TCP/IP¿ÍÕ»£ºNAME£ºWRECK DNSÐÒéÎó²î
Ðû²¼Ê±¼ä 2021-04-130x00 Îó²î¸ÅÊö
2021Äê04ÔÂ13ÈÕ£¬Çå¾²Ö°Ô±Åû¶ÁËTCP/IP¿ÍÕ»ÖÐDNSÐÒéÖÐͳ³ÆÎªNAME£ºWRECKµÄ9¸öÇå¾²Îó²î£¬ÕâЩÎó²îÖÁÉÙÓ°ÏìÁË1ÒÚ¸öInternetÉÏÔËÐеÄ×°±¸£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îʹÊÜÓ°ÏìµÄ×°±¸ÍÑ»ú»ò¶Ô×°±¸¾ÙÐпØÖÆ¡£
0x01 Îó²îÏêÇé

NAME£ºWRECKÊÇÎïÁªÍøÆóÒµÇå¾²¹«Ë¾ForescoutºÍÒÔÉ«ÁÐÇå¾²Ñо¿Ð¡×éJSOFµÄÅäºÏ·¢Ã÷µÄ£¬ÕâЩÎó²îÓ°ÏìµÄTCP/IP¿ÍÕ»°üÀ¨µ«²»ÏÞÓÚ£º
FreeBSD£¨Ó°Ïì°æ±¾£º12.1£©-BSDϵÁÐÖÐ×îÊ¢ÐеIJÙ×÷ϵͳ֮һ¡£
IPnet£¨Ó°Ïì°æ±¾£ºVxWorks 6.6£©-×î³õÓÉInterpeak¿ª·¢£¬ÏÖÔÚÓÉWindRiverά»¤£¬²¢ÓÉVxWorksʵʱ²Ù×÷ϵͳ£¨RTOS£©Ê¹Óá£
NetX£¨Ó°Ïì°æ±¾£º6.0.1£©-ThreadX RTOSµÄÒ»²¿·Ö£¬ÏÖÔÚÊÇMicrosoftά»¤µÄÒ»¸ö¿ªÔ´ÏîÄ¿£¬Ãû³ÆÎªAzure RTOS NetX¡£
Nucleus NET£¨Ó°Ïì°æ±¾£º4.3£©-ÓÉÎ÷ÃÅ×ÓÓªÒµMentor Graphicsά»¤µÄNucleus RTOSµÄÒ»²¿·Ö£¬ÓÃÓÚÒ½ÁÆ¡¢¹¤Òµ¡¢ÏûºÄÀà¡¢º½¿Õº½ÌìºÍÎïÁªÍø×°±¸¡£
¹¥»÷Õß¿ÉÒÔʹÓÃNAME£ºWRECKÎó²îÇÔÈ¡Ãô¸ÐÊý¾Ý¡¢Ð޸Ļòʹװ±¸ÍÑ»úÒÔ¶ÔÖÆÔìÐÐÒµÖеÄÕþ¸®»òÆóÒµ·þÎñÆ÷¡¢Ò½ÁÆ»ú¹¹¡¢ÁãÊÛÉÌ»ò¹«Ë¾Ôì³ÉÖØ´óÇ徲ʹʡ£

¹¥»÷Õß»¹¿ÉÒÔʹÓÃÕâЩÎó²î¸Ä¶¯×¡Õ¬»òÉÌÒµ³¡ºÏµÄÖÇÄÜ×°±¸£¬ÒÔ¿ØÖƹ©ÎÂů͸·ç¡¢½ûÓÃÇ徲ϵͳ»ò¸Ä¶¯×Ô¶¯ÕÕÃ÷ϵͳ¡£

Ñо¿Ö°Ô±ÔÚÆÊÎöÉÏÊöTCP/IP¿ÍÕ»ÖеÄDNSʱ£¬ÆÊÎöÁ˸ÃÐÒéµÄÐÂÎÅѹËõ¹¦Ð§¡£DNSÏìÓ¦Êý¾Ý°üÖаüÀ¨ÏàͬµÄÓòÃû»ò²¿·ÖÓòÃûµÄÇéÐβ¢²»ÉÙ¼û£¬Òò´ËËüʹÓÃÒ»ÖÖѹËõ»úÖÆÀ´¼õСDNSÐÂÎŵľÞϸ£¬ÕâÖÖ±àÂë²»µ«Ó¦ÓÃÔÚDNSÆÊÎöÆ÷ÖУ¬Ëü»¹Ó¦ÓÃÔڶಥDNS£¨mDNS£©¡¢DHCP¿Í»§¶ËºÍIPv6·ÓÉÆ÷ͨ¸æÖС£
ForescoutÔÚÆä±¨¸æÖÐÚ¹ÊÍ˵£¬Ö»¹ÜijЩÐÒ鲢δÕýʽ֧³ÖѹËõ£¬µ«¸Ã¹¦Ð§»¹±£´æÓÚÐí¶àÓ¦ÓÃÖС£ÖµµÃ×¢ÖØµÄÊÇ£¬²¢·ÇNAME£ºWRECKÖеÄËùÓÐÎó²î¶¼¿ÉÒÔ±»Ê¹ÓÃÀ´»ñµÃÏàͬµÄЧ¹û¡£ÆäÖÐ×îÑÏÖØµÄÊÇÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬Æä×î¸ßÆÀ·ÖΪ9.8£¨Âú·Ö10·Ö£©£¬9¸öÎó²îÈçϱíËùʾ£¬²¢·ÇËùÓÐÎó²î¶¼ÓëÐÂÎÅѹËõÓйأº
CVE ID | Stack | ÐÎò | ÊÜÓ°Ï칦Ч | DZÔÚÓ°Ïì | ÆÀ·Ö |
CVE-2020-7461 | FreeBSD |
-ÍøÂçÉϵĹ¥»÷Õß¿ÉÒÔ½«¶ñÒâÖÆ×÷µÄÊý¾Ý·¢Ë͵½DHCP¿Í»§¶Ë | Message compression | RCE | 7.7 |
CVE-2016-20009 | IPnet | -ÐÂÎŽâѹËõ¹¦Ð§»ùÓÚ¿ÍÕ»µÄÒç³ö | Message compression | RCE | 9.8 |
CVE-2020-15795 | Nucleus NET | -DNSÓòÃû±êÇ©ÆÊÎö¹¦Ð§ÎÞ·¨×¼È·ÑéÖ¤DNSÏìÓ¦ÖеÄÃû³Æ -ÆÊÎöÃûÌùýʧµÄÏìÓ¦¿ÉÄܵ¼ÖÂд²Ù×÷Áè¼Ý·ÖÅɵĽṹµÄĩβ | Domain name label parsing | RCE | 8.1 |
CVE-2020-27009 | Nucleus NET | -DNSÓòÃû¼Í¼½âѹËõ¹¦Ð§ÎÞ·¨×¼È·ÑéÖ¤Ö¸ÕëÆ«ÒÆÖµ -ÆÊÎöÃûÌùýʧµÄÏìÓ¦¿ÉÄܵ¼ÖÂд²Ù×÷Áè¼Ý·ÖÅɵĽṹµÄĩβ | Message compression | RCE | 8.1 |
CVE-2020-27736 | Nucleus NET | -DNSÓòÃû±êÇ©ÆÊÎö¹¦Ð§ÎÞ·¨×¼È·ÑéÖ¤DNSÏìÓ¦ÖеÄÃû³Æ -ÆÊÎöÃûÌùýʧµÄÏìÓ¦¿ÉÄܵ¼ÖÂд²Ù×÷Áè¼Ý·ÖÅɵĽṹµÄĩβ | Domain name label parsing | ¾Ü¾ø·þÎñ | 6.5 |
CVE-2020-27737 | Nucleus NET | -DNSÏìÓ¦ÆÊÎö¹¦Ð§ÎÞ·¨×¼È·ÑéÖ¤ÖÖÖÖ³¤¶ÈºÍ¼Í¼Êý -ÆÊÎöÃûÌùýʧµÄÏìÓ¦¿ÉÄܻᵼÖ¶ÁÈ¡Áè¼ÝÒÑ·ÖÅɽṹµÄĩβ | Domain name label parsing | ¾Ü¾ø·þÎñ | 6.5 |
CVE-2020-27738 | Nucleus NET | -DNSÓòÃû¼Í¼½âѹËõ¹¦Ð§ÎÞ·¨×¼È·ÑéÖ¤Ö¸ÕëÆ«ÒÆÖµ -ÆÊÎöÃûÌùýʧµÄÏìÓ¦¿ÉÄܵ¼ÖÂÁè¼Ý·ÖÅɽṹĩβµÄ¶ÁÈ¡»á¼û | Message compression | ¾Ü¾ø·þÎñ | 6.5 |
CVE-2021-25677 | Nucleus NET | -DNS¿Í»§¶ËÎÞ·¨×¼È·Ëæ»ú»¯DNSÊÂÎñID£¨TXID£©ºÍUDP¶Ë¿ÚºÅ | Transaction ID | DNS»º´æÖж¾/ÓÕÆ | 5.3 |
* | NetX | -DNSÆÊÎöÆ÷ÖеÄÁ½¸ö¹¦Ð§ÎÞ·¨¼ì²éѹËõÖ¸ÕëÊÇ·ñ²»¼´ÊÇÄ¿½ñÕýÔÚÆÊÎöµÄÏàÍ¬Æ«ÒÆÁ¿£¬´Ó¶ø¿ÉÄܵ¼ÖÂÎÞÏÞÑ»· | Message compression | ¾Ü¾ø·þÎñ | 6.5 |
ʹÓõ¥¸öÎó²î¿ÉÄܲ»»áÔì³ÉÌ«´óÓ°Ï죬µ«ÈôÊǹ¥»÷Õß½«ËüÃÇ×éºÏÔÚÒ»ÆðÀ´Ê¹Ó㬾ͿÉÄÜ»áÔì³ÉÑÏÖØÆÆËð¡£ÀýÈ磬¹¥»÷Õß¿ÉÒÔʹÓÃÒ»¸öÎó²î½«í§ÒâÊý¾ÝдÈëÒ×Êܹ¥»÷×°±¸µÄÃô¸ÐÄÚ´æÎ»Öã¬Ê¹ÓÃÁíÒ»¸öÎó²îÔÚÊý¾Ý°üÖÐ×¢Èë´úÂ룬ȻºóÔÙʹÓõÚÈý¸öÎó²î½«Æäת´ï¸øÄ¿µÄ¡£
Forescout¹«Ë¾µÄ±¨¸æÉîÈë̽ÌÖÁËÊÖÒÕϸ½Ú£¬¼´Ê¹ÓÃÔÚ¿ªÔ´TCP/IP¿ÍÕ»Öз¢Ã÷µÄNAME:WRECKÎó²îÒÔ¼°AMNESIA:33ÖеÄÎó²îÀ´ÊµÏÖÔ¶³Ì´úÂëÖ´Ðй¥»÷¡£¸Ã¹«Ë¾»¹ÌÖÂÛÁ˶à¸öÔÚDNSÐÂÎÅÆÊÎöÆ÷ÖÐÒ»Ö±ÖØ¸´µÄÖ´ÐÐÎÊÌ⣬ÕâЩÎÊÌâ±»³ÆÎªanti-patterns£¨·´Ä£Ê½£©£¬ËüÃÇÊÇÔì³ÉNAME:WRECKÎó²îµÄÔµ¹ÊÔÓÉ£º
ȱÉÙTXIDÑéÖ¤£¬Ëæ»úTXIDºÍÔ´UDP¶Ë¿Úȱ·¦£»
ȱ·¦ÓòÃû×Ö·ûÑéÖ¤£»
ȱÉÙ±êÇ©ºÍÃû³Æ³¤¶ÈÑéÖ¤£»
ȱÉÙNULLÖÕÖ¹ÑéÖ¤£»
ȱÉټͼ¼ÆÊý×Ö¶ÎÑéÖ¤£»
ȱ·¦ÓòÃûѹËõÖ¸ÕëºÍÆ«ÒÆÁ¿ÑéÖ¤£»
±ðµÄ£¬Forescout»¹ÌṩÁËÁ½¸ö¿ªÔ´¹¤¾ß£¬¿ÉÒÔ×ÊÖúÈ·¶¨Ä¿µÄÍøÂç×°±¸ÊÇ·ñÔËÐÐÌØ¶¨µÄǶÈëʽTCP/IPÐÒéÕ»£¨Project Memoria Detector£©ºÍÓÃÓÚ¼ì²âÀàËÆÓÚNAME:WRECKµÄÎÊÌ⣨namewreck£¬ÓëJoernÒ»ÆðʹÓã©¡£
0x02 ´¦Öóͷ£½¨Òé
NAME£ºWRECKµÄÐÞ¸´³ÌÐòÊÊÓÃÓÚ FreeBSD¡¢Nucleus NETºÍ NetX£¬½¨ÒéÏÈʵÑéÒÔÏÂÇå¾²½¨Ò飬ÔÙʵʱӦÓÃ×°±¸¹©Ó¦ÉÌÐû²¼µÄÇå¾²¸üС£
Çå¾²½¨Ò飺
ʹÓÃһЩ»º½âÐÅÏ¢À´¿ª·¢¼ì²âDNSÎó²îµÄÊðÃû£»
·¢Ã÷²¢ÇåµãÔËÐÐÒ×Êܹ¥»÷¿ÍÕ»µÄ×°±¸£»
ʵÑé·Ö¶Î¿ØÖƺÍÊʵ±µÄnetwork hygiene£»
¼àÊÓÊÜÓ°ÏìµÄ×°±¸¹©Ó¦ÉÌÐû²¼µÄ²¹¶¡£»
ÉèÖÃ×°±¸ÒÀÀµÄÚ²¿DNS·þÎñÆ÷£»
¼à¿ØËùÓÐÍøÂçÁ÷Á¿ÖеĶñÒâÊý¾Ý°ü¡£
0x03 ²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/name-wreck-dns-vulnerabilities-affect-over-100-million-devices/
https://www.freebsd.org/security/advisories/FreeBSD-SA-20:26.dhclient.asc
https://github.com/Forescout/project-memoria-detector
https://github.com/Forescout/namewreck
0x04 ʱ¼äÏß
2021-04-13 bleepingcomputerÅû¶Îó²î
2021-04-13 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ