Facebook WhatsApp TLSÁîÅÆ×ß©Îó²î¸´ÏÖ£¨CVE-2021-24027£©
Ðû²¼Ê±¼ä 2021-04-30Åä¾°
WhatsAppÊÇÃÀ¹úFacebookµÄ¼´Ê±Í¨Ñ¶Ó¦Ó㬣¬£¬ÔÚÍâÑóÓµÓÐÖØ´óµÄÓû§»ùÊý¡£¡£¡£¡£4ÔÂ14ÈÕ£¬£¬£¬Çå¾²Ñо¿Ô±Chariton KaramitasÅû¶Android WhatsApp±£´æÁîÅÆÐ¹Â¶Îó²î£¬£¬£¬Á¬ÏµÆäËûÎó²î¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¸ÃÎó²îÓ°ÏìWhatsApp v2.21.4.18ºÍWhatsApp Business v2.21.4.18֮ǰµÄ°æ±¾£¬£¬£¬½¨ÒéÓû§ÊµÊ±¸üе½2.21.4.18»ò¸ü¸ß°æ±¾£¬£¬£¬ÒÔ¹æ±Ü¸ÃÎó²î±£´æµÄ¹¥»÷Σº¦¡£¡£¡£¡£
Îó²îÆÊÎö
1¡¢ÁîÅÆÐ¹Â¶Îó²î£¨CVE-2021-24027£©
¸ÃÎó²î±£´æµÄÔµ¹ÊÔÓÉ£¬£¬£¬ÊÇÓÉÓÚWhatsApp½«TLS»á»°Éϰ¶ºóµÄÐòÁл¯ÁîÅÆÎļþ·ÅÔÚÁËsdcardĿ¼Ï£¬£¬£¬¸ÃĿ¼²¢Î´ÉèÖûá¼ûȨÏÞ¡£¡£¡£¡£
WhatsApp½ÓÄÉTLS1.3/TLS1.2À´¾ÙÐпͻ§¶Ëµ½Ð§ÀÍÆ÷µÄͨѶ£¬£¬£¬ÔÚTLSÎÕÊÖµÄÀú³ÌÖУ¬£¬£¬Í¨Ñ¶Ë«·½¾ÙÐÐÏ໥ÈÏÖ¤ºÍÃÜÔ¿ÐÉÌ£¬£¬£¬Ð§ÀÍÆ÷Éí·ÝÑé֤ʹÓ÷ǶԳƼÓÃÜ·½·¨£¬£¬£¬¹ØÓÚ½ÏС³ß´çµÄǶÈëʽװ±¸£¬£¬£¬ÕâÊÇÒ»¸öÅÌËãÁ¿ºÜÊÇ´óµÄÀú³Ì¡£¡£¡£¡£ÎªÁËïÔ̹¦ºÄ£¬£¬£¬½ÚÔ¼CPUÖÜÆÚ£¬£¬£¬Ìá³öÁ˻Ự»Ö¸´Àú³Ì£¬£¬£¬µ±ÖØÐ½¨ÉèÎÕÊÖʱ£¬£¬£¬¸´ÓÃ֮ǰµÄ»á»°ÐÅÏ¢¡£¡£¡£¡£
ÏÂͼÖÐΪÉèÖûỰ»º´æÎļþ¼ÐµÄ·´±àÒë´úÂë½ØÍ¼¼°ÏÖʵÎļþ·¾¶½ØÍ¼£¬£¬£¬WhatsApp½«Éϰ¶»á»°»º´æTLS1.2ºÍTLS1.3»®·Ö·ÅÔÚÎļþ¼ÐSSLSessionCacheºÍwatls-sessionsÖС£¡£¡£¡£ÕâЩĿ¼ÔÚ²»Êܱ£»£»£»£»£»£»¤µÄÍⲿ´æ´¢Ï¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÎïÀí½Ó´¥ÊÖ»ú»ñµÃÕâЩÎļþ£¬£¬£¬Ôì³ÉÁîÅÆ×ß©¡£¡£¡£¡£
2¡¢Ä¿Â¼´©Ô½Îó²î
WhatsAppÓÐEmojiºÍÕÕÆ¬Â˾µÈȸüй¦Ð§£¬£¬£¬ÎÒÃÇ¿ÉÒÔʹÓÃÖÐÐÄÈËÀ´¸Ä¶¯Emoji»òÕÕÆ¬Â˾µÈȸüÐÂʱµÄzip°ü¡£¡£¡£¡£zipÎļþ½âѹ·´±àÒë´úÂë½ØÍ¼ÈçÏ£º
WhatsApp¾ÙÐÐEmoji»òÕÕÆ¬Â˾µÈȸüÐÂʱ£¬£¬£¬Ã»ÓйýÂË¡±.//¡±£¬£¬£¬¿Éµ¼ÖÂĿ¼´©Ô½¡£¡£¡£¡£ÈôÊÇÊܺ¦Õß±»ÖÐÐÄÈËÐ®ÖÆ£¬£¬£¬²¢ÇÒ¹¥»÷Õ߸͝ÁËÈȸüÐÂzip°ü£¬£¬£¬ÆäÖаüÀ¨ÓÉ¡±.//¡±Ä¿Â¼×é³ÉµÄsoÎļþ£¬£¬£¬Ê¹ÆäÁýÕÖWhatsApp¶¯Ì¬Á´½Ó¿âsoÎļþ£¬£¬£¬½«µ¼ÖÂí§Òâ´úÂëÖ´ÐС£¡£¡£¡£
Îó²îʹÓÃ
Ç°ÃæÌáµ½ÐèҪͨ¹ýÎïÀí½Ó´¥»ñÈ¡ÁîÅÆ£¬£¬£¬¾ÖÏÞÐԽϴ󡣡£¡£¡£ÈôÊǹ¥»÷ÕßÅäºÏÍøÂç´¹ÂÚ£¬£¬£¬·¢ËÍÒ»¸öαװµÄhtmlÎļþ¸øÊܺ¦Õߣ¬£¬£¬µ±Êܺ¦ÕßʹÓÃChrome£¨±£´æÎó²îCVE-2020-6516£©·¿ª´Ëhtmlʱ£¬£¬£¬Ö´ÐÐhtmlÖеÄjs´úÂ룬£¬£¬±éÀúsdcardÎļþ¼Ð²éÕÒTLS»º´æÎļþ£¬£¬£¬²¢°ÑÎļþ·¢Ë͵½¹¥»÷ÕßÖ¸¶¨µÄЧÀÍÆ÷ÉÏ¡£¡£¡£¡£´óÖÂÀú³ÌÈçÏ£º
£¨1£©ÔÚ·¢ËÍÒ»ÌõÐÂÎÅʱ£¬£¬£¬°üÀ¨ÐÂÎŵÄÀàÐÍ¡¢ÐÂÎŵÄÔ¤ÀÀͼƬ¡¢ÐÂÎŵÄÎÊÌâºÍÐÂÎŵÄÏÖʵÄÚÈÝÎļþËIJ¿·Ö¡£¡£¡£¡£Àà·¾¶X/041µÄA0l×Ö¶Îָʾ·¢ËÍÐÂÎŵÄÀàÐÍ£¬£¬£¬Àà·¾¶X/0QeµÄA03×Ö¶ÎָʾÐÂÎŵÄÔ¤ÀÀͼƬµÄbyteÊý×飬£¬£¬Àà·¾¶X/0NdµÄA04×Ö¶Îָʾ·¢ËÍÐÂÎŵÄÎÊÌ⣬£¬£¬Àà·¾¶X/0M6µÄA05(Ljava/util/List;Landroid/net/Uri;Ljava/lang/String;LX/041;LX/02l;Z)ÒªÁìΪ×îÖÕ·¢ËÍÐÂÎÅÏÖʵÄÚÈÝÎļþµÄº¯Êý¡£¡£¡£¡£Ïà¹Ø½ØÍ¼ÈçÏ£º
£¨2£©¹¥»÷Õß½ÓÄÉfridaµÄRPCÔ¶³ÌŲÓù¦Ð§½¨ÉèÒ»¸öº¯Êý£¬£¬£¬²¢ÔÚhookº¯ÊýÖÐÐ޸ĵÚÒ»²½Öдý·¢Ë͵ÄÐÂÎÅ£¬£¬£¬½«ÐÂÎŵÄÔ¤ÀÀÍ¼Æ¬Ìæ»»³É¾ßÓÐÎüÒýÁ¦µÄͼƬ£¬£¬£¬²¢Å²ÓÃX/0M6µÄA05(Ljava/util/List;Landroid/net/Uri;Ljava/lang/String;LX/041;LX/02l;Z)ÒªÁ콫ÐÂÎÅ·¢Ë͸øÊܺ¦Õߣ¨µÚÒ»¸ö²ÎÊýΪÓÉÊܺ¦ÕßµÄWhatsAppµØµã×é³ÉµÄList£¬£¬£¬WhatAppµØµãÃûÌÃΪmobile_number@s.whatsapp.net£©£¬£¬£¬ÈôÊÇÊܺ¦Õßµã»÷ͼƬ£¬£¬£¬Å²ÓÃChrome·¿ª¶ñÒâhtmlÎļþ£¬£¬£¬TLS»º´æÁîÅÆ¿ÉÄܱ»·¢Ë͵½¹¥»÷ÕßЧÀÍÆ÷¡£¡£¡£¡£
£¨3£©htmlÎļþÒªº¦²¿·Ö½ØÍ¼ÈçÏ¡£¡£¡£¡£ÔÚÀֳɻñÈ¡µ½TLS»º´æÎļþºó£¬£¬£¬ÎÒÃǼ´¿É¾ÙÐÐÖÐÐÄÈ˹¥»÷¡£¡£¡£¡£
£¨4£©Ê¹ÓÃEmoji»òÕÕÆ¬Â˾µÈȸüй¦Ð§£¬£¬£¬Í¨¹ýÖÐÐÄÈËÀ´¸Ä¶¯Emoji»òÕÕÆ¬Â˾µÈȸüÐÂÏìÓ¦zip°ü£¬£¬£¬´Ó¶øµ¼ÖÂÔ¶³Ìí§Òâ´úÂëÖ´ÐУ¨ÑÝʾÊÓÆµÎªÁËÀû±ã£¬£¬£¬Ö±½ÓʹÓÃCharlesÀ´Ä£ÄâÈȸüÐÂÁýÕÖWhatsApp¶¯Ì¬Á´½Ó¿âsoÎļþ£¬£¬£¬À´µÖ´ïRCEµÄÀú³Ì£©¡£¡£¡£¡£
Îó²î¸´ÏÖ
1¡¢ÁîÅÆÐ¹Â¶Îó²î¸´ÏÖ
2¡¢RCEÎó²î¸´ÏÖ
²Î¿¼Á´½Ó£º
[1]https://www.census-labs.com/news/2021/04/14/whatsapp-mitd-remote-exploitation-CVE-2021-24027/
[2] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24027
[3] https://github.com/CENSUS/whatsapp-mitd-mitm
[4] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6516
[5]https://bugs.chromium.org/p/chromium/issues/detail?id=1092449
[6] https://youtu.be/sdVqTEXHxxY
[7] https://youtu.be/KO_K0F4W36I
¼øºÚµ£±£ÍøÆð¾¢·ÀÓùʵÑéÊÒ£¨ADLab£©
ADLab½¨ÉèÓÚ1999Ä꣬£¬£¬ÊÇÖйúÇå¾²ÐÐÒµ×îÔ罨ÉèµÄ¹¥·ÀÊÖÒÕÑо¿ÊµÑéÊÒÖ®Ò»£¬£¬£¬Î¢ÈíMAPPÍýÏë½¹µã³ÉÔ±£¬£¬£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Çå¾²Îó²î½ü1100¸ö£¬£¬£¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Çå¾²Îó²î1000Óà¸ö£¬£¬£¬Ò»Á¬¼á³Ö¹ú¼ÊÍøÂçÇå¾²ÁìÓòÒ»Á÷Ë®×¼¡£¡£¡£¡£ÊµÑéÊÒÑо¿Æ«Ïòº¸Ç²Ù×÷ϵͳÓëÓ¦ÓÃϵͳÇå¾²Ñо¿¡¢ÖÇÄÜÖÕ¶ËÇå¾²Ñо¿¡¢ÎïÁªÍøÖÇÄÜ×°±¸Çå¾²Ñо¿¡¢WebÇå¾²Ñо¿¡¢¹¤¿ØÏµÍ³Çå¾²Ñо¿¡¢ÔÆÇå¾²Ñо¿¡£¡£¡£¡£Ñо¿Ð§¹ûÓ¦ÓÃÓÚ²úÆ·½¹µãÊÖÒÕÑо¿¡¢¹ú¼ÒÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÇ徲ЧÀ͵ȡ£¡£¡£¡£