TCP/IP²Ö¿â£ºNAME£ºWRECK DNSºÍ̸·ì϶

°ä²¼¹¦·ò 2021-04-13

0x00 ·ì϶¸ÅÊö

2021Äê04ÔÂ13ÈÕ£¬ £¬£¬£¬ £¬£¬°²È«ÈËÔ±Åû¶ÁËTCP/IP²Ö¿âÖÐDNSºÍ̸ÖÐͳ³ÆÎªNAME£ºWRECKµÄ9¸ö°²È«·ì϶£¬ £¬£¬£¬ £¬£¬ÕâЩ·ì϶ÖÁÉÙÓ°ÏìÁË1ÒÚ¸öInternetÉÏÔËÐеÄÉ豸£¬ £¬£¬£¬ £¬£¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶ʹÊÜÓ°ÏìµÄÉ豸ÍÑ»ú»ò¶ÔÉ豸½øÐнÚÔì¡£¡£¡£¡£¡£¡£

 

0x01 ·ì϶ÏêÇé

image.png


NAME£ºWRECKÊÇÎïÁªÍøÆóÒµ°²È«¹«Ë¾ForescoutºÍÒÔÉ«Áа²È«×êÑÐÓ××éJSOFµÄ¹²Í¬·¢Ïֵģ¬ £¬£¬£¬ £¬£¬ÕâЩ·ì϶ӰÏìµÄTCP/IP²Ö¿âÔ̺¬µ«²»ÏÞÓÚ£º

FreeBSD£¨Ó°Ïì°æ±¾£º12.1£©-BSDϵÁÐÖÐ×îÊ¢ÐеIJÙ×÷ϵͳ֮һ¡£¡£¡£¡£¡£¡£

IPnet£¨Ó°Ïì°æ±¾£ºVxWorks 6.6£©-×î³õÓÉInterpeak¿ª·¢£¬ £¬£¬£¬ £¬£¬´Ë¿ÌÓÉWindRiverÊØ»¤£¬ £¬£¬£¬ £¬£¬²¢ÓÉVxWorksʵʱ²Ù×÷ϵͳ£¨RTOS£©Ê¹Óᣡ£¡£¡£¡£¡£

NetX£¨Ó°Ïì°æ±¾£º6.0.1£©-ThreadX RTOSµÄÒ»²¿ÃÅ£¬ £¬£¬£¬ £¬£¬´Ë¿ÌÊÇMicrosoftÊØ»¤µÄÒ»¸ö¿ªÔ´ÏîÄ¿£¬ £¬£¬£¬ £¬£¬Ãû³ÆÎªAzure RTOS NetX¡£¡£¡£¡£¡£¡£

Nucleus NET£¨Ó°Ïì°æ±¾£º4.3£©-ÓÉÎ÷ÃÅ×ÓÒµÎñMentor GraphicsÊØ»¤µÄNucleus RTOSµÄÒ»²¿ÃÅ£¬ £¬£¬£¬ £¬£¬ÓÃÓÚÒ½ÁÆ¡¢¹¤Òµ¡¢Ïû·ÑÀà¡¢º½¿Õº½ÌìºÍÎïÁªÍøÉ豸¡£¡£¡£¡£¡£¡£

 

¹¥»÷ÕßÄܹ»ÀûÓÃNAME£ºWRECK·ì϶ÇÔÈ¡Ãô¸ÐÊý¾Ý¡¢Åú¸Ä»òʹÉ豸ÍÑ»úÒÔ¶ÔÔì×÷ÐÐÒµÖÐÈ·µ±¾Ö»òÆóÒµ·þÎñÆ÷¡¢Ò½ÁÆ»ú¹¹¡¢ÁãÊÛÉÌ»ò¹«Ë¾Ôì³É³Á´ó°²È«±äÂÒ¡£¡£¡£¡£¡£¡£

image.png

 

¹¥»÷Õß»¹Äܹ»ÀûÓÃÕâЩ·ì϶´Û¸Äסլ»òóÒ׳¡ËùµÄÖÇÄÜÉ豸£¬ £¬£¬£¬ £¬£¬ÒÔ½ÚÔ칩ÎÂů͸·ç¡¢½ûÓð²Õûϵͳ»ò´Û¸Ä×Ô¶¯ÕÕÃ÷ϵͳ¡£¡£¡£¡£¡£¡£

image.png

 

×êÑÐÈËÔ±ÔÚ·ÖÎöÉÏÊöTCP/IP²Ö¿âÖеÄDNSʱ£¬ £¬£¬£¬ £¬£¬·ÖÎöÁ˸úÍ̸µÄÐÂÎÅѹËõÖ°ÄÜ¡£¡£¡£¡£¡£¡£DNSÏìÓ¦Êý¾Ý°üÖÐÔ̺¬Ò»ÑùµÄÓòÃû»ò²¿ÃÅÓòÃûµÄÇé¿ö²¢²»ÉÙ¼û£¬ £¬£¬£¬ £¬£¬Òò¶øËüʹÓÃÒ»ÖÖѹËõ»úÔìÀ´¼õÓ×DNSÐÂÎŵĴóÓ×£¬ £¬£¬£¬ £¬£¬ÕâÖÖ±àÂë²»½öÀûÓÃÔÚDNS½âÎöÆ÷ÖУ¬ £¬£¬£¬ £¬£¬Ëü»¹ÀûÓÃÔڶಥDNS£¨mDNS£©¡¢DHCP¿Í»§¶ËºÍIPv6·ÓÉÆ÷¹«¸æÖС£¡£¡£¡£¡£¡£

ForescoutÔÚÆä»ã±¨ÖÐÚ¹ÊÍ˵£¬ £¬£¬£¬ £¬£¬Ö»¹ÜijЩºÍ̸²¢Î´Õýʽ֧³ÖѹËõ£¬ £¬£¬£¬ £¬£¬µ«¸ÃÖ°ÄÜ»¹´æÔÚÓںܶàÀûÓÃÖС£¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬ £¬£¬£¬ £¬£¬²¢·ÇNAME£ºWRECKÖеÄËùÓзì϶¶¼Äܹ»±»ÀûÓÃÀ´»ñµÃÒ»ÑùµÄÁ˾Ö¡£¡£¡£¡£¡£¡£ÆäÖÐ×îÑϳÁµÄÊÇÔ¶³Ì´úÂëÖ´Ðзì϶£¬ £¬£¬£¬ £¬£¬Æä×î¸ßÆÀ·ÖΪ9.8£¨Âú·Ö10·Ö£©£¬ £¬£¬£¬ £¬£¬9¸ö·ì϶ÈçϱíËùʾ£¬ £¬£¬£¬ £¬£¬²¢·ÇËùÓзì϶¶¼ÓëÐÂÎÅѹËõÓйأº

CVE   ID

Stack

ÃèÊö

ÊÜÓ°ÏìÖ°ÄÜ

DZÔÚÓ°Ïì

ÆÀ·Ö

CVE-2020-7461

FreeBSD


  dhclient
£¨8£©µÄDHCPÊý¾Ý°üÖеÄÑ¡Ïî119Êý¾Ý½øÐнâÎöʱ³öÏÖÌìǵÃýÎó

-ÍøÂçÉϵĹ¥»÷ÕßÄܹ»½«¶ñÒâÔì×÷µÄÊý¾Ý·¢Ë͵½DHCP¿Í»§¶Ë

Message

compression   

RCE

7.7

CVE-2016-20009

IPnet

-ÐÂÎŽâѹËõÖ°ÄÜ»ùÓÚ²Ö¿âµÄÒç³ö

Message

compression   

RCE

9.8

CVE-2020-15795

Nucleus   NET

-DNSÓòÃû±êÇ©½âÎöÖ°ÄÜÎÞ·¨ÕýÈ·ÑéÖ¤DNSÏìÓ¦ÖеÄÃû³Æ

-½âÎöÌåʽÃýÎóµÄÏìÓ¦¿ÉÄܵ¼ÖÂд²Ù×÷³¬³ö·ÖÅäµÄ½á¹¹µÄĩβ

Domain   name

label   parsing

RCE

8.1

CVE-2020-27009

Nucleus   NET

-DNSÓòÃû¼Í¼½âѹËõÖ°ÄÜÎÞ·¨ÕýÈ·ÑéÖ¤Ö¸ÕëÆ«ÒÆÖµ

-½âÎöÌåʽÃýÎóµÄÏìÓ¦¿ÉÄܵ¼ÖÂд²Ù×÷³¬³ö·ÖÅäµÄ½á¹¹µÄĩβ

Message

compression

RCE

8.1

CVE-2020-27736

Nucleus   NET

-DNSÓòÃû±êÇ©½âÎöÖ°ÄÜÎÞ·¨ÕýÈ·ÑéÖ¤DNSÏìÓ¦ÖеÄÃû³Æ

-½âÎöÌåʽÃýÎóµÄÏìÓ¦¿ÉÄܵ¼ÖÂд²Ù×÷³¬³ö·ÖÅäµÄ½á¹¹µÄĩβ

Domain

name   label

parsing

»Ø¾ø·þÎñ

6.5

CVE-2020-27737

Nucleus   NET

-DNSÏìÓ¦½âÎöÖ°ÄÜÎÞ·¨ÕýÈ·ÑéÖ¤¸÷À೤¶ÈºÍ¼Í¼Êý

-½âÎöÌåʽÃýÎóµÄÏìÓ¦¿ÉÄܻᵼÖ¶ÁÈ¡³¬³öÒÑ·ÖÅä½á¹¹µÄĩβ

Domain   name

label   parsing

»Ø¾ø·þÎñ

6.5

CVE-2020-27738

Nucleus   NET

-DNSÓòÃû¼Í¼½âѹËõÖ°ÄÜÎÞ·¨ÕýÈ·ÑéÖ¤Ö¸ÕëÆ«ÒÆÖµ

-½âÎöÌåʽÃýÎóµÄÏìÓ¦¿ÉÄܵ¼Ö³¬³ö·ÖÅä½á¹¹Ä©Î²µÄ¶ÁÈ¡½Ó¼û

Message

compression

»Ø¾ø·þÎñ

6.5

CVE-2021-25677

Nucleus   NET

-DNS¿Í»§¶ËÎÞ·¨ÕýÈ·Ëæ»ú»¯DNSÊÂÎñID£¨TXID£©ºÍUDP¶Ë±êÓï

Transaction   ID

DNS»º´æÖж¾/ºýŪ

5.3

*

NetX

-DNS½âÎöÆ÷ÖеÄÁ½¸öÖ°ÄÜÎÞ·¨²é³­Ñ¹ËõÖ¸ÕëÊÇ·ñ²»µÅ×Úµ±Ç°ÔÚ½âÎöµÄÒ»ÑùÆ«ÒÆÁ¿£¬ £¬£¬£¬ £¬£¬´Ó¶ø¿ÉÄܵ¼ÖÂÎÞÏÞÑ­»·

Message

compression

»Ø¾ø·þÎñ

6.5

 

ÀûÓõ¥¸ö·ì϶¿ÉÄܲ»»áÔì³ÉÌ«´óÓ°Ï죬 £¬£¬£¬ £¬£¬µ«ÈôÊǹ¥»÷Õß½«ËüÃÇ×éºÏÔÚһ·À´ÀûÓ㬠£¬£¬£¬ £¬£¬¾Í¿ÉÄÜ»áÔì³ÉÑϳÁ·ÛËé¡£¡£¡£¡£¡£¡£ÀýÈ磬 £¬£¬£¬ £¬£¬¹¥»÷ÕßÄܹ»ÀûÓÃÒ»¸ö·ì϶½«ËÁÒâÊý¾ÝдÈëÒ×Êܹ¥»÷É豸µÄÃô¸ÐÄÚ´æµØÎ»£¬ £¬£¬£¬ £¬£¬ÀûÓÃÁíÒ»¸ö·ì϶ÔÚÊý¾Ý°üÖÐ×¢Èë´úÂ룬 £¬£¬£¬ £¬£¬¶øºóÔÙÀûÓõÚÈý¸ö·ì϶½«Æä´«µÝ¸øÖ¸±ê¡£¡£¡£¡£¡£¡£

Forescout¹«Ë¾µÄ»ã±¨Éî¿Ì̽ÇóÁ˼¼Êõϸ½Ú£¬ £¬£¬£¬ £¬£¬¼´ÀûÓÃÔÚ¿ªÔ´TCP/IP²Ö¿âÖз¢ÏÖµÄNAME:WRECK·ì϶ÒÔ¼°AMNESIA:33Öеķì϶À´ÊµÏÖÔ¶³Ì´úÂëÖ´Ðй¥»÷¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾»¹»áÉÌÁ˶à¸öÔÚDNSÐÂÎŽâÎöÆ÷Öв»ÐݳÁ¸´µÄÖ´ÐÐÎÊÌ⣬ £¬£¬£¬ £¬£¬ÕâЩÎÊÌâ±»³ÆÎªanti-patterns£¨·´Ä£Ê½£©£¬ £¬£¬£¬ £¬£¬ËüÃÇÊÇÔì³ÉNAME:WRECK·ì϶µÄÔ­Òò£º

¶ÌȱTXIDÑéÖ¤£¬ £¬£¬£¬ £¬£¬Ëæ»úTXIDºÍÔ´UDP¶Ë¿Ú²»¼°£»£»£»£»£»

²»×ãÓòÃû×Ö·ûÑéÖ¤£»£»£»£»£»

¶Ìȱ±êÇ©ºÍÃû³Æ³¤¶ÈÑéÖ¤£»£»£»£»£»

¶ÌȱNULLÖÕÖ¹ÑéÖ¤£»£»£»£»£»

¶Ìȱ¼Í¼¼ÆÊý×Ö¶ÎÑéÖ¤£»£»£»£»£»

²»×ãÓòÃûѹËõÖ¸ÕëºÍÆ«ÒÆÁ¿ÑéÖ¤£»£»£»£»£»

´Ë±í£¬ £¬£¬£¬ £¬£¬Forescout»¹ÌṩÁËÁ½¸ö¿ªÔ´¹¤¾ß£¬ £¬£¬£¬ £¬£¬Äܹ»Ô®ÊÖÈ·¶¨Ö¸±êÍøÂçÉ豸ÊÇ·ñÔËÐÐÌØ¶¨µÄǶÈëʽTCP/IPºÍ̸ջ£¨Project Memoria Detector£©ºÍÓÃÓÚ¼ì²âÀàËÆÓÚNAME:WRECKµÄÎÊÌ⣨namewreck£¬ £¬£¬£¬ £¬£¬ÓëJoernһ·ʹÓã©¡£¡£¡£¡£¡£¡£


0x02 ´ëÖý¨Òé

NAME£ºWRECKµÄ½¨¸´·¨Ê½ºÏÓÃÓÚ FreeBSD¡¢Nucleus NETºÍ NetX£¬ £¬£¬£¬ £¬£¬½¨ÒéÏÈÖ´ÐÐÒÔϰ²È«½¨Ò飬 £¬£¬£¬ £¬£¬ÔÙʵʱÀûÓÃÉ豸¹©¸øḚ́䲼µÄ°²È«¸üС£¡£¡£¡£¡£¡£

°²È«½¨Ò飺

ʹÓÃһЩ»º½âÐÅÏ¢À´¿ª·¢¼ì²âDNS·ì϶µÄÊðÃû£»£»£»£»£»

·¢ÏÖ²¢Å̵ãÔËÐÐÒ×Êܹ¥»÷²Ö¿âµÄÉ豸£»£»£»£»£»

Ö´ÐзֶνÚÔìºÍÊʵ±µÄnetwork hygiene£»£»£»£»£»

¼à¶½ÊÜÓ°ÏìµÄÉ豸¹©¸øḚ́䲼µÄ²¹¶¡£¡£¡£¡£¡£¡£»£»£»£»£»

ÅäÖÃÉ豸ÒÀÀµÄÚ²¿DNS·þÎñÆ÷£»£»£»£»£»

¼à¿ØËùÓÐÍøÂçÁ÷Á¿ÖеĶñÒâÊý¾Ý°ü¡£¡£¡£¡£¡£¡£

 

 

0x03 ²Î¿¼Á´½Ó

https://www.bleepingcomputer.com/news/security/name-wreck-dns-vulnerabilities-affect-over-100-million-devices/

https://www.freebsd.org/security/advisories/FreeBSD-SA-20:26.dhclient.asc

https://github.com/Forescout/project-memoria-detector

https://github.com/Forescout/namewreck

 

0x04 ¹¦·òÏß

2021-04-13  bleepingcomputerÅû¶·ì϶

2021-04-13  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png