TsuNAM·ì϶£º¿ÉDDoS DNS·þÎñÆ÷

°ä²¼¹¦·ò 2021-05-08

0x00 ·ì϶¸ÅÊö

CVE  ID


ʱ   ¼ä

2021-05-08

Àà   ÐÍ

DDoS

µÈ   ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ

·ñ

 

0x01 ·ì϶ÏêÇé

image.png

 

2021Äê05ÔÂ06ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬SIDN Labs£¨.nl×¢²á£©¡¢InternetNZ£¨.nz×¢²á£© ºÍÄϼÓÖÝ´óѧÐÅÏ¢¿ÆÑ§×êÑÐËùµÄ×êÑÐÈËÔ±¹«¿ªÅû¶ÁËÔÚDNS½âÎöÆ÷Öз¢ÏÖµÄÒ»¸ö¿Éµ¼ÖÂÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷µÄ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶±»³ÆÎªTsuNAME¡£¡£¡£¡£¡£¡£

ÏÖ½ñ»¥ÁªÍøÉÏ´óÎÞÊýʹÓõÄDNS·þÎñÆ÷¶¼Êǵݹé·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬£¬ËüÃǽÓÊÜÓû§µÄDNS²éÎʲ¢½«Æäת·¢µ½È¨ÍþDNS·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬£¬ÕâÖÖ¹¤×÷·½Ê½¾ÍÏñµç»°²¾Ò»Ñù£¬£¬£¬£¬£¬£¬£¬£¬Äܹ»·µ»ØÌض¨ÓòÃûµÄDNSÏìÓ¦¡£¡£¡£¡£¡£¡£

ÔÚÕý³£Çé¿öÏ£¬£¬£¬£¬£¬£¬£¬£¬ÊýÒÔ°ÙÍò¼ÆµÄµÝ¹éDNS·þÎñÆ÷ÿÌì»áÏòȨÍþÐÔDNS·þÎñÆ÷·¢ËÍÊýÊ®ÒÚ´ÎDNS²éÎÊ¡£¡£¡£¡£¡£¡£ÕâЩȨÍþÐÔDNS·þÎñÆ÷ͨ³£ÓÉ´óÐ͹«Ë¾ºÍ×éÖ¯ÍйܺÍÖÎÀí£¨ÄÚÈݽ»¸¶ÍøÂç¡¢´óÐͿƼ¼¾ÞÍ·¡¢»¥ÁªÍø·þÎñÌṩÉÌ¡¢ÓòÃû×¢²áÉÌ»òµ±¾Ö×éÖ¯£©£¬£¬£¬£¬£¬£¬£¬£¬ºÃ±ÈGoogleºÍCisco¡£¡£¡£¡£¡£¡£

×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Ôì×÷¶ñÒâµÄDNS²éÎÊ£¬£¬£¬£¬£¬£¬£¬£¬ÀûÓõݹéDNSÈí¼þµÄ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÏòÆäȨÍþDNS·þÎñÆ÷Ò»ÏòµØ·¢ËͶñÒâDNS²éÎÊ£¬£¬£¬£¬£¬£¬£¬£¬µ«ÕâÖÖ¹¥»÷ÒÀÀµÓÚÊÜÓ°ÏìµÄµÝ¹éDNSÈí¼þºÍȨÍþDNS·þÎñÆ÷ÉϵÄÃýÎóÅäÖᣡ£¡£¡£¡£¡£ÈôÊǹ¥»÷ÖÐ×¢²áÁË×ã¹»¶àµÄµÝ¹éDNS·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬£¬Ôò¹¥»÷ÕßÄܹ»ÌáÒéÖØ´óµÄDDoS¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶ø·ÛË鹨¼üµÄInternet½Úµã¡£¡£¡£¡£¡£¡£

×êÑÐÈËÔ±»¹·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬Ä³Ð©DNS½âÎöÆ÷ÔÚÓöµ½±»ÃýÎóÅäÖÃΪѭ»·ÒÀÀµNS¼Í¼µÄÓòÃûʱÆðÍ·Ñ­»·£¬£¬£¬£¬£¬£¬£¬£¬¶øÕâÖÖÑ­»·Äܹ»ÓÃÀ´¹¥»÷ȨÍþ·þÎñÆ÷¡£¡£¡£¡£¡£¡£

image.png

 

×êÑÐÈËÔ±Ôڻ㱨ÖÐÃèÊöÁË2020ÄêÔÚ.nz authroritative·þÎñÆ÷ÉϹ۲쵽µÄÒ»¸öÓëtsuNAMEÓйصÄÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬ÆäʱÓÐÁ½¸öÓòÃû±»ÃýÎóµØÅäÖÃΪѭ»·ÒÀÀµ¹ØÏµ£¬£¬£¬£¬£¬£¬£¬£¬Ëüµ¼ÖÂ×ÜÁ÷Á¿Ôö³¤ÁË50%¡£¡£¡£¡£¡£¡£Ôڻ㱨ÖУ¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËԹعʾÁËÒ»¸ö»ùÓÚÅ·Ã˵Ĺú¶È´úÂë¶¥¼¶ÓòÃûÈôºÎÒòÑ­»·ÒÀÀµµÄÃýÎóÅäÖöøµ¼ÖÂÁ÷Á¿Ôö³¤ÁË10±¶¡£¡£¡£¡£¡£¡£

×êÑÐÈËÔ±»¹°ä²¼ÁËÒ»ÖÖ³ÆÎªCycleHunterµÄ¹¤¾ß £¬£¬£¬£¬£¬£¬£¬£¬È¨ÍþDNS·þÎñÆ÷µÄÔËÓªÉÌÄܹ»Ê¹Óøù¤¾ßÔÚÆäDNSÇøÓòÎļþÖвéÕÒ²¢½â³ýÑ­»·ÒÀÀµÐÔ¡£¡£¡£¡£¡£¡£½â³ýÕâЩѭ»·ÒÀÀµÐÔ¿ÉÔÚδÀûÓò¹¶¡µÄÇé¿öÏÂÔ¤·À¹¥»÷ÕßÀûÓÃtsuNAME½øÐÐDDoS¹¥»÷¡£¡£¡£¡£¡£¡£

´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËԱʹÓÃCycleHunterÔÚÆß¸ö¶¥¼¶Óò£¨TLD£©ÖÐÆÀ¹ÀÁËÔ¼1.84ÒÚ¸öÓòÃû£¬£¬£¬£¬£¬£¬£¬£¬²¢·¢ÏÖÁËÔ¼1400¸öÓòÃûʹÓõÄ44¸öÑ­»·ÒÀÀµµÄNS¼Í¼£¨¿ÉÄÜÊÇÅäÖÃÃýÎ󣩣¬£¬£¬£¬£¬£¬£¬£¬ÕâЩ¼Í¼¿ÉÄܻᱻÀÄÓÃÓÚÖ®ºóµÄ¹¥»÷¡£¡£¡£¡£¡£¡£

 

Ó°ÏìÁìÓò

Google Public DNS£¨GDNS£©

Cisco OpenDNS

ÆäËüDNS½âÎöÆ÷

£¨×¢£ºUnbound¡¢BINDºÍKnotDNS²»ÊÜtsuNAMEÓ°Ï죩

 

0x02 ´ëÖý¨Òé

ĿǰGoogleºÍCiscoÒѾ­½¨¸´ÁË´Ë·ì϶£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓйØDNSÔËÓªÉ̾¡¿ìʹÓÃCycleHunter¹¤¾ß¼ì²â²¢½â³ýDNSÇøÓòÖеÄÑ­»·ÒÀÀµ¹ØÏµ»òʵʱ½¨¸´¸Ã·ì϶¡£¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://github.com/SIDN/CycleHunter

 

0x03 ²Î¿¼Á´½Ó

https://therecord.media/new-tsuname-bug-can-be-used-to-ddos-key-dns-servers/?

https://tsuname.io/

https://tsuname.io/tech_report.pdf

https://tsuname.io/advisory.pdf

 

0x04 ¹¦·òÏß

2021-05-06  ×êÑÐÈËÔ±¹«¿ªÅû¶·ì϶

2021-05-08  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png