¡¾·ì϶µý±¨¡¿Spectre CPU·ì϶£¨CVE-2017-5753£©

°ä²¼¹¦·ò 2021-03-02

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2017-5753

ʱ   ¼ä

2021-03-02

Àà   ÐÍ

Éè¼ÆÃýÎó  

µÈ   ¼¶


Ô¶³ÌÀûÓÃ


Ó°ÏìÁìÓò


 

0x01 ·ì϶ÏêÇé

image.png

2021Äê03ÔÂ01ÈÕ£¬°²È«×êÑÐÈËÔ±ÖìÀû°²¡¤ÎÖÒÁÉ­£¨Julien Voisin£©ÔÚVirusTotal¶ñÒâÈí¼þ·ÖÎöƽ̨ÉÏ·¢ÏÖÁËSpectre CPU·ì϶£¨CVE-2017-5753£©µÄLinux°æºÍWindows°æµÄ·ì϶ÀûÓ÷¨Ê½£¬Õⰵʾ¿ÉÄܽøÐÐÏÖʵ·ÛËé²¢ÆëÈ«±øÆ÷»¯µÄÓÐЧÀûÓ÷¨Ê½ÒѾ­ÔÚ¹«¹²ÁìÓòÖй«¿ª¡£

Spectre CPU·ì϶ÊÇ2018Äê1ÔÂGoogle Project ZeroÅû¶µÄIntel¡¢AMDºÍARM´¦ÖÃÆ÷¼Ü¹¹ÖеÄÓ²¼þÉè¼ÆÈ±µã£¨Meltdown£ºCVE-2017-5754¡¢Spectre£ºCVE-2017-5753ºÍCVE-2017-5715£©£¬¹¥»÷Õß¿ÉÄÜÀûÓ÷ì϶ÔËÐÐÀûÓ÷¨Ê½ÖеĴúÂëÀ´·ÛËé·ÖÆçÀûÓ÷¨Ê½Ö®¼äÔÚCPU²ãÃæµÄ¸ôÀ룬¶øºóÇÔȡͳһϵͳÉÏÔËÐÐµÄÆäËüÀûÓõÄÃô¸ÐÊý¾Ý¡£

Google°µÊ¾£¬Spectre CPU·ì϶»áÓ°ÏìÔ̺¬Windows¡¢Linux¡¢macOS¡¢AndroidºÍChromeOSµÈÔÚÄÚµÄÖ÷Á÷²Ù×÷ϵͳ¡£×Ô¾õÏָ÷ì϶ÒÔÀ´£¬ËùÓÐÖ÷Á÷CPUºÍOS¹©¸øÉ̾ù°ä²¼Á˹̼þ²¹¶¡ºÍÈí¼þ½¨¸´£¬µ«ÉÐδ¸üÐÂÆäϵͳµÄÓû§ÒÀÈ»ÈÝÒ×Êܵ½Spectre CPU·ì϶µÄ¹¥»÷£¬ÓÈÆäÊÇʹÓþɰæÐ¾Æ¬²¢ÔËÐоɰæ²Ù×÷ϵͳµÄÓû§£¨Èç2015Äê´úµÄPC£¬²¢Ê¹ÓÃHaswell»ò¾ÉµÄIntel´¦ÖÃÆ÷£©¡£

VirusTotalÉϵķì϶ÀûÓ÷¨Ê½ÊÇÉϸöÔÂÉÏ´«µÄ£¬¸ÃÈí¼þ°üÊǺÏÓÃÓÚWindowsºÍLinuxµÄImmunity Canvas 7.26×°Ö÷¨Ê½(Immunity CANVASΪȫÇòµÄÉøÈë²âÊÔÈËÔ±ºÍ°²È«×¨ÒµÈËÔ±ÌṩÁËÊý°ÙÖÖ·ì϶ÀûÓá¢×Ô¶¯»¯µÄ·ì϶ÀûÓÃϵͳÒÔ¼°È«Ãæ¡¢¿¿µÃסµÄ·ì϶ÀûÓÿª·¢¿ò¼Ü)¡£

image.png


´Ë·ì϶ÀûÓ÷¨Ê½Äܹ»Ê¹Í¨³£Óû§Äܹ»´ÓÖ¸±êÉ豸µÄÄÚºËÄÚ´æÖÐת´¢WindowsϵͳºÍLinuxϵͳÖÐ/etc/shadowÎļþÖеÄLM/NT¹þÏ£¡£´Ë±í£¬¸ÃÀûÓ÷¨Ê½»¹¿ÉÄÜת´¢Kerberos tickets£¬¿ÉÓëPsExecһ·ÓÃÓÚWindowsϵͳµÄ±¾µØÈ¨ÏÞÉý¼¶ºÍºáÏòÒÆ¶¯¡£ÕâÒâζ×Å£¬ÈôÊǸ÷ì϶±»³É¹¦ÀûÓã¬Ôò¹¥»÷ÕßÄܹ»ÇÔÈ¡ÊÜÓ°ÏìϵͳµÄÃô¸ÐÊý¾Ý£¬Ô̺¬ÃÜÂë¡¢ÎĵµÒÔ¼°ÄÚ´æÖÐÈκοÉÓÃµÄÆäËüÊý¾Ý¡£

image.png

image.png

 

ÈçVoisinËù˵£¬´ò¹ý¸Ã·ì϶²¹¶¡µÄLinux»òWindowsϵͳÔò²»ÊÜÓ°Ïì¡£¶øÎ¢Èí°µÊ¾£¬ÓÉÓÚ×°Öò¹¶¡ºóϵͳ»úÄÜ»áÓÐÏÔÖøµÄ½µÂ䣬Òò¶øÓû§×îÈÝÒ×Ìø¹ýÀûÓûº½â´ëÊ©¡£

³ý´ËÖ®±í£¬¼´±ã¹¥»÷ÕßÄõ½ÁËÕâÁ½¸ö·ì϶ÀûÓ÷¨Ê½Èí¼þ°üÖеÄÈκÎÒ»¸ö£¬Ö»ÔËÐÐËüÃÇÒ²²»»á²úÉúÈκÎÁ˾Ö£¬ÓÉÓÚËüÃǶ¼Ö»ÄÜÔÚÕýÈ·µÄ²ÎÊýÏÂÖ´ÐУ¬³ý·Ç¹¥»÷Õß¿ÉÄÜÔËÐÐÕýÈ·µÄ²ÎÊý¡£

 

0x02 ´ëÖý¨Òé

Spectre CPU·ì϶ÒÑÓÚ2018Ä꽨¸´£¬½¨Òéδʵʱ¸üеÄÓû§²Î¿¼CPUºÍOS¹©¸øÉ̹ٷ½°ä²¼µÄ½¨¸´·¨Ê½»ò»º½â´ëÊ©¡£

Õë¶Ôwindowsϵͳ£¬Î¢Èíͨ¹ý¸ü¸ÄWindowsºÍоƬ΢´úÂëÀ´»º½â´Ë·ì϶£¬²¢½¨ÒéʹÓÃWindows UpdateºÍоƬ΢´úÂë¸üС£

ÏêÇéÁ´½Ó£º

https://www.microsoft.com/security/blog/2018/01/09/understanding-the-performance-impact-of-spectre-and-meltdown-mitigations-on-windows-systems/

 

0x03 ²Î¿¼Á´½Ó

https://www.virustotal.com/gui/file/6461d0988c835e91eb534757a9fa3ab35afe010bec7d5406d4dfb30ea767a62c/detection

https://www.bleepingcomputer.com/news/security/working-windows-and-linux-spectre-exploits-found-on-virustotal/?

https://dustri.org/b/spectre-exploits-in-the-wild.html

https://therecord.media/first-fully-weaponized-spectre-exploit-discovered-online/

 

0x04 ¹¦·òÏß

2021-03-01  Julien VoisinÅû¶ÀûÓ÷¨Ê½

2021-03-02  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png