{"id":10541,"date":"2025-10-14T13:28:22","date_gmt":"2025-10-14T06:28:22","guid":{"rendered":"https:\/\/infosec.new88088.net\/?p=10541"},"modified":"2026-02-05T13:28:29","modified_gmt":"2026-02-05T06:28:29","slug":"hacker-khai-thac-loi-zero-day-trong-ie-mode-de-kiem-soat-thiet-bi-nguoi-dung","status":"publish","type":"post","link":"https:\/\/infosec.new88088.net\/2025\/10\/14\/hacker-khai-thac-loi-zero-day-trong-ie-mode-de-kiem-soat-thiet-bi-nguoi-dung\/","title":{"rendered":"Hacker khai th\u00e1c l\u1ed7i zero-day trong IE Mode \u0111\u1ec3 ki\u1ec3m so\u00e1t thi\u1ebft b\u1ecb ng\u01b0\u1eddi d\u00f9ng"},"content":{"rendered":"<p><b>Gi\u1eefa l\u00fac Internet Explorer (IE) \u0111\u00e3 ch\u00ednh th\u1ee9c \u201cngh\u1ec9 h\u01b0u\u201d, m\u1ed9t chi\u1ebfn d\u1ecbch t\u1ea5n c\u00f4ng m\u1ea1ng tinh vi m\u1edbi l\u1ea1i b\u1ea5t ng\u1edd khai th\u00e1c ch\u00ednh t\u00ednh n\u0103ng IE Mode trong tr\u00ecnh duy\u1ec7t Microsoft Edge, v\u1ed1n \u0111\u01b0\u1ee3c t\u1ea1o ra \u0111\u1ec3 gi\u00fap ng\u01b0\u1eddi d\u00f9ng truy c\u1eadp c\u00e1c trang web c\u0169.<\/b><\/p>\n<div style=\"text-align: center\"><a class=\"js-lbImage\" style=\"cursor: pointer\" href=\"https:\/\/whitehat.vn\/attachments\/1760431565760-png.17740\/\" target=\"_blank\" rel=\"noopener\" data-lb-sidebar-href=\"\" data-lb-caption-extra-html=\"\" data-fancybox=\"lb-thread-18834\" data-caption=\"&lt;h4&gt;1760431565760.png&lt;\/h4&gt;&lt;p&gt;&lt;a href=&quot;https:&amp;#x2F;&amp;#x2F;whitehat.vn&amp;#x2F;threads&amp;#x2F;hacker-khai-thac-loi-zero-day-trong-ie-mode-de-kiem-soat-thiet-bi-nguoi-dung.18834&amp;#x2F;#post-44352&quot; class=&quot;js-lightboxCloser&quot;&gt;WhiteHat Team \u00b7 14&amp;#x2F;10&amp;#x2F;2025 l\u00fac 3:57 PM&lt;\/a&gt;&lt;\/p&gt;\"><img fetchpriority=\"high\" decoding=\"async\" class=\"bbImage \" title=\"1760431565760.png\" src=\"https:\/\/whitehat.vn\/data\/attachments\/18\/18075-a836a6c988727d1d2b727c89fbaec0f7.jpg\" alt=\"1760431565760.png\" width=\"712\" height=\"400\" \/><\/a>\u200b<\/div>\n<p>Chi\u1ebfn d\u1ecbch tinh vi n\u00e0y xu\u1ea5t hi\u1ec7n v\u00e0o th\u00e1ng 8\/2025 l\u1ee3i d\u1ee5ng t\u00ednh n\u0103ng Internet Explorer (IE) mode trong Microsoft Edge. V\u1ec1 c\u01a1 b\u1ea3n, k\u1ebb t\u1ea5n c\u00f4ng kh\u00f4ng \u0111\u00e1nh th\u1eb3ng v\u00e0o Chrome\/Edge hi\u1ec7n \u0111\u1ea1i m\u00e0 d\u1ee5 n\u1ea1n nh\u00e2n chuy\u1ec3n trang sang IE mode (m\u00f4i tr\u01b0\u1eddng c\u0169, y\u1ebfu v\u1ec1 b\u1ea3o m\u1eadt), r\u1ed3i k\u00edch ho\u1ea1t l\u1ed7i zero-day trong Chakra (m\u00e1y th\u1ef1c thi JavaScript c\u1ee7a IE) \u0111\u1ec3 chi\u1ebfm quy\u1ec1n \u0111i\u1ec1u khi\u1ec3n, cho th\u1ea5y tin t\u1eb7c \u0111ang ng\u00e0y c\u00e0ng s\u00e1ng t\u1ea1o khi bi\u1ebft c\u00e1ch bi\u1ebfn m\u1ed9t c\u00f4ng c\u1ee5 t\u01b0\u01a1ng th\u00edch t\u01b0\u1edfng nh\u01b0 v\u00f4 h\u1ea1i th\u00e0nh v\u0169 kh\u00ed t\u1ea5n c\u00f4ng l\u1ee3i h\u1ea1i.<\/p>\n<h3>Hacker \u0111\u00e3 l\u1ee3i d\u1ee5ng IE Mode nh\u01b0 th\u1ebf n\u00e0o?\u200b<\/h3>\n<h4>B\u01b0\u1edbc 1: Gi\u0103ng b\u1eaby t\u00e2m l\u00fd, d\u1eabn d\u1ee5 ng\u01b0\u1eddi d\u00f9ng t\u1ef1 chuy\u1ec3n sang IE Mode\u200b<\/h4>\n<p>Tin t\u1eb7c \u0111\u1ea7u ti\u00ean d\u1ef1ng l\u00ean c\u00e1c trang web gi\u1ea3 m\u1ea1o tr\u00f4ng gi\u1ed1ng h\u1ec7t c\u00e1c trang ch\u00ednh th\u1ed1ng, nh\u01b0: C\u1ed5ng d\u1ecbch v\u1ee5 c\u00f4ng, ph\u1ea7n m\u1ec1m doanh nghi\u1ec7p hay trang camera an ninh, v\u1ed1n th\u01b0\u1eddng y\u00eau c\u1ea7u d\u00f9ng IE \u0111\u1ec3 hi\u1ec3n th\u1ecb ch\u00ednh x\u00e1c.<\/p>\n<p>Khi ng\u01b0\u1eddi d\u00f9ng truy c\u1eadp, m\u1ed9t th\u00f4ng b\u00e1o b\u1eadt l\u00ean (flyout notification) s\u1ebd xu\u1ea5t hi\u1ec7n, y\u00eau c\u1ea7u h\u1ecd \u201ct\u1ea3i l\u1ea1i trang b\u1eb1ng ch\u1ebf \u0111\u1ed9 Internet Explorer \u0111\u1ec3 t\u01b0\u01a1ng th\u00edch t\u1ed1t h\u01a1n\u201d.<\/p>\n<p>H\u00e0nh \u0111\u1ed9ng t\u01b0\u1edfng ch\u1eebng v\u00f4 h\u1ea1i n\u00e0y l\u1ea1i khi\u1ebfn tr\u00ecnh duy\u1ec7t chuy\u1ec3n t\u1eeb m\u00f4i tr\u01b0\u1eddng an to\u00e0n c\u1ee7a Edge sang n\u1ec1n IE l\u1ed7i th\u1eddi, n\u01a1i c\u00e1c l\u1edbp ph\u00f2ng v\u1ec7 b\u1ea3o m\u1eadt g\u1ea7n nh\u01b0 kh\u00f4ng c\u00f2n.<\/p>\n<h4>B\u01b0\u1edbc 2: Khai th\u00e1c l\u1ed7 h\u1ed5ng zero-day trong nh\u00e2n JavaScript c\u1ee7a IE\u200b<\/h4>\n<p>Ngay khi ng\u01b0\u1eddi d\u00f9ng k\u00edch ho\u1ea1t IE Mode, m\u00e3 \u0111\u1ed9c zero-day s\u1ebd \u0111\u01b0\u1ee3c k\u00edch ho\u1ea1t, khai th\u00e1c l\u1ed7 h\u1ed5ng trong Chakra Engine &#8211; b\u1ed9 x\u1eed l\u00fd JavaScript c\u0169 c\u1ee7a Internet Explorer.<\/p>\n<p>L\u1ed7 h\u1ed5ng n\u00e0y cho ph\u00e9p tin t\u1eb7c ch\u00e8n v\u00e0 th\u1ef1c thi m\u00e3 \u0111\u1ed9c t\u1eeb xa, chi\u1ebfm quy\u1ec1n \u0111i\u1ec1u khi\u1ec3n tr\u00ecnh duy\u1ec7t.<\/p>\n<h4>B\u01b0\u1edbc 3: Leo thang \u0111\u1eb7c quy\u1ec1n &#8211; chi\u1ebfm to\u00e0n quy\u1ec1n \u0111i\u1ec1u khi\u1ec3n h\u1ec7 th\u1ed1ng\u200b<\/h4>\n<p>Sau khi \u0111\u00e3 chi\u1ebfm quy\u1ec1n trong m\u00f4i tr\u01b0\u1eddng tr\u00ecnh duy\u1ec7t, k\u1ebb t\u1ea5n c\u00f4ng tri\u1ec3n khai payload th\u1ee9 hai \u0111\u1ec3 tho\u00e1t kh\u1ecfi \u201ch\u1ed9p c\u00e1t\u201d (sandbox) b\u1ea3o v\u1ec7 c\u1ee7a Edge.<br \/>\nT\u1eeb \u0111\u00f3, ch\u00fang c\u00f3 th\u1ec3:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">C\u00e0i \u0111\u1eb7t ph\u1ea7n m\u1ec1m gi\u00e1n \u0111i\u1ec7p ho\u1eb7c m\u00e3 \u0111\u1ed9c t\u1ed1ng ti\u1ec1n,<\/li>\n<li data-xf-list-type=\"ul\">Truy c\u1eadp d\u1eef li\u1ec7u h\u1ec7 th\u1ed1ng,<\/li>\n<li data-xf-list-type=\"ul\">Di chuy\u1ec3n sang c\u00e1c m\u00e1y kh\u00e1c trong c\u00f9ng m\u1ea1ng doanh nghi\u1ec7p,<\/li>\n<li data-xf-list-type=\"ul\">\u0110\u00e1nh c\u1eafp th\u00f4ng tin nh\u1ea1y c\u1ea3m.<\/li>\n<\/ul>\n<p>To\u00e0n b\u1ed9 qu\u00e1 tr\u00ecnh n\u00e0y di\u1ec5n ra \u00e2m th\u1ea7m, kh\u00f4ng c\u1ea3nh b\u00e1o, khi\u1ebfn ng\u01b0\u1eddi d\u00f9ng kh\u00f3 c\u00f3 th\u1ec3 nh\u1eadn bi\u1ebft.<\/p>\n<p>Theo Microsoft, nh\u00f3m t\u1ea5n c\u00f4ng n\u00e0y nh\u1eafm v\u00e0o c\u00e1c t\u1ed5 ch\u1ee9c v\u1eabn c\u00f2n ph\u1ee5 thu\u1ed9c v\u00e0o c\u00f4ng ngh\u1ec7 c\u0169 nh\u01b0:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">\u1ee8ng d\u1ee5ng doanh nghi\u1ec7p n\u1ed9i b\u1ed9 s\u1eed d\u1ee5ng ActiveX,<\/li>\n<li data-xf-list-type=\"ul\">H\u1ec7 th\u1ed1ng qu\u1ea3n l\u00fd camera ho\u1eb7c thi\u1ebft b\u1ecb an ninh c\u0169,<\/li>\n<li data-xf-list-type=\"ul\">M\u1ed9t s\u1ed1 c\u1ed5ng th\u00f4ng tin h\u00e0nh ch\u00ednh v\u1eabn y\u00eau c\u1ea7u ch\u1ea1y b\u1eb1ng IE.<\/li>\n<\/ul>\n<p>\u0110\u00e2y l\u00e0 \u0111\u1ed1i t\u01b0\u1ee3ng d\u1ec5 b\u1ecb t\u1ed5n th\u01b0\u01a1ng nh\u1ea5t, b\u1edfi h\u1ecd bu\u1ed9c ph\u1ea3i gi\u1eef IE Mode \u0111\u1ec3 truy c\u1eadp h\u1ec7 th\u1ed1ng, trong khi c\u01a1 ch\u1ebf b\u1ea3o v\u1ec7 hi\u1ec7n \u0111\u1ea1i c\u1ee7a Edge kh\u00f4ng c\u00f2n ph\u00e1t huy t\u00e1c d\u1ee5ng trong m\u00f4i tr\u01b0\u1eddng n\u00e0y.<\/p>\n<p>Cu\u1ed9c t\u1ea5n c\u00f4ng n\u00e0y \u0111\u01b0\u1ee3c \u0111\u00e1nh gi\u00e1 nghi\u00eam tr\u1ecdng v\u00ec:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">Khai th\u00e1c zero-day ch\u01b0a \u0111\u01b0\u1ee3c v\u00e1 trong m\u00f4i tr\u01b0\u1eddng c\u0169,<\/li>\n<li data-xf-list-type=\"ul\">Cho ph\u00e9p chi\u1ebfm to\u00e0n quy\u1ec1n \u0111i\u1ec1u khi\u1ec3n m\u00e1y t\u00ednh,<\/li>\n<li data-xf-list-type=\"ul\">D\u1ec5 d\u00e0ng lan r\u1ed9ng trong m\u1ea1ng n\u1ed9i b\u1ed9 doanh nghi\u1ec7p,<\/li>\n<li data-xf-list-type=\"ul\">C\u00f3 th\u1ec3 d\u1eabn \u0111\u1ebfn r\u00f2 r\u1ec9 d\u1eef li\u1ec7u ho\u1eb7c m\u00e3 \u0111\u1ed9c t\u1ed1ng ti\u1ec1n quy m\u00f4 l\u1edbn.<\/li>\n<\/ul>\n<p>N\u00f3i c\u00e1ch kh\u00e1c, IE Mode \u0111ang tr\u1edf th\u00e0nh \u201cc\u00e1nh c\u1eeda h\u1eadu\u201d (backdoor) h\u1ee3p ph\u00e1p m\u00e0 hacker c\u00f3 th\u1ec3 l\u1ee3i d\u1ee5ng.<\/p>\n<p>Ngay sau khi ph\u00e1t hi\u1ec7n chi\u1ebfn d\u1ecbch, Microsoft \u0111\u00e3 tri\u1ec3n khai c\u00e1c bi\u1ec7n ph\u00e1p kh\u1ea9n c\u1ea5p, bao g\u1ed3m:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">Gi\u1edbi h\u1ea1n quy\u1ec1n truy c\u1eadp IE Mode,<\/li>\n<li data-xf-list-type=\"ul\">G\u1ee1 b\u1ecf c\u00e1c ph\u00edm t\u1eaft v\u00e0 menu ng\u1eef c\u1ea3nh cho ph\u00e9p chuy\u1ec3n ch\u1ebf \u0111\u1ed9 nhanh,<\/li>\n<li data-xf-list-type=\"ul\">Duy tr\u00ec h\u1ed7 tr\u1ee3 IE Mode ch\u1ec9 cho doanh nghi\u1ec7p c\u00f3 ch\u00ednh s\u00e1ch qu\u1ea3n tr\u1ecb r\u00f5 r\u00e0ng, tr\u00e1nh ng\u01b0\u1eddi d\u00f9ng c\u00e1 nh\u00e2n t\u1ef1 b\u1eadt ch\u1ebf \u0111\u1ed9 n\u00e0y.<\/li>\n<\/ul>\n<p>\u0110\u1ec3 b\u1ea3o v\u1ec7 tr\u01b0\u1edbc h\u00ecnh th\u1ee9c t\u1ea5n c\u00f4ng m\u1edbi n\u00e0y, chuy\u00ean gia khuy\u1ebfn c\u00e1o:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">Kh\u00f4ng truy c\u1eadp c\u00e1c trang y\u00eau c\u1ea7u m\u1edf b\u1eb1ng IE Mode, tr\u1eeb khi \u0111\u00f3 l\u00e0 h\u1ec7 th\u1ed1ng n\u1ed9i b\u1ed9 \u0111\u01b0\u1ee3c ki\u1ec3m so\u00e1t ch\u1eb7t ch\u1ebd.<\/li>\n<li data-xf-list-type=\"ul\">V\u00f4 hi\u1ec7u h\u00f3a IE Mode n\u1ebfu kh\u00f4ng c\u1ea7n thi\u1ebft.<\/li>\n<li data-xf-list-type=\"ul\">C\u1eadp nh\u1eadt Microsoft Edge v\u00e0 Windows th\u01b0\u1eddng xuy\u00ean \u0111\u1ec3 nh\u1eadn b\u1ea3n v\u00e1 m\u1edbi nh\u1ea5t.<\/li>\n<li data-xf-list-type=\"ul\">\u0110\u00e0o t\u1ea1o nh\u00e2n vi\u00ean nh\u1eadn bi\u1ebft c\u00e1c c\u1ea3nh b\u00e1o v\u00e0 k\u1ef9 thu\u1eadt l\u1eeba \u0111\u1ea3o li\u00ean quan \u0111\u1ebfn \u201ct\u01b0\u01a1ng th\u00edch tr\u00ecnh duy\u1ec7t\u201d.<\/li>\n<li data-xf-list-type=\"ul\">Chuy\u1ec3n \u0111\u1ed5i d\u1ea7n sang n\u1ec1n t\u1ea3ng hi\u1ec7n \u0111\u1ea1i, thay v\u00ec ti\u1ebfp t\u1ee5c ph\u1ee5 thu\u1ed9c v\u00e0o c\u00f4ng ngh\u1ec7 c\u0169 nh\u01b0 ActiveX hay Flash.<\/li>\n<\/ul>\n<p>M\u1ed9t t\u00ednh n\u0103ng \u0111\u01b0\u1ee3c t\u1ea1o ra \u0111\u1ec3 h\u1ed7 tr\u1ee3 c\u00f4ng vi\u1ec7c, n\u1ebfu kh\u00f4ng \u0111\u01b0\u1ee3c qu\u1ea3n l\u00fd \u0111\u00fang c\u00e1ch, c\u00f3 th\u1ec3 tr\u1edf th\u00e0nh c\u1eeda ng\u00f5 cho hacker x\u00e2m nh\u1eadp h\u1ec7 th\u1ed1ng. Trong k\u1ef7 nguy\u00ean s\u1ed1, vi\u1ec7c duy tr\u00ec nh\u1eefng c\u00f4ng ngh\u1ec7 l\u1ed7i th\u1eddi ch\u1eb3ng kh\u00e1c n\u00e0o gi\u1eef l\u1ea1i c\u00e1nh c\u1eeda m\u1edf s\u1eb5n cho k\u1ebb x\u1ea5u, ch\u1ec9 c\u00f2n l\u00e0 v\u1ea5n \u0111\u1ec1 th\u1eddi gian tr\u01b0\u1edbc khi ch\u00fang b\u01b0\u1edbc v\u00e0o.<\/p>\n<div style=\"text-align: right\"><b><i>WhiteHat<\/i><\/b>\u200b<\/div>\n<div style=\"text-align: right;margin-top: 16px\"><i>Theo: <a href=\"https:\/\/whitehat.vn\/threads\/hacker-khai-thac-loi-zero-day-trong-ie-mode-de-kiem-soat-thiet-bi-nguoi-dung.18834\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/whitehat.vn\/threads\/hacker-khai-thac-loi-zero-day-trong-ie-mode-de-kiem-soat-thiet-bi-nguoi-dung.18834\/<\/a><\/i><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Gi\u1eefa l\u00fac Internet Explorer (IE) \u0111\u00e3 ch\u00ednh th\u1ee9c \u201cngh\u1ec9 h\u01b0u\u201d, m\u1ed9t chi\u1ebfn d\u1ecbch t\u1ea5n c\u00f4ng m\u1ea1ng tinh vi m\u1edbi l\u1ea1i b\u1ea5t ng\u1edd khai th\u00e1c ch\u00ednh t\u00ednh n\u0103ng IE Mode trong tr\u00ecnh duy\u1ec7t Microsoft Edge, v\u1ed1n \u0111\u01b0\u1ee3c t\u1ea1o ra \u0111\u1ec3 gi\u00fap ng\u01b0\u1eddi d\u00f9ng truy c\u1eadp c\u00e1c trang web c\u0169. \u200b Chi\u1ebfn d\u1ecbch tinh vi n\u00e0y xu\u1ea5t [&hellip;]<\/p>\n","protected":false},"author":46,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[33],"tags":[],"class_list":["post-10541","post","type-post","status-publish","format-standard","hentry","category-tin-tuc-cua-vien"],"_links":{"self":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/10541","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/comments?post=10541"}],"version-history":[{"count":0,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/10541\/revisions"}],"wp:attachment":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/media?parent=10541"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/categories?post=10541"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/tags?post=10541"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}