[์ •๋ณด] ์• ํ”Œ ๋ํŒ์™• ์ทจ์•ฝ์  Airborne ๊ณต๊ฐœ(0-Click, RCE, CVE-2025-24132)

2025. 5. 6. 22:29ยท๐Ÿค–์ •๋ณด๋ณด์•ˆ/๐Ÿ’™๋ธ”๋ฃจํŒ€

 

[๐Ÿšจ์œ„ํ—˜๋‚ด์šฉ]

- Apple AirPlay์˜ "๊ณต์ค‘ ์ „ํŒŒ" ์ œ๋กœํด๋ฆญ RCE ๊ณต๊ฒฉ์œผ๋กœ 23์–ต 5์ฒœ๋งŒ ๋Œ€ ์ด์ƒ์˜ ๊ธฐ๊ธฐ๊ฐ€ Wi-Fi ๊ธฐ๋ฐ˜ ์›๊ฒฉ ํ•˜์ด์žฌํ‚น์— ๋…ธ์ถœ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. Mac, iPhone, CarPlay, ์Šคํ”ผ์ปค, TV ๋“ฑ ๊ณต์œ  ๋„คํŠธ์›Œํฌ์—์„œ ๋ชจ๋‘ ์ทจ์•ฝํ•ฉ๋‹ˆ๋‹ค.

- ์›œ ๊ณต๊ฒฉ ๊ฐ€๋Šฅ. ์•…์šฉ ๊ฐ€๋Šฅ. 

- CVE-2025-24252

- ๊ฐ™์€ ๋„คํŠธ์›Œํฌ์— ์žˆ๊ณ  ์—์–ดํ”Œ๋ ˆ์ด ์—…๋ฐ์ดํŠธ๊ฐ€ ๋˜์–ด์žˆ์ง€ ์•Š๋‹ค๋ฉด ๋‹น์‹  ๋””๋ฐ”์ด์Šค๋Š” ์ทจ์•ฝ์ ์— ๋…ธ์ถœ ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.

 

[๐Ÿ”“๋Œ€์‘๋ฐฉ์•ˆ]
- ํŒจ์น˜(iOS/macOS 18.4 ์ด์ƒ).

- AirPlay ๋„๊ธฐ

 

[๋งฅ๋ถํ•ดํ‚น]

https://www.youtube.com/watch?v=ZmOvRLBL3Ys

 

 

[์Šคํ”ผ์ปคํ•ดํ‚น]

https://www.youtube.com/watch?v=vcs5G4JWab8

 

 

[์ž๋™์ฐจํ•ดํ‚น]

https://www.youtube.com/watch?v=eq8bUwFuSUM

 

 

[์ทจ์•ฝ์ ์ƒ์„ธ๋‚ด์šฉ]

https://www.oligo.security/blog/airborne

 

Airborne: Wormable Zero-Click RCE in Apple AirPlay Puts Billions of Devices at Risk | Oligo Security | Oligo Security

Oligo Security reveals AirBorne, a new set of vulnerabilities in Apple’s AirPlay protocol and SDK. Learn how zero-click RCEs, ACL bypasses, and wormable exploits could endanger Apple and IoT devices worldwide — and how to protect yourself.

www.oligo.security

 

[shodan์—์„œ ๋…ธ์ถœ๋œ ์„œ๋น„์Šค ๋ชฉ๋ก]

์ €์ž‘์žํ‘œ์‹œ ๋น„์˜๋ฆฌ ๋ณ€๊ฒฝ๊ธˆ์ง€ (์ƒˆ์ฐฝ์—ด๋ฆผ)

'๐Ÿค–์ •๋ณด๋ณด์•ˆ > ๐Ÿ’™๋ธ”๋ฃจํŒ€' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

SSL ์ธ์ฆ์„œ๋ณด์•ˆ์ •์ฑ…(feat. ํ”„๋ก์‹œ)  (0) 2025.03.07
[์ •๋ณด] ๊ตฌ Windows OS ์ „์šฉ Everything  (0) 2023.12.15
์œˆ๋„์šฐ ์•„ํ‹ฐํŽ™ํŠธ  (0) 2023.12.14
[์œˆ๋„์šฐ] Microsoft Windows Server 2008 ๋ฐฑ์‹   (0) 2023.12.12
[์œˆ๋„์šฐ] Windows Server 2008 ์šฉ autoruns  (0) 2023.12.12
'๐Ÿค–์ •๋ณด๋ณด์•ˆ/๐Ÿ’™๋ธ”๋ฃจํŒ€' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€
  • SSL ์ธ์ฆ์„œ๋ณด์•ˆ์ •์ฑ…(feat. ํ”„๋ก์‹œ)
  • [์ •๋ณด] ๊ตฌ Windows OS ์ „์šฉ Everything
  • ์œˆ๋„์šฐ ์•„ํ‹ฐํŽ™ํŠธ
  • [์œˆ๋„์šฐ] Microsoft Windows Server 2008 ๋ฐฑ์‹ 
TwoIceFish
TwoIceFish
https://github.com/TwoIceFIsh
  • TwoIceFish
    Cyber-Luna
    TwoIceFish
  • ์ „์ฒด
    ์˜ค๋Š˜
    ์–ด์ œ
    • ๋ถ„๋ฅ˜ ์ „์ฒด๋ณด๊ธฐ (593)
      • ๐Ÿค–์ •๋ณด๋ณด์•ˆ (77)
        • ๐Ÿ’™๋ธ”๋ฃจํŒ€ (24)
        • โค๏ธ๋ ˆ๋“œํŒ€ (21)
        • ๐Ÿ’œํผํ”ŒํŒ€ (1)
        • ๐Ÿ’ 1๋ถ„์ง€์‹ (30)
      • ํ”„๋กœ์ ํŠธ (14)
        • ๐Ÿ’Œ ์ •๋ณด๋ณด์•ˆ ๋ฉ”์ผ๋ง ์‹œ์Šคํ…œ (8)
        • ๐Ÿ” ์ธ์ฆ์„œ ๊ด€๋ฆฌ ์‹œ์Šคํ…œ (1)
        • ๐Ÿ ๊ธˆ์œต ์ปค๋ฎค๋‹ˆํ‹ฐ (5)
      • ๐Ÿžํ”„๋กœ๊ทธ๋ž˜๋ฐ (49)
        • Next.js (9)
      • ๊ธฐํƒ€์ •๋ณด (68)
        • ๐ŸŒ๊ทธ๋ฆฟ์š”๊ฑฐํŠธ (11)
  • ๋ธ”๋กœ๊ทธ ๋ฉ”๋‰ด

    • ํ™ˆ
    • ๋ฐฉ๋ช…๋ก
    • ๋กœ์ผ“ํŽ€์น˜
    • ๊นƒํ—ˆ๋ธŒ
    • ์ฝ”์ฝ”๋„ˆ์ธ 
    • ๊ทธ๋ฆฟ์š”๊ฑฐํŠธ
  • ๋งํฌ

  • ๊ณต์ง€์‚ฌํ•ญ

    • ์•ˆ๋…•ํ•˜์„ธ์š”
  • ์ธ๊ธฐ ๊ธ€

  • ํƒœ๊ทธ

    tomcat servlet
    ์•…์„ฑ๋ฉ”์ผ
    nmap
    ์‚ผ์„ฑ์ „์ž์šฐ
    SKํ•˜์ด๋‹‰์Šค
    ๋‹จ์ผ ๋„๋ฉ”์ธ ์ธ์ฆ์„œ ์—ฌ๋Ÿฌ๊ฐœ
    ์ˆ˜์ต๋ฅ  ๊ณ„์‚ฐ๊ธฐ
    ๋ฐฉ๋ฒ™
    ์ฝ”์ฝ”๋„›์ธ 
    eclipse
    ์•…์„ฑ๋ฉ”์žƒ๋ถ„์„
    ํ†ฐ์บฃ ์„œ๋ธ”๋ฆฟ
    vpn ์„ค์น˜
    ์„œ๋ธŒ๋„๋ฉ”์ธ ์ธ์ฆ์„œ
    ์• ํ”ŒํŽ˜์ด ์„ค์ •๋ฐฉ๋ฒ•
    jsp 200
    ๋ฉ”์ผํ—ค๋”๋ถ„์„
    Visual Studio
    ์‘๋‹ต์—†์Œ
    servlet 404
    ISMS-P
    ์ง€๊ฐ‘ ์•ฑ์— ์นด๋“œ ์ถ”๊ฐ€
    ์œ ๋‹ˆํ‹ฐ
    vpn ์˜คํ”ˆ์†Œ์Šค
    ๋ถ€๋™์‚ฐ ์ˆ˜์ต๋ฅ  ๊ณ„์‚ฐ๊ธฐ
    ๋ถ€ํŠธ์ŠคํŠธ๋žฉ
    ์™€์ดํŒŒ์ด ๋น„๋ฐ€๋ฒˆํ˜ธ ํƒˆ์ทจ
    ๋ชจ์˜ํ•ดํ‚น
    ์ธ์ฆ์„œ ์—ฌ๋Ÿฌ๊ฐœ
    jsp
  • ์ตœ๊ทผ ๋Œ“๊ธ€

  • hELLOยท Designed By์ •์ƒ์šฐ.v4.10.0
TwoIceFish
[์ •๋ณด] ์• ํ”Œ ๋ํŒ์™• ์ทจ์•ฝ์  Airborne ๊ณต๊ฐœ(0-Click, RCE, CVE-2025-24132)
์ƒ๋‹จ์œผ๋กœ

ํ‹ฐ์Šคํ† ๋ฆฌํˆด๋ฐ”