Wi-Fi WPA2 ¡°Kr00k¡±·ì϶·ÖÎöÓ븴ÏÖ

°ä²¼¹¦·ò 2020-03-26

1.×êÑв¼¾°


ÔÚ½ñÄê2Ô·ݵÄRSA´ó»áÉÏ£¬£¬£¬£¬£¬ESETµÄ×êÑÐÈËÔ±¹«¿ªÅû¶Wi-FiоƬ´æÔÚÑϳÁ°²È«·ì϶CVE-2019-15126£¬£¬£¬£¬£¬²¢½«Æä¶¨ÃûΪ¡°Kr00k¡±¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»ÀûÓá°Kr00k¡±½âÃÜÎÞÏßÍøÂçÁ÷Á¿£¬£¬£¬£¬£¬»ñÈ¡´«Êä¹ý³ÌÖеÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£


Kr00k·ì϶ӰÏ첿ÃÅ×°ÖÃBroadcomºÍCypress Wi-FiоƬµÄÉ豸£¬£¬£¬£¬£¬ÕâÁ½¼ÒоƬ²úÆ·±»¿í·ºÀûÓÃÓÚÊÖ»ú¡¢Æ½°åµçÄÔ¼°IOTÉ豸ÖÓ×£¡£¡£¡£¡£¡£¡£¡£ÊؾɹÀ¼Æ£¬£¬£¬£¬£¬È«Çò×ܼƳ¬¹ý10ÒÚµÄÉ豸Êܸ÷ì϶µÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£


2.·ì϶·ÖÎö


2.1 ·ì϶µÀÀí


ÔÚ½éÉÜKr00k·ì϶֮ǰ£¬£¬£¬£¬£¬Ïȵ¥Ò»ÏàʶÏÂWPA2ºÍ̸¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°»ùÓÚAES-CCMPµÄWPA2ºÍ̸ÊÇWi-FiÍøÂçÖÐ×îÆÕ±éµÄ³ß¶È¡£¡£¡£¡£¡£¡£¡£¡£ÏÂͼÊǿͻ§¶Ë£¨Station, STA£©ÏνӽÓÈëµã£¨Access Point, AP£©µÄÐÂÎŽ»»¥¹ý³Ì¡£¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


STAºÍAPÔÚËÄ´ÎÎÕÊÖÖУ¬£¬£¬£¬£¬Ð­É̻ỰÃÜÔ¿PTK£¨Pairwise Transient Key£©£¬£¬£¬£¬£¬PTKÊÇÓÉPMKºÍPKEÍÆËãÌìÉú£¬£¬£¬£¬£¬¶øPMKÓÉANonce¡¢SNonceºÍË«·½MACµØÖ·µÈÍÆËãÌìÉú¡£¡£¡£¡£¡£¡£¡£¡£PTK·ÖΪKCK¡¢KEKºÍTKÈý²¿ÃÅ£¬£¬£¬£¬£¬ÆäÖУ¬£¬£¬£¬£¬KCKÓÃÓÚMICУÑ飬£¬£¬£¬£¬KEKÓÃÓÚ¼ÓÃÜGTK£¬£¬£¬£¬£¬TKΪÊý¾Ý¼ÓÃÜÃÜÔ¿¡£¡£¡£¡£¡£¡£¡£¡£ËÄ´ÎÎÕÊÖʵÏֺ󣬣¬£¬£¬£¬´«ÊäÊý¾ÝʹÓÃTK½øÐмÓÃÜ¡£¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÔÚWPA2ºÍ̸ÖУ¬£¬£¬£¬£¬½â³ý¹ØÁª²Ù×÷Äܹ»ÓÉδ¾­Éí·ÝÑéÖ¤ºÍδ¼ÓÃܵÄÖÎÀíÖ¡´¥·¢£¬£¬£¬£¬£¬Kr00k·ì϶Óë½â³ý¹ØÁª²Ù×÷Ç×êÇÓйء£¡£¡£¡£¡£¡£¡£¡£±ÉÈËͼËùʾÖУ¬£¬£¬£¬£¬µ¹Ø¾µãµÄÏνӻỰ½â³ý¹ØÁªºó£¬£¬£¬£¬£¬±£ÁôÔÚWi-FiоƬÖеĻỰÃÜÔ¿(TK)±»ÖÃÁ㣬£¬£¬£¬£¬ÈôÊÇʹÓÃÒÑÖÃÁãµÄTKÃÜÔ¿¶ÔоƬ»º´æÖеÄÊý¾Ý½øÐмÓÃܲ¢´«Ê䣬£¬£¬£¬£¬½«µ¼Ö·ì϶²úÉú¡£¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¹¥»÷ÕßÀûÓÃÎÞÏßÍø¿¨¼´¿ÉʵÏÖÈëÇÖ£¬£¬£¬£¬£¬Í¨¹ý²»ÐÝ´¥·¢½â³ý¹ØÁª¡¢³ÁйØÁª£¬£¬£¬£¬£¬¶øºóʹÓÃÈ«ÁãTK¶Ô²¶»ñµÄÊý¾ÝÖ¡½øÐнâÃÜ£¬£¬£¬£¬£¬´Ó¶ø»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£


2.2 ¹Ì¼þ·ÖÎö


±¾ÎİÎÈ¡Nexus5ÖеÄBCM4339оƬ¹Ì¼þ½øÐзÖÎö¡£¡£¡£¡£¡£¡£¡£¡£Ê×ÏÈ£¬£¬£¬£¬£¬¶¨Î»¹Ì¼þÖÐÍÆËãptkµÄµØÎ»£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ¡£¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¶øºó£¬£¬£¬£¬£¬¶ÔÆäÉϲ㺯Êýwlc_wpa_sup_eapol½øÐзÖÎö¡£¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


wlc_wpa_sup_eapolŲÓÃwpa_pmk_to_ptkʱ£¬£¬£¬£¬£¬´«ÈëµÄ²ÎÊý±ðÀëΪmac1¡¢mac2¡¢Nonce1¡¢Nonce2¡¢pmk¡¢pmk_len¡¢ptk¡¢ptk_len¡£¡£¡£¡£¡£¡£¡£¡£ptkÍÆËãÁ˾ֱ»±£ÁôÔÚwpa_ptk½á¹¹ÌåÆ«ÒÆ0x8cµØÎ»ÖÓ×£¡£¡£¡£¡£¡£¡£¡£


wlc_sup_attachº¯ÊýÓÃÓÚ´¦ÖÃSTAµÄ³õʼ»¯Ïνӣ¬£¬£¬£¬£¬¸Ãº¯Êý¶Ôwpa_ptk½á¹¹Ìå½øÐÐÄÚ´æ·ÖÅäºÍ³õʼ»¯£¬£¬£¬£¬£¬wpa_ptk½á¹¹Ìå´óÓ×Ϊ0x13C¡£¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


µ±³õʼ»¯Ê§°Ü¡¢Ïνӳ¬Ê±»ò½â³ýÏνӵÄʱ³½£¬£¬£¬£¬£¬Ôò»áŲÓÃwlc_sup_detachº¯Êý¶Ôwpa_ptk½á¹¹Ìå½øÐÐÖÃÁã²Ù×÷¡£¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


3.·ì϶ÑéÖ¤


3.1 ²âÊÔ»·¾³



É豸Ãû³Æ

ÊýÁ¿

ÊÜÓ°ÏìµÄÉ豸

Nexus5

1

iphone6sÊÖ»ú

1

Attacker

NETGEARÍø¿¨

2

3.2 ²âÊÔ²½Öè


£¨1£©¶Ôwireshark½âÃÜÊý¾Ý°üµÄÓйØÖ°ÄܽøÐÐpatch£¬£¬£¬£¬£¬Ê¹Æä¿ÉÄܳɹ¦½âÃÜÈ«ÁãTK¼ÓÃܵÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£

£¨2£©Ê¹ÓÃpatchºóµÄwireshark¼àÌýÖ¸±êÉ豸ºÍAPͨѶµÄÊý¾Ý°ü¡£¡£¡£¡£¡£¡£¡£¡£

£¨3£©Ê¹ÓÃÖ¸±êÉ豸ÏνÓAP²¢ËÁÒâ½Ó¼ûÍøÒ³¡£¡£¡£¡£¡£¡£¡£¡£

£¨4£©¶ÔAPºÍ²âÊÔÖ¸±ê·¢ËÍDisassocation°ü¡£¡£¡£¡£¡£¡£¡£¡£

£¨5£©³Á¸´Ö´Ðв½Ö裨3£©ºÍ£¨4£©£¬£¬£¬£¬£¬¹Û²ìwiresharkÖÐÊý¾Ý°üÊÇ·ñ½âÃÜ¡£¡£¡£¡£¡£¡£¡£¡£


3.3 ²âÊÔÁ˾Ö


Nexus 5£º


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


iphone 6s£º


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Äܹ»¿´³ö£¬£¬£¬£¬£¬Nexus 5ºÍiphone 6s²¿ÃÅÊý¾Ý±»³É¹¦½âÃÜ¡£¡£¡£¡£¡£¡£¡£¡£


4.Ó°ÏìÁìÓò


ĿǰÒÑÖªÊÜÓ°ÏìµÄÉ豸ÓУº

Amazon Echo 2nd gen

Amazon Kindle 8th gen

Apple iPad mini 2

Apple iPhone 6, 6S, 8, XR

Apple MacBook Air Retina 13-inch 2018

Google Nexus 5

Google Nexus 6

Google Nexus 6P

Raspberry Pi 3

Samsung Galaxy S4 GT-I9505

Samsung Galaxy S8

Xiaomi Redmi 3S

Asus RT-N12

Huawei B612S-25d

Huawei EchoLife HG8245H

Huawei E5577Cs-321


5.°²È«½¨Òé


É豸Ôì×÷ÉÌÒѰ䲼µÄ°²È«½¨ÒéÈçÏ£º

?https://support.apple.com/en-us/HT210721

?https://support.apple.com/en-us/HT210722

?https://support.apple.com/en-us/HT210788

?https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-003.txt

?https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200226-wi-fi-info-disclosure

?https://www.huawei.com/en/psirt/security-notices/huawei-sn-20200228-01-kr00k-en

?https://www.microchip.com/design-centers/wireless-connectivity/embedded-wi-fi/kr00k-vulnerability

?https://www.mist.com/documentation/mist-security-advisory-kr00k-attack-faq/

?https://www.zebra.com/us/en/support-downloads/lifeguard-security/kr00k-vulnerability.html