¡¾Îó²îͨ¸æ¡¿À¶ÑÀ & WiFi оƬ12Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-12-14


0x00 Îó²î¸ÅÊö

2021Äê12ÔÂ13ÈÕ£¬£¬£¬£¬£¬¶à¸öÑо¿»ú¹¹ÁªºÏÐû²¼ÁËÀ¶ÑÀ¼°WiFi¼Ü¹¹ºÍЭÒéÖеĶà¸öÇå¾²Îó²î£¬£¬£¬£¬£¬ÕâЩÎó²îÓ°ÏìÁËÊýÊ®ÒÚWiFiºÍÀ¶ÑÀоƬ£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Ê¹ÓÃÎó²îÕë¶Ô×°±¸µÄÀ¶ÑÀ×é¼þÌáÈ¡ÃÜÂë²¢¼à¿ØWiFiоƬÉϵÄÁ÷Á¿¡£¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

ÏÖ´úÏûºÄÀàµç×Ó×°±¸£¨ÈçÖÇÄÜÊÖ»ú£©µÄSoC¾ßÓÐ×ÔÁ¦µÄÀ¶ÑÀ¡¢WiFiºÍLTE×é¼þ£¬£¬£¬£¬£¬Ã¿¸ö×é¼þ¶¼ÓÐ×Ô¼ºµÄרÓÃÇ徲ʵÏÖ£¬£¬£¬£¬£¬µ«ÕâЩ×é¼þͨ³£¹²ÏíÏàͬµÄ×ÊÔ´£¬£¬£¬£¬£¬¿ÉÒÔ½«ÕâЩ¹²Ïí×ÊÔ´ÓÃ×÷¿çÎÞÏßоƬ½çÏßÌᳫºáÏòȨÏÞÌáÉý¹¥»÷µÄÇÅÁº£¬£¬£¬£¬£¬ÒÔʵÏÖ´úÂëÖ´ÐС¢ÄÚ´æ¶ÁÈ¡ºÍ¾Ü¾øÐ§À͵ȡ£¡£¡£¡£¡£

image.png

ΪÁËʹÓÃÕâЩÎó²î£¬£¬£¬£¬£¬Ê×ÏÈÐèÒªÔÚÀ¶ÑÀ»ò WiFi оƬÉÏÖ´ÐдúÂ룬£¬£¬£¬£¬Ò»µ©ÊµÏÖ£¬£¬£¬£¬£¬¾Í¿ÉÒÔʹÓù²ÏíÄÚ´æ×ÊÔ´¶Ô×°±¸µÄÆäËûоƬ¾ÙÐкáÏò¹¥»÷¡£¡£¡£¡£¡£ÕâЩÎó²î°üÀ¨£º

l  CVE-2020-10368£ºWiFi δ¼ÓÃÜÊý¾Ýй¶£¨¼Ü¹¹£©

l  CVE-2020-10367£ºWi-Fi ´úÂëÖ´ÐУ¨¼Ü¹¹£©

l  CVE-2019-15063£ºWi-Fi ¾Ü¾øÐ§ÀÍ£¨Ð­Ò飩

l  CVE-2020-10370£ºÀ¶ÑÀ¾Ü¾øÐ§ÀÍ£¨Ð­Ò飩

l  CVE-2020-10369£ºÀ¶ÑÀÊý¾Ýй¶£¨Ð­Ò飩

l  CVE-2020-29531£ºWiFi ¾Ü¾øÐ§ÀÍ£¨Ð­Ò飩

l  CVE-2020-29533£ºWiFi Êý¾Ý×ß©£¨Ð­Ò飩

l  CVE-2020-29532£ºÀ¶ÑÀ¾Ü¾øÐ§ÀÍ£¨Ð­Ò飩

l  CVE-2020-29530£ºÀ¶ÑÀÊý¾Ýй¶£¨Ð­Ò飩

ÕâЩÎó²î±£´æÓÚBroadcom¡¢Silicon Labs ºÍ Cypress µÈÖÆÔìÉÌÉú²úµÄоƬÖУ¬£¬£¬£¬£¬¶øÕâЩоƬӦÓÃÓÚÊýÊ®ÒÚµç×Ó×°±¸ÖС£¡£¡£¡£¡£Ñо¿Ö°Ô±Õë¶Ô CVE-2020-10368 ºÍ CVE-2020-10367 ²âÊÔµÄ×°±¸ÈçÏ£º

image.png

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚÕâЩÎó²îÔÝδÍêÈ«ÐÞ¸´¡£¡£¡£¡£¡£½¨ÒéʹÓÃÈçϱ£»£»£»£»£»¤²½·¥£º

l  ɾ³ý²»ÐëÒªµÄÀ¶ÑÀ×°±¸Åä¶Ô£»£»£»£»£»

l  ´ÓÉèÖÃÖÐɾ³ý²»Ê¹ÓÃµÄ WiFi ÍøÂ磻£»£»£»£»

l  ÔÚ¹«¹²³¡ºÏʹÓÃÊÖʱ»ú¼û»¥ÁªÍø¶ø²»ÊÇ WiFi¡£¡£¡£¡£¡£

²Î¿¼Á´½Ó£º

https://arxiv.org/pdf/2112.05719.pdf

 

0x03 ²Î¿¼Á´½Ó

https://www.bleepingcomputer.com/news/security/bugs-in-billions-of-wifi-bluetooth-chips-allow-password-data-theft/

https://securityaffairs.co/wordpress/125585/hacking/wifi-chip-coexistence-attacks.html?utm_source=rss&utm_medium=rss&utm_campaign=wifi-chip-coexistence-attacks

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-12-14

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

¼øºÚµ£±£Íø¼ò½é

¼øºÚµ£±£Íø¹«Ë¾½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬£¬£¬£¬£¬ÊǺ£ÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÇå¾²²úÆ·¡¢¿ÉÐÅÇå¾²ÖÎÀíÆ½Ì¨¡¢Ç徲ЧÀÍÓë½â¾ö¼Æ»®µÄ×ÛºÏÌṩÉÌ¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬£¬£¬£¬£¬ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÇþµÀϵͳºÍÊÖÒÕÖ§³ÖÖÐÐÄ£¬£¬£¬£¬£¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£¡£¡£¡£¡£

¶àÄêÀ´£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£


¹ØÓÚ¼øºÚµ£±£Íø

¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£¡£

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º

image.png