¡¾Îó²îÇ鱨¡¿Spectre CPUÎó²î£¨CVE-2017-5753£©

Ðû²¼Ê±¼ä 2021-03-02

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2017-5753

ʱ   ¼ä

2021-03-02

Àà   ÐÍ

Éè¼Æ¹ýʧ  

µÈ   ¼¶


Ô¶³ÌʹÓÃ


Ó°Ïì¹æÄ£


 

0x01 Îó²îÏêÇé

image.png

2021Äê03ÔÂ01ÈÕ£¬£¬£¬£¬£¬£¬Çå¾²Ñо¿Ö°Ô±ÖìÀû°²¡¤ÎÖÒÁÉ­£¨Julien Voisin£©ÔÚVirusTotal¶ñÒâÈí¼þÆÊÎöƽ̨ÉÏ·¢Ã÷ÁËSpectre CPUÎó²î£¨CVE-2017-5753£©µÄLinux°æºÍWindows°æµÄÎó²îʹÓóÌÐò£¬£¬£¬£¬£¬£¬ÕâÌåÏÖÄܹ»¾ÙÐÐÏÖÊµÆÆËð²¢ÍêÈ«ÎäÆ÷»¯µÄÓÐÓÃʹÓóÌÐòÒѾ­ÔÚ¹«¹²ÁìÓòÖйûÕæ¡£¡£¡£

Spectre CPUÎó²îÊÇ2018Äê1ÔÂGoogle Project ZeroÅû¶µÄIntel¡¢AMDºÍARM´¦Öóͷ£Æ÷¼Ü¹¹ÖеÄÓ²¼þÉè¼ÆÈ±ÏÝ£¨Meltdown£ºCVE-2017-5754¡¢Spectre£ºCVE-2017-5753ºÍCVE-2017-5715£©£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Ê¹ÓÃÎó²îÔËÐÐÓ¦ÓóÌÐòÖеĴúÂëÀ´ÆÆËð²î±ðÓ¦ÓóÌÐòÖ®¼äÔÚCPU²ãÃæµÄ¸ôÀ룬£¬£¬£¬£¬£¬È»ºóÇÔȡͳһϵͳÉÏÔËÐÐµÄÆäËüÓ¦ÓõÄÃô¸ÐÊý¾Ý¡£¡£¡£

GoogleÌåÏÖ£¬£¬£¬£¬£¬£¬Spectre CPUÎó²î»áÓ°Ïì°üÀ¨Windows¡¢Linux¡¢macOS¡¢AndroidºÍChromeOSµÈÔÚÄÚµÄÖ÷Á÷²Ù×÷ϵͳ¡£¡£¡£×Ô¾õÏÖ¸ÃÎó²îÒÔÀ´£¬£¬£¬£¬£¬£¬ËùÓÐÖ÷Á÷CPUºÍOS¹©Ó¦É̾ùÐû²¼Á˹̼þ²¹¶¡ºÍÈí¼þÐÞ¸´£¬£¬£¬£¬£¬£¬µ«ÉÐδ¸üÐÂÆäϵͳµÄÓû§ÈÔÈ»ÈÝÒ×Êܵ½Spectre CPUÎó²îµÄ¹¥»÷£¬£¬£¬£¬£¬£¬ÓÈÆäÊÇʹÓþɰæÐ¾Æ¬²¢ÔËÐоɰæ²Ù×÷ϵͳµÄÓû§£¨Èç2015ÄêÔµÄPC£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃHaswell»ò¾ÉµÄIntel´¦Öóͷ£Æ÷£©¡£¡£¡£

VirusTotalÉϵÄÎó²îʹÓóÌÐòÊÇÉϸöÔÂÉÏ´«µÄ£¬£¬£¬£¬£¬£¬¸ÃÈí¼þ°üÊÇÊÊÓÃÓÚWindowsºÍLinuxµÄImmunity Canvas 7.26×°ÖóÌÐò(Immunity CANVASΪȫÇòµÄÉøÍ¸²âÊÔÖ°Ô±ºÍÇ徲רҵְԱÌṩÁËÊý°ÙÖÖÎó²îʹÓá¢×Ô¶¯»¯µÄÎó²îʹÓÃϵͳÒÔ¼°ÖÜÈ«¡¢¿É¿¿µÄÎó²îʹÓÿª·¢¿ò¼Ü)¡£¡£¡£

image.png


´ËÎó²îʹÓóÌÐò¿ÉÒÔʹͨË×Óû§¿ÉÒÔ´ÓÄ¿µÄ×°±¸µÄÄÚºËÄÚ´æÖÐת´¢WindowsϵͳºÍLinuxϵͳÖÐ/etc/shadowÎļþÖеÄLM/NT¹þÏ£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬¸ÃʹÓóÌÐò»¹Äܹ»×ª´¢Kerberos tickets£¬£¬£¬£¬£¬£¬¿ÉÓëPsExecÒ»ÆðÓÃÓÚWindowsϵͳµÄÍâµØÈ¨ÏÞÉý¼¶ºÍºáÏòÒÆ¶¯¡£¡£¡£ÕâÒâζ×Å£¬£¬£¬£¬£¬£¬ÈôÊǸÃÎó²î±»ÀÖ³ÉʹÓ㬣¬£¬£¬£¬£¬Ôò¹¥»÷Õß¿ÉÒÔÇÔÈ¡ÊÜÓ°ÏìϵͳµÄÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬£¬°üÀ¨ÃÜÂë¡¢ÎĵµÒÔ¼°ÄÚ´æÖÐÈκοÉÓÃµÄÆäËüÊý¾Ý¡£¡£¡£

image.png

image.png

 

ÈçVoisinËù˵£¬£¬£¬£¬£¬£¬´ò¹ý¸ÃÎó²î²¹¶¡µÄLinux»òWindowsϵͳÔò²»ÊÜÓ°Ïì¡£¡£¡£¶øÎ¢ÈíÌåÏÖ£¬£¬£¬£¬£¬£¬ÓÉÓÚ×°Öò¹¶¡ºóϵͳÐÔÄÜ»áÓÐÏÔ×ŵÄϽµ£¬£¬£¬£¬£¬£¬Òò´ËÓû§×îÈÝÒ×Ìø¹ýÓ¦Óûº½â²½·¥¡£¡£¡£

³ý´ËÖ®Í⣬£¬£¬£¬£¬£¬×ÝÈ»¹¥»÷ÕßÄõ½ÁËÕâÁ½¸öÎó²îʹÓóÌÐòÈí¼þ°üÖеÄÈκÎÒ»¸ö£¬£¬£¬£¬£¬£¬Ö»ÔËÐÐËüÃÇÒ²²»»á±¬·¢ÈκÎЧ¹û£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÃǶ¼Ö»ÄÜÔÚ׼ȷµÄ²ÎÊýÏÂÖ´ÐУ¬£¬£¬£¬£¬£¬³ý·Ç¹¥»÷ÕßÄܹ»ÔËÐÐ׼ȷµÄ²ÎÊý¡£¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

Spectre CPUÎó²îÒÑÓÚ2018ÄêÐÞ¸´£¬£¬£¬£¬£¬£¬½¨Òéδʵʱ¸üеÄÓû§²Î¿¼CPUºÍOS¹©Ó¦É̹ٷ½Ðû²¼µÄÐÞ¸´³ÌÐò»ò»º½â²½·¥¡£¡£¡£

Õë¶Ôwindowsϵͳ£¬£¬£¬£¬£¬£¬Î¢Èíͨ¹ý¸ü¸ÄWindowsºÍоƬ΢´úÂëÀ´»º½â´ËÎó²î£¬£¬£¬£¬£¬£¬²¢½¨ÒéʹÓÃWindows UpdateºÍоƬ΢´úÂë¸üС£¡£¡£

ÏêÇéÁ´½Ó£º

https://www.microsoft.com/security/blog/2018/01/09/understanding-the-performance-impact-of-spectre-and-meltdown-mitigations-on-windows-systems/

 

0x03 ²Î¿¼Á´½Ó

https://www.virustotal.com/gui/file/6461d0988c835e91eb534757a9fa3ab35afe010bec7d5406d4dfb30ea767a62c/detection

https://www.bleepingcomputer.com/news/security/working-windows-and-linux-spectre-exploits-found-on-virustotal/?

https://dustri.org/b/spectre-exploits-in-the-wild.html

https://therecord.media/first-fully-weaponized-spectre-exploit-discovered-online/

 

0x04 ʱ¼äÏß

2021-03-01  Julien VoisinÅû¶ʹÓóÌÐò

2021-03-02  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png