TCP/IP¿ÍÕ»£ºNAME£ºWRECK DNSЭÒéÎó²î

Ðû²¼Ê±¼ä 2021-04-13

0x00 Îó²î¸ÅÊö

2021Äê04ÔÂ13ÈÕ£¬£¬£¬Çå¾²Ö°Ô±Åû¶ÁËTCP/IP¿ÍÕ»ÖÐDNSЭÒéÖÐͳ³ÆÎªNAME£ºWRECKµÄ9¸öÇå¾²Îó²î£¬£¬£¬ÕâЩÎó²îÖÁÉÙÓ°ÏìÁË1ÒÚ¸öInternetÉÏÔËÐеÄ×°±¸£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îʹÊÜÓ°ÏìµÄ×°±¸ÍÑ»ú»ò¶Ô×°±¸¾ÙÐпØÖÆ¡£¡£¡£ ¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png


NAME£ºWRECKÊÇÎïÁªÍøÆóÒµÇå¾²¹«Ë¾ForescoutºÍÒÔÉ«ÁÐÇå¾²Ñо¿Ð¡×éJSOFµÄÅäºÏ·¢Ã÷µÄ£¬£¬£¬ÕâЩÎó²îÓ°ÏìµÄTCP/IP¿ÍÕ»°üÀ¨µ«²»ÏÞÓÚ£º

FreeBSD£¨Ó°Ïì°æ±¾£º12.1£©-BSDϵÁÐÖÐ×îÊ¢ÐеIJÙ×÷ϵͳ֮һ¡£¡£¡£ ¡£¡£¡£¡£

IPnet£¨Ó°Ïì°æ±¾£ºVxWorks 6.6£©-×î³õÓÉInterpeak¿ª·¢£¬£¬£¬ÏÖÔÚÓÉWindRiverά»¤£¬£¬£¬²¢ÓÉVxWorksʵʱ²Ù×÷ϵͳ£¨RTOS£©Ê¹Óᣡ£¡£ ¡£¡£¡£¡£

NetX£¨Ó°Ïì°æ±¾£º6.0.1£©-ThreadX RTOSµÄÒ»²¿·Ö£¬£¬£¬ÏÖÔÚÊÇMicrosoftά»¤µÄÒ»¸ö¿ªÔ´ÏîÄ¿£¬£¬£¬Ãû³ÆÎªAzure RTOS NetX¡£¡£¡£ ¡£¡£¡£¡£

Nucleus NET£¨Ó°Ïì°æ±¾£º4.3£©-ÓÉÎ÷ÃÅ×ÓÓªÒµMentor Graphicsά»¤µÄNucleus RTOSµÄÒ»²¿·Ö£¬£¬£¬ÓÃÓÚÒ½ÁÆ¡¢¹¤Òµ¡¢ÏûºÄÀà¡¢º½¿Õº½ÌìºÍÎïÁªÍø×°±¸¡£¡£¡£ ¡£¡£¡£¡£

 

¹¥»÷Õß¿ÉÒÔʹÓÃNAME£ºWRECKÎó²îÇÔÈ¡Ãô¸ÐÊý¾Ý¡¢Ð޸Ļòʹװ±¸ÍÑ»úÒÔ¶ÔÖÆÔìÐÐÒµÖеÄÕþ¸®»òÆóҵЧÀÍÆ÷¡¢Ò½ÁÆ»ú¹¹¡¢ÁãÊÛÉÌ»ò¹«Ë¾Ôì³ÉÖØ´óÇ徲ʹÊ¡£¡£¡£ ¡£¡£¡£¡£

image.png

 

¹¥»÷Õß»¹¿ÉÒÔʹÓÃÕâЩÎó²î¸Ä¶¯×¡Õ¬»òÉÌÒµ³¡ºÏµÄÖÇÄÜ×°±¸£¬£¬£¬ÒÔ¿ØÖƹ©ÎÂů͸·ç¡¢½ûÓÃÇ徲ϵͳ»ò¸Ä¶¯×Ô¶¯ÕÕÃ÷ϵͳ¡£¡£¡£ ¡£¡£¡£¡£

image.png

 

Ñо¿Ö°Ô±ÔÚÆÊÎöÉÏÊöTCP/IP¿ÍÕ»ÖеÄDNSʱ£¬£¬£¬ÆÊÎöÁ˸ÃЭÒéµÄÐÂÎÅѹËõ¹¦Ð§¡£¡£¡£ ¡£¡£¡£¡£DNSÏìÓ¦Êý¾Ý°üÖаüÀ¨ÏàͬµÄÓòÃû»ò²¿·ÖÓòÃûµÄÇéÐβ¢²»ÉÙ¼û£¬£¬£¬Òò´ËËüʹÓÃÒ»ÖÖѹËõ»úÖÆÀ´¼õСDNSÐÂÎŵĴóС£¡£¡£ ¡£¡£¡£¡£¬£¬£¬ÕâÖÖ±àÂë²»µ«Ó¦ÓÃÔÚDNSÆÊÎöÆ÷ÖУ¬£¬£¬Ëü»¹Ó¦ÓÃÔڶಥDNS£¨mDNS£©¡¢DHCP¿Í»§¶ËºÍIPv6·ÓÉÆ÷ͨ¸æÖС£¡£¡£ ¡£¡£¡£¡£

ForescoutÔÚÆä±¨¸æÖÐÚ¹ÊÍ˵£¬£¬£¬Ö»¹ÜijЩЭÒ鲢δÕýʽ֧³ÖѹËõ£¬£¬£¬µ«¸Ã¹¦Ð§»¹±£´æÓÚÐí¶àÓ¦ÓÃÖС£¡£¡£ ¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬²¢·ÇNAME£ºWRECKÖеÄËùÓÐÎó²î¶¼¿ÉÒÔ±»Ê¹ÓÃÀ´»ñµÃÏàͬµÄЧ¹û¡£¡£¡£ ¡£¡£¡£¡£ÆäÖÐ×îÑÏÖØµÄÊÇÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬Æä×î¸ßÆÀ·ÖΪ9.8£¨Âú·Ö10·Ö£©£¬£¬£¬9¸öÎó²îÈçϱíËùʾ£¬£¬£¬²¢·ÇËùÓÐÎó²î¶¼ÓëÐÂÎÅѹËõÓйأº

CVE   ID

Stack

ÐÎò

ÊÜÓ°Ï칦Ч

DZÔÚÓ°Ïì

ÆÀ·Ö

CVE-2020-7461

FreeBSD


  dhclient
£¨8£©µÄDHCPÊý¾Ý°üÖеÄÑ¡Ïî119Êý¾Ý¾ÙÐÐÆÊÎöʱ·ºÆð½çÏß¹ýʧ

-ÍøÂçÉϵĹ¥»÷Õß¿ÉÒÔ½«¶ñÒâÖÆ×÷µÄÊý¾Ý·¢Ë͵½DHCP¿Í»§¶Ë

Message

compression   

RCE

7.7

CVE-2016-20009

IPnet

-ÐÂÎŽâѹËõ¹¦Ð§»ùÓÚ¿ÍÕ»µÄÒç³ö

Message

compression   

RCE

9.8

CVE-2020-15795

Nucleus   NET

-DNSÓòÃû±êÇ©ÆÊÎö¹¦Ð§ÎÞ·¨×¼È·ÑéÖ¤DNSÏìÓ¦ÖеÄÃû³Æ

-ÆÊÎöÃûÌùýʧµÄÏìÓ¦¿ÉÄܵ¼ÖÂд²Ù×÷Áè¼Ý·ÖÅɵĽṹµÄĩβ

Domain   name

label   parsing

RCE

8.1

CVE-2020-27009

Nucleus   NET

-DNSÓòÃû¼Í¼½âѹËõ¹¦Ð§ÎÞ·¨×¼È·ÑéÖ¤Ö¸ÕëÆ«ÒÆÖµ

-ÆÊÎöÃûÌùýʧµÄÏìÓ¦¿ÉÄܵ¼ÖÂд²Ù×÷Áè¼Ý·ÖÅɵĽṹµÄĩβ

Message

compression

RCE

8.1

CVE-2020-27736

Nucleus   NET

-DNSÓòÃû±êÇ©ÆÊÎö¹¦Ð§ÎÞ·¨×¼È·ÑéÖ¤DNSÏìÓ¦ÖеÄÃû³Æ

-ÆÊÎöÃûÌùýʧµÄÏìÓ¦¿ÉÄܵ¼ÖÂд²Ù×÷Áè¼Ý·ÖÅɵĽṹµÄĩβ

Domain

name   label

parsing

¾Ü¾øÐ§ÀÍ

6.5

CVE-2020-27737

Nucleus   NET

-DNSÏìÓ¦ÆÊÎö¹¦Ð§ÎÞ·¨×¼È·ÑéÖ¤ÖÖÖÖ³¤¶ÈºÍ¼Í¼Êý

-ÆÊÎöÃûÌùýʧµÄÏìÓ¦¿ÉÄܻᵼÖ¶ÁÈ¡Áè¼ÝÒÑ·ÖÅɽṹµÄĩβ

Domain   name

label   parsing

¾Ü¾øÐ§ÀÍ

6.5

CVE-2020-27738

Nucleus   NET

-DNSÓòÃû¼Í¼½âѹËõ¹¦Ð§ÎÞ·¨×¼È·ÑéÖ¤Ö¸ÕëÆ«ÒÆÖµ

-ÆÊÎöÃûÌùýʧµÄÏìÓ¦¿ÉÄܵ¼ÖÂÁè¼Ý·ÖÅɽṹĩβµÄ¶ÁÈ¡»á¼û

Message

compression

¾Ü¾øÐ§ÀÍ

6.5

CVE-2021-25677

Nucleus   NET

-DNS¿Í»§¶ËÎÞ·¨×¼È·Ëæ»ú»¯DNSÊÂÎñID£¨TXID£©ºÍUDP¶Ë¿ÚºÅ

Transaction   ID

DNS»º´æÖж¾/ÓÕÆ­

5.3

*

NetX

-DNSÆÊÎöÆ÷ÖеÄÁ½¸ö¹¦Ð§ÎÞ·¨¼ì²éѹËõÖ¸ÕëÊÇ·ñ²»¼´ÊÇÄ¿½ñÕýÔÚÆÊÎöµÄÏàÍ¬Æ«ÒÆÁ¿£¬£¬£¬´Ó¶ø¿ÉÄܵ¼ÖÂÎÞÏÞÑ­»·

Message

compression

¾Ü¾øÐ§ÀÍ

6.5

 

ʹÓõ¥¸öÎó²î¿ÉÄܲ»»áÔì³ÉÌ«´óÓ°Ï죬£¬£¬µ«ÈôÊǹ¥»÷Õß½«ËüÃÇ×éºÏÔÚÒ»ÆðÀ´Ê¹Ó㬣¬£¬¾Í¿ÉÄÜ»áÔì³ÉÑÏÖØÆÆË𡣡£¡£ ¡£¡£¡£¡£ÀýÈ磬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÒ»¸öÎó²î½«í§ÒâÊý¾ÝдÈëÒ×Êܹ¥»÷×°±¸µÄÃô¸ÐÄÚ´æÎ»Ö㬣¬£¬Ê¹ÓÃÁíÒ»¸öÎó²îÔÚÊý¾Ý°üÖÐ×¢Èë´úÂ룬£¬£¬È»ºóÔÙʹÓõÚÈý¸öÎó²î½«Æäת´ï¸øÄ¿µÄ¡£¡£¡£ ¡£¡£¡£¡£

Forescout¹«Ë¾µÄ±¨¸æÉîÈë̽ÌÖÁËÊÖÒÕϸ½Ú£¬£¬£¬¼´Ê¹ÓÃÔÚ¿ªÔ´TCP/IP¿ÍÕ»Öз¢Ã÷µÄNAME:WRECKÎó²îÒÔ¼°AMNESIA:33ÖеÄÎó²îÀ´ÊµÏÖÔ¶³Ì´úÂëÖ´Ðй¥»÷¡£¡£¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾»¹ÌÖÂÛÁ˶à¸öÔÚDNSÐÂÎÅÆÊÎöÆ÷ÖÐÒ»Ö±ÖØ¸´µÄÖ´ÐÐÎÊÌ⣬£¬£¬ÕâЩÎÊÌâ±»³ÆÎªanti-patterns£¨·´Ä£Ê½£©£¬£¬£¬ËüÃÇÊÇÔì³ÉNAME:WRECKÎó²îµÄÔµ¹ÊÔ­ÓÉ£º

ȱÉÙTXIDÑéÖ¤£¬£¬£¬Ëæ»úTXIDºÍÔ´UDP¶Ë¿Úȱ·¦£»£»£»£»£»£»£»

ȱ·¦ÓòÃû×Ö·ûÑéÖ¤£»£»£»£»£»£»£»

ȱÉÙ±êÇ©ºÍÃû³Æ³¤¶ÈÑéÖ¤£»£»£»£»£»£»£»

ȱÉÙNULLÖÕÖ¹ÑéÖ¤£»£»£»£»£»£»£»

ȱÉټͼ¼ÆÊý×Ö¶ÎÑéÖ¤£»£»£»£»£»£»£»

ȱ·¦ÓòÃûѹËõÖ¸ÕëºÍÆ«ÒÆÁ¿ÑéÖ¤£»£»£»£»£»£»£»

±ðµÄ£¬£¬£¬Forescout»¹ÌṩÁËÁ½¸ö¿ªÔ´¹¤¾ß£¬£¬£¬¿ÉÒÔ×ÊÖúÈ·¶¨Ä¿µÄÍøÂç×°±¸ÊÇ·ñÔËÐÐÌØ¶¨µÄǶÈëʽTCP/IPЭÒéÕ»£¨Project Memoria Detector£©ºÍÓÃÓÚ¼ì²âÀàËÆÓÚNAME:WRECKµÄÎÊÌ⣨namewreck£¬£¬£¬ÓëJoernÒ»ÆðʹÓã©¡£¡£¡£ ¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé

NAME£ºWRECKµÄÐÞ¸´³ÌÐòÊÊÓÃÓÚ FreeBSD¡¢Nucleus NETºÍ NetX£¬£¬£¬½¨ÒéÏÈʵÑéÒÔÏÂÇå¾²½¨Ò飬£¬£¬ÔÙʵʱӦÓÃ×°±¸¹©Ó¦ÉÌÐû²¼µÄÇå¾²¸üС£¡£¡£ ¡£¡£¡£¡£

Çå¾²½¨Ò飺

ʹÓÃһЩ»º½âÐÅÏ¢À´¿ª·¢¼ì²âDNSÎó²îµÄÊðÃû£»£»£»£»£»£»£»

·¢Ã÷²¢ÇåµãÔËÐÐÒ×Êܹ¥»÷¿ÍÕ»µÄ×°±¸£»£»£»£»£»£»£»

ʵÑé·Ö¶Î¿ØÖƺÍÊʵ±µÄnetwork hygiene£»£»£»£»£»£»£»

¼àÊÓÊÜÓ°ÏìµÄ×°±¸¹©Ó¦ÉÌÐû²¼µÄ²¹¶¡£¡£¡£ ¡£¡£¡£¡£»£»£»£»£»£»£»

ÉèÖÃ×°±¸ÒÀÀµÄÚ²¿DNSЧÀÍÆ÷£»£»£»£»£»£»£»

¼à¿ØËùÓÐÍøÂçÁ÷Á¿ÖеĶñÒâÊý¾Ý°ü¡£¡£¡£ ¡£¡£¡£¡£

 

 

0x03 ²Î¿¼Á´½Ó

https://www.bleepingcomputer.com/news/security/name-wreck-dns-vulnerabilities-affect-over-100-million-devices/

https://www.freebsd.org/security/advisories/FreeBSD-SA-20:26.dhclient.asc

https://github.com/Forescout/project-memoria-detector

https://github.com/Forescout/namewreck

 

0x04 ʱ¼äÏß

2021-04-13  bleepingcomputerÅû¶Îó²î

2021-04-13  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png