¡¾Îó²îͨ¸æ¡¿Î¢ÈíSMBv3ÐÒéÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-0796£©PoC¹ûÕæ´¦Öóͷ£ÊÖ²á
2020-06-03
Ò». Îó²î¸ÅÊö
±±¾©Ê±¼ä6ÔÂ2ÈÕÍí£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½ÓÐÑо¿Ö°Ô±Ðû²¼ÁËSMBv3ÐÒéÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-0796£©Ô¶³ÌʹÓõÄPoC´úÂ룬¼«´óµÄÔöÌíÁ˸ÃÎó²îµÄDZÔÚΣº¦£¬½¨Ò黹δÐÞ¸´Îó²îµÄÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
Microsoft Server Message Block 3.1.1(SMBv3)ÐÒéÔÚ´¦Öóͷ£Ä³Ð©ÇëÇóµÄ·½·¨Öб£´æ´úÂëÖ´ÐÐÎó²î¡£¹¥»÷Õß¿ÉÒÔÈ«ÐĽṹÊý¾Ý°ü·¢Ë͵½SMB·þÎñÆ÷£¬ÎÞÐè¾ÓÉÉí·ÝÑéÖ¤£¬¼´¿ÉÔÚÄ¿µÄ·þÎñÆ÷ÉÏÖ´ÐÐí§Òâ´úÂë¡£¹¥»÷Õß¿Éͨ¹ý°²ÅÅһ̨¶ñÒâSMB v3·þÎñÆ÷£¬²¢ÓÕµ¼Óû§£¨¿Í»§¶Ë£©ÅþÁ¬µ½¸Ã·þÎñÆ÷£¬Ò»µ©Ä¿µÄÓû§ÅþÁ¬£¬¼´¿ÉÔÚÅÌËã»úÉÏÖ´Ðй¥»÷Õß×Ô½ç˵µÄ¶ñÒâ´úÂë¡£ÓÉÓÚÉÏÊöÎó²îÓëWannaCry£¨2017Äê5Ô“ÓÀºãÖ®À¶”£©Îó²î½ÏΪÏàËÆ£¬Ò×±»Èä³æÊ¹ÓÃÈö²¥¶ñÒâ³ÌÐò£¬¿ÉÄÜ»á³ÉΪ¶ñÒâÈí¼þºÍ¹¥»÷Õ߯ձéʹÓõÄÎó²î¡£
²Î¿¼Á´½Ó£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796
¶þ. Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
l Windows 10 Version 1903 for 32-bit Systems
l Windows 10 Version 1903 for ARM64-based Systems
l Windows 10 Version 1903 for x64-based Systems
l Windows 10 Version 1909 for 32-bit Systems
l Windows 10 Version 1909 for ARM64-based Systems
l Windows 10 Version 1909 for x64-based Systems
l Windows Server, version 1903 (Server Core installation)
l Windows Server, version 1909 (Server Core installation)
Èý. ʱ¼äÏß
3ÔÂ10ÈÕ£ºÎ¢ÈíÐû²¼Ç徲ͨ¸æADV200005£¬³ÆSMBv3ÐÒéÔÚ´¦Öóͷ£Ä³Ð©ÇëÇóµÄ·½·¨Öб£´æ´úÂëÖ´ÐÐÎó²î£¬²¢ÌṩÁË»º½â²½·¥¡£
3ÔÂ11ÈÕ£ºÍâÑóij³§ÉÌÕë¶Ô¸ÃÎó²îÐû²¼Çå¾²·À»¤¹æÔò¸üС£
3ÔÂ11ÈÕ£ºAG¹«Ë¾¿Æ¼¼Ðû²¼Î¢ÈíSMBv3ÐÒéÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-0796£©Í¨¸æ¡£
3ÔÂ12ÈÕ£ºÎ¢ÈíÕýʽÐû²¼CVE-2020-0796Ç徲ͨ¸æºÍÎó²îÐÞ¸´²¹¶¡¡£
3ÔÂ13ÈÕ£ºAG¹«Ë¾¿Æ¼¼Ðû²¼Î¢ÈíSMBv3ÐÒéÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-0796£©´¦Öóͷ£Êֲᡣ
AG¹«Ë¾¿Æ¼¼µÚһʱ¼ä¸´ÏÖÁ˵¼ÖÂϵͳÀ¶ÆÁµÄÎó²îʹÓóÌÐò£º

3ÔÂ30ÈÕ£ºAG¹«Ë¾¿Æ¼¼¼à²âµ½¸ÃÎó²îÍâµØÌáȨPoCÁ÷³ö¡£
3ÔÂ31ÈÕ£ºAG¹«Ë¾¿Æ¼¼¸´ÏÖÍâµØÌáȨʹÓò¢Ðû²¼PoCÇ鱨¡£

4ÔÂ14ÈÕ£ºÓÐÍâÑóÑо¿ÕßÐû²¼ÒÉËÆÎó²îʹÓÃEXPÑÝʾÊÓÆµ£¬Á´½Óhttps://twitter.com/RicercaSec/status/1249904222490918917¡£
6ÔÂ2ÈÕ£ºAG¹«Ë¾¿Æ¼¼¼à²âµ½Ñо¿Ö°Ô±Ðû²¼´ËÎó²îÔ¶³ÌʹÓôúÂ룬ÏÖʵÍþвÌáÉý¡£

6ÔÂ3ÈÕ£ºAG¹«Ë¾¿Æ¼¼Ðû²¼¸ÃÎó²îÔ¶³ÌʹÓÃPoC¹ûÕæÍ¨¸æ¡£
ËÄ. Îó²î¼ì²â
4.1 ϵͳ°æ±¾¼ì²â
¼ì²éÊÇ·ñʹÓÃ1903»ò1909²Ù×÷ϵͳ°æ±¾£º
£¨1£©ÓÒ¼üµã»÷×óϽÇWindowsͼ±ê£¬Ñ¡Ôñ“ÉèÖÔ£»
£¨2£©µã»÷“ϵͳ”£¬Ñ¡Ôñ×ó²àµÄ “¹ØÓڔѡÏ£»
£¨3£©Éó²é“Windows¹æ¸ñ”Öеē°æ±¾ºÅ”£¬ÈôÊǰ汾ºÅÏÔʾΪ1903»ò1909£¬Ôò֤ʵÊÜ´ËÎó²îÓ°Ï죬½¨ÒéÁ¬Ã¦×°Öò¹¶¡¡£

4.2 ²¹¶¡¼ì²â
ÔÚÊÜÓ°Ïì¹æÄ£ÄڵIJÙ×÷ϵͳÖУ¬¿ÉÖ´ÐÐÒÔÏÂÏÂÁîÉó²é²¹¶¡×°ÖõÄÇéÐΡ£
|
systeminfo | findstr KB4551762 |
ÏÂÁîÖ´Ðп¢ÊºóÈôÊÇûÓÐÅÌÎʵ½KB4551762²¹¶¡£¬Ôò¸Ãϵͳ±£´æÇ徲Σº¦¡£

4.3 ¹¤¾ß¼ì²â
´ËÎó²îÔÚÍøÉÏÒÑÓйûÕæµÄ¼ì²â¹¤¾ß£¬ÂÄÀúÖ¤ÏÂÁо籾¿É¶ÔSMB°æ±¾¾ÙÐмì²â£¬Ïà¹ØÓû§¿É×ÔÐÐÑ¡ÔñÏÂÔØÊ¹Óá£
Python¼ì²â¾ç±¾
ÏÂÔØÁ´½Ó£ºhttps://github.com/ollypwn/SMBGhost/blob/master/scanner.py
Nmap¼ì²â¾ç±¾(nse¾ç±¾)
ÏÂÔØÁ´½Ó£º
https://github.com/cyberstruggle/DeltaGroup/blob/master/CVE-2020-0796/CVE-2020-0796.nse
Powershell¼ì²â¾ç±¾
ÏÂÔØÁ´½Ó£º
https://github.com/T13nn3s/CVE-2020-0976/blob/master/CVE-2020-0796-Smbv3-checker.ps1
×¢£ºÓÉÓڴ˼ì²â·½·¨ÔÀíΪ¶ÔSMBv3°æ±¾¾ÙÐмì²â£¬Òò´ËÔÚ×°Öùٷ½²¹¶¡ºó£¬¿ÉÄ᷺ܻÆðÎ󱨵ÄÇéÐΡ£
4.4 ²úÆ·¼ì²â
AG¹«Ë¾¿Æ¼¼Ô¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨RSAS£©ÓëÍøÂçÈëÇÖ¼ì²âϵͳ£¨IDS£©¡¢Íþв̽Õ루UTS£©ÒѾ߱¸¶Ô´ËÎó²î£¨CVE-2020-0796£©µÄɨÃèÓë¼ì²âÄÜÁ¦£¬ÇëÓа²ÅÅÒÔÉÏ×°±¸µÄÓû§Éý¼¶ÖÁ×îа汾¡£
|
|
Éý¼¶°ü°æ±¾ºÅ |
Éý¼¶°üÏÂÔØÁ´½Ó |
|
RSAS V6 ϵͳ²å¼þ°ü |
V6.0R02F01.1712 |
http://update.nsfocus.com/update/downloads/id/103169 |
|
IDS |
5.6.9.22154 |
http://update.nsfocus.com/update/downloads/id/103167 |
|
5.6.10.22154 |
http://update.nsfocus.com/update/downloads/id/103168 |
|
|
UTS |
5.6.10.22154 |
http://update.nsfocus.com/update/downloads/id/103172 |
¹ØÓÚRSASµÄÉèÖÃÖ¸µ¼£¬Çë²Î¿¼ÈçÏÂÁ´½Ó£º
https://mp.weixin.qq.com/s/aLAWXs5DgRhNHf4WHHhQyg
Îå. Îó²î·À»¤
5.1 ²¹¶¡¸üÐÂ
΢Èí¹Ù·½ÒÑÕë¶Ô¸ÃÎó²îÐû²¼ÁËÇå¾²²¹¶¡KB4551762£¬½¨ÒéÊÜÓ°ÏìÓû§¿ªÆôϵͳ×Ô¶¯¸üÐÂ×°Öøò¹¶¡¾ÙÐзÀ»¤¡£
×¢£ºÓÉÓÚÍøÂçÎÊÌâ¡¢ÅÌËã»úÇéÐÎÎÊÌâµÈÔµ¹ÊÔÓÉ£¬Windows UpdateµÄ²¹¶¡¸üпÉÄÜ·ºÆðʧ°Ü¡£Óû§ÔÚ×°Öò¹¶¡ºó£¬Ó¦ÊµÊ±¼ì²é²¹¶¡ÊÇ·ñÀֳɸüС£ÓÒ¼üµã»÷×ÀÃæ×óϽǵÄWindowsͼ±ê£¬Ñ¡Ôñ“ÉèÖÃ(N)”£¬Ñ¡Ôñ“¸üкÍÇå¾²”-“Windows¸üД£¬Éó²é¸ÃÒ³ÃæÉϵÄÌáÐÑÐÅÏ¢£¬Ò²¿Éµã»÷“Éó²é¸üÐÂÀúÊ·¼Í¼”Éó²éÀúÊ·¸üÐÂÇéÐΣ¬È·ÈÏÆäÖÐÊÇ·ñ°üÀ¨“KB4551762”
Èô·ºÆðδÀÖ³É×°Öøüв¹¶¡µÄÇéÐΣ¬¿É´Ó¹ÙÍøÏÂÔØÀëÏß×°Öðü¾ÙÐиüУ¬ÏÂÔØÁ´½ÓÈçÏ£º
https://www.catalog.update.microsoft.com/Search.aspx?q=KB4551762

5.2 ÔÝʱ·À»¤²½·¥
ÈôÏà¹ØÓû§ÔÝʱÎÞ·¨×°Öò¹¶¡£¬¿Éͨ¹ýÏÂÁв½·¥¾ÙÐлº½â£º
5.2.1 ½ûÓÃSMBv3ѹËõ
ÒªÁìÒ»£ºÊ¹ÓÃÒÔÏÂPowerShellÏÂÁî½ûÓÃѹËõ¹¦Ð§£¬ÒÔ×èֹδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßʹÓÃSMBv3 ·þÎñÆ÷µÄÎó²î¡£
|
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" DisableCompression -Type DWORD -Value 1 -Force |
Óû§¿Éͨ¹ýÒÔÏÂPowerShellÏÂÁî×÷·Ï½ûÓÃѹËõ¹¦Ð§
|
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" DisableCompression -Type DWORD -Value 0 -Force |
ÒªÁì¶þ£ºÓÒ¼üµã»÷×ÀÃæ×óϽǵÄWindowsͼ±ê£¬ÔÚµ¯³ö²Ëµ¥ÖÐÑ¡Ôñ“ÔËÐД²Ëµ¥ÏÔÚµ¯³öµÄÔËÐпòÖÐÊäÈëregedit£¬·¿ª×¢²á±í±à¼Æ÷¡£
ÔÚ “HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters”Ŀ¼ÖÐÌí¼ÓÒ»¸öDWORDÀàÐ͵Ä×¢²á±íÏîDisableCompression £¬ÊýֵΪ1¡£

ÈçÐè×÷·Ï½ûÓÃSMBv3ѹËõ¹¦Ð§£¬½«¸Ã×¢²á±íÏîÊýÖµÐÞ¸ÄΪ0»òɾ³ý×¢²á±íÏî¼´¿É¡£
×¢£ºÊ¹ÓÃÒÔÉÏÒªÁì¾ÙÐиü¸Äºó£¬ÎÞÐèÖØÆô¼´¿ÉÉúЧ£»ÒÔÉÏÒªÁì½ö¿ÉÓÃÀ´·À»¤Õë¶ÔSMB·þÎñÆ÷£¨SMB SERVER£©µÄ¹¥»÷£¬ÎÞ·¨¶ÔSMB¿Í»§¶Ë£¨SMB Client£©¾ÙÐзÀ»¤¡£
5.2.2 ÉèÖ÷À»ðǽսÂÔ
ÔÚ½çÏß·À»ðǽ×öºÃÇå¾²Õ½ÂÔ£¬Õ¥È¡139ºÍ445¶Ë¿Ú¶ÔÍⲿ¿ª·Å£¬ÏêÇé¿É²Î¿¼Î¢Èí¹Ù·½Ö¸ÄÏ£º
https://support.microsoft.com/zh-cn/help/3185535/preventing-smb-traffic-from-lateral-connections
5.3 ²úÆ··À»¤
Õë¶Ô´ËÎó²î£¬AG¹«Ë¾¿Æ¼¼ÍøÂçÈëÇÖ·À»¤ÏµÍ³(IPS)ÒÑÐû²¼¹æÔòÉý¼¶°ü£¬ÇëÏà¹ØÓû§Éý¼¶¹æÔò£¬ÒÔÐγÉÇå¾²²úÆ··À»¤ÄÜÁ¦¡£Çå¾²·À»¤²úÆ·¹æÔò°æ±¾ºÅÈçÏ£º
|
Çå¾²·À»¤²úÆ·°æ±¾ |
Éý¼¶°ü°æ±¾ºÅ |
Éý¼¶°üÏÂÔØÁ´½Ó |
|
IPS¹æÔò5.6.9Éý¼¶°ü |
5.6.9.22154 |
http://update.nsfocus.com/update/downloads/id/103167 |
|
IPS¹æÔò5.6.10Éý¼¶°ü |
5.6.10.22154 |
http://update.nsfocus.com/update/downloads/id/103168 |
²úÆ·¹æÔòÉý¼¶µÄ²Ù×÷°ì·¨Ïê¼ûÈçÏÂÁ´½Ó£º
IPS£ºhttps://mp.weixin.qq.com/s/JsRktENQNj1TdZSU62N0Ww
5.4 ƽ̨¼à²â
AG¹«Ë¾ÆóÒµÇ徲ƽ̨£¨ESP£©ÓëAG¹«Ë¾ÖÇÄÜÇå¾²ÔËӪƽ̨£¨ISOP£©ÒѾ¾ß±¸Õë¶ÔWindows SMBv3¿Í»§¶Ë/·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-0796£©µÄ¼ì²âÄÜÁ¦£¬°²ÅÅÓÐAG¹«Ë¾¿Æ¼¼Æ½Ì¨Àà²úÆ·µÄÓû§£¬¿ÉʵÏÖ¶Ô´ËÎó²îµÄƽ̨¼à²âÄÜÁ¦¡£
|
Ç徲ƽ̨ |
Éý¼¶°ü/¹æÔò°æ±¾ºÅ |
|
ESP£¨AG¹«Ë¾ÆóÒµÇ徲ƽ̨½â¾ö¼Æ»®£© |
ESPƽ̨¹æÔòÎÞÐèÉý¼¶¡£ÈôÒÑ×°ÖÃAG¹«Ë¾IPS×°±¸£¬ÇëÉý¼¶IPS¹æÔòÖÁ5.6.10.22154»òÕß5.6.9.22154°æ±¾¼°ÒÔÉϼ´¿É¡£ |
|
ISOP£¨AG¹«Ë¾ÖÇÄÜÇå¾²ÔËӪƽ̨£© |
ʹÓùæÔòÉý¼¶°üÉý¼¶ attack_rule.1.0.0.0.207104.dat |
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚAG¹«Ë¾¿Æ¼¼
AG¹«Ë¾£¨¼ò³ÆAG¹«Ë¾¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ40¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬AG¹«Ë¾¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
AG¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£ºAG¹«Ë¾¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

AG¹«Ë¾ÔÆ







