¡¾Ç徲ͨ¸æ¡¿TCP/IPÐÒé¿âÎó²î AMNESIA:33
2020-12-08
×ÛÊö
12ÔÂ8ÈÕ£¬ForescoutÑо¿ÊµÑéÊÒÅû¶ÁËËĸö¿ªÔ´TCP/IPÈí¼þ¿âÖй²33¸öÎó²î¡£ÕâһϵÁÐÎó²î±»Í³³ÆÎª AMNESIA:33£¬ÊÜÓ°ÏìÈí¼þ¿â»®·ÖÊÇuIP£¨·¢Ã÷13¸öÎó²î£©¡¢picoTCP£¨10¸ö£©¡¢ FNET£¨5¸ö£©¡¢ºÍNut/Net£¨5¸ö£©¡£
ÕâЩÎó²îÔ¤¼ÆÓ°Ïì150¶à¼Ò¹©Ó¦É̺ÍÊý°ÙÍò×°±¸£¬É漰ǶÈëʽװ±¸µÄ²Ù×÷ϵͳ¡¢Ð¾Æ¬ÏµÍ³¡¢ÍøÂç×°±¸¡¢OT×°±¸ÒÔ¼°´ó×ÚÆóÒµ¼¶ºÍÏûºÄ¼¶ÎïÁªÍø×°±¸¡£
ʹÓÃÎó²î¹¥»÷ÕßÄܹ»ÆÆËð×°±¸¡¢Ö´ÐжñÒâ´úÂë¡¢Ôì³É¾Ü¾ø·þÎñ£¬±ðµÄ»¹ÄÜÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£
ÆäÖÐ4¸öÑÏÖØ¼¶±ðµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î»®·ÖÊÇ£º
CVE-2020-25111
DNSÓòÃû½âÂë/DNSÏìÓ¦´¦Öóͷ£×é¼þÖеÄÎÊÌâ¡£
CVE-2020-24338
ÆÊÎöÓòÃûµÄº¯Êýȱ·¦½çÏß¼ì²é£¬ÔÊÐí¹¥»÷ÕßÓÃαÔìµÄDNSÊý¾Ý°üÆÆËðÄÚ´æ¡£
CVE-2020-24336
ͨ¹ýNAT64·¢Ë͵ÄDNSÏìÓ¦Êý¾Ý°üÖÐÆÊÎöDNS¼Í¼µÄ´úÂëûÓÐÑéÖ¤ÏìÓ¦¼Í¼µÄ³¤¶È×ֶΣ¬ÔÊÐí¹¥»÷Õ߯ÆËðÄÚ´æ¡£
CVE-2020-25112
¶ÔIPv4/IPv6Í·³¤¶È¼ì²éȱ·¦£¬¶ÔIPv6Í·À©Õ¹³¤¶È¼ì²é·×ÆçÖ£¬Ê¹¹¥»÷Õß¿ÉÒÔÆÆËðÄÚ´æ¡£
¸üÍêÕûÎó²îÁбíÏê¼û£ºhttps://www.forescout.com/company/resources/amnesia33-how-tcp-ip-stacks-breed-critical-vulnerabilities-in-iot-ot-and-it-devices/
²Î¿¼Á´½Ó£º
https://searchsecurity.techtarget.com/news/252493283/Forescout-reports-33-new-TCP-IP-vulnerabilities
https://www.forescout.com/research-labs/amnesia33/
ÊÜÓ°Ïì²úÆ·
uIP
picoTCP
FNET
Nut/Net
½â¾ö¼Æ»®
ForescoutÒѺÍÊÜÓ°ÏìµÄ¹©Ó¦É̾ÙÐÐÁËÏàͬ£¬GitHubµÄÇå¾²ÍŶÓÒ²ÔÚÐÖúʶ±ðÊÜÓ°ÏìµÄTCP/IP ¿ÍÕ»¡£²»¹ý¾ÝForescoutÏÔʾ£¬Ö»ÓÐContiki-NG¡¢PicoTCP-NG¡¢FNETºÍNut/NetÏîÄ¿Õë¶ÔÎó²îÐû²¼Á˲¹¶¡£¬uIP¡¢ContikiºÍPicoTCPÏîÄ¿ÉÐδÐû²¼²¹¶¡¡£
³ýÁËÔÚ¿ÉÄܵÄÇéÐÎÏÂʵʱװÖò¹¶¡¸üÐÂÍ⣬½¨Òé½ÓÄÉÈçÏ»º½â²½·¥£º
ÆÀ¹ÀΣº¦
ÔÚ½ÓÄÉ·À»¤²½·¥Ö®Ç°£¬¾ÙÐг¹µ×µÄΣº¦ÆÀ¹À¡£Ê¶±ðDZÔÚÒ×Êܹ¥»÷×°±¸¡¢ÓªÒµÇéÐμ°ÆäÖ÷ÒªÐÔ£¬ÒÔ¼°ËüÃǵÄͨѶ·¾¶ºÍ»¥ÁªÍøÌ»Â¶ÇéÐΡ£
ÒÀÀµÄÚ²¿DNS·þÎñÆ÷
¾¡¿ÉÄÜÒÀÀµÄÚ²¿DNS·þÎñÆ÷£¬²¢ÇÒÇ×½ü¼àÊÓÍⲿDNSÁ÷Á¿£¬ÓÉÓÚAMNESIA:33ÖеöÎó²îÓëDNS¿Í»§¶ËÓйأ¬ËüÃDZ»Ê¹ÓÃʱÐèÒª¶ñÒâµÄDNS·þÎñÆ÷»Ø¸´¶ñÒâÊý¾Ý°ü¡£
½ûÓûò×èÖ¹²»ÐëÒªµÄIPv6ͨѶ
ÓÉÓÚAMNESIA:33ÖеĶà¸öÎó²îÓëIPv6×é¼þÓйأ¬Òò´ËÇë½ûÓûò×èÖ¹²»ÐëÒªµÄIPv6ÍøÂçÁ÷Á¿¡£
ÍøÂç·Ö¶Î
¹ØÓÚÎÞ·¨ÐÞ²¹µÄIoTºÍOT×°±¸£¬ÔÚ²»Ó°ÏìÒªº¦ÓªÒµ¹¦Ð§»òÓªÒµÔËÓªµÄÌõ¼þÏ£¬ÇëʹÓ÷ֶÎÒÔ×îºéÁ÷ƽµØïÔÌÆäÍøÂç̻¶¡£
¼àÊÓÃûÌùýʧµÄÊý¾Ý°ü
Ç×½ü¹Ø×¢ËùÓÐÍøÂçÁ÷Á¿ÖÐÃûÌùýʧµÄÊý¾Ý°ü£¨ÀýÈ磬ȱ·¦¸ñµÄÊý¾Ý°ü×ֶγ¤¶È»òУÑéºÍʧ°Ü£©¡£µ±¼ì²âµ½Òì³£Á÷Á¿Ê±£¬½ÓÄÉÏìÓ¦²½·¥£¬²¢¾ÙÐиüÑÏ¿áµÄ¹Ü¿Ø¡£
²Î¿¼Á´½Ó:
https://www.forescout.com/company/resources/amnesia33-faq/
https://www.forescout.com/company/resources/amnesia33-how-tcp-ip-stacks-breed-critical-vulnerabilities-in-iot-ot-and-it-devices/
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚAG¹«Ë¾¿Æ¼¼
AG¹«Ë¾£¨¼ò³ÆAG¹«Ë¾¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬AG¹«Ë¾¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
AG¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£ºAG¹«Ë¾¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

AG¹«Ë¾ÔÆ







