TsuNAM©¶´£º¿ÉDDoS DNS·þÎñÆ÷

Ðû²¼Ê±¼ä 2021-05-08

0x00 ©¶´¸ÅÊö

CVE  ID


ʱ   ¼ä

2021-05-08

Àà   ÐÍ

DDoS

µÈ   ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°Ï췶Χ


PoC/EXP

δ¹ûÈ»

ÔÚÒ°ÀûÓÃ

·ñ

 

0x01 ©¶´ÏêÇé

image.png

 

2021Äê05ÔÂ06ÈÕ£¬SIDN Labs£¨.nl×¢²á£©¡¢InternetNZ£¨.nz×¢²á£© ºÍÄϼÓÖÝ´óѧÐÅÏ¢¿ÆÑ§Ñо¿ËùµÄÑо¿ÈËÔ±¹ûÈ»Åû¶ÁËÔÚDNS½âÎöÆ÷Öз¢ÏÖµÄÒ»¸ö¿Éµ¼ÖÂÂþÑÜʽ¾Ü¾ø·þÎñ£¨DDoS£©¹¥»÷µÄ©¶´£¬¸Ã©¶´±»³ÆÎªTsuNAME ¡£

ÏÖ½ñ»¥ÁªÍøÉÏ´ó¶àÊýʹÓõÄDNS·þÎñÆ÷¶¼Êǵݹé·þÎñÆ÷£¬ËüÃǽÓÊÜÓû§µÄDNS²éѯ²¢½«Æäת·¢µ½È¨ÍþDNS·þÎñÆ÷£¬ÕâÖÖÊÂÇ鷽ʽ¾ÍÏñµç»°²¾Ò»Ñù£¬¿ÉÒÔ·µ»ØÌض¨ÓòÃûµÄDNSÏìÓ¦ ¡£

ÔÚÕý³£Çé¿öÏ£¬ÊýÒÔ°ÙÍò¼ÆµÄµÝ¹éDNS·þÎñÆ÷ÿÌì»áÏòȨÍþÐÔDNS·þÎñÆ÷·¢ËÍÊýÊ®ÒÚ´ÎDNS²éѯ ¡£ÕâЩȨÍþÐÔDNS·þÎñÆ÷ͨ³£ÓÉ´óÐ͹«Ë¾ºÍ×éÖ¯Íйܺ͹ÜÀí£¨ÄÚÈݽ»¸¶ÍøÂç¡¢´óÐͿƼ¼¾ÞÍ·¡¢»¥ÁªÍø·þÎñÌṩÉÌ¡¢ÓòÃû×¢²áÉÌ»òÕþ¸®×éÖ¯£©£¬ºÃ±ÈGoogleºÍCisco ¡£

Ñо¿ÈËÔ±ÌåÏÖ£¬¹¥»÷Õß¿ÉÒÔÖÆ×÷¶ñÒâµÄDNS²éѯ£¬ÀûÓõݹéDNSÈí¼þµÄ©¶´£¬ÏòÆäȨÍþDNS·þÎñÆ÷²»Í£µØ·¢ËͶñÒâDNS²éѯ£¬µ«ÕâÖÖ¹¥»÷ÒÀÀµÓÚÊÜÓ°ÏìµÄµÝ¹éDNSÈí¼þºÍȨÍþDNS·þÎñÆ÷ÉϵĴíÎóÅäÖà ¡£Èç¹û¹¥»÷ÖÐ×¢²áÁË×ã¹»¶àµÄµÝ¹éDNS·þÎñÆ÷£¬Ôò¹¥»÷Õß¿ÉÒÔÌᳫÅÓ´óµÄDDoS¹¥»÷£¬´Ó¶ø´Ý»ÙÒªº¦µÄInternet½Úµã ¡£

Ñо¿ÈËÔ±»¹·¢ÏÖ£¬Ä³Ð©DNS½âÎöÆ÷ÔÚÓöµ½±»´íÎóÅäÖÃΪѭ»·ÒÀÀµNS¼Ç¼µÄÓòÃûʱ¿ªÊ¼Ñ­»·£¬¶øÕâÖÖÑ­»·¿ÉÒÔÓÃÀ´¹¥»÷ȨÍþ·þÎñÆ÷ ¡£

image.png

 

Ñо¿ÈËÔ±ÔÚ³ÂËßÖÐÃèÊöÁË2020ÄêÔÚ.nz authroritative·þÎñÆ÷ÉÏÊӲ쵽µÄÒ»¸öÓëtsuNAMEÏà¹ØµÄʼþ£¬ÆäʱÓÐÁ½¸öÓòÃû±»´íÎóµØÅäÖÃΪѭ»·ÒÀÀµ¹ØÏµ£¬Ëüµ¼ÖÂ×ÜÁ÷Á¿Ôö³¤ÁË50% ¡£ÔÚ³ÂËßÖУ¬Ñо¿ÈËԱչʾÁËÒ»¸ö»ùÓÚÅ·Ã˵Ĺú¼Ò´úÂë¶¥¼¶ÓòÃûÈçºÎÒòÑ­»·ÒÀÀµµÄ´íÎóÅäÖöøµ¼ÖÂÁ÷Á¿Ôö³¤ÁË10±¶ ¡£

Ñо¿ÈËÔ±»¹Ðû²¼ÁËÒ»ÖÖ³ÆÎªCycleHunterµÄ¹¤¾ß £¬È¨ÍþDNS·þÎñÆ÷µÄÔËÓªÉÌ¿ÉÒÔʹÓøù¤¾ßÔÚÆäDNSÇøÓòÎļþÖвéÕÒ²¢Ïû³ýÑ­»·ÒÀÀµÐÔ ¡£Ïû³ýÕâЩѭ»·ÒÀÀµÐÔ¿ÉÔÚδӦÓò¹¶¡µÄÇé¿öÏ·ÀÖ¹¹¥»÷ÕßÀûÓÃtsuNAME½øÐÐDDoS¹¥»÷ ¡£

´ËÍ⣬Ñо¿ÈËԱʹÓÃCycleHunterÔÚÆß¸ö¶¥¼¶Óò£¨TLD£©ÖÐÆÀ¹ÀÁËÔ¼1.84ÒÚ¸öÓòÃû£¬²¢·¢ÏÖÁËÔ¼1400¸öÓòÃûʹÓõÄ44¸öÑ­»·ÒÀÀµµÄNS¼Ç¼£¨¿ÉÄÜÊÇÅäÖôíÎ󣩣¬ÕâЩ¼Ç¼¿ÉÄܻᱻÀÄÓÃÓÚÖ®ºóµÄ¹¥»÷ ¡£

 

Ó°Ï췶Χ

Google Public DNS£¨GDNS£©

Cisco OpenDNS

ÆäËüDNS½âÎöÆ÷

£¨×¢£ºUnbound¡¢BINDºÍKnotDNS²»ÊÜtsuNAMEÓ°Ï죩

 

0x02 ´¦Öý¨Òé

ĿǰGoogleºÍCiscoÒѾ­ÐÞ¸´ÁË´Ë©¶´£¬½¨ÒéÏà¹ØDNSÔËÓªÉ̾¡¿ìʹÓÃCycleHunter¹¤¾ß¼ì²â²¢Ïû³ýDNSÇøÓòÖеÄÑ­»·ÒÀÀµ¹ØÏµ»ò¼°Ê±ÐÞ¸´¸Ã©¶´ ¡£

ÏÂÔØÁ´½Ó£º

https://github.com/SIDN/CycleHunter

 

0x03 ²Î¿¼Á´½Ó

https://therecord.media/new-tsuname-bug-can-be-used-to-ddos-key-dns-servers/?

https://tsuname.io/

https://tsuname.io/tech_report.pdf

https://tsuname.io/advisory.pdf

 

0x04 ʱ¼äÏß

2021-05-06  Ñо¿ÈËÔ±¹ûÈ»Åû¶©¶´

2021-05-08  VSRCÐû²¼Äþ¾²Í¨¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png