Wi-Fi WPA2 ¡°Kr00k¡±·ì϶·ÖÎöÓ븴ÏÖ

°ä²¼¹¦·ò 2020-03-26

1.×êÑв¼¾°


ÔÚ½ñÄê2Ô·ݵÄRSA´ó»áÉÏ £¬ESETµÄ×êÑÐÈËÔ±¹«¿ªÅû¶Wi-FiоƬ´æÔÚÑϳÁ°²È«·ì϶CVE-2019-15126 £¬²¢½«Æä¶¨ÃûΪ¡°Kr00k¡±¡£¹¥»÷ÕßÄܹ»ÀûÓá°Kr00k¡±½âÃÜÎÞÏßÍøÂçÁ÷Á¿ £¬»ñÈ¡´«Êä¹ý³ÌÖеÄÃô¸ÐÊý¾Ý¡£


Kr00k·ì϶ӰÏ첿ÃÅ×°ÖÃBroadcomºÍCypress Wi-FiоƬµÄÉ豸 £¬ÕâÁ½¼ÒоƬ²úÆ·±»¿í·ºÀûÓÃÓÚÊÖ»ú¡¢Æ½°åµçÄÔ¼°IOTÉ豸ÖС£ÊؾɹÀ¼Æ £¬È«Çò×ܼƳ¬¹ý10ÒÚµÄÉ豸Êܸ÷ì϶µÄÓ°Ïì¡£


2.·ì϶·ÖÎö


2.1 ·ì϶µÀÀí


ÔÚ½éÉÜKr00k·ì϶֮ǰ £¬Ïȵ¥Ò»ÏàʶÏÂWPA2ºÍ̸¡£Ä¿Ç°»ùÓÚAES-CCMPµÄWPA2ºÍ̸ÊÇWi-FiÍøÂçÖÐ×îÆÕ±éµÄ³ß¶È¡£ÏÂͼÊǿͻ§¶Ë£¨Station, STA£©ÏνӽÓÈëµã£¨Access Point, AP£©µÄÐÂÎŽ»»¥¹ý³Ì¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


STAºÍAPÔÚËÄ´ÎÎÕÊÖÖÐ £¬Ð­É̻ỰÃÜÔ¿PTK£¨Pairwise Transient Key£© £¬PTKÊÇÓÉPMKºÍPKEÍÆËãÌìÉú £¬¶øPMKÓÉANonce¡¢SNonceºÍË«·½MACµØÖ·µÈÍÆËãÌìÉú¡£PTK·ÖΪKCK¡¢KEKºÍTKÈý²¿ÃÅ £¬ÆäÖÐ £¬KCKÓÃÓÚMICУÑé £¬KEKÓÃÓÚ¼ÓÃÜGTK £¬TKΪÊý¾Ý¼ÓÃÜÃÜÔ¿¡£ËÄ´ÎÎÕÊÖʵÏÖºó £¬´«ÊäÊý¾ÝʹÓÃTK½øÐмÓÃÜ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÔÚWPA2ºÍ̸ÖÐ £¬½â³ý¹ØÁª²Ù×÷Äܹ»ÓÉδ¾­Éí·ÝÑéÖ¤ºÍδ¼ÓÃܵÄÖÎÀíÖ¡´¥·¢ £¬Kr00k·ì϶Óë½â³ý¹ØÁª²Ù×÷Ç×êÇÓйØ¡£±ÉÈËͼËùʾÖÐ £¬µ¹Ø¾µãµÄÏνӻỰ½â³ý¹ØÁªºó £¬±£ÁôÔÚWi-FiоƬÖеĻỰÃÜÔ¿(TK)±»ÖÃÁã £¬ÈôÊÇʹÓÃÒÑÖÃÁãµÄTKÃÜÔ¿¶ÔоƬ»º´æÖеÄÊý¾Ý½øÐмÓÃܲ¢´«Êä £¬½«µ¼Ö·ì϶²úÉú¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¹¥»÷ÕßÀûÓÃÎÞÏßÍø¿¨¼´¿ÉʵÏÖÈëÇÖ £¬Í¨¹ý²»ÐÝ´¥·¢½â³ý¹ØÁª¡¢³ÁйØÁª £¬¶øºóʹÓÃÈ«ÁãTK¶Ô²¶»ñµÄÊý¾ÝÖ¡½øÐнâÃÜ £¬´Ó¶ø»ñÈ¡Ãô¸ÐÐÅÏ¢¡£


2.2 ¹Ì¼þ·ÖÎö


±¾ÎİÎÈ¡Nexus5ÖеÄBCM4339оƬ¹Ì¼þ½øÐзÖÎö¡£Ê×ÏÈ £¬¶¨Î»¹Ì¼þÖÐÍÆËãptkµÄµØÎ» £¬ÈçÏÂͼËùʾ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¶øºó £¬¶ÔÆäÉϲ㺯Êýwlc_wpa_sup_eapol½øÐзÖÎö¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


wlc_wpa_sup_eapolŲÓÃwpa_pmk_to_ptkʱ £¬´«ÈëµÄ²ÎÊý±ðÀëΪmac1¡¢mac2¡¢Nonce1¡¢Nonce2¡¢pmk¡¢pmk_len¡¢ptk¡¢ptk_len¡£ptkÍÆËãÁ˾ֱ»±£ÁôÔÚwpa_ptk½á¹¹ÌåÆ«ÒÆ0x8cµØÎ»ÖС£


wlc_sup_attachº¯ÊýÓÃÓÚ´¦ÖÃSTAµÄ³õʼ»¯ÏνÓ £¬¸Ãº¯Êý¶Ôwpa_ptk½á¹¹Ìå½øÐÐÄÚ´æ·ÖÅäºÍ³õʼ»¯ £¬wpa_ptk½á¹¹Ìå´óÓ×Ϊ0x13C¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


µ±³õʼ»¯Ê§°Ü¡¢Ïνӳ¬Ê±»ò½â³ýÏνӵÄʱ³½ £¬Ôò»áŲÓÃwlc_sup_detachº¯Êý¶Ôwpa_ptk½á¹¹Ìå½øÐÐÖÃÁã²Ù×÷¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


3.·ì϶ÑéÖ¤


3.1 ²âÊÔ»·¾³



É豸Ãû³Æ

ÊýÁ¿

ÊÜÓ°ÏìµÄÉ豸

Nexus5

1

iphone6sÊÖ»ú

1

Attacker

NETGEARÍø¿¨

2

3.2 ²âÊÔ²½Öè


£¨1£©¶Ôwireshark½âÃÜÊý¾Ý°üµÄÓйØÖ°ÄܽøÐÐpatch £¬Ê¹Æä¿ÉÄܳɹ¦½âÃÜÈ«ÁãTK¼ÓÃܵÄÊý¾Ý¡£

£¨2£©Ê¹ÓÃpatchºóµÄwireshark¼àÌýÖ¸±êÉ豸ºÍAPͨѶµÄÊý¾Ý°ü¡£

£¨3£©Ê¹ÓÃÖ¸±êÉ豸ÏνÓAP²¢ËÁÒâ½Ó¼ûÍøÒ³¡£

£¨4£©¶ÔAPºÍ²âÊÔÖ¸±ê·¢ËÍDisassocation°ü¡£

£¨5£©³Á¸´Ö´Ðв½Ö裨3£©ºÍ£¨4£© £¬¹Û²ìwiresharkÖÐÊý¾Ý°üÊÇ·ñ½âÃÜ¡£


3.3 ²âÊÔÁ˾Ö


Nexus 5£º


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


iphone 6s£º


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Äܹ»¿´³ö £¬Nexus 5ºÍiphone 6s²¿ÃÅÊý¾Ý±»³É¹¦½âÃÜ¡£


4.Ó°ÏìÁìÓò


ĿǰÒÑÖªÊÜÓ°ÏìµÄÉ豸ÓУº

Amazon Echo 2nd gen

Amazon Kindle 8th gen

Apple iPad mini 2

Apple iPhone 6, 6S, 8, XR

Apple MacBook Air Retina 13-inch 2018

Google Nexus 5

Google Nexus 6

Google Nexus 6P

Raspberry Pi 3

Samsung Galaxy S4 GT-I9505

Samsung Galaxy S8

Xiaomi Redmi 3S

Asus RT-N12

Huawei B612S-25d

Huawei EchoLife HG8245H

Huawei E5577Cs-321


5.°²È«½¨Òé


É豸Ôì×÷ÉÌÒѰ䲼µÄ°²È«½¨ÒéÈçÏ£º

?https://support.apple.com/en-us/HT210721

?https://support.apple.com/en-us/HT210722

?https://support.apple.com/en-us/HT210788

?https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-003.txt

?https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200226-wi-fi-info-disclosure

?https://www.huawei.com/en/psirt/security-notices/huawei-sn-20200228-01-kr00k-en

?https://www.microchip.com/design-centers/wireless-connectivity/embedded-wi-fi/kr00k-vulnerability

?https://www.mist.com/documentation/mist-security-advisory-kr00k-attack-faq/

?https://www.zebra.com/us/en/support-downloads/lifeguard-security/kr00k-vulnerability.html