Facebook WhatsApp TLSÁîÅÆ×ß©Îó²î¸´ÏÖ£¨CVE-2021-24027£©

Ðû²¼Ê±¼ä 2021-04-30

Åä¾°


WhatsAppÊÇÃÀ¹úFacebookµÄ¼´Ê±Í¨Ñ¶Ó¦Óà £¬ÔÚÍâÑóÓµÓÐÖØ´óµÄÓû§»ùÊý¡£4ÔÂ14ÈÕ £¬Çå¾²Ñо¿Ô±Chariton KaramitasÅû¶Android WhatsApp±£´æÁîÅÆÐ¹Â¶Îó²î £¬ÍŽáÆäËûÎó²î¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¸ÃÎó²îÓ°ÏìWhatsApp v2.21.4.18ºÍWhatsApp Business v2.21.4.18֮ǰµÄ°æ±¾ £¬½¨ÒéÓû§ÊµÊ±¸üе½2.21.4.18»ò¸ü¸ß°æ±¾ £¬ÒÔ¹æ±Ü¸ÃÎó²î±£´æµÄ¹¥»÷Σº¦¡£


Îó²îÆÊÎö


1¡¢ÁîÅÆÐ¹Â¶Îó²î£¨CVE-2021-24027£©


¸ÃÎó²î±£´æµÄÔµ¹ÊÔ­ÓÉ £¬ÊÇÓÉÓÚWhatsApp½«TLS»á»°Éϰ¶ºóµÄÐòÁл¯ÁîÅÆÎļþ·ÅÔÚÁËsdcardĿ¼Ï £¬¸ÃĿ¼²¢Î´ÉèÖûá¼ûȨÏÞ¡£


WhatsApp½ÓÄÉTLS1.3/TLS1.2À´¾ÙÐпͻ§¶Ëµ½·þÎñÆ÷µÄͨѶ £¬ÔÚTLSÎÕÊÖµÄÀú³ÌÖÐ £¬Í¨Ñ¶Ë«·½¾ÙÐÐÏ໥ÈÏÖ¤ºÍÃÜԿЭÉÌ £¬·þÎñÆ÷Éí·ÝÑé֤ʹÓ÷ǶԳƼÓÃÜ·½·¨ £¬¹ØÓÚ½ÏС³ß´çµÄǶÈëʽװ±¸ £¬ÕâÊÇÒ»¸öÅÌËãÁ¿ºÜÊÇ´óµÄÀú³Ì¡£ÎªÁËïÔÌ­¹¦ºÄ £¬½ÚÔ¼CPUÖÜÆÚ £¬Ìá³öÁ˻Ự»Ö¸´Àú³Ì £¬µ±ÖØÐ½¨ÉèÎÕÊÖʱ £¬¸´ÓÃ֮ǰµÄ»á»°ÐÅÏ¢¡£


ÏÂͼÖÐΪÉèÖûỰ»º´æÎļþ¼ÐµÄ·´±àÒë´úÂë½ØÍ¼¼°ÏÖʵÎļþ·¾¶½ØÍ¼ £¬WhatsApp½«Éϰ¶»á»°»º´æTLS1.2ºÍTLS1.3»®·Ö·ÅÔÚÎļþ¼ÐSSLSessionCacheºÍwatls-sessionsÖС£ÕâЩĿ¼ÔÚ²»Êܱ£»¤µÄÍⲿ´æ´¢Ï¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÎïÀí½Ó´¥ÊÖ»ú»ñµÃÕâЩÎļþ £¬Ôì³ÉÁîÅÆ×ß©¡£

1.png

2.png

3.png


2¡¢Ä¿Â¼´©Ô½Îó²î


WhatsAppÓÐEmojiºÍÕÕÆ¬Â˾µÈȸüй¦Ð§ £¬ÎÒÃÇ¿ÉÒÔʹÓÃÖÐÐÄÈËÀ´¸Ä¶¯Emoji»òÕÕÆ¬Â˾µÈȸüÐÂʱµÄzip°ü¡£zipÎļþ½âѹ·´±àÒë´úÂë½ØÍ¼ÈçÏ£º


4.png

5.png


WhatsApp¾ÙÐÐEmoji»òÕÕÆ¬Â˾µÈȸüÐÂʱ £¬Ã»ÓйýÂË¡±.//¡± £¬¿Éµ¼ÖÂĿ¼´©Ô½¡£ÈôÊÇÊܺ¦Õß±»ÖÐÐÄÈËÐ®ÖÆ £¬²¢ÇÒ¹¥»÷Õ߸͝ÁËÈȸüÐÂzip°ü £¬ÆäÖаüÀ¨ÓÉ¡±.//¡±Ä¿Â¼×é³ÉµÄsoÎļþ £¬Ê¹ÆäÁýÕÖWhatsApp¶¯Ì¬Á´½Ó¿âsoÎļþ £¬½«µ¼ÖÂí§Òâ´úÂëÖ´ÐС£


Îó²îʹÓÃ


Ç°ÃæÌáµ½ÐèҪͨ¹ýÎïÀí½Ó´¥»ñÈ¡ÁîÅÆ £¬¾ÖÏÞÐԽϴó¡£ÈôÊǹ¥»÷ÕßÅäºÏÍøÂç´¹ÂÚ £¬·¢ËÍÒ»¸öαװµÄhtmlÎļþ¸øÊܺ¦Õß £¬µ±Êܺ¦ÕßʹÓÃChrome£¨±£´æÎó²îCVE-2020-6516£©·­¿ª´Ëhtmlʱ £¬Ö´ÐÐhtmlÖеÄjs´úÂë £¬±éÀúsdcardÎļþ¼Ð²éÕÒTLS»º´æÎļþ £¬²¢°ÑÎļþ·¢Ë͵½¹¥»÷ÕßÖ¸¶¨µÄ·þÎñÆ÷ÉÏ¡£´óÖÂÀú³ÌÈçÏ£º


£¨1£©ÔÚ·¢ËÍÒ»ÌõÐÂÎÅʱ £¬°üÀ¨ÐÂÎŵÄÀàÐÍ¡¢ÐÂÎŵÄÔ¤ÀÀͼƬ¡¢ÐÂÎŵÄÎÊÌâºÍÐÂÎŵÄÏÖʵÄÚÈÝÎļþËIJ¿·Ö¡£Àà·¾¶X/041µÄA0l×Ö¶Îָʾ·¢ËÍÐÂÎŵÄÀàÐÍ £¬Àà·¾¶X/0QeµÄA03×Ö¶ÎָʾÐÂÎŵÄÔ¤ÀÀͼƬµÄbyteÊý×é £¬Àà·¾¶X/0NdµÄA04×Ö¶Îָʾ·¢ËÍÐÂÎŵÄÎÊÌâ £¬Àà·¾¶X/0M6µÄA05(Ljava/util/List;Landroid/net/Uri;Ljava/lang/String;LX/041;LX/02l;Z)ÒªÁìΪ×îÖÕ·¢ËÍÐÂÎÅÏÖʵÄÚÈÝÎļþµÄº¯Êý¡£Ïà¹Ø½ØÍ¼ÈçÏ£º


6.png

7.png

8.png9.png


£¨2£©¹¥»÷Õß½ÓÄÉfridaµÄRPCÔ¶³ÌŲÓù¦Ð§½¨ÉèÒ»¸öº¯Êý £¬²¢ÔÚhookº¯ÊýÖÐÐ޸ĵÚÒ»²½Öдý·¢Ë͵ÄÐÂÎÅ £¬½«ÐÂÎŵÄÔ¤ÀÀÍ¼Æ¬Ìæ»»³É¾ßÓÐÎüÒýÁ¦µÄͼƬ £¬²¢Å²ÓÃX/0M6µÄA05(Ljava/util/List;Landroid/net/Uri;Ljava/lang/String;LX/041;LX/02l;Z)ÒªÁ콫ÐÂÎÅ·¢Ë͸øÊܺ¦Õߣ¨µÚÒ»¸ö²ÎÊýΪÓÉÊܺ¦ÕßµÄWhatsAppµØÖ·×é³ÉµÄList £¬WhatAppµØÖ·ÃûÌÃΪmobile_number@s.whatsapp.net£© £¬ÈôÊÇÊܺ¦Õßµã»÷ͼƬ £¬Å²ÓÃChrome·­¿ª¶ñÒâhtmlÎļþ £¬TLS»º´æÁîÅÆ¿ÉÄܱ»·¢Ë͵½¹¥»÷Õß·þÎñÆ÷¡£


£¨3£©htmlÎļþÒªº¦²¿·Ö½ØÍ¼ÈçÏ¡£ÔÚÀֳɻñÈ¡µ½TLS»º´æÎļþºó £¬ÎÒÃǼ´¿É¾ÙÐÐÖÐÐÄÈ˹¥»÷¡£


10.png

11.png


£¨4£©Ê¹ÓÃEmoji»òÕÕÆ¬Â˾µÈȸüй¦Ð§ £¬Í¨¹ýÖÐÐÄÈËÀ´¸Ä¶¯Emoji»òÕÕÆ¬Â˾µÈȸüÐÂÏìÓ¦zip°ü £¬´Ó¶øµ¼ÖÂÔ¶³Ìí§Òâ´úÂëÖ´ÐУ¨ÑÝʾÊÓÆµÎªÁËÀû±ã £¬Ö±½ÓʹÓÃCharlesÀ´Ä£ÄâÈȸüÐÂÁýÕÖWhatsApp¶¯Ì¬Á´½Ó¿âsoÎļþ £¬À´µÖ´ïRCEµÄÀú³Ì£©¡£


Îó²î¸´ÏÖ


1¡¢ÁîÅÆÐ¹Â¶Îó²î¸´ÏÖ



 2¡¢RCEÎó²î¸´ÏÖ


²Î¿¼Á´½Ó£º

[1]https://www.census-labs.com/news/2021/04/14/whatsapp-mitd-remote-exploitation-CVE-2021-24027/

[2] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24027

[3] https://github.com/CENSUS/whatsapp-mitd-mitm

[4] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6516

[5]https://bugs.chromium.org/p/chromium/issues/detail?id=1092449

[6] https://youtu.be/sdVqTEXHxxY

[7] https://youtu.be/KO_K0F4W36I


×ðÁú¿­¹ÙÍøÈë¿ÚÆð¾¢·ÀÓùʵÑéÊÒ£¨ADLab£©


ADLab½¨ÉèÓÚ1999Äê £¬ÊÇÖйúÇå¾²ÐÐÒµ×îÔ罨ÉèµÄ¹¥·ÀÊÖÒÕÑо¿ÊµÑéÊÒÖ®Ò» £¬Î¢ÈíMAPPÍýÏë½¹µã³ÉÔ± £¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£×èÖ¹ÏÖÔÚ £¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Çå¾²Îó²î½ü1100¸ö £¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Çå¾²Îó²î1000Óà¸ö £¬Ò»Á¬¼á³Ö¹ú¼ÊÍøÂçÇå¾²ÁìÓòÒ»Á÷Ë®×¼¡£ÊµÑéÊÒÑо¿Æ«Ïòº­¸Ç²Ù×÷ϵͳÓëÓ¦ÓÃϵͳÇå¾²Ñо¿¡¢ÖÇÄÜÖÕ¶ËÇå¾²Ñо¿¡¢ÎïÁªÍøÖÇÄÜ×°±¸Çå¾²Ñо¿¡¢WebÇå¾²Ñо¿¡¢¹¤¿ØÏµÍ³Çå¾²Ñо¿¡¢ÔÆÇå¾²Ñо¿¡£Ñо¿Ð§¹ûÓ¦ÓÃÓÚ²úÆ·½¹µãÊÖÒÕÑо¿¡¢¹ú¼ÒÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÇå¾²·þÎñµÈ¡£


adlab.jpg