Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
Detect-CVE-2017-15361-TPM — 신뢰할 수 있는 플랫폼 모듈(TPM)이 활성화된 Windows 및 Linux 시스템 중 CVE-2017-15361에 취약한 시스템을 탐지합니다. #nsacyber | Kitploit
도구/GitHubGitHub/nsacyber/detect-cve-2017-15361-tpm
Vulnerability ScannersVulnerability AnalysisConfiguration AuditingForensicsCryptographyHardware SecurityArchived
GitHubnsacyber/detect-cve-2017-15361-tpm

Detect-CVE-2017-15361-TPM

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

신뢰할 수 있는 플랫폼 모듈(TPM)이 활성화된 Windows 및 Linux 시스템 중 CVE-2017-15361에 취약한 시스템을 탐지합니다. #nsacyber

저장소 보기
63307년 전Kitploit 검토 완료

CVE-2017-15361에 취약한 신뢰할 수 있는 플랫폼 모듈 탐지

이 저장소는 DoD 관리자가 CVE-2017-15361에 취약한 활성화된 TPM(신뢰할 수 있는 플랫폼 모듈)이 있는 시스템을 탐지하는 데 도움이 되는 콘텐츠를 제공하며, 정보보증 권고 RSA 키 생성 취약점이 신뢰할 수 있는 플랫폼 모듈에 영향을 미침의 동반 자료입니다. 이 저장소의 파일은 여기에서 zip 파일로 다운로드할 수 있습니다.

저장소의 주요 관심 파일은 다음과 같습니다:

  • windows/Detect-CVE-2017-15361-TPM.audit - DoD 관리자가 네트워크의 Windows 시스템을 Nessus로 스캔하려는 경우 유용한 사용자 정의 Nessus 감사 파일입니다(ACAS 프로그램을 통해 획득). TPM 1.2 및 TPM 2.0 장치가 지원됩니다.
  • windows/Detect-CVE-2017-15361-TPM.ps1 - DoD 관리자가 단일 독립형 시스템을 로컬에서 테스트하려는 경우 유용한 PowerShell 스크립트입니다. TPM 1.2 및 TPM 2.0 장치가 지원됩니다.
  • linux/Detect-CVE-2017-15361-TPM.audit - DoD 관리자가 네트워크의 Linux 시스템을 Nessus로 스캔하려는 경우 유용한 사용자 정의 Nessus 감사 파일입니다(ACAS 프로그램을 통해 획득). TPM 1.2 장치만 지원됩니다.
  • linux/Detect-CVE-2017-15361-TPM.sh - DoD 사용자가 단일 독립형 Linux 시스템을 로컬에서 테스트하려는 경우 유용한 bash 스크립트입니다. TPM 1.2 장치만 지원됩니다.

저장소의 지원 파일은 다음과 같습니다:

  • GenerateWindowsNessusAuditFile.ps1 - Detect-CVE-2017-15361-TPM.ps1 파일의 코드를 기반으로 Windows용 Detect-CVE-2017-15361-TPM.audit 파일을 생성하는 PowerShell 스크립트입니다.

영향을 받는 Infineon TPM 펌웨어 버전:

  • 4.0 - 4.33
  • 4.4 - 4.42
  • 5.0 - 5.61
  • 6.0 - 6.42
  • 7.0 - 7.61
  • 133.0 - 133.32
  • 149.0 - 149.32

링크

문제를 식별한 최초 연구:

  • https://crocs.fi.muni.cz/public/papers/rsa_ccs17

취약점에 대한 추가 정보:

  • https://www.kb.cert.org/vuls/id/307015
  • https://www.infineon.com/cms/en/product/promopages/rsa-update/
  • https://www.infineon.com/cms/en/product/promopages/rsa-update/rsa-background
  • https://www.infineon.com/cms/en/product/promopages/tpm-update/

운영 체제 패치 및 TPM 펌웨어 업데이트에 대한 추가 정보:

  • https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV170012
  • https://us.answers.acer.com/app/answers/detail/a_id/51137
  • http://www.fujitsu.com/global/support/products/software/security/products-f/ifsa-201701e.html
  • https://support.hp.com/us-en/document/c05792935
  • https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03789en_us
  • https://support.lenovo.com/us/en/product_security/LEN-15552
  • https://support.toshiba.com/sscontent?contentId=4015874
  • https://sites.google.com/a/chromium.org/dev/chromium-os/tpm_firmware_update

영향을 받는 기타 장치에 대한 추가 정보:

  • https://www.yubico.com/support/security-advisories/ysa-2017-01/
  • https://safenet.gemalto.com/technical-support/security-updates 및 https://gemalto.service-now.com/csm?id=kb_article&sys_id=19a55bdf4fb907c0873b69d18110c768

RSA 키가 영향을 받는지 확인하는 도구:

  • https://github.com/crocs-muni/roca
  • https://keychest.net/roca
  • https://keytester.cryptosense.com/
  • https://www.tenable.com/plugins/index.php?view=single&id=103864

라이선스

LICENSE를 참조하세요.

면책 조항

DISCLAIMER를 참조하세요.

도구 다운로드