
{"id":3789,"date":"2024-03-15T08:39:05","date_gmt":"2024-03-15T08:39:05","guid":{"rendered":"https:\/\/chuyendoiso.haiphong.gov.vn\/?p=3789"},"modified":"2025-04-17T08:41:42","modified_gmt":"2025-04-17T08:41:42","slug":"moi-de-doa-tiep-dien-cua-cac-lo-hong-bao-mat-chua-duoc-khac-phuc","status":"publish","type":"post","link":"https:\/\/chuyendoiso.haiphong.gov.vn\/index.php\/2024\/03\/15\/moi-de-doa-tiep-dien-cua-cac-lo-hong-bao-mat-chua-duoc-khac-phuc\/","title":{"rendered":"M\u1ed1i \u0111e d\u1ecda ti\u1ebfp di\u1ec5n c\u1ee7a c\u00e1c l\u1ed7 h\u1ed5ng b\u1ea3o m\u1eadt ch\u01b0a \u0111\u01b0\u1ee3c kh\u1eafc ph\u1ee5c"},"content":{"rendered":"<h4><strong>Ph\u1ea7n m\u1ec1m ch\u01b0a \u0111\u01b0\u1ee3c v\u00e1 l\u00e0 m\u1ed9t \u0111o\u1ea1n m\u00e3 m\u00e1y t\u00ednh c\u00f3 ch\u1ee9a c\u00e1c \u0111i\u1ec3m y\u1ebfu b\u1ea3o m\u1eadt \u0111\u00e3 bi\u1ebft. C\u00e1c l\u1ed7 h\u1ed5ng\u00a0ch\u01b0a \u0111\u01b0\u1ee3c v\u00e1 l\u00e0 nh\u1eefng \u0111i\u1ec3m y\u1ebfu cho ph\u00e9p k\u1ebb t\u1ea5n c\u00f4ng l\u1ee3i d\u1ee5ng m\u1ed9t l\u1ed7i b\u1ea3o m\u1eadt \u0111\u00e3 bi\u1ebft ch\u01b0a \u0111\u01b0\u1ee3c v\u00e1 b\u1eb1ng c\u00e1ch ch\u1ea1y m\u00e3 \u0111\u1ed9c. Khi c\u00e1c nh\u00e0 cung c\u1ea5p ph\u1ea7n m\u1ec1m bi\u1ebft \u0111\u1ebfn c\u00e1c l\u1ed7 h\u1ed5ng n\u00e0y, h\u1ecd s\u1ebd vi\u1ebft m\u1ed9t ph\u1ea7n b\u1ed5 sung v\u00e0o \u0111o\u1ea1n m\u00e3, \u0111\u01b0\u1ee3c g\u1ecdi l\u00e0 \u201cb\u1ea3n v\u00e1\u201d nh\u1eb1m b\u1ea3o v\u1ec7 nh\u1eefng \u0111i\u1ec3m y\u1ebfu n\u00e0y.<\/strong><\/h4>\n<p>K\u1ebb th\u00f9 th\u01b0\u1eddng th\u0103m d\u00f2 ph\u1ea7n m\u1ec1m c\u1ee7a b\u1ea1n, t\u00ecm ki\u1ebfm c\u00e1c h\u1ec7 th\u1ed1ng ch\u01b0a \u0111\u01b0\u1ee3c v\u00e1 v\u00e0 t\u1ea5n c\u00f4ng ch\u00fang tr\u1ef1c ti\u1ebfp ho\u1eb7c gi\u00e1n ti\u1ebfp. Vi\u1ec7c s\u1eed d\u1ee5ng ph\u1ea7n m\u1ec1m ch\u01b0a \u0111\u01b0\u1ee3c v\u00e1 l\u00e0 m\u1ed9t vi\u1ec7c r\u1ea5t r\u1ee7i ro. \u0110i\u1ec1u n\u00e0y l\u00e0 do nh\u1eefng k\u1ebb t\u1ea5n c\u00f4ng c\u00f3 th\u1eddi gian \u0111\u1ec3 nh\u1eadn bi\u1ebft v\u1ec1 c\u00e1c l\u1ed7 h\u1ed5ng ch\u01b0a \u0111\u01b0\u1ee3c v\u00e1\u00a0c\u1ee7a ph\u1ea7n m\u1ec1m tr\u01b0\u1edbc khi b\u1ea3n v\u00e1 \u0111\u01b0\u1ee3c xu\u1ea5t hi\u1ec7n.<\/p>\n<p>M\u1ed9t b\u00e1o c\u00e1o cho th\u1ea5y c\u00e1c l\u1ed7 h\u1ed5ng ch\u01b0a \u0111\u01b0\u1ee3c v\u00e1 l\u00e0 c\u00e1c h\u01b0\u1edbng t\u1ea5n c\u00f4ng ch\u00ednh c\u1ee7a c\u00e1c ransomware. Nh\u1eefng ghi ch\u00e9p cho th\u1ea5y r\u1eb1ng v\u00e0o n\u0103m 2021, c\u00f3 65 l\u1ed7 h\u1ed5ng m\u1edbi ph\u00e1t sinh c\u00f3 li\u00ean quan t\u1edbi ransomware. \u0110\u00e2y l\u00e0 m\u1ee9c t\u0103ng tr\u01b0\u1edfng 29% so v\u1edbi s\u1ed1 l\u01b0\u1ee3ng l\u1ed7 h\u1ed5ng b\u1ea3o m\u1eadt v\u00e0o n\u0103m 2020.<\/p>\n<p>C\u00e1c nh\u00f3m tin t\u1eb7c li\u00ean quan \u0111\u1ebfn ransomware kh\u00f4ng c\u00f2n ch\u1ec9 t\u1eadp trung v\u00e0o c\u00e1c tr\u01b0\u1eddng h\u1ee3p ch\u01b0a \u0111\u01b0\u1ee3c v\u00e1. H\u1ecd \u0111\u00e3 b\u1eaft \u0111\u1ea7u nh\u1eafm t\u1edbi c\u00e1c nh\u00f3m c\u00f3 nhi\u1ec1u l\u1ed7 h\u1ed5ng, c\u00e1c \u1ee9ng d\u1ee5ng c\u1ee7a b\u00ean th\u1ee9 ba d\u1ec5 c\u00f3 l\u1ed7 h\u1ed5ng, c\u00e1c giao th\u1ee9c li\u00ean quan \u0111\u1ebfn c\u00f4ng ngh\u1ec7, v.v. C\u1ea7n l\u01b0u \u00fd r\u1eb1ng c\u00e1c nh\u00f3m n\u00e0y \u0111\u00e3 ti\u1ebfn \u0111\u1ebfn m\u1ee9c ph\u00e1t \u0111\u1ed9ng c\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng b\u1eb1ng c\u00e1ch tuy\u1ec3n d\u1ee5ng nh\u1eefng tay trong.<\/p>\n<p>C\u00e1cc\u1ea3nh b\u00e1o li\u00ean quan \u0111\u1ebfn c\u00e1c m\u1ed1i \u0111e d\u1ecda an ninh m\u1ea1ng c\u1ee7a c\u00e1c l\u1ed7 h\u1ed5ng ch\u01b0a \u0111\u01b0\u1ee3c v\u00e1 \u0111\u1ed1i v\u1edbi c\u00e1c c\u01a1 s\u1edf h\u1ea1 t\u1ea7ng quan tr\u1ecdng \u0111\u00e3 \u0111\u01b0\u1ee3c \u0111\u01b0a ra b\u1edfi c\u00e1c t\u1ed5 ch\u1ee9c ch\u00ednh ph\u1ee7 kh\u00e1c nhau nh\u01b0 FBI, C\u01a1 quan An ninh Qu\u1ed1c gia, C\u01a1 quan An ninh M\u1ea1ng v\u00e0 C\u01a1 s\u1edf h\u1ea1 t\u1ea7ng v\u00e0 B\u1ed9 An ninh N\u1ed9i \u0111\u1ecba.<\/p>\n<p>B\u00e0i vi\u1ebft n\u00e0y th\u1ea3o lu\u1eadn m\u1ed9t v\u00e0i v\u00ed d\u1ee5 v\u1ec1 c\u00e1c l\u1ed7 h\u1ed5ng v\u00e0 t\u1ea1i sao c\u1eadp nh\u1eadt c\u00e1c \u1ee9ng d\u1ee5ng c\u00f3 th\u1ec3 gi\u00fap ng\u0103n ch\u1eb7n c\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng m\u1ea1ng.<\/p>\n<h2 id=\"top-3-l%E1%BB%97-h%E1%BB%95ng-nghi%C3%AAm-tr%E1%BB%8Dng-nh%E1%BA%A5t-n%C4%83m-2021\">Top 3 l\u1ed7 h\u1ed5ng nghi\u00eam tr\u1ecdng nh\u1ea5t n\u0103m 2021<\/h2>\n<p>Vi\u1ec7n Ti\u00eau chu\u1ea9n v\u00e0 C\u00f4ng ngh\u1ec7 Qu\u1ed1c gia (NIST) cho bi\u1ebft \u0111\u00e3 t\u00ecm th\u1ea5y\u00a0<a href=\"https:\/\/www.zdnet.com\/article\/with-18376-vulnerabilities-found-in-2021-nist-reports-fifth-straight-year-of-record-numbers\/?ref=hub.whitehub.net\">18.378<\/a>\u00a0l\u1ed7 h\u1ed5ng b\u1ea3o m\u1eadt v\u00e0o n\u0103m 2021. Theo HackerOne, c\u00e1c l\u1ed7 h\u1ed5ng ph\u1ea7n m\u1ec1m \u0111\u00e3 t\u0103ng\u00a0<a href=\"https:\/\/www.hackerone.com\/press-release\/software-vulnerabilities-increase-20-2021?ref=hub.whitehub.net#:~:text=SAN%20FRANCISCO%2C%208%20December%202021,264%25%20increase%20in%20reported%20vulnerabilities.\">20%<\/a>\u00a0\u200b\u200bv\u00e0o n\u0103m 2021 so v\u1edbi n\u0103m 2020.<\/p>\n<p>Danh s\u00e1ch \u0110i\u1ec3m y\u1ebfu Ph\u1ed5 bi\u1ebfn l\u00e0 m\u1ed9t danh s\u00e1ch do c\u1ed9ng \u0111\u1ed3ng ph\u00e1t tri\u1ec3n li\u1ec7t k\u00ea c\u00e1c lo\u1ea1i \u0111i\u1ec3m y\u1ebfu c\u1ee7a ph\u1ea7n m\u1ec1m v\u00e0 ph\u1ea7n c\u1ee9ng, \u0111\u00e3 ghi l\u1ea1i 25 \u0111i\u1ec3m y\u1ebfu ph\u1ea7n m\u1ec1m nguy hi\u1ec3m nh\u1ea5t (CWE Top 25). Danh s\u00e1ch n\u00e0y bao g\u1ed3m c\u00e1c v\u1ea5n \u0111\u1ec1 ph\u1ed5 bi\u1ebfn v\u00e0 c\u00f3 \u1ea3nh h\u01b0\u1edfng nh\u1ea5t trong v\u00f2ng 2 n\u0103m tr\u1edf l\u1ea1i \u0111\u00e2y. Ba l\u1ed7 h\u1ed5ng nghi\u00eam tr\u1ecdng h\u00e0ng \u0111\u1ea7u \u0111\u01b0\u1ee3c ghi nh\u1eadn v\u00e0o n\u0103m 2021 l\u00e0:<\/p>\n<ul>\n<li>L\u1ed7 h\u1ed5ng ghi ngo\u00e0i gi\u1edbi h\u1ea1n (Out-of-bounds Write): Trong lo\u1ea1i l\u1ed7 h\u1ed5ng n\u00e0y, ph\u1ea7n m\u1ec1m ghi d\u1eef li\u1ec7u qu\u00e1 ph\u1ea7n cu\u1ed1i c\u1ee7a b\u1ed9 \u0111\u1ec7m d\u1ef1 ki\u1ebfn \u200b\u200bho\u1eb7c tr\u01b0\u1edbc ph\u1ea7n b\u1eaft \u0111\u1ea7u c\u1ee7a n\u00f3. \u0110i\u1ec1u n\u00e0y d\u1eabn \u0111\u1ebfn d\u1eef li\u1ec7u b\u1ecb h\u1ecfng ho\u1eb7c b\u1ecb s\u1eadp. N\u00f3i m\u1ed9t c\u00e1ch d\u1ec5 hi\u1ec3u th\u00ec n\u00f3 g\u00e2y ra vi\u1ec7c h\u1ecfng b\u1ed9 nh\u1edb. \u0110\u00f3 l\u00e0 k\u1ebft qu\u1ea3 c\u1ee7a vi\u1ec7c ghi v\u00e0o b\u1ed9 nh\u1edb kh\u00f4ng h\u1ee3p l\u1ec7 ho\u1eb7c v\u01b0\u1ee3t qu\u00e1 gi\u1edbi h\u1ea1n c\u1ee7a b\u1ed9 \u0111\u1ec7m. Vi\u1ec7c sao ch\u00e9p li\u00ean ti\u1ebfp qu\u00e1 nhi\u1ec1u d\u1eef li\u1ec7u c\u00f3 ngu\u1ed3n g\u1ed1c t\u1eeb m\u1ed9t v\u1ecb tr\u00ed ch\u1ec9 l\u00e0 m\u1ed9t trong nhi\u1ec1u nguy\u00ean nh\u00e2n kh\u00e1c.<\/li>\n<li>L\u1ed7 h\u1ed5ng Cross-site-Scripting: L\u1ed7 h\u1ed5ng n\u00e0y c\u00f2n \u0111\u01b0\u1ee3c g\u1ecdi l\u00e0 \u2018V\u00f4 hi\u1ec7u h\u00f3a \u0111\u1ea7u v\u00e0o kh\u00f4ng ph\u00f9 h\u1ee3p trong qu\u00e1 tr\u00ecnh t\u1ea1o trang web\u2019. Trong tr\u01b0\u1eddng h\u1ee3p n\u00e0y, \u0111\u1ea7u v\u00e0o do ng\u01b0\u1eddi d\u00f9ng ki\u1ec3m so\u00e1t kh\u00f4ng \u0111\u01b0\u1ee3c v\u00f4 hi\u1ec7u h\u00f3a ho\u1eb7c b\u1ecb v\u00f4 hi\u1ec7u h\u00f3a kh\u00f4ng \u0111\u00fang c\u00e1ch tr\u01b0\u1edbc khi n\u00f3 \u0111\u01b0\u1ee3c \u0111\u01b0a qua \u0111\u1ea7u ra, sau \u0111\u00f3 \u0111\u01b0\u1ee3c s\u1eed d\u1ee5ng nh\u01b0 m\u1ed9t trang web cung c\u1ea5p cho nh\u1eefng ng\u01b0\u1eddi d\u00f9ng kh\u00e1c.<\/li>\n<\/ul>\n<p>C\u00e1c l\u1ed7 h\u1ed5ng ph\u1ea7n m\u1ec1m n\u00e0y cho ph\u00e9p k\u1ebb t\u1ea5n c\u00f4ng \u0111\u01b0a c\u00e1c t\u1eadp l\u1ec7nh script v\u00e0o c\u00e1c trang web \u0111\u01b0\u1ee3c ng\u01b0\u1eddi d\u00f9ng kh\u00e1c xem. N\u00f3 \u0111\u01b0\u1ee3c s\u1eed d\u1ee5ng \u0111\u1ec3 b\u1ecf qua c\u00e1c ki\u1ec3m so\u00e1t truy c\u1eadp ch\u1eb3ng h\u1ea1n nh\u01b0 ch\u00ednh s\u00e1ch c\u00f9ng ngu\u1ed3n g\u1ed1c (same-origin policy).<\/p>\n<ul>\n<li>L\u1ed7i \u0111\u1ecdc ngo\u00e0i gi\u1edbi h\u1ea1n (Out-of-bounds Read): Ph\u1ea7n m\u1ec1m \u0111\u1ecdc d\u1eef li\u1ec7u \u1edf ph\u1ea7n cu\u1ed1i ho\u1eb7c tr\u01b0\u1edbc ph\u1ea7n \u0111\u1ea7u c\u1ee7a b\u1ed9 \u0111\u1ec7m d\u1ef1 \u0111\u1ecbnh trong lo\u1ea1i l\u1ed7 h\u1ed5ng \u1ee9ng d\u1ee5ng n\u00e0y. Tin t\u1eb7c c\u00f3 th\u1ec3 truy c\u1eadp c\u00e1c th\u00f4ng tin nh\u1ea1y c\u1ea3m th\u00f4ng qua vi\u1ec7c r\u00f2 r\u1ec9 b\u1ed9 nh\u1edb tr\u00e1i ph\u00e9p v\u00e0 c\u00f3 th\u1ec3 l\u00e0m s\u1eadp h\u1ec7 th\u1ed1ng. S\u1ef1 c\u1ed1 x\u1ea3y ra khi m\u1ed9t \u0111o\u1ea1n m\u00e3 b\u00ean ngo\u00e0i c\u1ed1 g\u1eafng \u0111\u1ecdc m\u1ed9t l\u01b0\u1ee3ng l\u1edbn d\u1eef li\u1ec7u kh\u00e1c nhau. Khi b\u1eaft g\u1eb7p m\u1ed9t tr\u1ea1m g\u00e1c (sentinel), ho\u1ea1t \u0111\u1ed9ng \u0111\u1ecdc s\u1ebd b\u1ecb d\u1eebng l\u1ea1i trong qu\u00e1 tr\u00ecnh n\u00e0y d\u1eabn \u0111\u1ebfn l\u1ed7i tr\u00e0n b\u1ed9 \u0111\u1ec7m ho\u1eb7c l\u1ed7i ph\u00e2n \u0111o\u1ea1n (segmentation fault).<\/li>\n<\/ul>\n<h2 id=\"v%C3%AC-sao-vi%E1%BB%87c-c%E1%BA%ADp-nh%E1%BA%ADt-ph%E1%BA%A7n-m%E1%BB%81m-l%E1%BA%A1i-quan-tr%E1%BB%8Dng\">V\u00ec sao vi\u1ec7c c\u1eadp nh\u1eadt ph\u1ea7n m\u1ec1m l\u1ea1i quan tr\u1ecdng?<\/h2>\n<p>C\u00e1c l\u1ed7 h\u1ed5ng ph\u1ea7n m\u1ec1m c\u00f3 th\u1ec3 \u0111\u01b0\u1ee3c ng\u0103n ch\u1eb7n b\u1eb1ng c\u00e1ch ki\u1ec3m tra ph\u1ea7n m\u1ec1m c\u1ee7a b\u1ea1n b\u1eb1ng c\u00e1c c\u00f4ng c\u1ee5 \u0111\u00e1nh gi\u1ea5 l\u1ed7 h\u1ed5ng \u1ee9ng d\u1ee5ng, ki\u1ec3m tra h\u1ed9p tr\u1eafng, ki\u1ec3m tra h\u1ed9p \u0111en, s\u1eed d\u1ee5ng c\u00e1c k\u1ef9 thu\u1eadt kh\u00e1c v\u00e0 c\u1eadp nh\u1eadt n\u00f3 th\u01b0\u1eddng xuy\u00ean. B\u1ea1n c\u00f3 th\u1ec3 x\u00e1c \u0111\u1ecbnh m\u1ed9t lo\u1ea1t c\u00e1c nguy\u00ean t\u1eafc c\u1ea7n tu\u00e2n theo khi ph\u00e1t tri\u1ec3n t\u1eebng phi\u00ean b\u1ea3n c\u1ee7a ph\u1ea7n m\u1ec1m \u0111\u1ec3 ng\u0103n ch\u1eb7n c\u00e1c l\u1ed7 h\u1ed5ng b\u1ea3o m\u1eadt. K\u00fd m\u00e3 c\u1ee7a b\u1ea1n b\u1eb1ng ch\u1ee9ng ch\u1ec9 s\u1ed1 \u0111\u1ec3 duy tr\u00ec m\u00e3 ch\u1ed1ng gi\u1ea3 m\u1ea1o. \u0110i\u1ec1u n\u00e0y s\u1ebd gi\u00fap \u0111\u1ea3m b\u1ea3o an to\u00e0n k\u1ef9 thu\u1eadt s\u1ed1 v\u00e0 tr\u00e1nh c\u00e1c v\u1ea5n \u0111\u1ec1 v\u1ec1 b\u1ea3o m\u1eadt.<\/p>\n<p>M\u1ed9t quy tr\u00ecnh qu\u1ea3n l\u00fd b\u1ea3n v\u00e1 l\u00fd t\u01b0\u1edfng v\u00e0 hi\u1ec7u qu\u1ea3 n\u00ean bao g\u1ed3m m\u1ed9t h\u1ec7 th\u1ed1ng audit \u0111\u1ec3 x\u00e1c \u0111\u1ecbnh c\u00e1c b\u1ea3n v\u00e1 v\u00e0 h\u1ec7 th\u1ed1ng d\u1ec5 b\u1ecb t\u1ea5n c\u00f4ng, tri\u1ec3n khai c\u00e1c b\u1ea3n c\u1eadp nh\u1eadt v\u00e0 t\u1ef1 \u0111\u1ed9ng h\u00f3a quy tr\u00ecnh qu\u1ea3n l\u00fd b\u1ea3n v\u00e1.<\/p>\n<p>C\u1eadp nh\u1eadt ph\u1ea7n m\u1ec1m c\u00f3 th\u1ec3 bao g\u1ed3m vi\u1ec7c s\u1eeda ch\u1eefa c\u00e1c l\u1ed7 h\u1ed5ng b\u1ea3o m\u1eadt b\u1eb1ng c\u00e1ch th\u00eam v\u00e0o c\u00e1c t\u00ednh n\u0103ng m\u1edbi v\u00e0 \/ ho\u1eb7c c\u00e1c b\u1ea3n v\u00e1 ph\u1ea7n m\u1ec1m. B\u1ea1n c\u00f3 th\u1ec3 x\u00f3a c\u00e1c t\u00ednh n\u0103ng l\u1ed7i th\u1eddi, v\u00e0 thay v\u00e0o \u0111\u00f3 th\u00eam v\u00e0o c\u00e1c t\u00ednh n\u0103ng m\u1edbi nh\u1eb1m n\u00e2ng c\u1ea5p b\u1ea3o m\u1eadt \u1ee9ng d\u1ee5ng v\u00e0 ng\u0103n ch\u1eb7n c\u00e1c l\u1ed7 h\u1ed5ng ch\u01b0a \u0111\u01b0\u1ee3c v\u00e1.<\/p>\n<p>C\u00e1c l\u1ed7 h\u1ed5ng b\u1ea3o m\u1eadt \u0111\u01b0\u1ee3c v\u00e1 v\u00e0 d\u1eef li\u1ec7u c\u1ee7a b\u1ea1n \u0111\u01b0\u1ee3c b\u1ea3o v\u1ec7 kh\u1ecfi tin t\u1eb7c. \u0110i\u1ec1u n\u00e0y gi\u00fap ng\u0103n nh\u1eefng k\u1ebb t\u1ea5n c\u00f4ng truy c\u1eadp v\u00e0o th\u00f4ng tin v\u00e0 t\u00e0i li\u1ec7u c\u00e1 nh\u00e2n khi m\u00e0 nh\u1eefng t\u00e0i li\u1ec7u n\u00e0y c\u00f3 th\u1ec3 b\u1ecb l\u1ee3i d\u1ee5ng \u0111\u1ec3 ph\u1ea1m t\u1ed9i. D\u1eef li\u1ec7u \u0111\u01b0\u1ee3c m\u00e3 h\u00f3a trong tr\u01b0\u1eddng h\u1ee3p b\u1ecb t\u1ea5n c\u00f4ng b\u1eb1ng m\u00e3 \u0111\u1ed9c t\u1ed1ng ti\u1ec1n (ransomware). Vi\u1ec7c kh\u1eafc ph\u1ee5c c\u00e1c l\u1ed7 h\u1ed5ng b\u1ea3o m\u1eadt trong \u1ee9ng d\u1ee5ng c\u0169ng c\u00f3 th\u1ec3 l\u00e0m gi\u1ea3m nguy c\u01a1 b\u1ecb tin t\u1eb7c truy c\u1eadp v\u00e0o d\u1eef li\u1ec7u c\u1ee7a nh\u1eefng ng\u01b0\u1eddi b\u1ea1n c\u00f3 li\u00ean h\u1ec7.<\/p>\n<p>M\u1ed9t s\u1ef1 c\u1ed1 hack c\u00f3 th\u1ec3 l\u00e0m h\u1ecfng h\u00ecnh \u1ea3nh doanh nghi\u1ec7p c\u1ee7a b\u1ea1n. \u0110\u00e2y l\u00e0 m\u1ed9t trong nh\u1eefng l\u00fd do quan tr\u1ecdng nh\u1ea5t t\u1ea1i sao b\u1ea1n n\u00ean c\u00f3 trong tay m\u1ed9t quy tr\u00ecnh qu\u1ea3n l\u00fd l\u1ed7 h\u1ed5ng v\u00e0 b\u1ea3n v\u00e1 hi\u1ec7u qu\u1ea3, v\u00e0 li\u00ean t\u1ee5c c\u1eadp nh\u1eadt c\u00e1c \u1ee9ng d\u1ee5ng c\u1ee7a m\u00ecnh th\u01b0\u1eddng xuy\u00ean.<\/p>\n<h2 id=\"k%E1%BA%BFt-lu%E1%BA%ADn\">K\u1ebft lu\u1eadn<\/h2>\n<p>M\u1ed9t b\u00e1o c\u00e1o c\u1ee7a Redscan Labs cho th\u1ea5y 90% t\u1ea5t c\u1ea3 c\u00e1c l\u1ed7 h\u1ed5ng ph\u1ed5 bi\u1ebfn (CVE) \u0111\u01b0\u1ee3c ph\u00e1t hi\u1ec7n trong n\u0103m 2021 c\u00f3 th\u1ec3 b\u1ecb khai th\u00e1c b\u1edfi nh\u1eefng k\u1ebb t\u1ea5n c\u00f4ng m\u00e0 kh\u00f4ng c\u1ea7n b\u1ea5t k\u1ef3 k\u1ef9 n\u0103ng k\u1ef9 thu\u1eadt n\u00e0o. B\u00e1o c\u00e1o n\u00e0y ph\u00e2n lo\u1ea1i 54% l\u1ed7 h\u1ed5ng b\u1ea3o m\u1eadt c\u00f3 t\u00ednh kh\u1ea3 d\u1ee5ng \u201ccao\u201d, \u0111i\u1ec1u n\u00e0y c\u00f3 ngh\u0129a l\u00e0 tin t\u1eb7c c\u00f3 th\u1ec3 truy c\u1eadp ho\u1eb7c khai th\u00e1c ch\u00fang m\u1ed9t c\u00e1ch d\u1ec5 d\u00e0ng.<\/p>\n<p>\u0110i\u1ec1u n\u00e0y khi\u1ebfn cho vi\u1ec7c hi\u1ec3u CVE l\u00e0 g\u00ec l\u00e0 r\u1ea5t quan tr\u1ecdng v\u00e0 c\u1ea7n ph\u1ea3i l\u00e0m g\u00ec \u0111\u1ec3 ng\u0103n ch\u1eb7n ch\u00fang. B\u01b0\u1edbc \u0111\u1ea7u ti\u00ean l\u00e0 ph\u00e2n t\u00edch v\u00e0 c\u1eadp nh\u1eadt th\u01b0\u1eddng xuy\u00ean c\u00e1c \u1ee9ng d\u1ee5ng c\u1ee7a b\u1ea1n b\u1eb1ng c\u00e1c c\u00f4ng c\u1ee5 gi\u00e1m s\u00e1t b\u1ea3o m\u1eadt nh\u01b0 Indusface WAS. Th\u1ee9 hai, m\u1ed9t c\u00e1ch hi\u1ec7u qu\u1ea3 \u0111\u1ec3 ch\u1ed1ng gi\u1ea3 m\u1ea1o trang web c\u1ee7a b\u1ea1n l\u00e0 s\u1eed d\u1ee5ng ch\u1ee9ng ch\u1ec9 s\u1ed1.<\/p>\n<p>C\u00e1c l\u1ed7 h\u1ed5ng ch\u01b0a \u0111\u01b0\u1ee3c v\u00e1 r\u1ea5t nguy hi\u1ec3m \u0111\u1ed1i v\u1edbi an to\u00e0n k\u1ef9 thu\u1eadt s\u1ed1 v\u00e0 b\u1ea3o m\u1eadt d\u1eef li\u1ec7u c\u1ee7a b\u1ea1n. Do \u0111\u00f3, c\u00e1c nh\u00e0 cung c\u1ea5p ph\u1ea7n m\u1ec1m c\u00f3 tr\u00e1ch nhi\u1ec7m ph\u1ea3i hi\u1ec3u v\u00e0 tu\u00e2n th\u1ee7 c\u00e1c quy tr\u00ecnh \u0111\u1ec3 \u0111\u1ea3m b\u1ea3o v\u00e1 c\u00e1c l\u1ed7 h\u1ed5ng c\u1ee7a trang web v\u00e0 \u1ee9ng d\u1ee5ng.<\/p>\n<p>Ngu\u1ed3n: https:\/\/securitydaily.net<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ph\u1ea7n m\u1ec1m ch\u01b0a \u0111\u01b0\u1ee3c v\u00e1 l\u00e0 m\u1ed9t \u0111o\u1ea1n m\u00e3 m\u00e1y t\u00ednh c\u00f3 ch\u1ee9a c\u00e1c \u0111i\u1ec3m y\u1ebfu b\u1ea3o m\u1eadt \u0111\u00e3 bi\u1ebft. C\u00e1c l\u1ed7 h\u1ed5ng\u00a0ch\u01b0a \u0111\u01b0\u1ee3c v\u00e1 l\u00e0 nh\u1eefng \u0111i\u1ec3m y\u1ebfu cho ph\u00e9p k\u1ebb t\u1ea5n c\u00f4ng l\u1ee3i d\u1ee5ng m\u1ed9t l\u1ed7i b\u1ea3o m\u1eadt \u0111\u00e3 bi\u1ebft ch\u01b0a \u0111\u01b0\u1ee3c v\u00e1 b\u1eb1ng c\u00e1ch ch\u1ea1y m\u00e3 \u0111\u1ed9c. Khi c\u00e1c nh\u00e0 cung c\u1ea5p [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":3794,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"tdm_status":"","tdm_grid_status":"","footnotes":""},"categories":[13],"tags":[],"class_list":{"0":"post-3789","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tin-tuc"},"_links":{"self":[{"href":"https:\/\/chuyendoiso.haiphong.gov.vn\/index.php\/wp-json\/wp\/v2\/posts\/3789","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/chuyendoiso.haiphong.gov.vn\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/chuyendoiso.haiphong.gov.vn\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/chuyendoiso.haiphong.gov.vn\/index.php\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/chuyendoiso.haiphong.gov.vn\/index.php\/wp-json\/wp\/v2\/comments?post=3789"}],"version-history":[{"count":1,"href":"https:\/\/chuyendoiso.haiphong.gov.vn\/index.php\/wp-json\/wp\/v2\/posts\/3789\/revisions"}],"predecessor-version":[{"id":3795,"href":"https:\/\/chuyendoiso.haiphong.gov.vn\/index.php\/wp-json\/wp\/v2\/posts\/3789\/revisions\/3795"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/chuyendoiso.haiphong.gov.vn\/index.php\/wp-json\/wp\/v2\/media\/3794"}],"wp:attachment":[{"href":"https:\/\/chuyendoiso.haiphong.gov.vn\/index.php\/wp-json\/wp\/v2\/media?parent=3789"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/chuyendoiso.haiphong.gov.vn\/index.php\/wp-json\/wp\/v2\/categories?post=3789"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/chuyendoiso.haiphong.gov.vn\/index.php\/wp-json\/wp\/v2\/tags?post=3789"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}