FragAttacks·ì϶·ÖÎö
°ä²¼¹¦·ò 2021-05-18²¼¾°
½üÈÕ£¬£¬£¬£¬£¬£¬£¬Å¦Ô¼´óѧ°¢²¼Ôú±È·ÖУµÄ°²È«×êÑÐÔ±Mathy Vanhoef·¢ÏÖÁËһϵÁÐÓ°Ïì¾Þ´óµÄWi-Fi·ì϶£¬£¬£¬£¬£¬£¬£¬ÕâһϵÁзì϶±»Í³³ÆÎªFragAttacks£¬£¬£¬£¬£¬£¬£¬FragAttacksÓ°ÏìÁË1997ÄêWi-Fi¼¼Êõµ®ÉúÒÔÀ´µÄËùÓÐWi-FiÉ豸£¨Ô̺¬ÍÆËã»ú¡¢ÖÇÄÜÊÖ»ú¡¢Ô°ÇøÍøÂç¡¢¼Òͥ·ÓÉÆ÷¡¢ÖÇÄܼҾÓÉ豸¡¢ÖÇÄÜÆû³µ¡¢ÎïÁªÍøµÈµÈ£©¡£¡£¡£¡£¡£
ÆäÖÐÈý¸ö·ì϶ӰÏì´óÎÞÊýWiFiÉ豸£¬£¬£¬£¬£¬£¬£¬ÊôÓÚWi-Fi 802.11³ß¶ÈÖ¡¾ÛºÏºÍÖ¡·Ôì¬Ö°ÄÜÖеÄÉè¼ÆÈ±µã£¬£¬£¬£¬£¬£¬£¬¶øÆäËû·ì϶ÊÇWi-Fi²úÆ·Öеıà³ÌÃýÎ󡣡£¡£¡£¡£
ºÚ¿ÍÖ»ÓÐÔÚÖ¸±êÉ豸µÄWi-FiÁìÓòÄÚ£¬£¬£¬£¬£¬£¬£¬¾ÍÄÜÀûÓÃFragAttacks·ì϶ÇÔÈ¡Ãô¸ÐÓû§Êý¾Ý²¢Ö´ÐжñÒâ´úÂ룬£¬£¬£¬£¬£¬£¬ÉõÖÁÄܹ»ÊÕÊÜÕû¸öÉ豸¡£¡£¡£¡£¡£
8827Ì«Ñô¼¯ÍÅADLabµÚÒ»¹¦·ò¶Ô·ì϶½øÐÐÁË·ÖÎö£¬£¬£¬£¬£¬£¬£¬²¢Ìá³öÁËÏàÓ¦µÄ»º½â½¨Òé¡£¡£¡£¡£¡£ÓÉÓÚWiFi²úÆ·µÄºÍ̸ջ£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÁËSoft Mac¼°Full Mac¶àÖÖʵÏֹ滮¡£¡£¡£¡£¡£FragAttacksϵÁзì϶²»½ö´æÔÚÓ°Ïì²Ù×÷ϵͳÄںˡ¢WiFiÇý¶¯£¬£¬£¬£¬£¬£¬£¬»¹Ó°ÏìWiFiµÄSOCоƬ£¬£¬£¬£¬£¬£¬£¬ËùÒÔ·ì϶µÄÓ°Ïì³Ö¾Ã´æÔÚ¡£¡£¡£¡£¡£Çëʵʱ¹Ø×¢²¢¸üÐÂÉ豸¹©¸øÉ̵ݲȫ¸üС£¡£¡£¡£¡£
½¨¸´¼°»º½â½¨Òé
¡ñ ʵʱ¸üÐÂÉ豸¹©¸øḚ́䲼µÄFragAttacks·ì϶°²È«¸üС£¡£¡£¡£¡£
¡ñ È·±£Äú½Ó¼ûµÄËùÓÐÍøÕ¾ºÍÔÚÏß·þÎñ¶¼ÆôÓÃÁ˰²È«³¬Îı¾´«ÊäºÍ̸HTTPS(ºÃ±È×°ÖÃHTTPS Everywhere²å¼þ)¡£¡£¡£¡£¡£
¡ñ ÀýÈçÔÚWi-Fi 6£¨802.11ax£©É豸ÖнûÓ÷Ô쬣¬£¬£¬£¬£¬£¬£¬½ûÓóɶԳÁÐÂÌìÉúÃÜÔ¿ÒÔ¼°½ûÓö¯Ì¬·Ô쬡£¡£¡£¡£¡£
·ì϶ÁÐ±í¼°¾ßÌåÓ°Ïì
Wi-FiÉè¼ÆÈ±µãÓйصķì϶Ô̺¬£º
| CVE±àºÅ | ·ì϶½éÉÜ | ·ì϶ӰÏì |
|---|---|---|
| CVE-2020-24588 | Õë¶ÔA-MSDU¾ÛºÏµÄ×¢Èë¹¥»÷£¨ÎÞЧµÄSPP A-MSDU±£»£»£»£»£»£»¤»úÔ죩 | ¹¥»÷Õ߿ɲåÈë¶ñÒâÖ¡£¬£¬£¬£¬£¬£¬£¬´Û¸ÄÊý¾Ý°ü |
| CVE-2020-24587 | »ìºÏÃÜÔ¿¹¥»÷£¨³Á×éʱʹÓÃ·ÖÆçÃÜÔ¿¼ÓÃܵķÔì¬ | ÃÜÈ¡Óû§µÄÃô¸ÐÊý¾Ý |
| CVE-2020-24586 | ·Ô쬻º´æ¹¥»÷£¨³ÁÐÂÏνӵ½ÍøÂçʱ²»¶Ï¸ù·Ô쬻º´æ£© | ÇÔÈ¡Óû§Ãô¸ÐÊý¾Ý»ò´Û¸ÄËÁÒâÊý¾Ý°ü |
Wi-FiʵÏÖÓйصķì϶Ô̺¬£º
| CVE±àºÅ | ·ì϶½éÉÜ | ·ì϶ӰÏì |
|---|---|---|
| CVE-2020-26145 | ÔÚ¼ÓÃÜͨѶÖУ¬£¬£¬£¬£¬£¬£¬ÈÔ½ÓÊÜδ¼ÓÃܹ㲥·Ôì¬×÷ΪÆëȫ֡ | ¶ÀÁ¢ÓÚÍøÂçÅäÖ㬣¬£¬£¬£¬£¬£¬²åÈëËÁÒâÖ¡£¬£¬£¬£¬£¬£¬£¬´Ó¶ø´Û¸ÄÊý¾Ý°ü |
| CVE-2020-26144 | ÔÚ¼ÓÃÜͨѶÖУ¬£¬£¬£¬£¬£¬£¬ÈÔ½ÓÊÜδ¼ÓÃܵÄA-MSDUÖ¡ | |
| CVE-2020-26140 | ÔÚÊܱ£»£»£»£»£»£»¤µÄÍøÂçÖнÓÊÜδ¼ÓÃÜÊý¾ÝÖ¡ | |
CVE-2020-26143 | ÔÚÊܱ£»£»£»£»£»£»¤µÄÍøÂçÖнÓÊÜ·Ô쬵Äδ¼ÓÃÜÊý¾ÝÖ¡ | |
CVE-2020-26139 | ת·¢EAPOL֡ʱδÑéÖ¤·¢ËͶ˵ÄÉí·Ý | ºÍCVE-2020-24588½áºÏÆðÀ´£¬£¬£¬£¬£¬£¬£¬²åÈëÈι¥»÷Õ߿ɲåÈë¶ñÒâÖ¡£¬£¬£¬£¬£¬£¬£¬´Û¸ÄÊý¾Ý°ü |
CVE-2020-26146 | ¶ÔÓÚ·ÇÂ½ÐøÊý¾Ý°ü±àºÅµÄ¼ÓÃÜ·Ôì¬ÒÀÈ»½øÐгÁÐÂ×éºÏ | ÇÔÈ¡Óû§Ãô¸ÐÊý¾Ý |
CVE-2020-26147 | ¶Ô·Ô쬽øÐгÁÐÂ×éӦʱ²»·Ö±æ¼ÓÃÜ»òδ¼ÓÃÜ | ¹¥»÷Õ߿ɲåÈë¶ñÒâÖ¡£¬£¬£¬£¬£¬£¬£¬´Û¸ÄÊý¾Ý°ü |
CVE-2020-26142 | ½«·Ôì¬Ö¡×÷ΪÆëȫ֡½øÐд¦Öà | |
CVE-2020-26141 | ²»ÑéÖ¤·Ôì¬Ö¡µÄTKIP MIC |
ͨ¹ýÕâһϵÁзì϶£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߯ëÈ«Äܹ»»ñµÃÓû§µÄÃô¸ÐÐÅÏ¢»òÖ±½Ó½ÚÔìÖÇÄÜÉ豸£¬£¬£¬£¬£¬£¬£¬Èç½ÚÔìÖÇÄܵçÔ´²å×ù£¬£¬£¬£¬£¬£¬£¬ÉõÖÁÖ±½Ó¹ÜÊÜÍøÂçÖдæÔÚ·ì϶µÄÍÆËã»ú£¬£¬£¬£¬£¬£¬£¬°Ý¼ûÏÂÎIJο¼×ÊÁÏ[2]¡£¡£¡£¡£¡£
·ì϶·ÖÎö
ÎÒÃǰÎÈ¡ÁËÔÚËùÓÐÉ豸ÆÕ±é´æÔÚµÄCVE-2020-24586¡¢CVE-2020-24587¡¢CVE-2020-24588Èý¸öÉè¼Æ·ì϶½øÐзÖÎö¡£¡£¡£¡£¡£ÓÉÓÚCVE-2020-24588µÄ·ì϶ӰÏì½Ï´ó£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ×ųÁ½øÐнéÉÜCVE-2020-24588¡£¡£¡£¡£¡£
1¡¢¼¼Êõ²¼¾°
ÓÉÓÚ802.11MAC²ãºÍ̸ºÄ·ÑÁËÏ൱¶à¿ªÏúÓÃ×÷Á´Â·µÄÊØ»¤£¬£¬£¬£¬£¬£¬£¬ÎªÁËÌá¸ßMAC²ãµÄЧÄÜ£¬£¬£¬£¬£¬£¬£¬802.11nÒýÈëÖ¡¾ÛºÏ¼¼Êõ£¬£¬£¬£¬£¬£¬£¬±¨ÎÄÖ¡¾ÛºÏ¼¼ÊõÔ̺¬£ºA-MSDU(MAC·þÎñÊý¾Ýµ¥Ôª¾ÛºÏ) ¼° A-MPDU(MACºÍ̸Êý¾Ýµ¥Ôª¾ÛºÏ)¡£¡£¡£¡£¡£
A-MSDUÔÊÐí¶ÔÖ÷Õŵؼ°ÀûÓö¼Ò»ÑùµÄ¶à¸öA-MSDU×ÓÖ¡½øÐоۺϣ¬£¬£¬£¬£¬£¬£¬¾ÛºÏºóµÄ¶à¸ö×ÓÖ¡Ö»ÓÐÒ»¸ö¹²Í¬µÄMACÖ¡Í·£¬£¬£¬£¬£¬£¬£¬µ±¶à¸ö×ÓÖ¡¾ÛºÏµ½Ò»Â·ºó£¬£¬£¬£¬£¬£¬£¬´Ó¶øÏ÷¼õÁË·¢ËÍÿһ¸ö802.11±¨ÎÄËùÐèµÄPLCP Preamble¡¢PLCP HeaderºÍ802.11MACÍ·µÄ¿ªÏú£¬£¬£¬£¬£¬£¬£¬Í¬Ê±Ï÷¼õÁËÓ¦´ðÖ¡µÄÊýÁ¿£¬£¬£¬£¬£¬£¬£¬´Ó¶øÌá¸ßÎÞÏß´«ÊäЧÄÜ¡£¡£¡£¡£¡£A-MSDU±¨ÎÄÖ¡¾ÛºÏ¼¼ÊõÊÇ802.11nºÍ̸µÄÇ¿ÔìÒªÇ󣬣¬£¬£¬£¬£¬£¬ËùÓÐÖ§³Ö802.11nºÍ̸µÄÉ豸¶¼±ØÐëÖ§³Ö¡£¡£¡£¡£¡£
ÏÂͼʾÒâÁËÔÚ802.11ºÍ̸ջÖУ¬£¬£¬£¬£¬£¬£¬·¢ËͶ˺ͽӹܶËÊÇÈôºÎ´¦ÖÃA-MSDUÊý¾ÝµÄ¡£¡£¡£¡£¡£

ͼ1. 802.11ºÍ̸Êý¾Ý´¦ÖÃÁ÷³Ì
ÔÚ802.11ºÍ̸ջÖУ¬£¬£¬£¬£¬£¬£¬·¢ËͶ˽«À´×Ô3-7²ãµÄÍøÂçÊý¾Ý¾¹ýÊý¾ÝÁ´Â·²ãµÄLLC×Ó²ãÔö³¤LLC/SNAPÍ·ºó·â×°³ÉMSDU(MAC·þÎñÊý¾Ýµ¥Ôª£©£¬£¬£¬£¬£¬£¬£¬MSDU¾¹ýÔö³¤DA¡¢SA¡¢³¤¶È¼°padingºó£¬£¬£¬£¬£¬£¬£¬·â×°³ÉA-MSDU×ÓÖ¡£¬£¬£¬£¬£¬£¬£¬ÔÚMAC×Ó²ãµÄ¶¥²ã½«¶à¸öA-MSDU×ÓÖ¡·â×°³ÉA-MSDU£¬£¬£¬£¬£¬£¬£¬¾MAC×Ó²ãºó£¬£¬£¬£¬£¬£¬£¬Ö¡Êý¾Ý±»Ôö³¤ÉÏMACÍ·¼°Ö¡Î²·â×°³É802.11Êý¾ÝÖ¡£¡£¡£¡£¡£¨MPDU£©£¬£¬£¬£¬£¬£¬£¬MPDU/PSDU¾¹ýÎïÀí²ãÔö³¤PLCP Preamble£¨PLCPǰµ¼Â룩¼°PLCP Header£¨PHYÍ·£©£¬£¬£¬£¬£¬£¬£¬ÎÞÏß²à×îºóͨ¹ýÉ䯵¿Ú½«¶þ½øÔìÁ÷·¢Ë͵½½Ó¹Ü¶Ë¡£¡£¡£¡£¡£
½Ó¹Ü¶Ëͨ¹ýÏà·´õè¾¶¶Ô802.11Êý¾ÝÖ¡½øÐвð½â£¬£¬£¬£¬£¬£¬£¬×îºó»ñµÃ·¢ËͶ˵Ä3-7²ãµÄÍøÂçÊý¾Ý¡£¡£¡£¡£¡£
A-MSDUµÄºÍ̸Êý¾Ý×é³ÉÈçͼ2Ëùʾ£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ´ÓÉϵ½Ï½øÐбðÀë×¢Ã÷£º
£¨1£©Ò»¸öMSDUÓÉLCC/SNAPÍ·¡¢IPÍ·¡¢TCP/UDPÍ·¼°ºÍ̸Êý¾ÝData×é³É¡£¡£¡£¡£¡£
£¨2£©MSDUÔö³¤DA(Ö÷ÕŵØÖ·)£¬£¬£¬£¬£¬£¬£¬SA(Ô´µØÖ·)£¬£¬£¬£¬£¬£¬£¬ºóÐøÊý¾Ý³¤¶È¼°Padding(ËÄ×Ö½Ú¶ÔÆë)×é³ÉÒ»¸öMSDU×ÓÖ¡¡£¡£¡£¡£¡£
£¨3£©¶à¸öMSDU×ÓÖ¡×é³ÉÒ»¸ö802.11Ö¡µÄA-MSDUÓò¡£¡£¡£¡£¡£
£¨4£©802.11Êý¾Ý֡ͨ¹ýQOS ControlµÄA-MSDU PresentλÀ´°µÊ¾ÕâÊÇÒ»¸öÔ̺¬A-MSDUÓòµÄÊý¾ÝÖ¡¡£¡£¡£¡£¡£

ͼ2. A-MSDUÊý¾Ý×é³ÉʾÒâ
ÔÚ802.11ºÍ̸ÖУ¬£¬£¬£¬£¬£¬£¬Ò»¸öͨ³£µÄ802.11Êý¾ÝÖ¡ÓëA-MSDUÊý¾ÝÖ¡µÄ½á¹¹ÊÇÒ»ÑùµÄ£¬£¬£¬£¬£¬£¬£¬Ö»ÊÇQOS ControlÓòµÄA-MSDU Presetλ Ϊ1£¬£¬£¬£¬£¬£¬£¬Ôò±êʾÁ˸ÃÊý¾ÝÖ¡ÊÇÒ»¸öA-MSDUÊý¾ÝÖ¡¡£¡£¡£¡£¡£A-MSDU PresetλΪ0£¬£¬£¬£¬£¬£¬£¬Ôò±êʾÕâÊÇͨ³£802.11Êý¾ÝÖ¡¡£¡£¡£¡£¡£
ÔÚ802.11ºÍ̸ÖÐWEP¼°CCMPÖ»±£»£»£»£»£»£»¤802.11MACµÄÓÐÐ§ÔØºÉ£¬£¬£¬£¬£¬£¬£¬ÖÁÓÚ802.11Ö¡Í·ÒÔ¼°»ù²ãºÍ̸µÄ±êÍ·ÔòÔ·â²»¶¯£¬£¬£¬£¬£¬£¬£¬Ò²¾ÍÊÇ˵802.11ºÍ̸ÖÐÊý¾ÝÖ¡ÖÐQOS Control²¢Ã»ÓмÓÃÜ£¬£¬£¬£¬£¬£¬£¬ÕâΪ¹¥»÷ÕßÌṩÁ˹¥»÷Èë¿Ú¡£¡£¡£¡£¡£

ͼ3. CCMP¼ÓÃܵÄ802.11Êý¾ÝÖ¡Ìåʽ
ΪԤ·ÀÖÐÑëÈ˹¥»÷£¬£¬£¬£¬£¬£¬£¬IEEEÔÚ2011ÄêÉè¼ÆÁËSPPA-MSDU»úÔìÀ´±£»£»£»£»£»£»¤A-MSDU Presetλ¼°A-MSDUµÄPayload¡£¡£¡£¡£¡£SPP A-MSDUͨ¹ýÔÚRSN capabilities ÓòÖÐÔö³¤SPP A-MSDU Capable¼°SPP A-MSDU RequiredÀ´±êʾÊÇ·ñÖ§³ÖSPP A-MSDU»úÔì¼°ÊÇ·ñѡȡSPP A-MSDU»úÔì¡£¡£¡£¡£¡£

ͼ4. RSN Capabilities ÓòÊý¾ÝÌåʽ
2¡¢Õë¶ÔA-MSDU¾ÛºÏµÄÖ¡×¢Èë¹¥»÷(CVE-2020-24588)
¹ÌÈ»ÓÐSPP A-MSDU»úÔìÀ´±£»£»£»£»£»£»¤A-MSDU Presetλ²»±»´Û¸Ä£¬£¬£¬£¬£¬£¬£¬µ«ÊÇÔÚÏÖʵµÄ²âÊÔÖУ¬£¬£¬£¬£¬£¬£¬ÏÕЩËùÓеÄÉ豸¶¼²»×ñÑSPP A-MSDU»úÔ죬£¬£¬£¬£¬£¬£¬ÕâʹµÃÖÐÑëÈ˹¥»÷³ÉΪ¿ÉÄÜ¡£¡£¡£¡£¡£
ÎÒÃÇÈç¹û·¢ËͶ˷¢ËÍÁËÒ»¸öÕý³£µÄ802.11Êý¾ÝÖ¡£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»¸öÀïÃæ·â×°µÄÊÇÒ»¸öͨ³£TCP°ü£¬£¬£¬£¬£¬£¬£¬Æädst=¡°192.168.1.2", src="1.2.3.4", id=34

ͼ5. ÔʼµÄ802.11Êý¾ÝÖ¡
ÓÉÓÚÆ«ÒÆ0x18µÄQOS Control(0200£©²»Êܱ£»£»£»£»£»£»¤£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»½« QOS ControlÓòÖеÄA-MSDU Preset·×ªÎª1£¬£¬£¬£¬£¬£¬£¬Ê¹µÃQOS ControlµÄֵΪ8200£¬£¬£¬£¬£¬£¬£¬Í¬Ê±ÔÚ֡ĩβעÈë¶ñÒâµÄA-MSDU×ÓÖ¡2£¨ÈçÏÂͼµÄºìÉ«Ïß±êʾ£©£¬£¬£¬£¬£¬£¬£¬×îºó·¢Ë͸ø½Ó¹Ü¶Ë¡£¡£¡£¡£¡£

ͼ6. ´Û¸ÄºóµÄ802.11A-MSDUÊý¾ÝÖ¡
ÓÉÓÚQOS ControlÓòÖеÄA-MSDU Preset·×ªÎª1£¬£¬£¬£¬£¬£¬£¬µ±½Ó¹Ü¶Ë½Ó¹Üµ½Êý¾ÝÖ¡ºó£¬£¬£¬£¬£¬£¬£¬»á°´A-MSDUÌåʽÀ´²ð½âÀïÃæµÄÊý¾Ý¡£¡£¡£¡£¡£Êý¾Ý±»¼ø±ð³ÉÁ½¸öA-MSDU×ÓÖ¡¡£¡£¡£¡£¡£A-MSDU×ÓÖ¡1ÖеÄÊý¾ÝÊÇÔʼµÄMSDUÊý¾Ý£¬£¬£¬£¬£¬£¬£¬ËùÒԻᱻºÍ̸ջÅׯú£¬£¬£¬£¬£¬£¬£¬µ«µÚ¶þ¸ö×ÓÖ¡»á±»ÕýÈ·½âÎö²¢´¦Öᣡ£¡£¡£¡£ÕâÉÏÃæµÄÀý×ÓÖеڶþ¸ö×ÓÖ¡»á±»¼ø±ð³ÉICMP ping°ü£¬£¬£¬£¬£¬£¬£¬½Ó¹Ü¶Ë»á»Ø¸´Ò»¸öICMP echo Reply¸ø·¢ËͶˡ£¡£¡£¡£¡£
ÊÓÆµ1. ·¢ËͶËÊÕµ½ICMP echo Reply
ÏÂͼʾÒâÁËÖÐÑëÈËÖ¡×¢ÈëÁ÷³Ì£º

ͼ7. ÖÐÑëÈËÖ¡×¢ÈëÁ÷³Ì
£¨1£©STA£¨ÖÕ¶Ë£©ºÍAP£¨Èȵã/ÎÞÏß·ÓÉÆ÷£©ÐÅ·A£¨ÈçÐÅ·6£©, ³ÉÁ¢¹ØÁª
£¨2£©MITMÀûÓöàÐÅ·ÖÐÑëÈ˼¼ÊõʹµÃSTAÒÔΪAPÒѾÇл»µ½ÐÅ·B£¨ÈçÐÅ·11£©¡£¡£¡£¡£¡£
£¨3£©STAÔÚÐÅ·11¸ø MITM·¢ËͼÓÃܵÄWifiÕý³£Êý¾ÝÖ¡¡£¡£¡£¡£¡£
£¨4£©MITM½« ½Ó¹Üµ½µÄWifiÖ¡QOSÓòµÄA-MSDU Preset±êʾÉèΪ1£¬£¬£¬£¬£¬£¬£¬Í¬Ê±²åÈë´Û¸ÄµÄA-MSDUÊý¾Ý¡£¡£¡£¡£¡£°ÑÒ»¸öÕý³£µÄWifiÖ¡¸Ä³ÉÒ»¸öA-MSDUÖ¡£¬£¬£¬£¬£¬£¬£¬²¢×¢ÈëÒ»¸öICMPÒªÇó°ü£¬£¬£¬£¬£¬£¬£¬²¢ÔÚͨ·6·¢¸øAP¡£¡£¡£¡£¡£
£¨5£©AP½Ó¹Üµ½A-MSDUÊý¾ÝÖ¡£¬£¬£¬£¬£¬£¬£¬AP²ð½âA-MSDU£¬£¬£¬£¬£¬£¬£¬·Ö³É¶à¸öA-MSDU×ÓÖ¡£¬£¬£¬£¬£¬£¬£¬ÆäÖеÚÒ»¸öA-MSDU×Ó֡Ϊ·¸·¨°ü£¬£¬£¬£¬£¬£¬£¬»á±»Åׯú£¬£¬£¬£¬£¬£¬£¬µ«ºóÐøµÄMSDU×ÓÖ¡»á±»ÏµÍ³Õý³£´¦Öᣡ£¡£¡£¡£AP»á»Ø¸´ÊÕµ½Ò»¸öICMP Echo Ó¦´ð¸øMITM¡£¡£¡£¡£¡£
£¨6£©MITMÊÕµ½APµÄ»Ø¸´ºó£¬£¬£¬£¬£¬£¬£¬½«½Ó¹Üµ½µÄWIFI֡ת·¢¸øSTA£¬£¬£¬£¬£¬£¬£¬ÕâÑùSTAÊÕµ½AP»Ø¸´µÄICMPÓ¦´ð¡£¡£¡£¡£¡£
CVE-2020-24588µÄ½¨¸´
½ñÄê3ÔÂWindows°ä²¼ÁËÏàÓ¦µÄ²¹¶¡£¬£¬£¬£¬£¬£¬£¬½¨¸´ÁËFragAttacksϵÁзì϶£¬£¬£¬£¬£¬£¬£¬5ÔÂ11ÈÕLinuxÒ²°ä²¼ÁËFragAttacksϵÁзì϶²¹¶¡[6]£¬£¬£¬£¬£¬£¬£¬LinuxÕë¶ÔCVE-2020-24588µÄ½¨¸´ÈçÏ£º
---
net/wireless/util.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/net/wireless/util.c b/net/wireless/util.c
index 39966a873e40..7ec021a610ae 100644
--- a/net/wireless/util.c
+++ b/net/wireless/util.c
@@ -771,6 +771,9 @@ void ieee80211_amsdu_to_8023s(struct sk_buff *skb, struct sk_buff_head *list,
remaining = skb->len - offset;
if (subframe_len > remaining)
goto purge;
+/* mitigate A-MSDU aggregation injection attacks */
+if (ether_addr_equal(eth.h_dest, rfc1042_header))
+goto purge;
offset += sizeof(struct ethhdr);
last = remaining <= subframe_len + padding;
--
ÓÉÓÚÔÚA-MSDU¾ÛºÏ×¢Èë¹¥»÷ÖУ¬£¬£¬£¬£¬£¬£¬±ØÒª½«Í¨³£¼ÓÃÜWi-Fi֡ת»»ÎªA-MSDUÖ¡¡£¡£¡£¡£¡£ÕâÒâζ×ŵÚÒ»¸öA-MSDU×ÓÖ¡µÄǰ6×Ö½Ú¶ÔÓ¦ÓÚRFC1042µÄÖ¡Í·£¬£¬£¬£¬£¬£¬£¬liunxÄÚºËͨ¹ýÔö³¤ÅжÏDA£¨Ö¸±êµØÖ·£©ÊÇ·ñºÍrfc1042_header(\xaa\xaa\x03\x00\x00\x00)Ò»Ö£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÏà³ÆÔòÒÔΪÊǶñÒâ¹¥»÷£¬£¬£¬£¬£¬£¬£¬Äܹ»°ÑÕâ¸öA-MSDUÖ¡Åׯú¡£¡£¡£¡£¡£
»ìºÏÃÜÔ¿¹¥»÷(CVE-2020-24587)

ͼ8.»ìºÏÃÜÔ¿¹¥»÷Á÷³Ì
ÔÚ²½Öè1°ø±ß£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÓÕµ¼Êܺ¦Õß½Ó¼ûÊܹ¥»÷Õß½ÚÔìµÄ·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬Í¨¹ýһЩ¼¿Á©£¬£¬£¬£¬£¬£¬£¬ºÃ±ÈÖ¸¶¨Ò»¸ö³¬³¤µÄURL£¬£¬£¬£¬£¬£¬£¬´Ó¶øÊ¹Êܺ¦Õß·¢Ë͵ÄÊý¾Ý°ü²»µÃ²»·Ö³ÉÁ½¶Î½øÐд«Ê䣬£¬£¬£¬£¬£¬£¬·Ô쬵ÄÊý¾Ý°üÓÃÃØÔ¿k¼ÓÃÜ£¬£¬£¬£¬£¬£¬£¬ÕâÁ½¸öÊý¾Ý°üΪºÍ¡£¡£¡£¡£¡£¶ø¹¥»÷Õßͨ¹ý¶àÐÅ·µÄÖÐÑëÈ˽øÐÐÀ¹½Ø£¬£¬£¬£¬£¬£¬£¬Ò»µ©¼à²âµ½¹¥»÷ÕßÖ¸¶¨IPÊý¾Ý°ü£¬£¬£¬£¬£¬£¬£¬±ã½«´ËÊý¾Ý°üת·¢¸øAP£¬£¬£¬£¬£¬£¬£¬¼´APÒ»µ©ÊÕµ½´ËÊý¾Ý°üºó£¬£¬£¬£¬£¬£¬£¬¾Í½«Æä½âÃܺó´æÔÚÄÚ´æ°ø±ß¡£¡£¡£¡£¡£
ÔÚ²½Öè2½øÐÐ֮ǰ£¬£¬£¬£¬£¬£¬£¬Êܺ¦Õß±ØÒªÓëAP³ÁнøÐÐËÄ´ÎÎÕÊÖ²¢ÐÉÌеÄÃÜÔ¿¡£¡£¡£¡£¡£Ö®ºó¹¥»÷ÕßÆÚ´ýÊܺ¦Õß·¢ËÍÔ̺¬Ãô¸ÐÐÅÏ¢µÄÊý¾Ý°ü£¬£¬£¬£¬£¬£¬£¬¼´ºÍ¡£¡£¡£¡£¡£¹¥»÷Õß½«Êý¾Ý°üºÅÂëΪn+1µÄÊý¾Ý°üÀ¹½Ø£¬£¬£¬£¬£¬£¬£¬²¢½«ÆäÐòÁкÅÅú¸ÄΪs£¬£¬£¬£¬£¬£¬£¬¶øºóת·¢¸øAP£¬£¬£¬£¬£¬£¬£¬¼´Êý¾Ý°ü¡£¡£¡£¡£¡£¶øAPÖ±½Ó°ÑËûµ±×÷ÐòÁкÅsÊý¾Ý°üµÄµÚ¶þ¸ö·Ôì¬ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬½«Ëû½âÃܺó³Á×é³ÉеÄÊý¾Ý°ü£¬£¬£¬£¬£¬£¬£¬¶øÐµÄÊý¾Ý°üÖÐÔ̺¬Êܺ¦ÕßµÄÃô¸ÐÐÅÏ¢Óë¹¥»÷ÕßÖ¸¶¨µÄIP¡£¡£¡£¡£¡£Òò¶øÃô¸ÐÐÅÏ¢¾Í±»·¢Ë͵½Êܺ¦Õß½ÚÔìµÄ·þÎñÆ÷ÉÏ£¬£¬£¬£¬£¬£¬£¬Ôì³ÉÐÅϢй¶¡£¡£¡£¡£¡£
·Ô쬻º´æÍ¶¶¾¹¥»÷(CVE-2020-24586)

ͼ9.·Ô쬻º´æÍ¶¶¾¹¥»÷Á÷³Ì
ÔÚ²½Öè1ÖУ¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÐá̽µ½Êܺ¦ÕßµÄMACµØÖ·ºó£¬£¬£¬£¬£¬£¬£¬Î±ÔìÊܺ¦ÕßMACµØÖ·È¥ÏνÓAP¡£¡£¡£¡£¡£ÕâÑù¾ÍÄܹ»ºÏ·¨µÄÓÃÊܺ¦ÕßµÄÉí·ÝÔÚAPµÄÄÚ´æÖвåÈë·Ô쬡£¡£¡£¡£¡£
ÔÚ²½Öè2ÖУ¬£¬£¬£¬£¬£¬£¬Êܺ¦Õß½øÐÐÕý³£µÄÈÏÖ¤¹¤×÷£¬£¬£¬£¬£¬£¬£¬´Ëʱ¹¥»÷Õß·¢ËÍÊý¾Ý°ü£¬£¬£¬£¬£¬£¬£¬Õâ¸öÊý¾Ý°üÖÐÔ̺¬¹¥»÷ÕßÖ¸¶¨µÄIPÊý¾Ý°ü¡£¡£¡£¡£¡£¶øºóAP½âÃÜ´ËÊý¾Ý°ü£¬£¬£¬£¬£¬£¬£¬²¢±£ÁôÔÚÄÚ´æÖУ¬£¬£¬£¬£¬£¬£¬ÒÔÊܺ¦ÕßµÄMACµØÖ·×÷Ϊ±êʶ¡£¡£¡£¡£¡£¶øºó¹¥»÷Õßͨ¹ý·¢Ëͽâ³ýÈÏÖ¤µÄÊý¾Ý°ü²¢¶Ï¿ªÏνӣ¬£¬£¬£¬£¬£¬£¬ËæºóÔÚÊܺ¦ÕߺÍAPÖ®¼ä³ÉÁ¢Ò»¸ö¶àÐÅ·µÄÖÐÑëÈË¡£¡£¡£¡£¡£°ÑÎÈ´ËʱAPÄÚ´æÖеķÔ쬲¢Ã»Óб»¶Ï¸ù¡£¡£¡£¡£¡£
Ö®ºóÊܺ¦ÕßÓëAPÖ®¼ä½øÐÐÕý³£µÄÏνӡ£¡£¡£¡£¡£´Ëʱ¹¥»÷ÕßÖ»±ØÒªÆÚ´ýÊܺ¦Õß·¢Ë͵ڶþ¸ö·Ô쬣¬£¬£¬£¬£¬£¬£¬Êý¾Ý°üºÅÂëΪn+1£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß½«´ËÊý¾Ý°üÀ¹½Øºó£¬£¬£¬£¬£¬£¬£¬²¢½«´ËÊý¾Ý°üµÄÐòÁкÅÅú¸ÄΪs£¬£¬£¬£¬£¬£¬£¬¶øºóÆäת·¢¸øAP£¬£¬£¬£¬£¬£¬£¬¼´Êý¾Ý°ü£¬£¬£¬£¬£¬£¬£¬Ò»µ©APÊÕµ½´ËÊý¾Ý°ü£¬£¬£¬£¬£¬£¬£¬ºÍ»ìºÏÃÜÔ¿·ì϶ÀàËÆ£¬£¬£¬£¬£¬£¬£¬AP»á½«´ËÊý¾Ý°ü½âÃÜ£¬£¬£¬£¬£¬£¬£¬²¢ºÍ֮ǰ±£ÁôÔÚ»º´æÖеÄÊý¾Ý°ü³Á×é³ÉеÄÊý¾Ý°ü£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÕâÁ½¸öÊý¾Ý°üÔ̺¬Ò»ÑùµÄMACµØÖ·ºÍÐòÁкš£¡£¡£¡£¡£×îºó£¬£¬£¬£¬£¬£¬£¬AP½«³Á×éºóµÄÊý¾Ý°ü·¢Ë͸ø¹¥»÷Õß½ÚÔìµÄ·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬´Ó¶øÔì³ÉÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó£º
¡¾1¡¿https://papers.mathyvanhoef.com/usenix2021.pdf
¡¾2¡¿https://www.youtube.com/embed/88YZ4061tYw
¡¾3¡¿https://www.fragattacks.com/#notpatched
¡¾4¡¿https://github.com/vanhoefm/fragattacks
¡¾5¡¿https://lore.kernel.org/linux-wireless/20210511180259.159598-1-johannes@sipsolutions.net/
8827Ì«Ñô¼¯ÍÅ»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©
ADLab³ÉÁ¢ÓÚ1999Ä꣬£¬£¬£¬£¬£¬£¬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò»£¬£¬£¬£¬£¬£¬£¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ±£¬£¬£¬£¬£¬£¬£¬¡°ºÚȸ¹¥»÷¡±¸ÅÏëÊ×ÍÆÕß¡£¡£¡£¡£¡£½ØÖ¹Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬ADLabÒÑͨ¹ýCVEÀۼư䲼°²È«·ì϶½ü1100¸ö£¬£¬£¬£¬£¬£¬£¬Í¨¹ý CNVD/CNNVDÀۼư䲼°²È«·ì϶1000Óà¸ö£¬£¬£¬£¬£¬£¬£¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£¡£¡£¡£¡£³¢ÊÔÊÒ×êÑз½Ïòº¸Ç²Ù×÷ϵͳÓëÀûÓÃϵͳ°²È«×êÑÓ×¢ÖÇÄÜÖն˰²È«×êÑÓ×¢ÎïÁªÍøÖÇÄÜÉ豸°²È«×êÑÓ×¢Web°²È«×êÑÓ×¢¹¤¿ØÏµÍ³°²È«×êÑÓ×¢ÔÆ°²È«×êÑС£¡£¡£¡£¡£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑÓ×¢¹ú¶È³Áµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨Òµ°²È«·þÎñµÈ¡£¡£¡£¡£¡£



¾©¹«Íø°²±¸11010802024551ºÅ