¡¾Îó²îÇ鱨¡¿Spectre CPUÎó²î£¨CVE-2017-5753£©

Ðû²¼Ê±¼ä 2021-03-02

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2017-5753

ʱ   ¼ä

2021-03-02

Àà   ÐÍ

Éè¼Æ¹ýʧ  

µÈ   ¼¶


Ô¶³ÌʹÓÃ


Ó°Ïì¹æÄ£


 

0x01 Îó²îÏêÇé

image.png

2021Äê03ÔÂ01ÈÕ£¬£¬£¬Çå¾²Ñо¿Ö°Ô±ÖìÀû°²¡¤ÎÖÒÁÉ­£¨Julien Voisin£©ÔÚVirusTotal¶ñÒâÈí¼þÆÊÎöƽ̨ÉÏ·¢Ã÷ÁËSpectre CPUÎó²î£¨CVE-2017-5753£©µÄLinux°æºÍWindows°æµÄÎó²îʹÓóÌÐò£¬£¬£¬ÕâÌåÏÖÄܹ»¾ÙÐÐÏÖÊµÆÆËð²¢ÍêÈ«ÎäÆ÷»¯µÄÓÐÓÃʹÓóÌÐòÒѾ­ÔÚ¹«¹²ÁìÓòÖйûÕæ¡£¡£¡£¡£¡£¡£¡£

Spectre CPUÎó²îÊÇ2018Äê1ÔÂGoogle Project ZeroÅû¶µÄIntel¡¢AMDºÍARM´¦Öóͷ£Æ÷¼Ü¹¹ÖеÄÓ²¼þÉè¼ÆÈ±ÏÝ£¨Meltdown£ºCVE-2017-5754¡¢Spectre£ºCVE-2017-5753ºÍCVE-2017-5715£©£¬£¬£¬¹¥»÷ÕßÄܹ»Ê¹ÓÃÎó²îÔËÐÐÓ¦ÓóÌÐòÖеĴúÂëÀ´ÆÆËð²î±ðÓ¦ÓóÌÐòÖ®¼äÔÚCPU²ãÃæµÄ¸ôÀ룬£¬£¬È»ºóÇÔȡͳһϵͳÉÏÔËÐÐµÄÆäËüÓ¦ÓõÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£

GoogleÌåÏÖ£¬£¬£¬Spectre CPUÎó²î»áÓ°Ïì°üÀ¨Windows¡¢Linux¡¢macOS¡¢AndroidºÍChromeOSµÈÔÚÄÚµÄÖ÷Á÷²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£¡£×Ô¾õÏÖ¸ÃÎó²îÒÔÀ´£¬£¬£¬ËùÓÐÖ÷Á÷CPUºÍOS¹©Ó¦É̾ùÐû²¼Á˹̼þ²¹¶¡ºÍÈí¼þÐÞ¸´£¬£¬£¬µ«ÉÐδ¸üÐÂÆäϵͳµÄÓû§ÈÔÈ»ÈÝÒ×Êܵ½Spectre CPUÎó²îµÄ¹¥»÷£¬£¬£¬ÓÈÆäÊÇʹÓþɰæÐ¾Æ¬²¢ÔËÐоɰæ²Ù×÷ϵͳµÄÓû§£¨Èç2015ÄêÔµÄPC£¬£¬£¬²¢Ê¹ÓÃHaswell»ò¾ÉµÄIntel´¦Öóͷ£Æ÷£©¡£¡£¡£¡£¡£¡£¡£

VirusTotalÉϵÄÎó²îʹÓóÌÐòÊÇÉϸöÔÂÉÏ´«µÄ£¬£¬£¬¸ÃÈí¼þ°üÊÇÊÊÓÃÓÚWindowsºÍLinuxµÄImmunity Canvas 7.26×°ÖóÌÐò(Immunity CANVASΪȫÇòµÄÉøÍ¸²âÊÔÖ°Ô±ºÍÇ徲רҵְԱÌṩÁËÊý°ÙÖÖÎó²îʹÓá¢×Ô¶¯»¯µÄÎó²îʹÓÃϵͳÒÔ¼°ÖÜÈ«¡¢¿É¿¿µÄÎó²îʹÓÿª·¢¿ò¼Ü)¡£¡£¡£¡£¡£¡£¡£

image.png


´ËÎó²îʹÓóÌÐò¿ÉÒÔʹͨË×Óû§¿ÉÒÔ´ÓÄ¿µÄ×°±¸µÄÄÚºËÄÚ´æÖÐת´¢WindowsϵͳºÍLinuxϵͳÖÐ/etc/shadowÎļþÖеÄLM/NT¹þÏ£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬¸ÃʹÓóÌÐò»¹Äܹ»×ª´¢Kerberos tickets£¬£¬£¬¿ÉÓëPsExecÒ»ÆðÓÃÓÚWindowsϵͳµÄÍâµØÈ¨ÏÞÉý¼¶ºÍºáÏòÒÆ¶¯¡£¡£¡£¡£¡£¡£¡£ÕâÒâζ×Å£¬£¬£¬ÈôÊǸÃÎó²î±»ÀÖ³ÉʹÓ㬣¬£¬Ôò¹¥»÷Õß¿ÉÒÔÇÔÈ¡ÊÜÓ°ÏìϵͳµÄÃô¸ÐÊý¾Ý£¬£¬£¬°üÀ¨ÃÜÂë¡¢ÎĵµÒÔ¼°ÄÚ´æÖÐÈκοÉÓÃµÄÆäËüÊý¾Ý¡£¡£¡£¡£¡£¡£¡£

image.png

image.png

 

ÈçVoisinËù˵£¬£¬£¬´ò¹ý¸ÃÎó²î²¹¶¡µÄLinux»òWindowsϵͳÔò²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¶øÎ¢ÈíÌåÏÖ£¬£¬£¬ÓÉÓÚ×°Öò¹¶¡ºóϵͳÐÔÄÜ»áÓÐÏÔ×ŵÄϽµ£¬£¬£¬Òò´ËÓû§×îÈÝÒ×Ìø¹ýÓ¦Óûº½â²½·¥¡£¡£¡£¡£¡£¡£¡£

³ý´ËÖ®Í⣬£¬£¬×ÝÈ»¹¥»÷ÕßÄõ½ÁËÕâÁ½¸öÎó²îʹÓóÌÐòÈí¼þ°üÖеÄÈκÎÒ»¸ö£¬£¬£¬Ö»ÔËÐÐËüÃÇÒ²²»»á±¬·¢ÈκÎЧ¹û£¬£¬£¬ÓÉÓÚËüÃǶ¼Ö»ÄÜÔÚ׼ȷµÄ²ÎÊýÏÂÖ´ÐУ¬£¬£¬³ý·Ç¹¥»÷ÕßÄܹ»ÔËÐÐ׼ȷµÄ²ÎÊý¡£¡£¡£¡£¡£¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

Spectre CPUÎó²îÒÑÓÚ2018ÄêÐÞ¸´£¬£¬£¬½¨Òéδʵʱ¸üеÄÓû§²Î¿¼CPUºÍOS¹©Ó¦É̹ٷ½Ðû²¼µÄÐÞ¸´³ÌÐò»ò»º½â²½·¥¡£¡£¡£¡£¡£¡£¡£

Õë¶Ôwindowsϵͳ£¬£¬£¬Î¢Èíͨ¹ý¸ü¸ÄWindowsºÍоƬ΢´úÂëÀ´»º½â´ËÎó²î£¬£¬£¬²¢½¨ÒéʹÓÃWindows UpdateºÍоƬ΢´úÂë¸üС£¡£¡£¡£¡£¡£¡£

ÏêÇéÁ´½Ó£º

https://www.microsoft.com/security/blog/2018/01/09/understanding-the-performance-impact-of-spectre-and-meltdown-mitigations-on-windows-systems/

 

0x03 ²Î¿¼Á´½Ó

https://www.virustotal.com/gui/file/6461d0988c835e91eb534757a9fa3ab35afe010bec7d5406d4dfb30ea767a62c/detection

https://www.bleepingcomputer.com/news/security/working-windows-and-linux-spectre-exploits-found-on-virustotal/?

https://dustri.org/b/spectre-exploits-in-the-wild.html

https://therecord.media/first-fully-weaponized-spectre-exploit-discovered-online/

 

0x04 ʱ¼äÏß

2021-03-01  Julien VoisinÅû¶ʹÓóÌÐò

2021-03-02  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png