Wi-Fi WPA2 ¡°Kr00k¡±Îó²îÆÊÎöÓ븴ÏÖ
Ðû²¼Ê±¼ä 2020-03-261.Ñо¿Åä¾°
ÔÚ½ñÄê2Ô·ݵÄRSA´ó»áÉÏ£¬£¬£¬ESETµÄÑо¿Ö°Ô±¹ûÕæÅû¶Wi-FiоƬ±£´æÑÏÖØÇå¾²Îó²îCVE-2019-15126£¬£¬£¬²¢½«ÆäÃüÃûΪ¡°Kr00k¡±¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓá°Kr00k¡±½âÃÜÎÞÏßÍøÂçÁ÷Á¿£¬£¬£¬»ñÈ¡´«ÊäÀú³ÌÖеÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£
Kr00kÎó²îÓ°Ï첿·Ö×°ÖÃBroadcomºÍCypress Wi-FiоƬµÄ×°±¸£¬£¬£¬ÕâÁ½¼ÒоƬ²úÆ·±»ÆÕ±éÓ¦ÓÃÓÚÊÖ»ú¡¢Æ½°åµçÄÔ¼°IOT×°±¸ÖС£¡£¡£¡£¡£¡£ÊؾÉÔ¤¼Æ£¬£¬£¬È«Çò×ܼÆÁè¼Ý10ÒÚµÄ×°±¸ÊܸÃÎó²îµÄÓ°Ïì¡£¡£¡£¡£¡£¡£
2.Îó²îÆÊÎö
2.1 Îó²îÔÀí
ÔÚÏÈÈÝKr00kÎó²î֮ǰ£¬£¬£¬ÏȼòÆÓÏàʶÏÂWPA2ÐÒé¡£¡£¡£¡£¡£¡£ÏÖÔÚ»ùÓÚAES-CCMPµÄWPA2ÐÒéÊÇWi-FiÍøÂçÖÐ×îÆÕ±éµÄ±ê×¼¡£¡£¡£¡£¡£¡£ÏÂͼÊǿͻ§¶Ë£¨Station, STA£©ÅþÅþÁÚÈëµã£¨Access Point, AP£©µÄÐÂÎŽ»»¥Àú³Ì¡£¡£¡£¡£¡£¡£
STAºÍAPÔÚËÄ´ÎÎÕÊÖÖУ¬£¬£¬ÐÉ̻ỰÃÜÔ¿PTK£¨Pairwise Transient Key£©£¬£¬£¬PTKÊÇÓÉPMKºÍPKEÅÌËãÌìÉú£¬£¬£¬¶øPMKÓÉANonce¡¢SNonceºÍË«·½MACµØµãµÈÅÌËãÌìÉú¡£¡£¡£¡£¡£¡£PTK·ÖΪKCK¡¢KEKºÍTKÈý²¿·Ö£¬£¬£¬ÆäÖУ¬£¬£¬KCKÓÃÓÚMICУÑ飬£¬£¬KEKÓÃÓÚ¼ÓÃÜGTK£¬£¬£¬TKΪÊý¾Ý¼ÓÃÜÃÜÔ¿¡£¡£¡£¡£¡£¡£ËÄ´ÎÎÕÊÖÍê³Éºó£¬£¬£¬´«ÊäÊý¾ÝʹÓÃTK¾ÙÐмÓÃÜ¡£¡£¡£¡£¡£¡£
ÔÚWPA2ÐÒéÖУ¬£¬£¬É¨³ý¹ØÁª²Ù×÷¿ÉÒÔÓÉδ¾Éí·ÝÑéÖ¤ºÍδ¼ÓÃܵÄÖÎÀíÖ¡´¥·¢£¬£¬£¬Kr00kÎó²îÓëɨ³ý¹ØÁª²Ù×÷Ç×½üÏà¹Ø¡£¡£¡£¡£¡£¡£ÔÚÏÂͼËùʾÖУ¬£¬£¬µ±Õ¾µãµÄÅþÁ¬»á»°É¨³ý¹ØÁªºó£¬£¬£¬ÉúÑÄÔÚWi-FiоƬÖеĻỰÃÜÔ¿(TK)±»ÖÃÁ㣬£¬£¬ÈôÊÇʹÓÃÒÑÖÃÁãµÄTKÃÜÔ¿¶ÔоƬ»º´æÖеÄÊý¾Ý¾ÙÐмÓÃܲ¢´«Ê䣬£¬£¬½«µ¼ÖÂÎó²î±¬·¢¡£¡£¡£¡£¡£¡£
¹¥»÷ÕßʹÓÃÎÞÏßÍø¿¨¼´¿ÉÍê³ÉÈëÇÖ£¬£¬£¬Í¨¹ýÒ»Ö±´¥·¢É¨³ý¹ØÁª¡¢ÖØÐ¹ØÁª£¬£¬£¬È»ºóʹÓÃÈ«ÁãTK¶Ô²¶»ñµÄÊý¾ÝÖ¡¾ÙÐнâÃÜ£¬£¬£¬´Ó¶ø»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£
2.2 ¹Ì¼þÆÊÎö
±¾ÎÄѡȡNexus5ÖеÄBCM4339оƬ¹Ì¼þ¾ÙÐÐÆÊÎö¡£¡£¡£¡£¡£¡£Ê×ÏÈ£¬£¬£¬¶¨Î»¹Ì¼þÖÐÅÌËãptkµÄλÖ㬣¬£¬ÈçÏÂͼËùʾ¡£¡£¡£¡£¡£¡£
È»ºó£¬£¬£¬¶ÔÆäÉϲ㺯Êýwlc_wpa_sup_eapol¾ÙÐÐÆÊÎö¡£¡£¡£¡£¡£¡£
wlc_wpa_sup_eapolŲÓÃwpa_pmk_to_ptkʱ£¬£¬£¬´«ÈëµÄ²ÎÊý»®·ÖΪmac1¡¢mac2¡¢Nonce1¡¢Nonce2¡¢pmk¡¢pmk_len¡¢ptk¡¢ptk_len¡£¡£¡£¡£¡£¡£ptkÅÌËãЧ¹û±»ÉúÑÄÔÚwpa_ptk½á¹¹ÌåÆ«ÒÆ0x8cλÖÃÖС£¡£¡£¡£¡£¡£
wlc_sup_attachº¯ÊýÓÃÓÚ´¦Öóͷ£STAµÄ³õʼ»¯ÅþÁ¬£¬£¬£¬¸Ãº¯Êý¶Ôwpa_ptk½á¹¹Ìå¾ÙÐÐÄÚ´æ·ÖÅɺͳõʼ»¯£¬£¬£¬wpa_ptk½á¹¹Ìå¾ÞϸΪ0x13C¡£¡£¡£¡£¡£¡£
µ±³õʼ»¯Ê§°Ü¡¢ÅþÁ¬³¬Ê±»òɨ³ýÅþÁ¬µÄʱ¼ä£¬£¬£¬Ôò»áŲÓÃwlc_sup_detachº¯Êý¶Ôwpa_ptk½á¹¹Ìå¾ÙÐÐÖÃÁã²Ù×÷¡£¡£¡£¡£¡£¡£
3.Îó²îÑéÖ¤
3.1 ²âÊÔÇéÐÎ
|
×°±¸Ãû³Æ |
ÊýÄ¿ |
ÊÜÓ°ÏìµÄ×°±¸ |
Nexus5 |
1 |
iphone6sÊÖ»ú |
1 |
|
Attacker |
NETGEARÍø¿¨ |
2 |
3.2 ²âÊÔ°ì·¨
£¨1£©¶Ôwireshark½âÃÜÊý¾Ý°üµÄÏà¹Ø¹¦Ð§¾ÙÐÐpatch£¬£¬£¬Ê¹ÆäÄܹ»ÀֳɽâÃÜÈ«ÁãTK¼ÓÃܵÄÊý¾Ý¡£¡£¡£¡£¡£¡£
£¨2£©Ê¹ÓÃpatchºóµÄwireshark¼àÌýÄ¿µÄ×°±¸ºÍAPͨѶµÄÊý¾Ý°ü¡£¡£¡£¡£¡£¡£
£¨3£©Ê¹ÓÃÄ¿µÄ×°±¸ÅþÁ¬AP²¢í§Òâ»á¼ûÍøÒ³¡£¡£¡£¡£¡£¡£
£¨4£©¶ÔAPºÍ²âÊÔÄ¿µÄ·¢ËÍDisassocation°ü¡£¡£¡£¡£¡£¡£
£¨5£©Öظ´Ö´Ðа취£¨3£©ºÍ£¨4£©£¬£¬£¬ÊÓ²ìwiresharkÖÐÊý¾Ý°üÊÇ·ñ½âÃÜ¡£¡£¡£¡£¡£¡£
3.3 ²âÊÔЧ¹û
Nexus 5£º
iphone 6s£º
¿ÉÒÔ¿´³ö£¬£¬£¬Nexus 5ºÍiphone 6s²¿·ÖÊý¾Ý±»ÀֳɽâÃÜ¡£¡£¡£¡£¡£¡£
4.Ó°Ïì¹æÄ£
ÏÖÔÚÒÑÖªÊÜÓ°ÏìµÄ×°±¸ÓУº
Amazon Echo 2nd gen
Amazon Kindle 8th gen
Apple iPad mini 2
Apple iPhone 6, 6S, 8, XR
Apple MacBook Air Retina 13-inch 2018
Google Nexus 5
Google Nexus 6
Google Nexus 6P
Raspberry Pi 3
Samsung Galaxy S4 GT-I9505
Samsung Galaxy S8
Xiaomi Redmi 3S
Asus RT-N12
Huawei B612S-25d
Huawei EchoLife HG8245H
Huawei E5577Cs-321
5.Çå¾²½¨Òé
×°±¸ÖÆÔìÉÌÒÑÐû²¼µÄÇå¾²½¨ÒéÈçÏ£º
?https://support.apple.com/en-us/HT210721
?https://support.apple.com/en-us/HT210722
?https://support.apple.com/en-us/HT210788
?https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-003.txt
?https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200226-wi-fi-info-disclosure
?https://www.huawei.com/en/psirt/security-notices/huawei-sn-20200228-01-kr00k-en
?https://www.microchip.com/design-centers/wireless-connectivity/embedded-wi-fi/kr00k-vulnerability
?https://www.mist.com/documentation/mist-security-advisory-kr00k-attack-faq/
?https://www.zebra.com/us/en/support-downloads/lifeguard-security/kr00k-vulnerability.html