¡¾Îó²îÇ鱨¡¿Spectre CPUÎó²î£¨CVE-2017-5753£©

Ðû²¼Ê±¼ä 2021-03-02

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2017-5753

ʱ   ¼ä

2021-03-02

Àà   ÐÍ

Éè¼Æ¹ýʧ  

µÈ   ¼¶


Ô¶³ÌʹÓÃ


Ó°Ïì¹æÄ£


 

0x01 Îó²îÏêÇé

image.png

2021Äê03ÔÂ01ÈÕ£¬Çå¾²Ñо¿Ö°Ô±ÖìÀû°²¡¤ÎÖÒÁÉ­£¨Julien Voisin£©ÔÚVirusTotal¶ñÒâÈí¼þÆÊÎöƽ̨ÉÏ·¢Ã÷ÁËSpectre CPUÎó²î£¨CVE-2017-5753£©µÄLinux°æºÍWindows°æµÄÎó²îʹÓóÌÐò£¬ÕâÌåÏÖÄܹ»¾ÙÐÐÏÖÊµÆÆËð²¢ÍêÈ«ÎäÆ÷»¯µÄÓÐÓÃʹÓóÌÐòÒѾ­ÔÚ¹«¹²ÁìÓòÖйûÕæ¡£

Spectre CPUÎó²îÊÇ2018Äê1ÔÂGoogle Project ZeroÅû¶µÄIntel¡¢AMDºÍARM´¦Öóͷ£Æ÷¼Ü¹¹ÖеÄÓ²¼þÉè¼ÆÈ±ÏÝ£¨Meltdown£ºCVE-2017-5754¡¢Spectre£ºCVE-2017-5753ºÍCVE-2017-5715£©£¬¹¥»÷ÕßÄܹ»Ê¹ÓÃÎó²îÔËÐÐÓ¦ÓóÌÐòÖеĴúÂëÀ´ÆÆËð²î±ðÓ¦ÓóÌÐòÖ®¼äÔÚCPU²ãÃæµÄ¸ôÀ룬ȻºóÇÔȡͳһϵͳÉÏÔËÐÐµÄÆäËüÓ¦ÓõÄÃô¸ÐÊý¾Ý¡£

GoogleÌåÏÖ£¬Spectre CPUÎó²î»áÓ°Ïì°üÀ¨Windows¡¢Linux¡¢macOS¡¢AndroidºÍChromeOSµÈÔÚÄÚµÄÖ÷Á÷²Ù×÷ϵͳ¡£×Ô¾õÏÖ¸ÃÎó²îÒÔÀ´£¬ËùÓÐÖ÷Á÷CPUºÍOS¹©Ó¦É̾ùÐû²¼Á˹̼þ²¹¶¡ºÍÈí¼þÐÞ¸´£¬µ«ÉÐδ¸üÐÂÆäϵͳµÄÓû§ÈÔÈ»ÈÝÒ×Êܵ½Spectre CPUÎó²îµÄ¹¥»÷£¬ÓÈÆäÊÇʹÓþɰæÐ¾Æ¬²¢ÔËÐоɰæ²Ù×÷ϵͳµÄÓû§£¨Èç2015ÄêÔµÄPC£¬²¢Ê¹ÓÃHaswell»ò¾ÉµÄIntel´¦Öóͷ£Æ÷£©¡£

VirusTotalÉϵÄÎó²îʹÓóÌÐòÊÇÉϸöÔÂÉÏ´«µÄ£¬¸ÃÈí¼þ°üÊÇÊÊÓÃÓÚWindowsºÍLinuxµÄImmunity Canvas 7.26×°ÖóÌÐò(Immunity CANVASΪȫÇòµÄÉøÍ¸²âÊÔÖ°Ô±ºÍÇ徲רҵְԱÌṩÁËÊý°ÙÖÖÎó²îʹÓá¢×Ô¶¯»¯µÄÎó²îʹÓÃϵͳÒÔ¼°ÖÜÈ«¡¢¿É¿¿µÄÎó²îʹÓÿª·¢¿ò¼Ü)¡£

image.png


´ËÎó²îʹÓóÌÐò¿ÉÒÔʹͨË×Óû§¿ÉÒÔ´ÓÄ¿µÄ×°±¸µÄÄÚºËÄÚ´æÖÐת´¢WindowsϵͳºÍLinuxϵͳÖÐ/etc/shadowÎļþÖеÄLM/NT¹þÏ£¡£±ðµÄ£¬¸ÃʹÓóÌÐò»¹Äܹ»×ª´¢Kerberos tickets£¬¿ÉÓëPsExecÒ»ÆðÓÃÓÚWindowsϵͳµÄÍâµØÈ¨ÏÞÉý¼¶ºÍºáÏòÒÆ¶¯¡£ÕâÒâζ×Å£¬ÈôÊǸÃÎó²î±»ÀÖ³ÉʹÓã¬Ôò¹¥»÷Õß¿ÉÒÔÇÔÈ¡ÊÜÓ°ÏìϵͳµÄÃô¸ÐÊý¾Ý£¬°üÀ¨ÃÜÂë¡¢ÎĵµÒÔ¼°ÄÚ´æÖÐÈκοÉÓÃµÄÆäËüÊý¾Ý¡£

image.png

image.png

 

ÈçVoisinËù˵£¬´ò¹ý¸ÃÎó²î²¹¶¡µÄLinux»òWindowsϵͳÔò²»ÊÜÓ°Ïì¡£¶øÎ¢ÈíÌåÏÖ£¬ÓÉÓÚ×°Öò¹¶¡ºóϵͳÐÔÄÜ»áÓÐÏÔ×ŵÄϽµ£¬Òò´ËÓû§×îÈÝÒ×Ìø¹ýÓ¦Óûº½â²½·¥¡£

³ý´ËÖ®Í⣬×ÝÈ»¹¥»÷ÕßÄõ½ÁËÕâÁ½¸öÎó²îʹÓóÌÐòÈí¼þ°üÖеÄÈκÎÒ»¸ö£¬Ö»ÔËÐÐËüÃÇÒ²²»»á±¬·¢ÈκÎЧ¹û£¬ÓÉÓÚËüÃǶ¼Ö»ÄÜÔÚ׼ȷµÄ²ÎÊýÏÂÖ´ÐУ¬³ý·Ç¹¥»÷ÕßÄܹ»ÔËÐÐ׼ȷµÄ²ÎÊý¡£

 

0x02 ´¦Öóͷ£½¨Òé

Spectre CPUÎó²îÒÑÓÚ2018ÄêÐÞ¸´£¬½¨Òéδʵʱ¸üеÄÓû§²Î¿¼CPUºÍOS¹©Ó¦É̹ٷ½Ðû²¼µÄÐÞ¸´³ÌÐò»ò»º½â²½·¥¡£

Õë¶Ôwindowsϵͳ£¬Î¢Èíͨ¹ý¸ü¸ÄWindowsºÍоƬ΢´úÂëÀ´»º½â´ËÎó²î£¬²¢½¨ÒéʹÓÃWindows UpdateºÍоƬ΢´úÂë¸üС£

ÏêÇéÁ´½Ó£º

https://www.microsoft.com/security/blog/2018/01/09/understanding-the-performance-impact-of-spectre-and-meltdown-mitigations-on-windows-systems/

 

0x03 ²Î¿¼Á´½Ó

https://www.virustotal.com/gui/file/6461d0988c835e91eb534757a9fa3ab35afe010bec7d5406d4dfb30ea767a62c/detection

https://www.bleepingcomputer.com/news/security/working-windows-and-linux-spectre-exploits-found-on-virustotal/?

https://dustri.org/b/spectre-exploits-in-the-wild.html

https://therecord.media/first-fully-weaponized-spectre-exploit-discovered-online/

 

0x04 ʱ¼äÏß

2021-03-01  Julien VoisinÅû¶ʹÓóÌÐò

2021-03-02  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png