¡¾Îó²îͨ¸æ¡¿À¶ÑÀ & WiFi оƬ12Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-12-14


0x00 Îó²î¸ÅÊö

2021Äê12ÔÂ13ÈÕ£¬£¬£¬£¬¶à¸öÑо¿»ú¹¹ÁªºÏÐû²¼ÁËÀ¶ÑÀ¼°WiFi¼Ü¹¹ºÍЭÒéÖеĶà¸öÇå¾²Îó²î£¬£¬£¬£¬ÕâЩÎó²îÓ°ÏìÁËÊýÊ®ÒÚWiFiºÍÀ¶ÑÀоƬ£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Ê¹ÓÃÎó²îÕë¶Ô×°±¸µÄÀ¶ÑÀ×é¼þÌáÈ¡ÃÜÂë²¢¼à¿ØWiFiоƬÉϵÄÁ÷Á¿¡£¡£¡£¡£¡£ ¡£

 

0x01 Îó²îÏêÇé

image.png

ÏÖ´úÏûºÄÀàµç×Ó×°±¸£¨ÈçÖÇÄÜÊÖ»ú£©µÄSoC¾ßÓÐ×ÔÁ¦µÄÀ¶ÑÀ¡¢WiFiºÍLTE×é¼þ£¬£¬£¬£¬Ã¿¸ö×é¼þ¶¼ÓÐ×Ô¼ºµÄרÓÃÇ徲ʵÏÖ£¬£¬£¬£¬µ«ÕâЩ×é¼þͨ³£¹²ÏíÏàͬµÄ×ÊÔ´£¬£¬£¬£¬¿ÉÒÔ½«ÕâЩ¹²Ïí×ÊÔ´ÓÃ×÷¿çÎÞÏßоƬ½çÏßÌᳫºáÏòȨÏÞÌáÉý¹¥»÷µÄÇÅÁº£¬£¬£¬£¬ÒÔʵÏÖ´úÂëÖ´ÐС¢ÄÚ´æ¶ÁÈ¡ºÍ¾Ü¾øÐ§À͵È¡£¡£¡£¡£¡£ ¡£

image.png

ΪÁËʹÓÃÕâЩÎó²î£¬£¬£¬£¬Ê×ÏÈÐèÒªÔÚÀ¶ÑÀ»ò WiFi оƬÉÏÖ´ÐдúÂ룬£¬£¬£¬Ò»µ©ÊµÏÖ£¬£¬£¬£¬¾Í¿ÉÒÔʹÓù²ÏíÄÚ´æ×ÊÔ´¶Ô×°±¸µÄÆäËûоƬ¾ÙÐкáÏò¹¥»÷¡£¡£¡£¡£¡£ ¡£ÕâЩÎó²î°üÀ¨£º

l  CVE-2020-10368£ºWiFi δ¼ÓÃÜÊý¾Ýй¶£¨¼Ü¹¹£©

l  CVE-2020-10367£ºWi-Fi ´úÂëÖ´ÐУ¨¼Ü¹¹£©

l  CVE-2019-15063£ºWi-Fi ¾Ü¾øÐ§ÀÍ£¨Ð­Ò飩

l  CVE-2020-10370£ºÀ¶ÑÀ¾Ü¾øÐ§ÀÍ£¨Ð­Ò飩

l  CVE-2020-10369£ºÀ¶ÑÀÊý¾Ýй¶£¨Ð­Ò飩

l  CVE-2020-29531£ºWiFi ¾Ü¾øÐ§ÀÍ£¨Ð­Ò飩

l  CVE-2020-29533£ºWiFi Êý¾Ý×ß©£¨Ð­Ò飩

l  CVE-2020-29532£ºÀ¶ÑÀ¾Ü¾øÐ§ÀÍ£¨Ð­Ò飩

l  CVE-2020-29530£ºÀ¶ÑÀÊý¾Ýй¶£¨Ð­Ò飩

ÕâЩÎó²î±£´æÓÚBroadcom¡¢Silicon Labs ºÍ Cypress µÈÖÆÔìÉÌÉú²úµÄоƬÖУ¬£¬£¬£¬¶øÕâЩоƬӦÓÃÓÚÊýÊ®ÒÚµç×Ó×°±¸ÖС£¡£¡£¡£¡£ ¡£Ñо¿Ö°Ô±Õë¶Ô CVE-2020-10368 ºÍ CVE-2020-10367 ²âÊÔµÄ×°±¸ÈçÏ£º

image.png

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚÕâЩÎó²îÔÝδÍêÈ«ÐÞ¸´¡£¡£¡£¡£¡£ ¡£½¨ÒéʹÓÃÈçϱ £»£»£»£»£»¤²½·¥£º

l  ɾ³ý²»ÐëÒªµÄÀ¶ÑÀ×°±¸Åä¶Ô £»£»£»£»£»

l  ´ÓÉèÖÃÖÐɾ³ý²»Ê¹ÓÃµÄ WiFi ÍøÂç £»£»£»£»£»

l  ÔÚ¹«¹²³¡ºÏʹÓÃÊÖʱ»ú¼û»¥ÁªÍø¶ø²»ÊÇ WiFi¡£¡£¡£¡£¡£ ¡£

²Î¿¼Á´½Ó£º

https://arxiv.org/pdf/2112.05719.pdf

 

0x03 ²Î¿¼Á´½Ó

https://www.bleepingcomputer.com/news/security/bugs-in-billions-of-wifi-bluetooth-chips-allow-password-data-theft/

https://securityaffairs.co/wordpress/125585/hacking/wifi-chip-coexistence-attacks.html?utm_source=rss&utm_medium=rss&utm_campaign=wifi-chip-coexistence-attacks

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-12-14

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

c7c7ÓéÀÖÆ½Ì¨¼ò½é

c7c7ÓéÀÖÆ½Ì¨¹«Ë¾½¨ÉèÓÚ1996Ä꣬£¬£¬£¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬£¬£¬£¬ÊǺ£ÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÇå¾²²úÆ·¡¢¿ÉÐÅÇå¾²ÖÎÀíÆ½Ì¨¡¢Ç徲ЧÀÍÓë½â¾ö¼Æ»®µÄ×ÛºÏÌṩÉÌ¡£¡£¡£¡£¡£ ¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬£¬£¬£¬ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÇþµÀϵͳºÍÊÖÒÕÖ§³ÖÖÐÐÄ£¬£¬£¬£¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£¡£¡£¡£¡£ ¡£

¶àÄêÀ´£¬£¬£¬£¬c7c7ÓéÀÖÆ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£ ¡£


¹ØÓÚc7c7ÓéÀÖÆ½Ì¨

c7c7ÓéÀÖÆ½Ì¨Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£¡£ ¡£

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º

image.png