{"id":10463,"date":"2025-07-21T12:34:51","date_gmt":"2025-07-21T05:34:51","guid":{"rendered":"https:\/\/infosec.new88088.net\/?p=10463"},"modified":"2026-02-05T12:34:58","modified_gmt":"2026-02-05T05:34:58","slug":"khong-phai-lo-hong-chinh-tinh-nang-da-mo-cua-cho-ke-tan-cong","status":"publish","type":"post","link":"https:\/\/infosec.new88088.net\/2025\/07\/21\/khong-phai-lo-hong-chinh-tinh-nang-da-mo-cua-cho-ke-tan-cong\/","title":{"rendered":"Kh\u00f4ng ph\u1ea3i l\u1ed7 h\u1ed5ng, ch\u00ednh t\u00ednh n\u0103ng \u0111\u00e3 &#8220;m\u1edf c\u1eeda&#8221; cho k\u1ebb t\u1ea5n c\u00f4ng"},"content":{"rendered":"<p><b>M\u1ed9t k\u1ef9 thu\u1eadt t\u1ea5n c\u00f4ng m\u1edbi v\u1eeba \u0111\u01b0\u1ee3c ph\u00e1t hi\u1ec7n, cho ph\u00e9p nh\u00f3m hacker PoisonSeed v\u01b0\u1ee3t qua c\u01a1 ch\u1ebf b\u1ea3o v\u1ec7 c\u1ee7a kh\u00f3a b\u1ea3o m\u1eadt FIDO v\u1ed1n \u0111\u01b0\u1ee3c xem l\u00e0 &#8220;ti\u00eau chu\u1ea9n v\u00e0ng&#8221; trong x\u00e1c th\u1ef1c kh\u00f4ng m\u1eadt kh\u1ea9u v\u00e0 ch\u1ed1ng phishing hi\u1ec7n nay. \u0110i\u1ec3m \u0111\u1eb7c bi\u1ec7t c\u1ee7a k\u1ef9 thu\u1eadt n\u00e0y kh\u00f4ng n\u1eb1m \u1edf vi\u1ec7c khai th\u00e1c l\u1ed7 h\u1ed5ng trong giao th\u1ee9c FIDO m\u00e0 \u1edf c\u00e1ch m\u00e0 k\u1ebb t\u1ea5n c\u00f4ng l\u1ee3i d\u1ee5ng t\u00ednh n\u0103ng h\u1ee3p ph\u00e1p: c\u01a1 ch\u1ebf \u0111\u0103ng nh\u1eadp li\u00ean thi\u1ebft b\u1ecb (cross-device sign-in).<\/b><\/p>\n<div style=\"text-align: center\">\n<div class=\"bbImageWrapper  js-lbImage\" title=\"1753079507535.png\" data-src=\"https:\/\/whitehat.vn\/attachments\/1753079507535-png.17343\/\" data-lb-sidebar-href=\"\" data-lb-caption-extra-html=\"\" data-single-image=\"1\"><img fetchpriority=\"high\" decoding=\"async\" class=\"bbImage\" title=\"1753079507535.png\" src=\"https:\/\/whitehat.vn\/attachments\/1753079507535-png.17343\/\" alt=\"1753079507535.png\" width=\"728\" height=\"380\" data-url=\"\" data-zoom-target=\"1\" \/><\/div>\n<p>\u200b<\/p><\/div>\n<h3>B\u1ea3n ch\u1ea5t c\u1ee7a cu\u1ed9c t\u1ea5n c\u00f4ng\u200b<\/h3>\n<p>T\u00ednh n\u0103ng cross-device sign-in cho ph\u00e9p ng\u01b0\u1eddi d\u00f9ng x\u00e1c th\u1ef1c \u0111\u0103ng nh\u1eadp tr\u00ean m\u1ed9t thi\u1ebft b\u1ecb (v\u00ed d\u1ee5: m\u00e1y t\u00ednh \u0111\u1ec3 b\u00e0n) b\u1eb1ng c\u00e1ch s\u1eed d\u1ee5ng thi\u1ebft b\u1ecb kh\u00e1c (nh\u01b0 \u0111i\u1ec7n tho\u1ea1i c\u00f3 ch\u1ee9a kh\u00f3a FIDO). \u0110\u00e2y l\u00e0 m\u1ed9t ph\u01b0\u01a1ng th\u1ee9c ti\u1ec7n l\u1ee3i, nh\u01b0ng l\u1ea1i m\u1edf ra m\u1ed9t \u0111i\u1ec3m m\u00f9 v\u1ec1 b\u1ea3o m\u1eadt trong b\u1ed1i c\u1ea3nh ng\u01b0\u1eddi d\u00f9ng kh\u00f4ng th\u1ec3 tr\u1ef1c ti\u1ebfp x\u00e1c minh t\u00ean mi\u1ec1n \u0111ang y\u00eau c\u1ea7u x\u00e1c th\u1ef1c.<\/p>\n<p><b>Chu\u1ed7i t\u1ea5n c\u00f4ng \u0111\u01b0\u1ee3c th\u1ef1c hi\u1ec7n nh\u01b0 sau:<\/b><\/p>\n<ol>\n<li data-xf-list-type=\"ol\">K\u1ebb t\u1ea5n c\u00f4ng g\u1eedi email phishing, d\u1ee5 ng\u01b0\u1eddi d\u00f9ng truy c\u1eadp v\u00e0o m\u1ed9t c\u1ed5ng \u0111\u0103ng nh\u1eadp gi\u1ea3 m\u1ea1o (v\u00ed d\u1ee5: gi\u1ea3 m\u1ea1o Okta).<\/li>\n<li data-xf-list-type=\"ol\">Ng\u01b0\u1eddi d\u00f9ng nh\u1eadp t\u00ean \u0111\u0103ng nh\u1eadp v\u00e0 m\u1eadt kh\u1ea9u v\u00e0o trang gi\u1ea3 m\u1ea1o.<\/li>\n<li data-xf-list-type=\"ol\">Th\u00f4ng tin \u0111\u0103ng nh\u1eadp \u0111\u01b0\u1ee3c chuy\u1ec3n ti\u1ebfp ng\u1ea7m \u0111\u1ebfn trang \u0111\u0103ng nh\u1eadp th\u1eadt.<\/li>\n<li data-xf-list-type=\"ol\">Trang \u0111\u0103ng nh\u1eadp th\u1eadt ph\u1ea3n h\u1ed3i b\u1eb1ng c\u00e1ch sinh m\u00e3 QR ph\u1ee5c v\u1ee5 x\u00e1c th\u1ef1c li\u00ean thi\u1ebft b\u1ecb.<\/li>\n<li data-xf-list-type=\"ol\">M\u00e3 QR n\u00e0y \u0111\u01b0\u1ee3c chuy\u1ec3n l\u1ea1i cho ng\u01b0\u1eddi d\u00f9ng tr\u00ean giao di\u1ec7n gi\u1ea3 m\u1ea1o.<\/li>\n<li data-xf-list-type=\"ol\">Khi ng\u01b0\u1eddi d\u00f9ng qu\u00e9t m\u00e3 QR b\u1eb1ng \u1ee9ng d\u1ee5ng x\u00e1c th\u1ef1c tr\u00ean thi\u1ebft b\u1ecb di \u0111\u1ed9ng, h\u1ecd \u0111\u00e3 v\u00f4 t\u00ecnh x\u00e1c th\u1ef1c cho m\u1ed9t phi\u00ean \u0111\u0103ng nh\u1eadp do k\u1ebb t\u1ea5n c\u00f4ng kh\u1edfi t\u1ea1o, d\u1eabn \u0111\u1ebfn vi\u1ec7c b\u1ecb chi\u1ebfm quy\u1ec1n truy c\u1eadp t\u00e0i kho\u1ea3n.<\/li>\n<\/ol>\n<p>V\u1ec1 b\u1ea3n ch\u1ea5t, ng\u01b0\u1eddi d\u00f9ng \u0111ang x\u00e1c th\u1ef1c m\u1ed9t phi\u00ean \u0111\u0103ng nh\u1eadp kh\u00f4ng ph\u1ea3i c\u1ee7a m\u00ecnh, nh\u01b0ng v\u1eabn tin r\u1eb1ng qu\u00e1 tr\u00ecnh n\u00e0y l\u00e0 h\u1ee3p ph\u00e1p.<\/p>\n<div style=\"text-align: center\">\n<div class=\"bbImageWrapper  js-lbImage\" title=\"1753079519842.png\" data-src=\"https:\/\/whitehat.vn\/attachments\/1753079519842-png.17344\/\" data-lb-sidebar-href=\"\" data-lb-caption-extra-html=\"\" data-single-image=\"1\"><img decoding=\"async\" class=\"bbImage\" title=\"1753079519842.png\" src=\"https:\/\/whitehat.vn\/attachments\/1753079519842-png.17344\/\" alt=\"1753079519842.png\" width=\"728\" height=\"428\" data-url=\"\" data-zoom-target=\"1\" \/><\/div>\n<\/div>\n<h3>V\u00ec sao k\u1ef9 thu\u1eadt n\u00e0y nguy hi\u1ec3m?\u200b<\/h3>\n<p>\u0110\u00e2y l\u00e0 m\u1ed9t v\u00ed d\u1ee5 \u0111i\u1ec3n h\u00ecnh c\u1ee7a k\u1ef9 thu\u1eadt downgrade authentication, t\u1ee9c l\u00e0 h\u1ea1 c\u1ea5p qu\u00e1 tr\u00ecnh x\u00e1c th\u1ef1c xu\u1ed1ng m\u1ed9t h\u00ecnh th\u1ee9c d\u1ec5 b\u1ecb thao t\u00fang, d\u00f9 c\u00f4ng ngh\u1ec7 \u0111ang d\u00f9ng l\u00e0 hi\u1ec7n \u0111\u1ea1i v\u00e0 an to\u00e0n.<\/p>\n<p><b>\u0110i\u1ec3m \u0111\u00e1ng ch\u00fa \u00fd:<\/b><\/p>\n<ul>\n<li data-xf-list-type=\"ul\">V\u01b0\u1ee3t qua \u0111\u01b0\u1ee3c l\u1edbp b\u1ea3o v\u1ec7 FIDO d\u00f9 kh\u00f4ng khai th\u00e1c l\u1ed7 h\u1ed5ng k\u1ef9 thu\u1eadt n\u00e0o.<\/li>\n<li data-xf-list-type=\"ul\">L\u1ee3i d\u1ee5ng t\u00ednh n\u0103ng h\u1ee3p ph\u00e1p n\u00ean g\u1ea7n nh\u01b0 kh\u00f4ng b\u1ecb h\u1ec7 th\u1ed1ng gi\u00e1m s\u00e1t ph\u00e1t hi\u1ec7n.<\/li>\n<li data-xf-list-type=\"ul\">Khi k\u1ebft h\u1ee3p v\u1edbi m\u00f4 h\u00ecnh Adversary-in-the-Middle (AitM), t\u1ea5n c\u00f4ng c\u00e0ng kh\u00f3 ph\u00e1t hi\u1ec7n h\u01a1n.<\/li>\n<li data-xf-list-type=\"ul\">K\u1ebb t\u1ea5n c\u00f4ng sau \u0111\u00f3 c\u00f3 th\u1ec3 g\u00e1n kh\u00f3a FIDO c\u1ee7a ch\u00ednh m\u00ecnh v\u00e0o t\u00e0i kho\u1ea3n n\u1ea1n nh\u00e2n, v\u00f4 hi\u1ec7u h\u00f3a kh\u1ea3 n\u0103ng kh\u00f4i ph\u1ee5c c\u1ee7a ng\u01b0\u1eddi d\u00f9ng th\u1eadt.<\/li>\n<\/ul>\n<p>T\u00ednh \u0111\u1ebfn th\u1eddi \u0111i\u1ec3m hi\u1ec7n t\u1ea1i, ch\u01b0a c\u00f3 ghi nh\u1eadn c\u1ee5 th\u1ec3 n\u00e0o v\u1ec1 c\u00e1c t\u1ed5 ch\u1ee9c ho\u1eb7c ng\u01b0\u1eddi d\u00f9ng t\u1ea1i Vi\u1ec7t Nam tr\u1edf th\u00e0nh n\u1ea1n nh\u00e2n trong chi\u1ebfn d\u1ecbch n\u00e0y. Tuy nhi\u00ean, nh\u00f3m t\u1ea5n c\u00f4ng PoisonSeed \u0111\u00e3 tri\u1ec3n khai k\u1ef9 thu\u1eadt n\u00e0y tr\u00ean quy m\u00f4 to\u00e0n c\u1ea7u, t\u1eadn d\u1ee5ng c\u00e1c n\u1ec1n t\u1ea3ng CRM v\u00e0 h\u1ec7 th\u1ed1ng email h\u00e0ng lo\u1ea1t \u0111\u1ec3 ph\u00e1t t\u00e1n li\u00ean k\u1ebft phishing ch\u1ee9a m\u00e3 QR \u0111\u1ed9c h\u1ea1i.<\/p>\n<p>Do \u0111\u00f3, c\u00e1c t\u1ed5 ch\u1ee9c t\u1ea1i Vi\u1ec7t Nam, \u0111\u1eb7c bi\u1ec7t l\u00e0 nh\u1eefng doanh nghi\u1ec7p s\u1eed d\u1ee5ng n\u1ec1n t\u1ea3ng nh\u01b0 Okta, Google Workspace, Microsoft 365 ho\u1eb7c c\u00f3 tri\u1ec3n khai kh\u00f3a FIDO c\u1ea7n ch\u1ee7 \u0111\u1ed9ng theo d\u00f5i v\u00e0 \u0111\u00e1nh gi\u00e1 r\u1ee7i ro.<\/p>\n<p>Chuy\u00ean gia an ninh m\u1ea1ng cho c\u00e1c t\u1ed5 ch\u1ee9c, doanh nghi\u1ec7p c\u1ea7n l\u01b0u \u00fd th\u00eam:<\/p>\n<ol>\n<li data-xf-list-type=\"ol\">Kh\u00f4ng ch\u1ec9 tri\u1ec3n khai FIDO m\u00e0 c\u00f2n c\u1ea7n \u0111\u1ea3m b\u1ea3o c\u1ea5u h\u00ecnh \u0111\u00fang domain x\u00e1c th\u1ef1c \u0111\u1ec3 tr\u00e1nh x\u00e1c th\u1ef1c nh\u1ea7m.<\/li>\n<li data-xf-list-type=\"ol\">H\u1ea1n ch\u1ebf ho\u1eb7c v\u00f4 hi\u1ec7u h\u00f3a \u0111\u0103ng nh\u1eadp li\u00ean thi\u1ebft b\u1ecb n\u1ebfu kh\u00f4ng c\u1ea7n thi\u1ebft, \u0111\u1eb7c bi\u1ec7t tr\u00ean c\u00e1c t\u00e0i kho\u1ea3n nh\u1ea1y c\u1ea3m.<\/li>\n<li data-xf-list-type=\"ol\">\u0110\u00e0o t\u1ea1o ng\u01b0\u1eddi d\u00f9ng nh\u1eadn di\u1ec7n k\u1ef9 thu\u1eadt phishing qua m\u00e3 QR v\u00e0 email gi\u1ea3 m\u1ea1o k\u00e8m h\u01b0\u1edbng d\u1eabn x\u00e1c th\u1ef1c.<\/li>\n<li data-xf-list-type=\"ol\">Thi\u1ebft l\u1eadp c\u1ea3nh b\u00e1o khi c\u00f3 thi\u1ebft b\u1ecb x\u00e1c th\u1ef1c m\u1edbi (FIDO key) \u0111\u01b0\u1ee3c th\u00eam v\u00e0o t\u00e0i kho\u1ea3n.<\/li>\n<li data-xf-list-type=\"ol\">B\u1ea3o v\u1ec7 to\u00e0n b\u1ed9 v\u00f2ng \u0111\u1eddi t\u00e0i kho\u1ea3n, bao g\u1ed3m c\u1ea3 giai \u0111o\u1ea1n kh\u00f4i ph\u1ee5c m\u1eadt kh\u1ea9u v\u1ed1n l\u00e0 \u0111i\u1ec3m y\u1ebfu ph\u1ed5 bi\u1ebfn.<\/li>\n<\/ol>\n<p>G\u00f3c nh\u00ecn c\u1ee7a chuy\u00ean gia WhiteHat: K\u1ef9 thu\u1eadt t\u1ea5n c\u00f4ng n\u00e0y m\u1ed9t l\u1ea7n n\u1eefa cho th\u1ea5y nguy c\u01a1 b\u1ea3o m\u1eadt kh\u00f4ng ch\u1ec9 \u0111\u1ebfn t\u1eeb c\u00e1c l\u1ed7 h\u1ed5ng ph\u1ea7n m\u1ec1m m\u00e0 c\u00f2n n\u1eb1m \u1edf c\u00e1ch ch\u00fang ta thi\u1ebft k\u1ebf v\u00e0 s\u1eed d\u1ee5ng c\u00e1c t\u00ednh n\u0103ng t\u01b0\u1edfng ch\u1eebng &#8220;v\u00f4 h\u1ea1i&#8221; trong h\u1ec7 th\u1ed1ng. Vi\u1ec7c m\u1ed9t ch\u1ee9c n\u0103ng nh\u01b0 \u0111\u0103ng nh\u1eadp li\u00ean thi\u1ebft b\u1ecb v\u1ed1n sinh ra \u0111\u1ec3 h\u1ed7 tr\u1ee3 ng\u01b0\u1eddi d\u00f9ng thu\u1eadn ti\u1ec7n h\u01a1n l\u1ea1i b\u1ecb l\u1ee3i d\u1ee5ng \u0111\u1ec3 v\u01b0\u1ee3t qua c\u1ea3 FIDO key l\u00e0 l\u1eddi c\u1ea3nh t\u1ec9nh r\u1ea5t r\u00f5 r\u00e0ng.<\/p>\n<p>V\u1edbi nh\u1eefng ng\u01b0\u1eddi l\u00e0m b\u1ea3o m\u1eadt, \u0111\u00e2y l\u1eddi nh\u1eafc c\u1ea7n nh\u00ecn nh\u1eadn l\u1ea1i to\u00e0n b\u1ed9 ki\u1ebfn tr\u00fac x\u00e1c th\u1ef1c, \u0111\u1eb7c bi\u1ec7t l\u00e0 c\u00e1ch m\u00e0 ng\u01b0\u1eddi d\u00f9ng t\u01b0\u01a1ng t\u00e1c v\u1edbi n\u00f3 trong \u0111\u1eddi th\u1ef1c. M\u1ed9t h\u1ec7 th\u1ed1ng m\u1ea1nh \u0111\u1ebfn \u0111\u00e2u c\u0169ng c\u00f3 th\u1ec3 b\u1ecb \u0111\u00e1nh b\u1ea1i n\u1ebfu ng\u01b0\u1eddi d\u00f9ng x\u00e1c th\u1ef1c sai phi\u00ean \u0111\u0103ng nh\u1eadp ho\u1eb7c n\u1ebfu ch\u00ednh c\u00e1c t\u00ednh n\u0103ng h\u1ed7 tr\u1ee3 l\u1ea1i tr\u1edf th\u00e0nh &#8220;k\u1ebd h\u1edf&#8221;.<\/p>\n<p>Gi\u00e1m s\u00e1t h\u00e0nh vi, ph\u1ea3n \u1ee9ng nhanh v\u1edbi b\u1ea5t th\u01b0\u1eddng v\u00e0 \u0111\u1eb7t c\u00e2u h\u1ecfi cho t\u1eebng t\u00ednh n\u0103ng \u0111\u01b0\u1ee3c m\u1edf ra cho ng\u01b0\u1eddi d\u00f9ng, \u0111\u00f3 l\u00e0 c\u00f4ng vi\u1ec7c kh\u00f4ng bao gi\u1edd \u0111\u01b0\u1ee3c xem nh\u1eb9.<\/p>\n<div style=\"text-align: right\">\n<b><i>Theo The Hacker News<\/i><\/b>\u200b<\/div>\n<div style=\"text-align: right;margin-top: 16px\"><i>Theo: <a href=\"https:\/\/whitehat.vn\/threads\/khong-phai-lo-hong-chinh-tinh-nang-da-mo-cua-cho-ke-tan-cong.18583\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/whitehat.vn\/threads\/khong-phai-lo-hong-chinh-tinh-nang-da-mo-cua-cho-ke-tan-cong.18583\/<\/a><\/i><\/div>\n","protected":false},"excerpt":{"rendered":"<p>M\u1ed9t k\u1ef9 thu\u1eadt t\u1ea5n c\u00f4ng m\u1edbi v\u1eeba \u0111\u01b0\u1ee3c ph\u00e1t hi\u1ec7n, cho ph\u00e9p nh\u00f3m hacker PoisonSeed v\u01b0\u1ee3t qua c\u01a1 ch\u1ebf b\u1ea3o v\u1ec7 c\u1ee7a kh\u00f3a b\u1ea3o m\u1eadt FIDO v\u1ed1n \u0111\u01b0\u1ee3c xem l\u00e0 &#8220;ti\u00eau chu\u1ea9n v\u00e0ng&#8221; trong x\u00e1c th\u1ef1c kh\u00f4ng m\u1eadt kh\u1ea9u v\u00e0 ch\u1ed1ng phishing hi\u1ec7n nay. \u0110i\u1ec3m \u0111\u1eb7c bi\u1ec7t c\u1ee7a k\u1ef9 thu\u1eadt n\u00e0y kh\u00f4ng n\u1eb1m \u1edf vi\u1ec7c [&hellip;]<\/p>\n","protected":false},"author":46,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[33],"tags":[],"class_list":["post-10463","post","type-post","status-publish","format-standard","hentry","category-tin-tuc-cua-vien"],"_links":{"self":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/10463","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/comments?post=10463"}],"version-history":[{"count":0,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/10463\/revisions"}],"wp:attachment":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/media?parent=10463"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/categories?post=10463"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/tags?post=10463"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}