{"id":111506,"date":"2023-11-14T21:10:14","date_gmt":"2023-11-14T19:10:14","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/vossozdanie-rsa-klyuchej-cherez-analiz-ssh-soedinenij-k-sbojnym-serveram"},"modified":"2023-11-14T21:10:14","modified_gmt":"2023-11-14T19:10:14","slug":"vossozdanie-rsa-klyuchej-cherez-analiz-ssh-soedinenij-k-sbojnym-serveram","status":"publish","type":"post","link":"https:\/\/prohoster.info\/pl\/blog\/news\/vossozdanie-rsa-klyuchej-cherez-analiz-ssh-soedinenij-k-sbojnym-serveram","title":{"rendered":"Rekonstrukcja kluczy RSA poprzez analiz\u0119 po\u0142\u0105cze\u0144 SSH z uszkodzonymi serwerami","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Grupa badawcza z Uniwersytetu Kalifornijskiego w San Diego wykaza\u0142a mo\u017cliwo\u015b\u0107 odtworzenia zamkni\u0119tych kluczy RSA serwera SSH, korzystaj\u0105c z pasywnej analizy ruchu SSH. Atak mo\u017ce by\u0107 przeprowadzony na serwerach, na kt\u00f3rych na skutek okoliczno\u015bci lub dzia\u0142a\u0144 atakuj\u0105cego wyst\u0119puj\u0105 awarie podczas obliczania podpisu cyfrowego przy nawi\u0105zywaniu po\u0142\u0105czenia SSH. Awarie mog\u0105 by\u0107 zar\u00f3wno programowe (nieprawid\u0142owe wykonywanie operacji matematycznych, uszkodzenie pami\u0119ci), jak i sprz\u0119towe (b\u0142\u0119dy w pracy NVRAM i DRAM lub awarie przy przerwach w zasilaniu).    <\/p>\n<p>Jednym z mo\u017cliwych sposob\u00f3w na wywo\u0142anie awarii mog\u0105 by\u0107 ataki klasy RowHammer, kt\u00f3re m.in. pozwalaj\u0105 na zdalne lub w trakcie przetwarzania kodu JavaScript w przegl\u0105darce na wywo\u0142anie zniekszta\u0142cenia zawarto\u015bci poszczeg\u00f3lnych bit\u00f3w pami\u0119ci podczas intensywnego cyklicznego odczytu danych z s\u0105siaduj\u0105cych kom\u00f3rek pami\u0119ci. Innym sposobem na wywo\u0142anie awarii mo\u017ce by\u0107 wykorzystanie luk w zabezpieczeniach, kt\u00f3re prowadz\u0105 do przepe\u0142nienia bufora i uszkodzenia danych z kluczami w pami\u0119ci.    <\/p>\n<p>W opublikowanym badaniu pokazano, \u017ce podczas korzystania w SSH z cyfrowych podpis\u00f3w opartych na algorytmie RSA, ataki maj\u0105ce na celu odtworzenie zamkni\u0119tych kluczy RSA metod\u0105 Lattice (Fault Attack) s\u0105 mo\u017cliwe w przypadku wyst\u0105pienia programowych lub sprz\u0119towych awarii podczas procesu obliczania podpisu. Istota metody polega na tym, \u017ce por\u00f3wnuj\u0105c poprawne i uszkodzone cyfrowe podpisy RSA, mo\u017cna ustali\u0107 najwi\u0119kszy wsp\u00f3lny dzielnik w celu wyodr\u0119bnienia jednej z liczb pierwszych u\u017cytych do tworzenia klucza.     <\/p>\n<p>Podstaw\u0105 szyfrowania RSA jest operacja pot\u0119gowania modulo du\u017cej liczby. W kluczu publicznym znajduje si\u0119 modu\u0142 i wyk\u0142adnik. Modu\u0142 jest tworzony na podstawie dw\u00f3ch losowych liczb pierwszych, kt\u00f3re s\u0105 znane tylko w\u0142a\u015bcicielowi klucza prywatnego. Atak mo\u017ce by\u0107 stosowany w implementacjach RSA, kt\u00f3re wykorzystuj\u0105 Chi\u0144skie twierdzenie o resztach oraz deterministyczne schematy wype\u0142nienia, takie jak PKCS#1 v1.5.           <\/p>\n<p>A passive observation of legitimate connections to the SSH server is enough to identify a faulty digital signature in the traffic, which can be used as a source of information to recreate the private RSA key. After recreating the host's RSA key, an attacker can stealthily redirect requests to a fake host pretending to be the compromised SSH server and organize the interception of data transmitted to it. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/pl\/server\/\"   title=\"serwer\" data-wpil-keyword-link=\"linked\">serwer<\/a> danych.        <\/p>\n<p>As a result of studying a collection of intercepted network data, which includes approximately 5.2 billion records related to the use of the SSH protocol, researchers identified about 3.2 billion open host keys and digital signatures used during SSH session negotiation. Of these, 1.2 billion (39.1%) were generated using the RSA algorithm. In 593,671 cases (0.048%), the RSA signature was corrupted and failed verification. For 4,962 faulty signatures, the Lattice factorization method was applied to determine the private key from the known public key, which ultimately allowed for the recreation of 189 unique RSA key pairs (in many cases, the same keys and faulty devices were used to generate different corrupted signatures). Recreating the keys took about 26 hours of processor time.      <center><img decoding=\"async\" alt=\"Rekonstrukcja kluczy RSA poprzez analiz\u0119 po\u0142\u0105cze\u0144 SSH z uszkodzonymi serwerami\" src=\"\/wp-content\/uploads\/2023\/11\/0a77241c5e2b5fd6ec42ce93d1b77c52.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>      <\/p>\n<p>The problem only affects specific implementations of the SSH protocol, primarily used in embedded devices. Products from Zyxel, Cisco, Mocana, and Hillstone Networks are mentioned as examples of devices with problematic SSH implementations. OpenSSH is not vulnerable to the issue, as it uses the OpenSSL (or LibreSSL) library for key generation, which has included protection against fault analysis attacks since 2001. Moreover, in OpenSSH, the ssh-rsa digital signature scheme (based on sha1) was deprecated in 2020 and disabled in version 8.8 (support for rsa-sha2-256 and rsa-sha2-512 schemes remains). The attack may potentially apply to the IPsec protocol as well, but researchers lacked sufficient experimental data to confirm such an attack in practice.<br \/>\n<br \/>\u0179r\u00f3d\u0142o: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=60106\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u041a\u0430\u043b\u0438\u0444\u043e\u0440\u043d\u0438\u0439\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0432 \u0421\u0430\u043d-\u0414\u0438\u0435\u0433\u043e \u043f\u0440\u043e\u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0438\u0440\u043e\u0432\u0430\u043b\u0430 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0432\u043e\u0441\u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0437\u0430\u043a\u0440\u044b\u0442\u044b\u0445 \u0445\u043e\u0441\u0442\u043e\u0432\u044b\u0445 RSA-\u043a\u043b\u044e\u0447\u0435\u0439 SSH-\u0441\u0435\u0440\u0432\u0435\u0440\u0430, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043f\u0430\u0441\u0441\u0438\u0432\u043d\u044b\u0439 \u0430\u043d\u0430\u043b\u0438\u0437 \u0442\u0440\u0430\u0444\u0438\u043a\u0430 SSH. \u0410\u0442\u0430\u043a\u0430 \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u0430 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u044b, \u043d\u0430 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0432 \u0441\u0438\u043b\u0443 \u0441\u0442\u0435\u0447\u0435\u043d\u0438\u044f \u043e\u0431\u0441\u0442\u043e\u044f\u0442\u0435\u043b\u044c\u0441\u0442\u0432 \u0438\u043b\u0438 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0439 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0435\u0433\u043e \u0432\u043e\u0437\u043d\u0438\u043a\u0430\u044e\u0442 \u0441\u0431\u043e\u0438 \u0432\u043e \u0432\u0440\u0435\u043c\u044f \u0432\u044b\u0447\u0438\u0441\u043b\u0435\u043d\u0438\u044f \u0446\u0438\u0444\u0440\u043e\u0432\u043e\u0439 \u043f\u043e\u0434\u043f\u0438\u0441\u0438 \u043f\u0440\u0438 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0435 SSH-\u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f. \u0421\u0431\u043e\u0438 \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u043a\u0430\u043a \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u043d\u044b\u043c\u0438 (\u043d\u0435\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u043c\u0430\u0442\u0435\u043c\u0430\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0445 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u0439, \u043f\u043e\u0432\u0440\u0435\u0436\u0434\u0435\u043d\u0438\u0435 \u043f\u0430\u043c\u044f\u0442\u0438), [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":111507,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-111506","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u041a\u0430\u043b\u0438\u0444\u043e\u0440\u043d\u0438\u0439\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0432 \u0421\u0430\u043d-\u0414\u0438\u0435\u0433\u043e \u043f\u0440\u043e\u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0438\u0440\u043e\u0432\u0430\u043b\u0430 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0432\u043e\u0441\u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0437\u0430\u043a\u0440\u044b\u0442\u044b\u0445 \u0445\u043e\u0441\u0442\u043e\u0432\u044b\u0445 RSA-\u043a\u043b\u044e\u0447\u0435\u0439 SSH-\u0441\u0435\u0440\u0432\u0435\u0440\u0430, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043f\u0430\u0441\u0441\u0438\u0432\u043d\u044b\u0439 \u0430\u043d\u0430\u043b\u0438\u0437 \u0442\u0440\u0430\u0444\u0438\u043a\u0430 SSH.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/pl\/blog\/news\/vossozdanie-rsa-klyuchej-cherez-analiz-ssh-soedinenij-k-sbojnym-serveram\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"pl_PL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412\u043e\u0441\u0441\u043e\u0437\u0434\u0430\u043d\u0438\u0435 RSA-\u043a\u043b\u044e\u0447\u0435\u0439 \u0447\u0435\u0440\u0435\u0437 \u0430\u043d\u0430\u043b\u0438\u0437 SSH-\u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0439 \u043a \u0441\u0431\u043e\u0439\u043d\u044b\u043c \u0441\u0435\u0440\u0432\u0435\u0440\u0430\u043c | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u041a\u0430\u043b\u0438\u0444\u043e\u0440\u043d\u0438\u0439\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0432 \u0421\u0430\u043d-\u0414\u0438\u0435\u0433\u043e \u043f\u0440\u043e\u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0438\u0440\u043e\u0432\u0430\u043b\u0430 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0432\u043e\u0441\u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0437\u0430\u043a\u0440\u044b\u0442\u044b\u0445 \u0445\u043e\u0441\u0442\u043e\u0432\u044b\u0445 RSA-\u043a\u043b\u044e\u0447\u0435\u0439 SSH-\u0441\u0435\u0440\u0432\u0435\u0440\u0430, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043f\u0430\u0441\u0441\u0438\u0432\u043d\u044b\u0439 \u0430\u043d\u0430\u043b\u0438\u0437 \u0442\u0440\u0430\u0444\u0438\u043a\u0430 SSH.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/pl\/blog\/news\/vossozdanie-rsa-klyuchej-cherez-analiz-ssh-soedinenij-k-sbojnym-serveram\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-11-14T19:10:14+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-11-14T19:10:14+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Odtworzenie kluczy RSA poprzez analiz\u0119 po\u0142\u0105cze\u0144 SSH z awaryjnymi serwerami | ProHoster","description":"A group of researchers from the University of California, San Diego demonstrated the possibility of recreating private host RSA keys of the SSH server using passive analysis of SSH traffic.","canonical_url":"https:\/\/prohoster.info\/pl\/blog\/news\/vossozdanie-rsa-klyuchej-cherez-analiz-ssh-soedinenij-k-sbojnym-serveram","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"pl_PL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412\u043e\u0441\u0441\u043e\u0437\u0434\u0430\u043d\u0438\u0435 RSA-\u043a\u043b\u044e\u0447\u0435\u0439 \u0447\u0435\u0440\u0435\u0437 \u0430\u043d\u0430\u043b\u0438\u0437 SSH-\u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0439 \u043a \u0441\u0431\u043e\u0439\u043d\u044b\u043c \u0441\u0435\u0440\u0432\u0435\u0440\u0430\u043c | ProHoster","og:description":"\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u041a\u0430\u043b\u0438\u0444\u043e\u0440\u043d\u0438\u0439\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0432 \u0421\u0430\u043d-\u0414\u0438\u0435\u0433\u043e \u043f\u0440\u043e\u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0438\u0440\u043e\u0432\u0430\u043b\u0430 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0432\u043e\u0441\u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0437\u0430\u043a\u0440\u044b\u0442\u044b\u0445 \u0445\u043e\u0441\u0442\u043e\u0432\u044b\u0445 RSA-\u043a\u043b\u044e\u0447\u0435\u0439 SSH-\u0441\u0435\u0440\u0432\u0435\u0440\u0430, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043f\u0430\u0441\u0441\u0438\u0432\u043d\u044b\u0439 \u0430\u043d\u0430\u043b\u0438\u0437 \u0442\u0440\u0430\u0444\u0438\u043a\u0430 SSH.","og:url":"https:\/\/prohoster.info\/pl\/blog\/news\/vossozdanie-rsa-klyuchej-cherez-analiz-ssh-soedinenij-k-sbojnym-serveram","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-11-14T19:10:14+00:00","article:modified_time":"2023-11-14T19:10:14+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts\/111506","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/comments?post=111506"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts\/111506\/revisions"}],"predecessor-version":[{"id":173001,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts\/111506\/revisions\/173001"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/media\/111507"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/media?parent=111506"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/categories?post=111506"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/tags?post=111506"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}