˼¿Æ°²È«Æô¶¯Ó²¼þ´Û¸ÄThrangrycat·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-05-17

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-1649£¬£¬£¬£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£ºÖм¶£¬£¬£¬£¬£¬£¬ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º6.7£¬£¬£¬£¬£¬£¬ £¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-1862£¬£¬£¬£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ß¼¶£¬£¬£¬£¬£¬£¬ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.2£¬£¬£¬£¬£¬£¬ £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾

CVE-2019-1649

Ö§³ÖTAmµÄ100¶à¿î˼¿Æ²úÆ·


CVE-2019-1862

ÔËÐÐIOS XE°æ±¾16ÇÒÆôÓÃÁËHTTP ServerÖ°ÄܵÄ˼¿ÆÉ豸


·ì϶¸ÅÊö


×êÑÐÈËÔ±ÔÚ˼¿Æ²úÆ·Öз¢ÏÖÁËÒ»¸ö·ì϶£¬£¬£¬£¬£¬£¬ £¬¿Éµ¼Ö¹¥»÷ÕßÔÚÆóÒµºÍµ±¾ÖÍøÂçÖеĴóÁ¿É豸Èç·ÓÉÆ÷¡¢»¥»»»úºÍ·À»ðǽÉÏÖ²ÈëÓÆ¾ÃºóÃÅ ¡£¡£¡£¡£¡£Õâ¸ö·ì϶±»¶¨ÃûΪ¡°Thrangrycat¡±£¨¡°ÈýÖ»ÄÕÅ­µÄ衱£©£¬£¬£¬£¬£¬£¬ £¬Óɰ²È«¹«Ë¾Red Baloon·¢ÏÖÇÒ±àºÅΪCVE-2019-1649£¬£¬£¬£¬£¬£¬ £¬Ó°ÏìÖ§³ÖÐÅÀµÃªµãÄ£¿ £¿£¿£¿£¿é(TAm)µÄ¶à¿î˼¿Æ²úÆ· ¡£¡£¡£¡£¡£


ƾ¾Ý°²È«³§ÉÌRed BalloonµÄ»ã±¨£¬£¬£¬£¬£¬£¬ £¬Thrangrycat·ì϶ÊÇÓÉ˼¿ÆÐÅÀµÃªÄ£¿ £¿£¿£¿£¿é£¨TAm£©ÖеÄÓ²¼þÉè¼ÆÈ±µãÒýÆðµÄ ¡£¡£¡£¡£¡£Ë¼¿ÆTAmÊÇ×Ô2013ÄêÒÔÀ´ÏÕЩÔÚËùÓÐ˼¿ÆÆóÒµÉ豸ÖÐʵÏֵĻùÓÚÓ²¼þµÄ°²È«Æô¶¯Ö°ÄÜ£¬£¬£¬£¬£¬£¬ £¬ÓÃÓÚÈ·±£ÔÚÓ²¼þƽ̨ÉÏÔËÐеĹ̼þÊÇÕæÊµÇÒδ¾­Åú¸ÄµÄ ¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÓÉÓÚ¶Ô´úÂëÇøÓòµÄ²»ÕýÈ·²é³­Ôì³ÉµÄ£¬£¬£¬£¬£¬£¬ £¬¸Ã´úÂëÇøÓòÖÎÀí°²È«Æô¶¯Ó²¼þµÄFPGA±¾µØ¸üР¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÅú¸ÄFPGA±ÈÌØÁ÷£¬£¬£¬£¬£¬£¬ £¬¿É½«¶ñÒâ¹Ì¼þдÈë¸Ã×é¼þ£¬£¬£¬£¬£¬£¬ £¬´Ó¶ø·ÛË鰲ȫÆô¶¯¹ý³Ì²¢Ê¹Ë¼¿ÆµÄÐÅÀµÁ´´Óµ××ÓÉÏÎÞЧ ¡£¡£¡£¡£¡£ÕâÒ»Åú¸ÄÓµÓÐÓÆ¾ÃÐÔ£¬£¬£¬£¬£¬£¬ £¬¿ÉÔÚºóÐøµÄÆô¶¯¹ý³ÌÖнûÓÃÐÅÀµÃª£¬£¬£¬£¬£¬£¬ £¬Ò²¿É½ûÓÃÖ®ºóµÄTAmÈí¼þ¸üР¡£¡£¡£¡£¡£


ÓÉÓÚÀûÓø÷ì϶±ØÒªÓµÓиùȨÏÞ£¬£¬£¬£¬£¬£¬ £¬Òò¶øË¼¿Æ°ä²¼°²È«²¼¸æ°µÊ¾£¬£¬£¬£¬£¬£¬ £¬Ö»ÓÐÓµÓжÔÖ¸±êϵͳÎïÀí½Ó¼ûȨÏ޵ı¾µØ¹¥»÷ÕßÄÜÁ¦ÔÚ×é¼þÖÐдÈë¾­Åú¸ÄµÄ¹Ì¼þ¾µÏñ ¡£¡£¡£¡£¡£


È»¶ø£¬£¬£¬£¬£¬£¬ £¬Red Balloon×êÑÐÈËÔ±Ö¸³ö£¬£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÒ²ÄÜÁ´½ÓÆäËüȱµãÔ¶³ÌÀûÓÃThrangrycat·ì϶£¬£¬£¬£¬£¬£¬ £¬´Ó¶ø»ñÈ¡¸ùȨÏÞ»òÕßÖÁÉÙÒÔ¸ùÉí·ÝÖ´ÐкÅÁî ¡£¡£¡£¡£¡£


ΪÁËÑÝʾ¸Ã¹¥»÷£¬£¬£¬£¬£¬£¬ £¬×êÑÐÈËÔ±Åû¶ÁË»ùÓÚwebµÄ˼¿ÆIOS²Ù×÷ϵͳµÄÓû§½Ó¿ÚRCE·ì϶CVE-2019-1862£¬£¬£¬£¬£¬£¬ £¬¿Éµ¼ÖÂÒѵǼµÄÖÎÀíÔ±ÒÔ¸ùȨÏÞÔÚÊÜÓ°ÏìÉ豸µÄµ×²ãLinux shellÉÏÖ´ÐÐËÁÒâºÅÁî ¡£¡£¡£¡£¡£


»ñµÃ¸ù½Ó¼ûȨÏ޺󣬣¬£¬£¬£¬£¬ £¬¶ñÒâÖÎÀíÔ±¿ÉÄÜʹÓÃThrangrycat·ì϶Զ³ÌÈÆ¹ýÖ¸±êÉ豸ÉϵÄTAm£¬£¬£¬£¬£¬£¬ £¬²¢×°ÖöñÒâºóÃÅ ¡£¡£¡£¡£¡£


×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬£¬ £¬Í¨¹ýÁ´½ÓThrangrycatºÍÔ¶³ÌºÅÁî×¢Èë·ì϶£¬£¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉÄÜÔ¶³Ì²¢ÓƾõØÈƹý˼¿ÆµÄ°²È«Æô¶¯»úÔì²¢Ëø¶¨ËùÓÐTAmµÄ½«À´Èí¼þ¸üР¡£¡£¡£¡£¡£

·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP ¡£¡£¡£¡£¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬£¬£¬£¬£¬£¬ £¬²¹¶¡»ñÈ¡Á´½Ó£º


CVE-2019-1649

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190513-secureboot


CVE-2019-1862

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190513-webui#fshttps://thrangrycat.com/


²Î¿¼Á´½Ó


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190513-secureboot
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190513-webui#fshttps://thrangrycat.com/
https://thehackernews.com/2019/05/cisco-secure-boot-bypass.html