{"id":10517,"date":"2025-10-20T13:26:05","date_gmt":"2025-10-20T06:26:05","guid":{"rendered":"https:\/\/infosec.new88088.net\/?p=10517"},"modified":"2026-02-05T13:26:11","modified_gmt":"2026-02-05T06:26:11","slug":"lo-hong-trong-he-thong-xac-thuc-linux-pam-co-the-cho-phep-nguoi-dung-chiem-quyen-root","status":"publish","type":"post","link":"https:\/\/infosec.new88088.net\/2025\/10\/20\/lo-hong-trong-he-thong-xac-thuc-linux-pam-co-the-cho-phep-nguoi-dung-chiem-quyen-root\/","title":{"rendered":"L\u1ed7 h\u1ed5ng trong h\u1ec7 th\u1ed1ng x\u00e1c th\u1ef1c Linux-PAM c\u00f3 th\u1ec3 cho ph\u00e9p ng\u01b0\u1eddi d\u00f9ng chi\u1ebfm quy\u1ec1n root"},"content":{"rendered":"<p><b>M\u1ed9t l\u1ed7 h\u1ed5ng b\u1ea3o m\u1eadt v\u1eeba \u0111\u01b0\u1ee3c c\u00f4ng b\u1ed1 trong h\u1ec7 th\u1ed1ng x\u00e1c th\u1ef1c n\u1ed5i ti\u1ebfng Pluggable Authentication Modules (Linux-PAM). \u0110\u01b0\u1ee3c \u0111\u1ecbnh danh v\u1edbi m\u00e3 CVE-2025-8941, l\u1ed7 h\u1ed5ng n\u00e0y cho ph\u00e9p ng\u01b0\u1eddi d\u00f9ng c\u00f3 quy\u1ec1n truy c\u1eadp c\u1ee5c b\u1ed9 c\u00f3 th\u1ec3 khai th\u00e1c \u0111\u1ec3 chi\u1ebfm to\u00e0n quy\u1ec1n ki\u1ec3m so\u00e1t h\u1ec7 th\u1ed1ng th\u00f4ng qua m\u1ed9t chu\u1ed7i c\u00e1c k\u1ef9 thu\u1eadt tinh vi nh\u01b0: T\u1ea5n c\u00f4ng li\u00ean k\u1ebft t\u01b0\u1ee3ng tr\u01b0ng v\u00e0 \u0110i\u1ec1u ki\u1ec7n tranh ch\u1ea5p.<\/b><\/p>\n<div style=\"text-align: center\"><a class=\"js-lbImage\" style=\"cursor: pointer\" href=\"https:\/\/whitehat.vn\/attachments\/1760942587457-png.17760\/\" target=\"_blank\" rel=\"noopener\" data-lb-sidebar-href=\"\" data-lb-caption-extra-html=\"\" data-fancybox=\"lb-thread-18847\" data-caption=\"&lt;h4&gt;1760942587457.png&lt;\/h4&gt;&lt;p&gt;&lt;a href=&quot;https:&amp;#x2F;&amp;#x2F;whitehat.vn&amp;#x2F;threads&amp;#x2F;lo-hong-trong-he-thong-xac-thuc-linux-pam-co-the-cho-phep-nguoi-dung-chiem-quyen-root.18847&amp;#x2F;#post-44365&quot; class=&quot;js-lightboxCloser&quot;&gt;WhiteHat Team \u00b7 20&amp;#x2F;10&amp;#x2F;2025 l\u00fac 1:57 PM&lt;\/a&gt;&lt;\/p&gt;\"><img fetchpriority=\"high\" decoding=\"async\" class=\"bbImage \" title=\"1760942587457.png\" src=\"https:\/\/whitehat.vn\/data\/attachments\/18\/18095-c9a78fe2e56eca4a535160ba07cb2b87.jpg\" alt=\"1760942587457.png\" width=\"712\" height=\"400\" \/><\/a>\u200b<\/div>\n<p>D\u00f9 kh\u00f4ng th\u1ec3 khai th\u00e1c t\u1eeb xa, nh\u01b0ng trong m\u00f4i tr\u01b0\u1eddng nhi\u1ec1u ng\u01b0\u1eddi d\u00f9ng ho\u1eb7c h\u1ec7 th\u1ed1ng m\u00e1y ch\u1ee7, nguy c\u01a1 b\u1ecb khai th\u00e1c l\u1ed7 h\u1ed5ng n\u00e0y \u0111\u1ec3 l\u00e0m r\u00f2 r\u1ec9 d\u1eef li\u1ec7u, c\u00e0i m\u00e3 \u0111\u1ed9c ho\u1eb7c ph\u00e1 h\u1ee7y h\u1ec7 th\u1ed1ng l\u00e0 ho\u00e0n to\u00e0n c\u00f3 th\u1ec3 x\u1ea3y ra v\u00e0 \u0111ang khi\u1ebfn gi\u1edbi b\u1ea3o m\u1eadt ph\u1ea3i \u201c\u0111\u1ee9ng ng\u1ed3i kh\u00f4ng y\u00ean\u201d.<\/p>\n<p>L\u1ed7 h\u1ed5ng \u0111\u01b0\u1ee3c ph\u00e1t hi\u1ec7n v\u00e0 c\u00f4ng b\u1ed1 b\u1edfi c\u00e1c chuy\u00ean gia b\u1ea3o m\u1eadt t\u1eeb nh\u00f3m nghi\u00ean c\u1ee9u Ameeba Security. H\u1ecd \u0111\u00e3 ph\u00e2n t\u00edch s\u00e2u v\u00e0o module pam_namespace (m\u1ed9t th\u00e0nh ph\u1ea7n trong Linux-PAM ch\u1ecbu tr\u00e1ch nhi\u1ec7m t\u1ea1o kh\u00f4ng gian t\u00ean ri\u00eang bi\u1ec7t cho c\u00e1c phi\u00ean l\u00e0m vi\u1ec7c c\u1ee7a ng\u01b0\u1eddi d\u00f9ng).<\/p>\n<p>M\u1ee5c ti\u00eau ban \u0111\u1ea7u c\u1ee7a module n\u00e0y l\u00e0 b\u1ea3o v\u1ec7 ng\u01b0\u1eddi d\u00f9ng b\u1eb1ng c\u00e1ch t\u00e1ch bi\u1ec7t m\u00f4i tr\u01b0\u1eddng l\u00e0m vi\u1ec7c, nh\u01b0ng l\u1ea1i v\u00f4 t\u00ecnh \u0111\u1ec3 l\u1ed9 ra m\u1ed9t \u0111i\u1ec3m y\u1ebfu ch\u1ebft ng\u01b0\u1eddi: X\u1eed l\u00fd kh\u00f4ng \u0111\u00fang c\u00e1c \u0111\u01b0\u1eddng d\u1eabn do ng\u01b0\u1eddi d\u00f9ng ki\u1ec3m so\u00e1t, d\u1eabn \u0111\u1ebfn vi\u1ec7c c\u00f3 th\u1ec3 ch\u00e8n c\u00e1c li\u00ean k\u1ebft t\u01b0\u1ee3ng tr\u01b0ng (symlink) v\u00e0 khai th\u00e1c \u0111i\u1ec1u ki\u1ec7n th\u1eddi gian (race condition) khi h\u1ec7 th\u1ed1ng t\u1ea1o th\u01b0 m\u1ee5c.<\/p>\n<h4>2. C\u00e1ch th\u1ee9c khai th\u00e1c\u200b<\/h4>\n<p>T\u01b0\u1edfng t\u01b0\u1ee3ng m\u1ed9t ng\u01b0\u1eddi d\u00f9ng b\u00ecnh th\u01b0\u1eddng tr\u00ean h\u1ec7 th\u1ed1ng Linux t\u1ea1o m\u1ed9t li\u00ean k\u1ebft t\u01b0\u1ee3ng tr\u01b0ng t\u1eeb th\u01b0 m\u1ee5c c\u1ee7a m\u00ecnh \u0111\u1ebfn th\u01b0 m\u1ee5c \/root (v\u1ed1n ch\u1ec9 d\u00e0nh ri\u00eang cho qu\u1ea3n tr\u1ecb vi\u00ean h\u1ec7 th\u1ed1ng):<\/p>\n<blockquote class=\"bbCodeBlock bbCodeBlock--expandable bbCodeBlock--quote js-expandWatch\">\n<div class=\"bbCodeBlock-content\">\n<div class=\"bbCodeBlock-expandContent js-expandContent \">ln -s \/root \/tmp\/victim\/symlink<\/div>\n<div class=\"bbCodeBlock-expandLink js-expandLink\"><a role=\"button\">Nh\u1ea5n \u0111\u1ec3 m\u1edf r\u1ed9ng&#8230;<\/a><\/div>\n<\/div>\n<\/blockquote>\n<p>Khi h\u1ec7 th\u1ed1ng \u0111ang th\u1ef1c hi\u1ec7n vi\u1ec7c t\u1ea1o th\u01b0 m\u1ee5c c\u00e1ch ly cho ng\u01b0\u1eddi d\u00f9ng n\u00e0y, n\u1ebfu ng\u01b0\u1eddi t\u1ea5n c\u00f4ng canh \u0111\u00fang th\u1eddi \u0111i\u1ec3m, h\u1ec7 th\u1ed1ng s\u1ebd v\u00f4 t\u00ecnh t\u1ea1o th\u01b0 m\u1ee5c b\u00ean trong \/root. L\u00fac n\u00e0y, th\u00f4ng qua vi\u1ec7c \u0111i\u1ec1u ch\u1ec9nh quy\u1ec1n truy c\u1eadp, ng\u01b0\u1eddi d\u00f9ng th\u01b0\u1eddng c\u00f3 th\u1ec3 chi\u1ebfm to\u00e0n quy\u1ec1n \u0111i\u1ec1u khi\u1ec3n h\u1ec7 th\u1ed1ng:<\/p>\n<blockquote class=\"bbCodeBlock bbCodeBlock--expandable bbCodeBlock--quote js-expandWatch\">\n<div class=\"bbCodeBlock-content\">\n<div class=\"bbCodeBlock-expandContent js-expandContent \">chmod 777 \/root<\/div>\n<div class=\"bbCodeBlock-expandLink js-expandLink\"><a role=\"button\">Nh\u1ea5n \u0111\u1ec3 m\u1edf r\u1ed9ng&#8230;<\/a><\/div>\n<\/div>\n<\/blockquote>\n<p>D\u00f9 vi\u1ec7c khai th\u00e1c th\u1ef1c t\u1ebf \u0111\u00f2i h\u1ecfi k\u1ef9 thu\u1eadt cao v\u00e0 k\u1ecbch b\u1ea3n ph\u1ee9c t\u1ea1p, nh\u01b0ng k\u1ebft qu\u1ea3 cu\u1ed1i c\u00f9ng l\u00e0 quy\u1ec1n root (quy\u1ec1n cao nh\u1ea5t trong h\u1ec7 \u0111i\u1ec1u h\u00e0nh Unix\/Linux). M\u1ed9t khi \u0111\u1ea1t \u0111\u01b0\u1ee3c, k\u1ebb t\u1ea5n c\u00f4ng c\u00f3 th\u1ec3:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">C\u00e0i m\u00e3 \u0111\u1ed9c v\u00e0o h\u1ec7 th\u1ed1ng<\/li>\n<li data-xf-list-type=\"ul\">Truy c\u1eadp ho\u1eb7c x\u00f3a d\u1eef li\u1ec7u nh\u1ea1y c\u1ea3m<\/li>\n<li data-xf-list-type=\"ul\">Nghe l\u00e9n ho\u1eb7c ghi l\u1ea1i ho\u1ea1t \u0111\u1ed9ng ng\u01b0\u1eddi d\u00f9ng kh\u00e1c<\/li>\n<li data-xf-list-type=\"ul\">Ph\u00e1 ho\u1ea1i to\u00e0n b\u1ed9 h\u1ec7 th\u1ed1ng ho\u1eb7c t\u1ea1o backdoor<\/li>\n<\/ul>\n<h4>3. M\u1ee9c \u0111\u1ed9 \u1ea3nh h\u01b0\u1edfng v\u00e0 t\u00ednh nghi\u00eam tr\u1ecdng\u200b<\/h4>\n<p>Theo h\u1ec7 th\u1ed1ng ch\u1ea5m \u0111i\u1ec3m CVSS, l\u1ed7 h\u1ed5ng CVE-2025-8941 \u0111\u1ea1t \u0111i\u1ec3m 7,8 (High Severity). C\u00e1c y\u1ebfu t\u1ed1 khi\u1ebfn l\u1ed7 h\u1ed5ng n\u00e0y nguy hi\u1ec3m bao g\u1ed3m:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">T\u1ea5n c\u00f4ng t\u1eeb b\u00ean trong: Kh\u00f4ng c\u1ea7n k\u1ebft n\u1ed1i m\u1ea1ng, ch\u1ec9 c\u1ea7n t\u00e0i kho\u1ea3n ng\u01b0\u1eddi d\u00f9ng tr\u00ean h\u1ec7 th\u1ed1ng.<\/li>\n<li data-xf-list-type=\"ul\">Y\u00eau c\u1ea7u quy\u1ec1n h\u1ea1n th\u1ea5p: Ch\u1ec9 c\u1ea7n t\u00e0i kho\u1ea3n th\u00f4ng th\u01b0\u1eddng, kh\u00f4ng c\u1ea7n quy\u1ec1n qu\u1ea3n tr\u1ecb.<\/li>\n<li data-xf-list-type=\"ul\">C\u00f3 t\u01b0\u01a1ng t\u00e1c ng\u01b0\u1eddi d\u00f9ng: Nh\u01b0ng m\u1ee9c \u0111\u1ed9 t\u01b0\u01a1ng t\u00e1c r\u1ea5t nh\u1ecf, d\u1ec5 th\u1ef1c hi\u1ec7n trong m\u00f4i tr\u01b0\u1eddng chia s\u1ebb t\u00e0i nguy\u00ean (nh\u01b0 m\u00e1y ch\u1ee7 ho\u1eb7c m\u00e1y t\u00ednh d\u00f9ng chung).<\/li>\n<li data-xf-list-type=\"ul\">C\u00f3 th\u1ec3 chi\u1ebfm quy\u1ec1n root, g\u00e2y r\u00f2 r\u1ec9 d\u1eef li\u1ec7u, ki\u1ec3m so\u00e1t to\u00e0n h\u1ec7 th\u1ed1ng.<\/li>\n<\/ul>\n<p>T\u1ea5t c\u1ea3 c\u00e1c h\u1ec7 th\u1ed1ng Linux-PAM ch\u01b0a \u0111\u01b0\u1ee3c c\u1eadp nh\u1eadt b\u1ea3n v\u00e1 m\u1edbi nh\u1ea5t \u0111\u1ec1u c\u00f3 nguy c\u01a1 b\u1ecb khai th\u00e1c, bao g\u1ed3m c\u00e1c b\u1ea3n ph\u00e2n ph\u1ed1i ph\u1ed5 bi\u1ebfn nh\u01b0:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">Ubuntu<\/li>\n<li data-xf-list-type=\"ul\">Red Hat Enterprise Linux<\/li>\n<li data-xf-list-type=\"ul\">Fedora<\/li>\n<li data-xf-list-type=\"ul\">Debian<\/li>\n<li data-xf-list-type=\"ul\">CentOS<\/li>\n<\/ul>\n<p>&#8230;v\u00e0 nhi\u1ec1u h\u1ec7 \u0111i\u1ec1u h\u00e0nh Linux kh\u00e1c \u0111ang d\u00f9ng Linux-PAM.<\/p>\n<p>\u0110\u00e2y kh\u00f4ng ch\u1ec9 l\u00e0 c\u1ea3nh b\u00e1o d\u00e0nh ri\u00eang cho c\u00e1c chuy\u00ean gia IT, m\u00e0 c\u00f2n l\u00e0 l\u1eddi nh\u1eafc nh\u1edf cho t\u1ea5t c\u1ea3 ng\u01b0\u1eddi d\u00f9ng h\u1ec7 \u0111i\u1ec1u h\u00e0nh Linux, t\u1eeb m\u00e1y t\u00ednh c\u00e1 nh\u00e2n \u0111\u1ebfn h\u1ec7 th\u1ed1ng doanh nghi\u1ec7p.<\/p>\n<p>C\u00e1c khuy\u1ebfn c\u00e1o t\u1eeb chuy\u00ean gia b\u1ea3o m\u1eadt:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">C\u1eadp nh\u1eadt ngay c\u00e1c b\u1ea3n v\u00e1 m\u1edbi nh\u1ea5t t\u1eeb nh\u00e0 cung c\u1ea5p h\u1ec7 \u0111i\u1ec1u h\u00e0nh (Ubuntu, Red Hat, Fedora\u2026)<\/li>\n<li data-xf-list-type=\"ul\">T\u1ea1m th\u1eddi v\u00f4 hi\u1ec7u h\u00f3a module pam_namespace n\u1ebfu kh\u00f4ng c\u1ea7n thi\u1ebft<\/li>\n<li data-xf-list-type=\"ul\">Gi\u00e1m s\u00e1t c\u00e1c ho\u1ea1t \u0111\u1ed9ng li\u00ean quan \u0111\u1ebfn symlink ho\u1eb7c truy c\u1eadp th\u01b0 m\u1ee5c \/tmp<\/li>\n<li data-xf-list-type=\"ul\">H\u1ea1n ch\u1ebf t\u1ed1i \u0111a quy\u1ec1n truy c\u1eadp c\u1ee5c b\u1ed9 cho ng\u01b0\u1eddi d\u00f9ng kh\u00f4ng c\u1ea7n thi\u1ebft<\/li>\n<li data-xf-list-type=\"ul\">Th\u01b0\u1eddng xuy\u00ean ki\u1ec3m tra quy\u1ec1n truy c\u1eadp, ph\u00e2n quy\u1ec1n \u0111\u00fang c\u00e1ch trong h\u1ec7 th\u1ed1ng<\/li>\n<li data-xf-list-type=\"ul\">\u0110\u01b0a l\u1ed7 h\u1ed5ng n\u00e0y v\u00e0o k\u1ebf ho\u1ea1ch v\u00e1 l\u1ed7i \u0111\u1ecbnh k\u1ef3 trong chu tr\u00ecnh b\u1ea3o tr\u00ec h\u1ec7 th\u1ed1ng<\/li>\n<\/ul>\n<p>D\u00f9 CVE-2025-8941 kh\u00f4ng ph\u1ea3i l\u00e0 l\u1ed7i \u0111\u1ea7u ti\u00ean hay cu\u1ed1i c\u00f9ng trong c\u00e1c h\u1ec7 th\u1ed1ng m\u00e3 ngu\u1ed3n m\u1edf, nh\u01b0ng n\u00f3 cho th\u1ea5y r\u1eb1ng ngay c\u1ea3 nh\u1eefng th\u00e0nh ph\u1ea7n c\u1ed1t l\u00f5i, uy t\u00edn nh\u01b0 Linux-PAM c\u0169ng kh\u00f4ng n\u1eb1m ngo\u00e0i t\u1ea7m ng\u1eafm c\u1ee7a k\u1ebb t\u1ea5n c\u00f4ng.<\/p>\n<p>Trong th\u1eddi \u0111\u1ea1i m\u00e0 an ninh m\u1ea1ng l\u00e0 tuy\u1ebfn ph\u00f2ng th\u1ee7 quan tr\u1ecdng h\u00e0ng \u0111\u1ea7u, c\u1eadp nh\u1eadt ph\u1ea7n m\u1ec1m, hi\u1ec3u r\u00f5 r\u1ee7i ro v\u00e0 ph\u1ea3n \u1ee9ng nhanh l\u00e0 ba tr\u1ee5 c\u1ed9t s\u1ed1ng c\u00f2n \u0111\u1ec3 b\u1ea3o v\u1ec7 h\u1ec7 th\u1ed1ng kh\u1ecfi c\u00e1c m\u1ed1i \u0111e d\u1ecda ng\u00e0y c\u00e0ng tinh vi.<\/p>\n<div style=\"text-align: right\"><b><i>WhiteHat<\/i><\/b>\u200b<\/div>\n<div style=\"text-align: right;margin-top: 16px\"><i>Theo: <a href=\"https:\/\/whitehat.vn\/threads\/lo-hong-trong-he-thong-xac-thuc-linux-pam-co-the-cho-phep-nguoi-dung-chiem-quyen-root.18847\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/whitehat.vn\/threads\/lo-hong-trong-he-thong-xac-thuc-linux-pam-co-the-cho-phep-nguoi-dung-chiem-quyen-root.18847\/<\/a><\/i><\/div>\n","protected":false},"excerpt":{"rendered":"<p>M\u1ed9t l\u1ed7 h\u1ed5ng b\u1ea3o m\u1eadt v\u1eeba \u0111\u01b0\u1ee3c c\u00f4ng b\u1ed1 trong h\u1ec7 th\u1ed1ng x\u00e1c th\u1ef1c n\u1ed5i ti\u1ebfng Pluggable Authentication Modules (Linux-PAM). \u0110\u01b0\u1ee3c \u0111\u1ecbnh danh v\u1edbi m\u00e3 CVE-2025-8941, l\u1ed7 h\u1ed5ng n\u00e0y cho ph\u00e9p ng\u01b0\u1eddi d\u00f9ng c\u00f3 quy\u1ec1n truy c\u1eadp c\u1ee5c b\u1ed9 c\u00f3 th\u1ec3 khai th\u00e1c \u0111\u1ec3 chi\u1ebfm to\u00e0n quy\u1ec1n ki\u1ec3m so\u00e1t h\u1ec7 th\u1ed1ng th\u00f4ng qua m\u1ed9t chu\u1ed7i [&hellip;]<\/p>\n","protected":false},"author":46,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[33],"tags":[],"class_list":["post-10517","post","type-post","status-publish","format-standard","hentry","category-tin-tuc-cua-vien"],"_links":{"self":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/10517","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/comments?post=10517"}],"version-history":[{"count":0,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/10517\/revisions"}],"wp:attachment":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/media?parent=10517"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/categories?post=10517"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/tags?post=10517"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}