C\u00e1c CNG (Cryptographic Next Generation) Key Iolation d\u1ecbch v\u1ee5 cung c\u1ea5p c\u00e1ch ly quy tr\u00ecnh kh\u00f3a \u0111\u1ed1i v\u1edbi kh\u00f3a c\u00e1 nh\u00e2n v\u00e0 m\u1ed9t \u1ed1 ho\u1ea1t \u0111\u1ed9ng m\u1eadt m\u00e3 li\u00ean quan <\/p>\n
<\/p>\n
<\/p>\n
N\u1ed9i Dung:<\/h2>\n
C\u00e1c CNG (Cryptographic Next Generation) Key Isolation<\/strong> d\u1ecbch v\u1ee5 cung c\u1ea5p c\u00e1ch ly quy tr\u00ecnh kh\u00f3a \u0111\u1ed1i v\u1edbi kh\u00f3a c\u00e1 nh\u00e2n v\u00e0 m\u1ed9t s\u1ed1 ho\u1ea1t \u0111\u1ed9ng m\u1eadt m\u00e3 li\u00ean quan theo y\u00eau c\u1ea7u c\u1ee7a Ti\u00eau chu\u1ea9n chung<\/strong>. \u0110\u01b0\u1eddng d\u1eabn m\u1eb7c \u0111\u1ecbnh \u0111\u1ebfn t\u1ec7p thi h\u00e0nh \u0111\u01b0\u1ee3c li\u00ean k\u1ebft v\u1edbi d\u1ecbch v\u1ee5 C\u00e1ch ly kh\u00f3a CNG l\u00e0 C: windows system32 lsass.exe.B\u1ea1n \u0111ang xem: Cng key isolation l\u00e0 g\u00ec<\/strong><\/p>\n C\u00e1c CNG kh\u00f3a c\u00e1ch ly<\/strong> d\u1ecbch v\u1ee5 ch\u1ea1y nh\u01b0 m\u1ed9t LocalSystem trong m\u1ed9t quy tr\u00ecnh \u0111\u01b0\u1ee3c chia s\u1ebb (\u0111\u01b0\u1ee3c l\u01b0u tr\u1eef trong LSA<\/strong> qu\u00e1 tr\u00ecnh). D\u1ecbch v\u1ee5 l\u01b0u tr\u1eef c\u00e1c kh\u00f3a t\u1ed3n t\u1ea1i l\u00e2u d\u00e0i \u0111\u1ec3 x\u00e1c th\u1ef1c ng\u01b0\u1eddi d\u00f9ng trong d\u1ecbch v\u1ee5 Winlogon. V\u00ed d\u1ee5: d\u1ecbch v\u1ee5 C\u00e1ch ly kh\u00f3a CNG s\u1ebd l\u01b0u tr\u1eef kh\u00f3a m\u1ea1ng kh\u00f4ng d\u00e2y ho\u1eb7c th\u00f4ng tin m\u1eadt m\u00e3 c\u1ea7n thi\u1ebft cho th\u1ebb th\u00f4ng minh. T\u1ea5t c\u1ea3 c\u00e1c ho\u1ea1t \u0111\u1ed9ng \u0111\u01b0\u1ee3c th\u1ef1c hi\u1ec7n b\u1edfi d\u1ecbch v\u1ee5 C\u00e1ch ly Kh\u00f3a CNG \u0111\u01b0\u1ee3c th\u1ef1c hi\u1ec7n b\u1eb1ng c\u00e1ch l\u00e0m theo Ti\u00eau chu\u1ea9n chung<\/strong> c\u00e1c y\u00eau c\u1ea7u.<\/p>\n B\u1ea1n \u0111ang xem: Cng key isolation l\u00e0 g\u00ec<\/a><\/p>\n Trong tr\u01b0\u1eddng h\u1ee3p d\u1ecbch v\u1ee5 C\u00e1ch ly kh\u00f3a CNG kh\u00f4ng t\u1ea3i ho\u1eb7c kh\u1edfi ch\u1ea1y \u0111\u01b0\u1ee3c, h\u00e0nh Httl.com.vn\/wiki \u0111\u01b0\u1ee3c ghi l\u1ea1i trong Nh\u1eadt k\u00fd s\u1ef1 ki\u1ec7n<\/strong>. H\u1ea7u h\u1ebft th\u1eddi gian, d\u1ecbch v\u1ee5 kh\u00f4ng th\u1ec3 kh\u1edfi \u0111\u1ed9ng v\u00ec Cu\u1ed9c g\u1ecdi th\u1ee7 t\u1ee5c t\u1eeb xa (RPC)<\/strong> d\u1ecbch v\u1ee5 bu\u1ed9c ph\u1ea3i d\u1eebng ho\u1eb7c v\u00f4 hi\u1ec7u h\u00f3a. N\u1ebfu d\u1ecbch v\u1ee5 C\u00e1ch ly Kh\u00f3a CNG b\u1ecb d\u1eebng, Giao th\u1ee9c x\u00e1c th\u1ef1c c\u00f3 th\u1ec3 m\u1edf r\u1ed9ng<\/strong> (EAP) s\u1ebd kh\u00f4ng kh\u1edfi \u0111\u1ed9ng v\u00e0 kh\u1edfi ch\u1ea1y \u0111\u01b0\u1ee3c khi kh\u1edfi \u0111\u1ed9ng.<\/p>\n Nh\u01b0 b\u1ea1n s\u1ebd th\u1ea5y b\u00ean d\u01b0\u1edbi, D\u1ecbch v\u1ee5 c\u00e1ch ly kh\u00f3a CNG<\/strong> chia s\u1ebb m\u1ed9t t\u1ec7p th\u1ef1c thi (lsass.exe<\/strong>) c\u00f9ng m\u1ed9t s\u1ed1 d\u1ecbch v\u1ee5 kh\u00e1c.<\/p>\n LSASS<\/strong> Httl.com.vn\/wiki\u1ebft t\u1eaft c\u1ee7a D\u1ecbch v\u1ee5 h\u1ec7 th\u1ed1ng con c\u1ee7a c\u01a1 quan an ninh \u0111\u1ecba ph\u01b0\u01a1ng<\/strong>. Ch\u00ednh h\u00e3ng lsass.exe<\/strong> l\u00e0 m\u1ed9t ph\u1ea7n th\u00e0nh ph\u1ea7n ph\u1ea7n m\u1ec1m h\u1ee3p ph\u00e1p c\u1ee7a m\u00f4i tr\u01b0\u1eddng Windows. T\u1ec7p th\u1ef1c thi \u0111\u01b0\u1ee3c coi l\u00e0 m\u1ed9t quy tr\u00ecnh th\u1ea9m quy\u1ec1n c\u1ee5c b\u1ed9 c\u1ee7a h\u1ec7 th\u1ed1ng c\u1ed1t l\u00f5i \u0111\u01b0\u1ee3c t\u00edch h\u1ee3p s\u1eb5n trong Windows. H\u1ec7 \u0111i\u1ec1u h\u00e0nh v\u1ecb tr\u00ed m\u1eb7c \u0111\u1ecbnh lsass.exe<\/strong> trong C: Windows H\u1ec7 th\u1ed1ng 32<\/strong>.<\/p>\n C\u00e1c Lass.exe<\/strong> quy tr\u00ecnh x\u1eed l\u00fd b\u1ed1n d\u1ecbch v\u1ee5 x\u00e1c th\u1ef1c ch\u00ednh trong Windows:<\/p>\n KeyIso (CNG Key Isolation)<\/strong> – D\u1ecbch v\u1ee5 x\u00e1c th\u1ef1c quan tr\u1ecdng nh\u1ea5t \u0111\u01b0\u1ee3c l\u01b0u tr\u1eef trong quy tr\u00ecnh LSA. N\u00f3 cung c\u1ea5p c\u00e1ch ly quy tr\u00ecnh kh\u00f3a \u0111\u1ed1i v\u1edbi kh\u00f3a c\u00e1 nh\u00e2n v\u00e0 c\u00e1c ho\u1ea1t \u0111\u1ed9ng m\u1eadt m\u00e3 li\u00ean quan.EFS (H\u1ec7 th\u1ed1ng t\u1ec7p m\u00e3 h\u00f3a)<\/strong> – M\u1ed9t c\u00f4ng ngh\u1ec7 m\u00e3 h\u00f3a t\u1ec7p c\u1ed1t l\u00f5i ch\u1ee7 y\u1ebfu \u0111\u01b0\u1ee3c s\u1eed d\u1ee5ng \u0111\u1ec3 l\u01b0u tr\u1eef c\u00e1c t\u1ec7p \u0111\u01b0\u1ee3c m\u00e3 h\u00f3a tr\u00ean kh\u1ed1i l\u01b0\u1ee3ng h\u1ec7 th\u1ed1ng t\u1ec7p NTFS. furnituremaisak.com\u1ec7c d\u1eebng d\u1ecbch v\u1ee5 n\u00e0y s\u1ebd ng\u0103n h\u1ec7 th\u1ed1ng c\u1ee7a b\u1ea1n truy c\u1eadp v\u00e0o c\u00e1c t\u1ec7p \u0111\u01b0\u1ee3c m\u00e3 h\u00f3a.SamSS (Ng\u01b0\u1eddi qu\u1ea3n l\u00fd t\u00e0i kho\u1ea3n b\u1ea3o m\u1eadt) <\/strong>– M\u1ee5c \u0111\u00edch ch\u00ednh c\u1ee7a d\u1ecbch v\u1ee5 n\u00e0y l\u00e0 ho\u1ea1t \u0111\u1ed9ng nh\u01b0 m\u1ed9t ng\u1ecdn h\u1ea3i \u0111\u0103ng v\u00e0 b\u00e1o hi\u1ec7u c\u00e1c d\u1ecbch v\u1ee5 kh\u00e1c khi Ng\u01b0\u1eddi qu\u1ea3n l\u00fd t\u00e0i kho\u1ea3n b\u1ea3o m\u1eadt<\/strong>(SAM)<\/strong> s\u1eb5n s\u00e0ng nh\u1eadn y\u00eau c\u1ea7u. furnituremaisak.com\u1ec7c d\u1eebng d\u1ecbch v\u1ee5 n\u00e0y s\u1ebd ng\u0103n kh\u00f4ng cho c\u00e1c d\u1ecbch v\u1ee5 kh\u00e1c d\u1ef1a v\u00e0o Tr\u00ecnh qu\u1ea3n l\u00fd t\u00e0i kho\u1ea3n b\u1ea3o m\u1eadt \u0111\u01b0\u1ee3c th\u00f4ng b\u00e1o. \u0110i\u1ec1u n\u00e0y s\u1ebd t\u1ea1o ra hi\u1ec7u \u1ee9ng qu\u1ea3 c\u1ea7u tuy\u1ebft khi\u1ebfn nhi\u1ec1u d\u1ecbch v\u1ee5 ph\u1ee5 thu\u1ed9c b\u1ecb l\u1ed7i ho\u1eb7c kh\u1edfi \u0111\u1ed9ng kh\u00f4ng ch\u00ednh x\u00e1c.Ch\u00ednh s\u00e1ch IPSEC c\u1ee5c b\u1ed9<\/strong> – Qu\u1ea3n l\u00fd v\u00e0 b\u1eaft \u0111\u1ea7u ISAKMP \/ Oakley (IKE)<\/strong> v\u00e0 c\u00e1c tr\u00ecnh \u0111i\u1ec1u khi\u1ec3n b\u1ea3o m\u1eadt IP kh\u00e1c nhau trong m\u00e1y ch\u1ee7 Windows<\/strong>.<\/p>\n Xem th\u00eam: <\/a><\/p>\n Tuy nhi\u00ean, c\u00f3 m\u1ed9t lo\u1ea1i Httl.com.vn\/wikirus copy-cat \u0111\u00e3 \u0111\u01b0\u1ee3c bi\u1ebft \u0111\u1ebfn \u0111\u00e3 l\u00e2y nhi\u1ec5m c\u00e1c h\u1ec7 th\u1ed1ng b\u1eb1ng c\u00e1ch ng\u1ee5y trang v\u00e0o t\u1ec7p th\u1ef1c thi Lsass. Quy tr\u00ecnh t\u01b0\u01a1ng t\u1ef1, nh\u01b0ng kh\u00f4ng gi\u1ed1ng v\u1edbi ch\u00ednh h\u00e3ng D\u1ecbch v\u1ee5 h\u1ec7 th\u1ed1ng con c\u1ee7a c\u01a1 quan an ninh \u0111\u1ecba ph\u01b0\u01a1ng<\/strong>. Qu\u00e1 tr\u00ecnh \u00e1c \u00fd \u0111\u01b0\u1ee3c \u0111\u1eb7t t\u00ean isass.exe,<\/strong> tr\u00e1i ng\u01b0\u1ee3c v\u1edbi quy tr\u00ecnh h\u1ee3p ph\u00e1p \u0111\u01b0\u1ee3c \u0111\u1eb7t t\u00ean lsass.exe<\/strong>. N\u1ebfu b\u1ea1n th\u1ea5y r\u1eb1ng qu\u00e1 tr\u00ecnh n\u00e0y b\u1eaft \u0111\u1ea7u b\u1eb1ng v\u1ed1n T\u00f4i<\/strong> thay v\u00ec Httl.com.vn\/wiki\u1ebft th\u01b0\u1eddng L<\/strong>, h\u1ec7 th\u1ed1ng c\u1ee7a b\u1ea1n c\u00f3 th\u1ec3 b\u1ecb nhi\u1ec5m.<\/p>\n B\u1ea1n c\u00f3 th\u1ec3 x\u00e1c nh\u1eadn l\u00fd thuy\u1ebft n\u00e0y b\u1eb1ng c\u00e1ch ki\u1ec3m tra v\u1ecb tr\u00ed c\u1ee7a lsass.exe. N\u00f3i chung, n\u1ebfu Lsass<\/strong> th\u1ef1c thi \u0111\u01b0\u1ee3c \u0111\u1eb7t t\u1ea1i C: Windows H\u1ec7 th\u1ed1ng 32<\/strong>, b\u1ea1n c\u00f3 th\u1ec3 y\u00ean t\u00e2m cho r\u1eb1ng \u0111\u00f3 l\u00e0 D\u1ecbch v\u1ee5 h\u1ec7 th\u1ed1ng con c\u1ee7a c\u01a1 quan an ninh \u0111\u1ecba ph\u01b0\u01a1ng<\/strong>. \u0110\u1ec3 th\u1ef1c hi\u1ec7n Httl.com.vn\/wiki\u1ec7c n\u00e0y, h\u00e3y m\u1edf Tr\u00ecnh qu\u1ea3n l\u00fd t\u00e1c v\u1ee5 (Ctrl + Shift + Esc<\/strong>) v\u00e0 cu\u1ed9n xu\u1ed1ng trong danh s\u00e1ch Quy tr\u00ecnh \u0111\u1ec3 Quy tr\u00ecnh C\u01a1 quan An ninh \u0110\u1ecba ph\u01b0\u01a1ng. <\/strong>Nh\u1ea5p chu\u1ed9t ph\u1ea3i v\u00e0o n\u00f3 v\u00e0 ch\u1ecdn M\u1edf v\u1ecb tr\u00ed file<\/strong>. N\u1ebfu quy tr\u00ecnh kh\u00f4ng n\u1eb1m trong H\u1ec7 th\u1ed1ng 32, b\u1ea1n c\u00f3 th\u1ec3 ch\u1eafc ch\u1eafn r\u1eb1ng m\u00ecnh \u0111ang x\u1eed l\u00fd s\u1ef1 l\u00e2y nhi\u1ec5m ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i.<\/p>\n C\u00e1c \u201cIsass.exe\u201d<\/strong> l\u00e0 m\u1ed9t lo\u1ea1i Httl.com.vn\/wikirus trojan v\u1edbi c\u00e1c thu\u1ed9c t\u00ednh keylogging \u0111\u01b0\u1ee3c bi\u1ebft \u0111\u1ebfn l\u00e0 S\u00e2u b\u1ecd<\/strong> gia \u0111\u00ecnh. M\u1ee5c \u0111\u00edch ch\u00ednh c\u1ee7a n\u00f3 l\u00e0 \u00e2m th\u1ea7m thu th\u1eadp d\u1eef li\u1ec7u t\u1eeb h\u1ec7 th\u1ed1ng c\u1ee7a b\u1ea1n. B\u1eb1ng c\u00e1ch \u0111\u0103ng k\u00fd m\u1ecdi t\u1ed5 h\u1ee3p ph\u00edm b\u1ea1n nh\u1eadp, Httl.com.vn\/wiki-r\u00fat \u0111\u01b0\u1ee3c c\u1ea5u h\u00ecnh \u0111\u1ec3 truy l\u00f9ng t\u00ean ng\u01b0\u1eddi d\u00f9ng t\u00e0i kho\u1ea3n, m\u1eadt kh\u1ea9u, s\u1ed1 th\u1ebb t\u00edn d\u1ee5ng v\u00e0 b\u1ea5t k\u1ef3 d\u1eef li\u1ec7u nh\u1ea1y c\u1ea3m n\u00e0o kh\u00e1c cu\u1ed1i c\u00f9ng \u0111\u01b0\u1ee3c s\u1eed d\u1ee5ng cho m\u1ee5c \u0111\u00edch thu l\u1ee3i b\u1ea5t h\u1ee3p ph\u00e1p.<\/p>\n Httl.com.vn\/wikirus \u0111\u00e3 xu\u1ea5t hi\u1ec7n \u0111\u01b0\u1ee3c v\u00e0i n\u0103m v\u00e0 Microsoft \u0111\u00e3 c\u00f3 nh\u1eefng bi\u1ec7n ph\u00e1p ch\u1ed1ng l\u1ea1i n\u00f3. N\u1ebfu ph\u00e1t hi\u1ec7n m\u00ecnh b\u1ecb nhi\u1ec5m, b\u1ea1n c\u00f3 th\u1ec3 s\u1eed d\u1ee5ng c\u00f4ng c\u1ee5 Lo\u1ea1i b\u1ecf ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i c\u1ee7a Microsoft \u0111\u1ec3 x\u00f3a m\u1ecdi d\u1ea5u v\u1ebft c\u1ee7a S\u00e2u b\u1ecd<\/strong>. Sau nhi\u1ec1u th\u00e1ng l\u00e2y nhi\u1ec5m cho v\u00f4 s\u1ed1 ng\u01b0\u1eddi d\u00f9ng Windows 7 v\u00e0 XP, Microsoft \u0111\u00e3 v\u00e1 l\u1ed7 h\u1ed5ng cho ph\u00e9p Httl.com.vn\/wikirus l\u00e2y nhi\u1ec5m sang m\u00e1y Windows. Hi\u1ec7n t\u1ea1i, b\u1ea1n kh\u00f4ng th\u1ec3 b\u1ecb nhi\u1ec5m s\u00e2u Sasser n\u1eefa n\u1ebfu b\u1ea1n c\u00f3 b\u1ea3n c\u1eadp nh\u1eadt b\u1ea3o m\u1eadt Windows m\u1edbi nh\u1ea5t.<\/p>\n Kh\u00f4ng. D\u1ecbch v\u1ee5 c\u00e1ch ly kh\u00f3a CNG l\u00e0 m\u1ed9t quy tr\u00ecnh h\u1ec7 th\u1ed1ng quan tr\u1ecdng c\u1ea7n thi\u1ebft \u0111\u1ec3 l\u01b0u tr\u1eef th\u00f4ng tin m\u1eadt m\u00e3 m\u1ed9t c\u00e1ch an to\u00e0n. Trong m\u1ecdi tr\u01b0\u1eddng h\u1ee3p kh\u00f4ng n\u00ean h\u1ee3p ph\u00e1p D\u1ecbch v\u1ee5 c\u00e1ch ly kh\u00f3a CNG (KeyISO)<\/strong> n\u00ean b\u1ecb v\u00f4 hi\u1ec7u h\u00f3a v\u0129nh Httl.com.vn\/wiki\u1ec5n.<\/p>\n K\u1ebft th\u00fac qu\u00e1 tr\u00ecnh lsass.exe trong Tr\u00ecnh qu\u1ea3n l\u00fd t\u00e1c v\u1ee5 c\u0169ng s\u1ebd d\u1eebng d\u1ecbch v\u1ee5 c\u00e1ch ly kh\u00f3a CNG. Nh\u01b0ng h\u00e3y nh\u1edb r\u1eb1ng \u0111i\u1ec1u n\u00e0y c\u00f3 th\u1ec3 khi\u1ebfn h\u1ec7 th\u1ed1ng c\u1ee7a b\u1ea1n bu\u1ed9c ph\u1ea3i t\u1eaft. V\u00ec n\u00f3 ki\u1ec3m so\u00e1t ph\u1ea7n quan tr\u1ecdng nh\u1ea5t c\u1ee7a b\u1ea3o m\u1eadt nh\u1eadt k\u00fd, c\u00e1ch ly kh\u00f3a CNG l\u00e0 m\u1ed9t ch\u1ee9c n\u0103ng thi\u1ebft y\u1ebfu c\u1ee7a Windows.<\/p>\n Tuy nhi\u00ean, n\u1ebfu b\u1ea1n nghi ng\u1edd r\u1eb1ng D\u1ecbch v\u1ee5 c\u00e1ch ly kh\u00f3a CNG <\/strong>kh\u00f4ng ho\u1ea1t \u0111\u1ed9ng b\u00ecnh th\u01b0\u1eddng ho\u1eb7c \u0111ang g\u00e2y ra s\u1ef1 c\u1ed1 v\u1edbi h\u1ec7 th\u1ed1ng c\u1ee7a b\u1ea1n, b\u1ea1n c\u00f3 th\u1ec3 th\u1eed kh\u1edfi \u0111\u1ed9ng l\u1ea1i d\u1ecbch v\u1ee5. \u0110\u1ec3 th\u1ef1c hi\u1ec7n Httl.com.vn\/wiki\u1ec7c n\u00e0y, h\u00e3y m\u1edf c\u1eeda s\u1ed5 Run (Ph\u00edm Windows + R<\/strong>) v\u00e0 lo\u1ea1i serHttl.com.vn\/wikices.msc<\/strong>. Sau \u0111\u00f3, \u0111\u00e1nh \u0110i v\u00e0o<\/strong> \u0111\u1ec3 m\u1edf D\u1ecbch v\u1ee5<\/strong> c\u1eeda s\u1ed5.<\/p>\nGi\u1ea3i th\u00edch s\u1ef1 c\u00f4 l\u1eadp ch\u00ednh c\u1ee7a CNG<\/strong><\/h3>\n
Lsass.exe l\u00e0 g\u00ec?<\/strong><\/h3>\n
R\u1ee7i ro b\u1ea3o m\u1eadt ti\u1ec1m \u1ea9n v\u1edbi lsass.exe<\/strong><\/h3>\n
T\u00f4i c\u00f3 n\u00ean t\u1eaft d\u1ecbch v\u1ee5 c\u00e1ch ly kh\u00f3a CNG kh\u00f4ng?<\/strong><\/h3>\n