SSL 3.0 POODLE¹¥»÷ÐÅϢй¶Îó²î (Alert2014-10)
2014-10-15
ÐÎò£º
CVE ID£ºCVE-2014-3566ÊÜÓ°ÏìµÄÈí¼þ¼°ÏµÍ³£º
====================
SSL 3.0
δÊÜÓ°ÏìµÄÈí¼þ¼°ÏµÍ³£º
======================
TLS 1.0
TLS 1.1
TLS 1.2
×ÛÊö£º
======
SSL 3.0ÐÒé±»·¢Ã÷±£´æÒ»¸öÇå¾²Îó²î£¬ÓÐÌõ¼þÖ´ÐÐÖÐÐÄÈ˹¥»÷µÄ¹¥»÷Õß¿ÉÒÔ¶Ô¼ÓÃÜÊý¾Ý¾ÙÐÐÆÆ½â£¬´Ó¶ø»ñÈ¡HTTP cookieµÈÃô¸ÐÐÅÏ¢¡£
ÆÊÎö£º
======
SSL3.0ÊÇÒѹýʱÇÒ²»Çå¾²µÄÐÒ飬ÏÖÔÚÒѱ»TLS 1.0£¬TLS 1.1£¬TLS 1.2Ìæ»»£¬ÓÉÓÚ¼æÈÝÐÔÔµ¹ÊÔÓÉ£¬´ó´ó¶¼µÄTLSʵÏÖÒÀÈ»¼æÈÝSSL3.0¡£
TLSÐÒéµÄÎÕÊֽ׶ΰüÀ¨Á˰汾ÐḚ́취£¬Ò»Ñùƽ³£À´Ëµ£¬¿Í»§¶ËºÍ·þÎñÆ÷¶ËµÄ×îеÄÐÒé°æ±¾½«»á±»Ê¹Óá£
ΪÁËͨÓÃÐÔµÄ˼Á¿£¬ÏÖÔÚ´ó¶¼ä¯ÀÀÆ÷°æ±¾¶¼Ö§³ÖSSL3.0£¬ÆäÔÚÓë·þÎñÆ÷¶ËµÄÎÕÊֽ׶ξÙÐа汾ÐÉ̵Äʱ£¬Ê×ÏÈÌṩÆäËùÖ§³ÖÐÒéµÄ×îа汾£¬Èô¸ÃÎÕÊÖʧ°Ü£¬ÔòʵÑéÒԽϾɵÄÐÒé°æ±¾ÐÉÌ¡£Äܹ»ÊµÑéÖÐÐÄÈ˹¥»÷µÄ¹¥»÷Õßͨ¹ýʹÊÜÓ°Ïì°æ±¾ä¯ÀÀÆ÷Óë·þÎñÆ÷¶ËʹÓýÏÐÂÐÒéµÄÐÉ̵ÄÅþÁ¬Ê§°Ü£¬¿ÉÒÔÀÖ³ÉʵÏÖ½µ¼¶¹¥»÷£¬´Ó¶øÊ¹µÃ¿Í»§¶ËÓë·þÎñÆ÷¶ËʹÓò»Çå¾²µÄSSL3.0¾ÙÐÐͨѶ£¬´Ëʱ£¬ÓÉÓÚSSL 3.0ʹÓõÄCBC¿é¼ÓÃܵÄʵÏÖ±£´æÎó²î£¬¹¥»÷Õß¿ÉÒÔÀÖ³ÉÆÆ½âSSLÅþÁ¬µÄ¼ÓÃÜÐÅÏ¢£¬ºÃ±È»ñÈ¡Óû§cookieÊý¾Ý¡£ÕâÖÖ¹¥»÷±»³ÆÎªPOODLE¹¥»÷(Padding Oracle On Downgraded Legacy Encryption)¡£
´ËÎó²îÓ°Ïì¾ø´ó´ó¶¼SSL·þÎñÆ÷ºÍ¿Í»§¶Ë£¬Ó°Ïì¹æÄ£ÆÕ±é¡£µ«¹¥»÷ÕßÈçҪʹÓÃÀֳɣ¬ÐèÒªÄܹ»¿ØÖƿͻ§¶ËºÍ·þÎñÆ÷Ö®¼äµÄÊý¾Ý(Ö´ÐÐÖÐÐÄÈ˹¥»÷)¡£
½â¾öÒªÁ죺
ÈôÊDz»¿ÉʵʱװÖò¹¶¡£¬½¨Òé½ÓÄÉÈçÏ·À»¤²½·¥:* ½ûÓÃSSL 3.0ÐÒé¡£
ÏÖÔÚ³£ÓÃä¯ÀÀÆ÷Ö»ÓÐIE 6.0ÈÔÈ»²»Ö§³ÖTLS 1.0£¬½ûÓÃSSL 3.0ÐÒ齫ӰÏìIE 6¿Í»§µÄ
SSL»á¼û¡£
·þÎñ¶Ë½ûÓÃÒªÁ죺
Apache 2.x:
ÔÚmod_sslÉèÖÃÎļþÖÐʹÓÃÈçÏÂÏÂÁî½ûÓÃSSLv2ºÍSSLv3£º
SSLProtocol All -SSLv2 -SSLv3
ÖØÆôApache
Nginx:
ÔÚÉèÖÃÎļþÖÐʹÓãº
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ÖØÆôNginx
IIS:
²éÕÒÈçÏÂ×¢²á±íÏ
HKey_Local_MachineSystemCurrentControlSetControlSecurityProviders SCHANNELProtocols
¸Ã×¢²á±íÏîͨ³£°üÀ¨ÒÔÏÂ×ÓÏ
* PCT 1.0
* SSL 2.0
* SSL 3.0
* TLS 1.0
ÿ¸ö×¢²á±íÏî¶¼±£´æÊÊÓÃÓÚ¸ÃÏîµÄÐÒéÏà¹ØÐÅÏ¢¡£¿ÉÒÔÔÚ·þÎñÆ÷ÉϽûÓÃÕâЩÐÒéÖеÄÈÎÒ»ÖÖ¡£Îª´Ë£¬
ÇëÔÚÐÒéSSL 3.0µÄ·þÎñÆ÷×ÓÏîÖн¨ÉèÒ»¸öеÄDWORDÖµ¡£½«DWORDÖµÉèÖÃΪ¡°00 00 00 00¡±¡£
ä¯ÀÀÆ÷½ûÓÃÒªÁ죺
IE:
"¹¤¾ß" -> "Internet Ñ¡Ïî" -> "¸ß¼¶" £¬×÷·Ï"ʹÓà SSL 3.0"µÄ¸´Ñ¡¿ò¡£
Chrome:
¸´ÖÆÒ»¸öƽʱ·¿ª Chrome ä¯ÀÀÆ÷µÄ¿ì½Ý·½·¨£¬ÔÚеĿì½Ý·½·¨ÉÏÓÒ¼üµã»÷£¬½øÈëÊôÐÔ£¬
ÔÚ"Ä¿µÄ"ºóÃæµÄ¿Õ¸ñÖÐ×ֶεÄĩβÊäÈëÒÔÏÂÏÂÁî --ssl-version-min=tls1
FireFox:
ÔڵصãÀ¸ÊäÈë"about:config"£¬È»ºó½« security.tls.version.min µ÷ÖÁ 1¡£
³§ÉÌ״̬£º
==========
³§ÉÌÔÝʱûÓÐÌṩÉý¼¶²¹¶¡¡£FireFoxºÍChrome¶¼ÍýÏëÔÚа汾ÖнûÓÃSSL 3.0¡£
¸½¼ÓÐÅÏ¢£º
==========
1. https://www.openssl.org/~bodo/ssl-poodle.pdf
2. https://technet.microsoft.com/en-us/library/security/3009008
3. http://www.nsfocus.net/index.php?act=alert&do=view&aid=152

AG¹«Ë¾ÔÆ





