TCP/IP Èí¼þ¿âRipple20·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-06-180x00 ·ì϶¸ÅÊö
ÒÔÉ«ÁÐÍøÂ簲ȫ¹«Ë¾JSOFµÄ×êÑÐÈËÔ±ÔÚTreck£¬£¬£¬£¬£¬£¬Inc.¿ª·¢µÄTCP/IPÈí¼þ¿âÖз¢ÏÖÁË19¸ö0day·ì϶£¬£¬£¬£¬£¬£¬ÕâһϵÁзì϶ͳ³ÆÎª¡°Ripple20¡±¡£¡£¡£¡£¡£¡£¡£È«ÇòÊýÒŲ́£¨ÉõÖÁ¸ü¶à£©IoTÉ豸¿ÉÄÜ»áÊܵ½Ô¶³Ì¹¥»÷¡£¡£¡£¡£¡£¡£¡£
0x01 ·ì϶ÏêÇé
Ripple20Ó°ÏìÁËÀ´×Ô¿í·ºÁìÓòµÄ¹Ø¼üÎïÁªÍøÉ豸£¬£¬£¬£¬£¬£¬Éæ¼°Á˶à¶à¹©¸øÉÌ¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ¹©¸øÉÌÁìÓòºÜ¹ã£¬£¬£¬£¬£¬£¬Ô̺¬HP¡¢Schneider Electric¡¢Intel¡¢Rockwell Automation¡¢Caterpillar¡¢BaxterÒÔ¼°ºÜ¶àÆäËûÔÚÒ½ÁÆ¡¢ÔËÊä¡¢¹¤Òµ½ÚÔì·½ÃæµÄÖØÒª¹ú¼Ê¹©¸øÉÌ¡¢ÆóÒµ¡¢ÄÜÔ´£¨Ê¯ÓÍ/ÌìÈ»Æø£©¡¢µçÐÅ¡¢ÁãÊÛºÍóÒ×ÒÔ¼°ÆäËûÐÐÒµ¡£¡£¡£¡£¡£¡£¡£
19¸ö·ì϶¶¼ÊÇÄÚ´æ°Ü»µÎÊÌ⣬£¬£¬£¬£¬£¬Ô´ÓÚʹÓÃ·ÖÆçºÍ̸£¨Ô̺¬IPv4£¬£¬£¬£¬£¬£¬ICMPv4£¬£¬£¬£¬£¬£¬IPv6£¬£¬£¬£¬£¬£¬IPv6OverIPv4£¬£¬£¬£¬£¬£¬TCP£¬£¬£¬£¬£¬£¬UDP£¬£¬£¬£¬£¬£¬ARP£¬£¬£¬£¬£¬£¬DHCP£¬£¬£¬£¬£¬£¬DNS»òÒÔÌ«ÍøÁ´Â·²ã£©ÔÚÍøÂçÉÏ·¢Ë͵ÄÊý¾Ý°üµÄ´¦ÖÃÃýÎ󡣡£¡£¡£¡£¡£¡£
ÆäÖÐÔ̺¬ËĸöÑϳÁ·ì϶£ºÓÐÁ½¸ö·ì϶CVSSÆÀ·Ö10·Ö£¬£¬£¬£¬£¬£¬CVE-2020-11896¿ÉÄܵ¼ÖÂÔ¶³ÌÖ´ÐдúÂ룬£¬£¬£¬£¬£¬CVE-2020-11897¿ÉÄܵ¼ÖÂÔ½½çдÈë¡£¡£¡£¡£¡£¡£¡£ÆäËûÁ½¸ö·ì϶µÄCVSSÆÀ·Ö±ðÀëΪ9ºÍ9.1£¬£¬£¬£¬£¬£¬CVE-2020-11901¿ÉÄܵ¼ÖÂÔ¶³ÌÖ´ÐдúÂ룬£¬£¬£¬£¬£¬CVE-2020-11898¿ÉÄܵ¼ÖÂй¼ûô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
¶øÆäËû15¸ö·ì϶µÄÑϳÁˮƽ·ÖÆç£¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö´Ó3.1µ½8.2£¬£¬£¬£¬£¬£¬¾ßÌåÐÅÏ¢ÈçÏ£º
|
CVE ID |
·ìϼûèÊö |
½¨¸´°æ±¾ |
|
CVE-2020-11896 |
ÔÚ´¦ÖÃÓÉδ¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬¶ÔIPv4 / UDP×é¼þÖеij¤¶È²ÎÊý²»Ò»ÖµĴ¦Öò»µ±¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÄܵ¼ÖÂÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£ |
6.0.1.66 (release 30/03/2020) |
|
CVE-2020-11897 |
ÔÚ´¦ÖÃδ¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬¶ÔIPv6×é¼þÖеij¤¶È²ÎÊý²»Ò»ÖµĴ¦Öò»µ±¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÄܵ¼ÖÂÔ½½çдÈë¡£¡£¡£¡£¡£¡£¡£ |
5.0.1.35 (release 04/06/2009) |
|
CVE-2020-11901 |
´¦ÖÃδ¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬DNS½âÎöÆ÷×é¼þÖеÄÊäÈëÑéÖ¤²»ÕýÈ·¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÄܵ¼ÖÂÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/2020) |
|
CVE-2020-11898 |
´¦ÖÃδ¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬¶ÔIPv4 / ICMPv4×é¼þÖеij¤¶È²ÎÊý²»Ò»ÖµĴ¦Öò»µ±¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÄܵ¼ÖÂÃô¸ÐÐÅϢ¶³ö¡£¡£¡£¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/2020) |
|
CVE-2020-11900 |
´¦ÖÃÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬IPv4Ëí·×é¼þÖпÉÄÜ´æÔÚË«³Á¿ªÊÍ¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÄܵ¼ÖÂUse After Free¡£¡£¡£¡£¡£¡£¡£ |
6.0.1.41 (release 10/15/2014) |
|
CVE-2020-11902 |
´¦ÖÃδ¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬IPv6OverIPv4Ëí·×é¼þÖеÄÊäÈëÑéÖ¤²»ÕýÈ·¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÄܵ¼ÖÂÔ½½ç¶ÁÈ¡¡£¡£¡£¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/20) |
|
CVE-2020-11904 |
´¦ÖÃδ¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬ÄÚ´æ·ÖÅä×é¼þÖпÉÄÜ´æÔÚÕûÊýÒç³ö¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÄܵ¼ÖÂÔ½½çдÈë¡£¡£¡£¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/2020) |
|
CVE-2020-11899 |
´¦ÖÃδ¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬IPv6×é¼þÖеÄÊäÈëÑéÖ¤²»ÕýÈ·¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÄܵ¼ÖÂÔ½½ç¶ÁÈ¡»ò»Ø¾ø·þÎñ¡£¡£¡£¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/20) |
|
CVE-2020-11903 |
´¦ÖÃδ¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬DHCP×é¼þÖдæÔÚÔ½½ç¶ÁÈ¡ÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÄܵ¼ÖÂÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£ |
6.0.1.28 (release 10/10/12) |
|
CVE-2020-11905 |
´¦ÖÃδ¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬DHCPv6×é¼þÖдæÔÚÔ½½ç¶ÁÈ¡ÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÄܵ¼ÖÂÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/20) |
|
CVE-2020-11906 |
ÔÚ´¦ÖÃδ¾ÊÚȨÓû§·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬ÒÔÌ«ÍøÁ´Â·²ã×é¼þÖÐÊäÈëÑéÖ¤²»ÕýÈ·¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÄܵ¼ÖÂÕûÊýÒç³ö¡£¡£¡£¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/20) |
|
CVE-2020-11907 |
´¦ÖÃδ¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬TCP×é¼þÖжԲÎÊý³¤¶È²»Ò»ÖµĴ¦Öò»µ±¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÄܵ¼ÖÂÕûÊýÒç³ö¡£¡£¡£¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/20) |
|
CVE-2020-11909 |
´¦ÖÃδ¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬IPv4×é¼þÖеÄÊäÈëÑéÖ¤²»ÕýÈ·¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÄܵ¼ÖÂÕûÊýÒç³ö¡£¡£¡£¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/20) |
|
CVE-2020-11910 |
´¦ÖÃδ¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬ICMPv4×é¼þÖеÄÊäÈëÑéÖ¤²»ÕýÈ·¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÄܵ¼ÖÂÔ½½ç¶ÁÈ¡¡£¡£¡£¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/20) |
|
CVE-2020-11911 |
´¦ÖÃδ¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬ICMPv4×é¼þÖеĽӼû½ÚÔì²»ÕýÈ·¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÄܵ¼Ö¹ؼü×ÊÔ´µÄȨÏÞ·ÖÅäÃýÎ󡣡£¡£¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/20) |
|
CVE-2020-11912 |
´¦ÖÃδ¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬TCP×é¼þÖеÄÊäÈëÑéÖ¤²»ÕýÈ·¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÄܵ¼ÖÂÔ½½ç¶ÁÈ¡¡£¡£¡£¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/20) |
|
CVE-2020-11913 |
´¦ÖÃδ¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬IPv6×é¼þÖеÄÊäÈëÑéÖ¤²»ÕýÈ·¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÄܵ¼ÖÂÔ½½ç¶ÁÈ¡¡£¡£¡£¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/20) |
|
CVE-2020-11914 |
´¦ÖÃδ¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬ARP×é¼þÖеÄÊäÈëÑéÖ¤²»ÕýÈ·¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÄܵ¼ÖÂÔ½½ç¶ÁÈ¡¡£¡£¡£¡£¡£¡£¡£ |
6.0.1.66 (release 03/03/20) |
|
CVE-2020-11908 |
´¦ÖÃδ¾ÊÚȨµÄÍøÂç¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üʱ£¬£¬£¬£¬£¬£¬DHCP×é¼þÖеÄNull Termination²»ÕýÈ·¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÄܵ¼ÖÂÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£ |
4.7.1.27 (release 11/08/07) |
JSOFÒÑÓë¶à¼Ò×éÖ¯ºÏ×÷£¬£¬£¬£¬£¬£¬Ðµ÷·ì϶Åû¶ºÍ½¨²¹¹¤×÷£¬£¬£¬£¬£¬£¬Ô̺¬CERT / CC£¬£¬£¬£¬£¬£¬CISA£¬£¬£¬£¬£¬£¬FDA£¬£¬£¬£¬£¬£¬¹ú¶ÈCERT£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ¹©¸øÉÌºÍÆäËûÍøÂ簲ȫ¹«Ë¾¡£¡£¡£¡£¡£¡£¡£
µ½Ä¿Ç°ÎªÖ¹£¬£¬£¬£¬£¬£¬ÒѾȷÈÏÀ´×Ô11¸ö¹©¸øÉ̵IJúÆ·Ò×Êܹ¥»÷£¬£¬£¬£¬£¬£¬Éæ¼°´òÓ¡»ú¡¢UPSϵͳ¡¢ÍøÂçÉ豸¡¢IPÉãÏñ»ú¡¢ÊÓÆµ»áÒéϵͳ¡¢Â¥Óî×Ô¶¯»¯É豸ºÍICSÉ豸µÈ¡£¡£¡£¡£¡£¡£¡£µ«²»Ö¹ÓÚ´Ë£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÒÔΪÕâЩ·ì϶¿ÉÄÜ»áÓ°ÏìÀ´×Ô100¶à¼Ò¹©¸øÉ̵ÄÊýÒŲ́É豸¡£¡£¡£¡£¡£¡£¡£
0x02 ´ëÖý¨Òé
ÈÔÔÚʹÓÃÉ豸ʱ£¬£¬£¬£¬£¬£¬Ripple20×é³É³Á´ó·çÏÕ¡£¡£¡£¡£¡£¡£¡£Ç±ÔڵķçÏÕ³¡¾°Ô̺¬£º
? ÈôÊÇÃæÏò»¥ÁªÍø£¬£¬£¬£¬£¬£¬ÔòÀ´×ÔÍøÂç±í²¿µÄ¹¥»÷Õß½«½ÚÔìÍøÂçÖеÄÉ豸£»£»£»£»£»
? ÒѾÉè·¨ÉøÈëµ½ÍøÂçµÄ¹¥»÷ÕßÄܹ»Ê¹Óÿâ·ì϶À´Õë¶ÔÍøÂçÖеÄÌØ¶¨É豸£»£»£»£»£»
? ¹¥»÷ÕßÄܹ»¹ã²¥¿ÉÄÜͬʱÊÕÊÜÍøÂçÖÐËùÓÐÊÜÓ°ÏìÉ豸µÄ¹¥»÷£»£»£»£»£»
? ¹¥»÷Õß¿ÉÄÜÀûÓÃÊÜÓ°ÏìµÄÉ豸°µ²ØÔÚÄÚÍøÖУ»£»£»£»£»
? ¸´ÔӵĹ¥»÷Õß¿ÉÄÜ»á´ÓÍøÂçÌìǵ±í²¿¶ÔÍøÂçÄÚµÄÉ豸½øÐй¥»÷£¬£¬£¬£¬£¬£¬´Ó¶øÈƹýÈκÎNATÅäÖᣡ£¡£¡£¡£¡£¡£ÕâÄܹ»Í¨¹ýÖ´ÐÐMITM¹¥»÷»òdns»º´æÖж¾À´ÊµÏÖ£»£»£»£»£»
? ÔÚijЩÇé¿öÏ£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜ¿ÉÄÜͨ¹ýÏìÓ¦ÍÑÀëÍøÂçÌìǵµÄÊý¾Ý°ü£¬£¬£¬£¬£¬£¬ÈƹýNAT£¬£¬£¬£¬£¬£¬´ÓÍøÂç±í²¿Ö´Ðй¥»÷£»£»£»£»£»
? ÔÚËùÓÐÇé¿öÏ£¬£¬£¬£¬£¬£¬¹¥»÷Õß¶¼Äܹ»Ô¶³Ì½ÚÔìÖ¸±êÉ豸£¬£¬£¬£¬£¬£¬¶øÎÞÐèÓû§¹ýÎÊ¡£¡£¡£¡£¡£¡£¡£
JSOF½¨Òé²ÉÈ¡´ëÊ©ÒÔ×îÓ×»¯»ò¼õÇáÉ豸¿ª·¢µÄ·çÏÕ¡£¡£¡£¡£¡£¡£¡£É豸¹©¸øÉ̽«Ñ¡È¡ÓëÍøÂçÔËÓªÉÌ·ÖÆçµÄ²½Öè¡£¡£¡£¡£¡£¡£¡£Í¨³££¬£¬£¬£¬£¬£¬ÎÒÃǽ¨ÒéÖ´ÐÐÒÔϲ½Ö裺
? ËùÓÐ×éÖ¯ÔÚ²¿Êð·ÀÓù´ëʩ֮ǰ¶¼±ØÐë½øÐÐÈ«ÃæµÄ·çÏÕÆÀ¹À¡£¡£¡£¡£¡£¡£¡£
? ½¨Ò鲿Êð·ÀÓù´ëÊ©¡£¡£¡£¡£¡£¡£¡£
? É豸¹©¸øÉ̵Ļº½â´ëÊ©£º
1. È·¶¨ÄúÊÇ·ñʹÓÃÁËÒ×Êܹ¥»÷µÄTreck²Ö¿â£»£»£»£»£»
2. ÁªÏµTreckÏàʶ·çÏÕ£»£»£»£»£»
3. ¸üе½×îеÄTreck²Ö¿â°æ±¾£¨6.0.1.67»ò¸ü¸ß°æ±¾£©£»£»£»£»£»
4. ÈôÊÇÎÞ·¨¸üУ¬£¬£¬£¬£¬£¬Çë˼¿¼½ûÓÃÒ×Êܹ¥»÷µÄÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£
? ¶ÔÔËÓªÉ̺ÍÍøÂçµÄ»º½â£º£¨»ùÓÚCERT/CCºÍCISA ICS-CERTÕ÷ѯ£©
1. ½«ËùÓÐÉ豸¸üе½×îа汾£»£»£»£»£»
2. ÈôÊÇÎÞ·¨¸üÐÂÉ豸£¬£¬£¬£¬£¬£¬½¨ÒéÖ´ÐÐÒÔϲ½Ö裺
1) ×î´óÏ޶ȵØÏ÷¼õǶÈëʽºÍ¹Ø¼üÉ豸µÄÍøÂç¶³ö£¬£¬£¬£¬£¬£¬²¢È·±£ÎÞ·¨´ÓInternet½Ó¼û£»£»£»£»£»
2) ¶¨Î»·À»ðǽ·À»¤µÄOTÍøÂçºÍÉ豸£¬£¬£¬£¬£¬£¬²¢½«ÆäÓëÒµÎñÍøÂç¸ôÀ룻£»£»£»£»
3) ½öÆôÓð²È«µÄÔ¶³Ì½Ó¼û²½Ö裬£¬£¬£¬£¬£¬½¨ÒéʹÓÃÐ鹹רÓÃÍøÂ磨VPN£©¡£¡£¡£¡£¡£¡£¡£
3. ×èÖ¹Òì³£IPÁ÷Á¿£»£»£»£»£»
4. ͨ¹ýÉî¶ÈÊý¾Ý°ü²é³À´×èÖ¹ÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬ÒÔ½µµÍTreckǶÈëʽÆôÓÃTCP/ IPµÄÉ豸µÄ·çÏÕ¡£¡£¡£¡£¡£¡£¡£
ÇÀռʽÁ÷Á¿¹ýÂËÊÇÒ»ÖÖÓÐЧµÄ¼¼Êõ£¬£¬£¬£¬£¬£¬Äܹ»Êʱ¾µØÀûÓÃÓÚÄúµÄÍøÂç»·¾³¡£¡£¡£¡£¡£¡£¡£¹ýÂËÑ¡ÏîÔ̺¬£º
? ÈôÊÇÄúµÄ»·¾³²»Ö§³Ö£¬£¬£¬£¬£¬£¬Ôò¹æ·¶»¯»ò×èÖ¹IP¶Î£»£»£»£»£»
? ÈôÊDz»±ØÒª£¬£¬£¬£¬£¬£¬Çë½ûÓûò×èÖ¹IPËí·£¨IPv6-in-IPv4»òIP-in-IPËí·£©£»£»£»£»£»
? ×èÖ¹IPԴ·ÓÉÒÔ¼°ËùÓв»ÔÞ³ÉʹÓÃIPv6µÄÖ°ÄÜ£¬£¬£¬£¬£¬£¬ÀýÈç·ÓɱêÍ·VU££267289£»£»£»£»£»
? Ç¿ÔìÖ´ÐÐTCP²é³£¬£¬£¬£¬£¬£¬»Ø¾øÌåʽÃýÎóµÄTCPÊý¾Ý°ü£»£»£»£»£»
? ×èֹδʹÓõÄICMP½ÚÔìÐÂÎÅ£¬£¬£¬£¬£¬£¬ÀýÈçMTU¸üк͵ØÖ·ÑÚÂë¸üУ»£»£»£»£»
? ͨ¹ý°²È«µÄµÝ¹é·þÎñÆ÷»òDNS²é³·À»ðǽ¹æ·¶DNS£»£»£»£»£»
? ÌṩDHCP/DHCPv6°²È«ÐÔ£¬£¬£¬£¬£¬£¬²¢ÓµÓÐDHCP¼àÌýµÈÖ°ÄÜ£»£»£»£»£»
? ÈôÊÇδÔÚ»¥»»»ù´¡¼Ü¹¹ÖÐʹÓ㬣¬£¬£¬£¬£¬Çë½ûÓÃ/×èÖ¹IPv6¶à²¥Ö°ÄÜ£»£»£»£»£»
? ÔÚÄܹ»Ê¹Óþ²Ì¬IPµÄ´¦Ëù½ûÓÃDHCP£»£»£»£»£»
? ʹÓÃÍøÂçIDSºÍIPSÊðÃû£»£»£»£»£»
? ÈôÊÇ¿ÉÓ㬣¬£¬£¬£¬£¬Çë»®·ÖÍøÂç¡£¡£¡£¡£¡£¡£¡£
0x03 ÓйØÐÂÎÅ
https://www.zdnet.com/article/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come/#ftag=RSSbaffb68
0x04 ²Î¿¼Á´½Ó
https://www.jsof-tech.com/ripple20/
0x05 ¹¦·òÏß
2020-06-16 JSOFÅû¶·ì϶
2020-06-17 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ