÒÔÀûÓÃÖмäÈËÀ´¸Ä¶¯Emoji»òÕÕƬÂ˾µÈȸüÐÂʱµÄzip°ü¡£zipÎļþ½âѹ·´±àÒë´úÂë½ØͼÈçÏ£º
WhatsApp½øÐÐEmoji»òÕÕƬÂ˾µÈȸüÐÂʱ£¬Ã»ÓйýÂË¡±.//¡±£¬¿Éµ¼ÖÂĿ¼´©Ô½¡£Èç¹ûÊܺ¦Õß±»ÖмäÈ˽ٳ֣¬¶øÇÒ¹¥»÷Õ߸Ķ¯ÁËÈȸüÐÂzip°ü£¬ÆäÖаüÂÞÓÉ¡±.//¡±Ä¿Â¼×é³ÉµÄsoÎļþ£¬Ê¹ÆäÁýÕÖWhatsApp¶¯Ì¬Á´½Ó¿âsoÎļþ£¬½«µ¼ÖÂÈÎÒâ´úÂëÖ´ÐС£
©¶´ÀûÓÃ
Ç°ÃæÌáµ½ÐèҪͨ¹ýÎïÀí½Ó´¥»ñÈ¡ÁîÅÆ£¬¾ÖÏÞÐԽϴó¡£Èç¹û¹¥»÷ÕßÅäºÏÍøÂçµöÓ㣬·¢ËÍÒ»¸öαװµÄhtmlÎļþ¸øÊܺ¦Õߣ¬µ±Êܺ¦ÕßʹÓÃChrome£¨´æÔÚ©¶´CVE-2020-6516£©´ò¿ª´Ëhtmlʱ£¬Ö´ÐÐhtmlÖеÄjs´úÂ룬±éÀúsdcardÎļþ¼Ð²éÕÒTLS»º´æÎļþ£¬²¢°ÑÎļþ·¢Ë͵½¹¥»÷ÕßÖ¸¶¨µÄ·þÎñÆ÷ÉÏ¡£´óÖ¹ý³ÌÈçÏ£º
£¨1£©ÔÚ·¢ËÍÒ»ÌõÏûϢʱ£¬°üÂÞÏûÏ¢µÄÀàÐÍ¡¢ÏûÏ¢µÄÔ¤ÀÀͼƬ¡¢ÏûÏ¢µÄ±êÌâºÍÏûÏ¢µÄʵ¼ÊÄÚÈÝÎļþËIJ¿ÃÅ¡£Àà·¾¶X/041µÄA0l×Ö¶Îָʾ·¢ËÍÏûÏ¢µÄÀàÐÍ£¬Àà·¾¶X/0QeµÄA03×Ö¶ÎָʾÏûÏ¢µÄÔ¤ÀÀͼƬµÄbyteÊý×飬Àà·¾¶X/0NdµÄA04×Ö¶Îָʾ·¢ËÍÏûÏ¢µÄ±êÌ⣬Àà·¾¶X/0M6µÄA05(Ljava/util/List;Landroid/net/Uri;Ljava/lang/String;LX/041;LX/02l;Z)ÒªÁìΪ×îÖÕ·¢ËÍÏûϢʵ¼ÊÄÚÈÝÎļþµÄº¯Êý¡£Ïà¹Ø½ØͼÈçÏ£º
£¨2£©¹¥»÷Õß½ÓÄÉfridaµÄRPCÔ¶³Ìµ÷Óù¦Ð§´´½¨Ò»¸öº¯Êý£¬²¢ÔÚhookº¯ÊýÖÐÐ޸ĵÚÒ»²½Öдý·¢Ë͵ÄÏûÏ¢£¬½«ÏûÏ¢µÄÔ¤ÀÀͼƬ¸ü»»³É¾ßÓÐÎüÒýÁ¦µÄͼƬ£¬²¢µ÷ÓÃX/0M6µÄA05(Ljava/util/List;Landroid/net/Uri;Ljava/lang/String;LX/041;LX/02l;Z)ÒªÁ콫ÏûÏ¢·¢Ë͸øÊܺ¦Õߣ¨µÚÒ»¸ö²ÎÊýΪÓÉÊܺ¦ÕßµÄWhatsAppµØÖ·×é³ÉµÄList£¬WhatAppµØÖ·¸ñʽΪmobile_number@s.whatsapp.net£©£¬Èç¹ûÊܺ¦Õßµã»÷ͼƬ£¬µ÷ÓÃChrome´ò¿ª¶ñÒâhtmlÎļþ£¬TLS»º´æÁîÅÆ¿ÉÄܱ»·¢Ë͵½¹¥»÷Õß·þÎñÆ÷¡£
£¨3£©htmlÎļþÒªº¦²¿ÃŽØͼÈçÏ¡£ÔÚÀֳɻñÈ¡µ½TLS»º´æÎļþºó£¬ÎÒÃǼ´¿É½øÐÐÖмäÈ˹¥»÷¡£
£¨4£©ÀûÓÃEmoji»òÕÕƬÂ˾µÈȸüй¦Ð§£¬Í¨¹ýÖмäÈËÀ´¸Ä¶¯Emoji»òÕÕƬÂ˾µÈȸüÐÂÏìÓ¦zip°ü£¬´Ó¶øµ¼ÖÂÔ¶³ÌÈÎÒâ´úÂëÖ´ÐУ¨ÑÝʾÊÓƵΪÁË·½±ã£¬Ö±½ÓʹÓÃCharlesÀ´Ä£ÄâÈȸüÐÂÁýÕÖWhatsApp¶¯Ì¬Á´½Ó¿âsoÎļþ£¬À´µ½´ïRCEµÄ¹ý³Ì£©¡£
©¶´¸´ÏÖ
1¡¢ÁîÅÆ鶩¶´¸´ÏÖ
2¡¢RCE©¶´¸´ÏÖ
²Î¿¼Á´½Ó£º
[1]https://www.census-labs.com/news/2021/04/14/whatsapp-mitd-remote-exploitation-CVE-2021-24027/
[2] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24027
[3] https://github.com/CENSUS/whatsapp-mitd-mitm
[4] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6516
[5]https://bugs.chromium.org/p/chromium/issues/detail?id=1092449
[6] https://youtu.be/sdVqTEXHxxY
[7] https://youtu.be/KO_K0F4W36I
¶«Éƽ̨»ý¼«·ÀÓùʵÑéÊÒ£¨ADLab£©
ADLab½¨Á¢ÓÚ1999Ä꣬ÊÇÖйúÄþ¾²ÐÐÒµ×îÔ罨Á¢µÄ¹¥·À¼¼ÊõÑо¿ÊµÑéÊÒÖ®Ò»£¬Î¢ÈíMAPP¼Æ»®ºËÐijÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£½ØֹĿǰ£¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Äþ¾²Â©¶´½ü1100¸ö£¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Äþ¾²Â©¶´1000Óà¸ö£¬Á¬Ðø±£³Ö¹ú¼ÊÍøÂçÄþ¾²ÁìÓòÒ»Á÷Ë®×¼¡£ÊµÑéÊÒÑо¿Æ«Ïòº¸Ç²Ù×÷ϵͳÓëÓ¦ÓÃϵͳÄþ¾²Ñо¿¡¢ÖÇÄÜÖÕ¶ËÄþ¾²Ñо¿¡¢ÎïÁªÍøÖÇÄÜÉ豸Äþ¾²Ñо¿¡¢WebÄþ¾²Ñо¿¡¢¹¤¿ØϵͳÄþ¾²Ñо¿¡¢ÔÆÄþ¾²Ñо¿¡£Ñо¿½á¹ûÓ¦ÓÃÓÚ²úÎïºËÐļ¼ÊõÑо¿¡¢¹ú¼ÒÖصã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÄþ¾²·þÎñµÈ¡£