CVE-2020-0096 | Android ÌØÈ¨ÌáÉýÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-05-270x00 Îó²î¸ÅÊö
|
CVE ID |
CVE-2020-0096 |
ʱ ¼ä |
2020-05-27 |
|
Àà ÐÍ |
EOA |
µÈ ¼¶ |
ÑÏÖØ |
|
Ô¶³ÌʹÓà |
ÊÇ |
Ó°Ïì¹æÄ£ |
Android <= 9.0 |
0x01 Îó²îÏêÇé
AndroidÊÇÃÀ¹ú¹È¸è£¨Google£©ºÍ¿ªËÉÊÖ³Ö×°±¸Í¬ÃË£¨¼ò³ÆOHA£©µÄÒ»Ì×ÒÔLinuxΪ»ù´¡µÄ¿ªÔ´²Ù×÷ϵͳ¡£FrameworkÊÇÆäÖеÄÒ»¸öAndroid¿ò¼Ü×é¼þ¡£
PromonÑо¿Ö°Ô±·¢Ã÷ÁËAndroidÖеÄÒ»¸öеÄÌØÈ¨ÌáÉýÎó²î£¨CVE-2020-0096£©£¬¸ÃÎó²îʹ¶ñÒâÓ¦ÓÃαװ³É´ó´ó¶¼Õýµ±Ó¦Ó㬲¢´ÓAndroidÓû§ÄÇÀïÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£ÓÉÓÚ¸ÃÎó²îÓë¸Ã¹«Ë¾ÓÚ2019Äê·¢Ã÷µÄÎÛÃûÕÑÖøµÄStrandHoggÎó²îÏàËÆ£¬Òò´Ë±»PromonÃüÃûΪStrandHogg 2.0¡£
Strandhogg 2.0ÊÇͨ¹ý·´ÉäÖ´Ðе쬴ӶøÔÊÐí¶ñÒâÓ¦ÓÃ×ÔÓɵؼٶ¨Õýµ±Ó¦ÓõÄÉí·Ý£¬Í¬Ê±Ò²¼á³ÖÍêÈ«Òþ²Ø¡£Ò»µ©×°±¸ÉÏ×°ÖÃÁ˶ñÒâÓ¦Ó㬹¥»÷Õ߾ͿÉÒÔ»á¼û˽ÈËSMSÐÂÎźÍÕÕÆ¬£¬ÇÔÈ¡Êܺ¦ÕߵĵǼƾ֤£¬¸ú×ÙGPSÒÆ¶¯£¬¼Í¼µç»°¶Ô»°ÒÔ¼°Í¨¹ýµç»°µÄÉãÏñÍ·ºÍÂó¿Ë·ç¾ÙÐÐÌØ¹¤Ô˶¯¡£
×°±¸ÉÏ×°ÖõĶñÒâÓ¦ÓóÌÐò¿ÉÒÔ¹¥»÷²¢ÓÕÆÓû§£¬ÔÚµ¥»÷Õýµ±Ó¦ÓóÌÐòµÄͼ±êʱ£¬ÔÚÓû§ÆÁÄ»ÉÏÏÔʾ¶ñÒâ°æ±¾£¬ÈôÊÇÊܺ¦ÕßËæºóÔڴ˽çÃæÖÐÊäÈëÆäµÇ¼ƾ֤£¬ÔòÕâЩÃô¸ÐÏêϸÐÅÏ¢½«Á¬Ã¦·¢Ë͸ø¹¥»÷Õß¡£
ͨ¹ýʹÓÃStrandHogg 2.0£¬¹¥»÷Õß²»ÐèÒªroot»á¼ûȨÏÞ»ò×°±¸µÄÈκÎȨÏÞ¼´¿ÉÖ´ÐÐÖÖÖÖ¶ñÒâʹÃü£¬ÏêϸÈçÏ£º
? ͨ¹ýÂó¿Ë·çÊÕÌýÓû§
? ͨ¹ýÏà»úÕÕÏà
? ÔĶÁºÍ·¢ËÍSMSÐÂÎÅ
? ¼Í¼µç»°¶Ô»°
? ÍøÂç´¹ÂڵǼƾ֤
? »á¼û×°±¸ÉÏËùÓÐ˽ÈËÕÕÆ¬ºÍÎļþ
? »ñȡλÖúÍGPSÐÅÏ¢
? »á¼ûÁªÏµÈËÁбí
? »á¼ûµç»°ÈÕÖ¾
GoogleÒÑÓÚ2019Äê12ÔÂÊÕµ½¸ÃÎó²îµÄ֪ͨ£¬²¢ÓÚ2020Äê4ÔÂÏòAndroidÉú̬ϵͳÏàÖúͬ°éÍÆ³öÁ˲¹¶¡³ÌÐòºó£¬ÒѾÕë¶ÔAndroid 8.0¡¢8.1ºÍ9°æ±¾Ðû²¼ÁËÇå¾²ÐÞ¸´³ÌÐò¡£
PromonÊ×ϯÊÖÒÕ¹Ù¼æÊ×´´ÈËÌÀÄ·¡¤À³ÈûÃ×Èû¡¤ººÉ£¨Tom Lysemose Hansen£©ÌåÏÖ£º¡°AndroidÓû§Ó¦¾¡¿ì½«Æä×°±¸¸üе½×îй̼þ£¬ÒÔ±£»¤×Ô¼ºÃâÊÜʹÓÃStrandHogg 2.0µÄ¹¥»÷¡£¡±
ÐÒÔ˵ÄÊÇ£¬µ½ÏÖÔÚΪֹ£¬»¹Ã»Óз¢Ã÷¶ñÒâÈí¼þÆð¾¢Ê¹ÓÃÒ°ÍâÇå¾²Îó²î¡£
PromonÕ¹Íû£¬¹¥»÷Õß½«Í¬Ê±Ê¹ÓÃStrandHoggºÍStrandHogg 2.0£¬ÓÉÓÚÕâÁ½¸öÎó²î¶¼ÒÔÆæÒìµÄ·½·¨ÒÔ²î±ðµÄ·½·¨¹¥»÷×°±¸¡£ÓÉÓÚ¾ø´ó´ó¶¼Óû§ÈÔÔÚÆä×°±¸ÉÏÔËÐÐAndroid 9.0»ò¸üÔç°æ±¾£¬Áè¼Ý90£¥µÄAndroidÓû§ÈÝÒ×Êܵ½¹¥»÷¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬²¹¶¡»ñÈ¡Á´½Ó£º
https://source.android.com/security/bulletin/2020-05-01
0x03 Ïà¹ØÐÂÎÅ
https://www.bleepingcomputer.com/news/security/critical-android-bug-lets-malicious-apps-hide-in-plain-sight/
0x04 ²Î¿¼Á´½Ó
https://promon.co/strandhogg-2-0/
https://source.android.com/security/bulletin/2020-05-01
0x05 ʱ¼äÏß
2020-05-26 PromonÑо¿Ö°Ô±Ðû²¼Í¨¸æ
2020-05-27 VSRCÐû²¼Îó²îͨ¸æ


¾©¹«Íø°²±¸11010802024551ºÅ