<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	 xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>OWASP &#8211; AnonyViet &#8211; English Version</title>
	<atom:link href="https://en.anonyviet.com/tag/owasp/feed/" rel="self" type="application/rss+xml" />
	<link>https://en.anonyviet.com</link>
	<description>The most popular website for sharing information technology, computer networks, and security knowledge. Stay up to date with the hottest news and tips</description>
	<lastBuildDate>Tue, 19 Dec 2023 05:31:48 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://en.anonyviet.com/wp-content/uploads/2023/01/cropped-ico-logo-75x75-1.png</url>
	<title>OWASP &#8211; AnonyViet &#8211; English Version</title>
	<link>https://en.anonyviet.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Instructions for getting 3TB Google Drive for free from OWASP</title>
		<link>https://en.anonyviet.com/instructions-for-getting-3tb-google-drive-for-free-from-owasp/</link>
					<comments>https://en.anonyviet.com/instructions-for-getting-3tb-google-drive-for-free-from-owasp/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Tue, 19 Dec 2023 05:31:48 +0000</pubDate>
				<category><![CDATA[Tips]]></category>
		<category><![CDATA[3TB]]></category>
		<category><![CDATA[drive]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Instructions]]></category>
		<category><![CDATA[OWASP]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=14135</guid>

					<description><![CDATA[How to post 3TB Google Drive free with OWASP is one of the tricks that many people are looking for. Google Drive is a very safe and convenient data storage and sharing service. However, Google Drive only offers 15GB of free storage per account, if you want to increase the storage you have to pay [&#8230;]]]></description>
										<content:encoded><![CDATA[
<div id="ftwp-postcontent">
<p><strong>How to post 3TB Google Drive</strong> free with OWASP is one of the tricks that many people are looking for.  Google Drive is a very safe and convenient data storage and sharing service.  However, <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fcach-nhan-2tb-google-drive-6-thang-khong-ton-dong-nao%2F" class="local-link" rel="noopener">Google Drive</a> only offers 15GB of free storage per account, if you want to increase the storage you have to pay a monthly fee.  So is there any way to own 3TB Google Drive for free?  The answer is yes, and you will know how to do it in this article.  Reference article from J2Team</p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> belong to <span style="color: #008080;">AnonyViet</span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietoffical" class="local-link" rel="noopener">Link</a></span>  👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<h2 id="ftoc-cach-dang-ky-3tb-google-drive-mien-phi-voi-owasp" class="ftwp-heading"><strong>How to register 3TB Google Drive for free with OWASP</strong></h2>
<p><strong>Step 1:</strong> You access the link <strong><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fowasp.org%2Fmembership%2F%3Fstudent%3Dyes" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">The following</a></strong>choose region Israel or Ukraine and you will get 1 year free.</p>
<figure id="attachment_53939" aria-describedby="caption-attachment-53939" style="width: 800px" class="wp-caption aligncenter"><img fetchpriority="high" decoding="async" class="wp-image-53939 size-full" src="https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-1.jpg" alt="How to own 3TB Google Drive" width="800" height="399" title="Instructions for getting 3TB Google Drive for free from OWASP 15" srcset="https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-1.jpg 800w, https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-1-300x150.jpg 300w, https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-1-768x383.jpg 768w, https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-1-360x180.jpg 360w, https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-1-750x374.jpg 750w" sizes="(max-width: 800px) 100vw, 800px"/><figcaption id="caption-attachment-53939" class="wp-caption-text">Select region as Israel or Ukraine</figcaption></figure>
<p><strong>Step 2:</strong> Check the 3 boxes that the website displays</p>
<p><strong>Step 3:</strong> Fill in information including name, email, school, postal code,&#8230; as shown below</p>
<figure id="attachment_53940" aria-describedby="caption-attachment-53940" style="width: 800px" class="wp-caption aligncenter"><img decoding="async" class="wp-image-53940 size-full" src="https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-2.jpg" alt="How to own 3TB Google Drive" width="800" height="534" title="Instructions for getting 3TB Google Drive for free from OWASP 16" srcset="https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-2.jpg 800w, https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-2-300x200.jpg 300w, https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-2-768x513.jpg 768w, https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-2-750x501.jpg 750w" sizes="(max-width: 800px) 100vw, 800px"/><figcaption id="caption-attachment-53940" class="wp-caption-text">Fill in information</figcaption></figure>
<p><strong>Step 4:</strong> Click on &#39;Manage Membership&#39;</p>
<figure id="attachment_53941" aria-describedby="caption-attachment-53941" style="width: 800px" class="wp-caption aligncenter"><img decoding="async" class="wp-image-53941 size-full" src="https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-3.jpg" alt="How to own 3TB Google Drive" width="800" height="306" title="Instructions for getting 3TB Google Drive for free from OWASP 17" srcset="https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-3.jpg 800w, https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-3-300x115.jpg 300w, https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-3-768x294.jpg 768w, https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-3-750x287.jpg 750w" sizes="(max-width: 800px) 100vw, 800px"/><figcaption id="caption-attachment-53941" class="wp-caption-text">Click on &#39;Manage Membership&#39;</figcaption></figure>
<p><strong>Step 5:</strong> Enter the email used to register earlier > Select &#39;Request Account Information&#39;</p>
<figure id="attachment_53942" aria-describedby="caption-attachment-53942" style="width: 800px" class="wp-caption aligncenter"><img decoding="async" class="wp-image-53942 size-full" src="https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-4.jpg" alt="How to own 3TB Google Drive" width="800" height="406" title="Instructions for getting 3TB Google Drive for free from OWASP 18" srcset="https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-4.jpg 800w, https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-4-300x152.jpg 300w, https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-4-768x390.jpg 768w, https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-4-750x381.jpg 750w" sizes="(max-width: 800px) 100vw, 800px"/><figcaption id="caption-attachment-53942" class="wp-caption-text">Select &#39;Request Account Information&#39;</figcaption></figure>
<p>Now you will receive an email from OWASP, click &#39;Manage your account&#39; to open the website containing your owasp.org email information.</p>
<figure id="attachment_53943" aria-describedby="caption-attachment-53943" style="width: 451px" class="wp-caption aligncenter"><img decoding="async" class="wp-image-53943 size-full" src="https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-5.jpg" alt="How to own 3TB Google Drive" width="451" height="650" title="Instructions for getting 3TB Google Drive for free from OWASP 19" srcset="https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-5.jpg 451w, https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-5-208x300.jpg 208w" sizes="(max-width: 451px) 100vw, 451px"/><figcaption id="caption-attachment-53943" class="wp-caption-text">Click &#39;Manage your account&#39;</figcaption></figure>
<p><strong>Step 6:</strong> Click on the owasp email address > Click &#39;Provision&#39; and wait until it displays a success message.</p>
<figure id="attachment_53944" aria-describedby="caption-attachment-53944" style="width: 381px" class="wp-caption aligncenter"><img decoding="async" class="wp-image-53944 size-full" src="https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-6.jpg" alt="How to own 3TB Google Drive" width="381" height="650" title="Instructions for getting 3TB Google Drive for free from OWASP 20" srcset="https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-6.jpg 381w, https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-6-176x300.jpg 176w" sizes="(max-width: 381px) 100vw, 381px"/><figcaption id="caption-attachment-53944" class="wp-caption-text">Click &#39;Provision&#39;</figcaption></figure>
<p><strong>Step 7:</strong> At this point, go to your email, log in with the @owasp.org account > Click &#39;Forgot your password?&#39;.</p>
<figure id="attachment_53945" aria-describedby="caption-attachment-53945" style="width: 593px" class="wp-caption aligncenter"><img decoding="async" class="wp-image-53945 size-full" src="https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-7.jpg" alt="How to own 3TB Google Drive" width="593" height="650" title="Instructions for getting 3TB Google Drive for free from OWASP 21" srcset="https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-7.jpg 593w, https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-7-274x300.jpg 274w" sizes="(max-width: 593px) 100vw, 593px"/><figcaption id="caption-attachment-53945" class="wp-caption-text">Click &#39;Forgot your password?&#39;.</figcaption></figure>
<p><strong>Step 8:</strong> Fill in the recovery email (the gmail extension you filled out in step 3) > Click &#39;Send&#39;</p>
<figure id="attachment_53946" aria-describedby="caption-attachment-53946" style="width: 452px" class="wp-caption aligncenter"><img decoding="async" class="wp-image-53946 size-full" src="https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-8.jpg" alt="How to own 3TB Google Drive" width="452" height="650" title="Instructions for getting 3TB Google Drive for free from OWASP 22" srcset="https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-8.jpg 452w, https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-8-209x300.jpg 209w" sizes="(max-width: 452px) 100vw, 452px"/><figcaption id="caption-attachment-53946" class="wp-caption-text">Fill in your recovery email</figcaption></figure>
<p><strong>Step 9:</strong> You will now receive a verification code > Enter that code.  You can change your password for convenience the next time you log in.</p>
<p>It is done!  You have successfully logged in to Google using Owasp mail</p>
<figure id="attachment_53947" aria-describedby="caption-attachment-53947" style="width: 800px" class="wp-caption aligncenter"><img decoding="async" class="wp-image-53947 size-full" src="https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-9.jpg" alt="How to own 3TB Google Drive" width="800" height="417" title="Instructions for getting 3TB Google Drive for free from OWASP 23" srcset="https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-9.jpg 800w, https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-9-300x156.jpg 300w, https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-9-768x400.jpg 768w, https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-9-750x391.jpg 750w" sizes="(max-width: 800px) 100vw, 800px"/><figcaption id="caption-attachment-53947" class="wp-caption-text">Successfully logged in to Google using Owasp email</figcaption></figure>
<p>Now you can go to Drive to check if the capacity is currently 3TB!</p>
<figure id="attachment_53948" aria-describedby="caption-attachment-53948" style="width: 366px" class="wp-caption aligncenter"><img decoding="async" class="wp-image-53948 size-full" src="https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-10.jpg" alt="How to own 3TB Google Drive" width="366" height="211" title="Instructions for getting 3TB Google Drive for free from OWASP 24" srcset="https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-10.jpg 366w, https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi-10-300x173.jpg 300w" sizes="(max-width: 366px) 100vw, 366px"/><figcaption id="caption-attachment-53948" class="wp-caption-text">How to own 3TB Google Drive</figcaption></figure>
<h2 id="ftoc-loi-ket" class="ftwp-heading"><strong>Epilogue</strong></h2>
<p><strong>How to own 3TB Google Drive</strong> Free with OWASP that I just shared above will help you store and share data comfortably and easily.  Hope you are succesful.</p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom kksr-disabled" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;53937&quot;,&quot;readonly&quot;:&quot;1&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;101&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 5\/5 - (101 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;title&quot;:&quot;H\u01b0\u1edbng d\u1eabn nh\u1eadn 3TB Google Drive mi\u1ec5n ph\u00ed c\u1ee7a OWASP&quot;,&quot;width&quot;:&quot;142.5&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>  The article scored: 5/5 &#8211; (101 votes)</p>
</div>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/instructions-for-getting-3tb-google-drive-for-free-from-owasp/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2023/12/cach-so-huu-3tb-google-drive-mien-phi.jpg" medium="image"></media:content>
            	</item>
		<item>
		<title>Top 10 web security vulnerabilities according to OWASP 2020 announcement</title>
		<link>https://en.anonyviet.com/top-10-web-security-vulnerabilities-according-to-owasp-2020-announcement/</link>
					<comments>https://en.anonyviet.com/top-10-web-security-vulnerabilities-according-to-owasp-2020-announcement/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Fri, 27 Jan 2023 13:04:30 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[announcement]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Top]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[web]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=4889</guid>

					<description><![CDATA[OWASP stands for Open Web Application Security Project, an online community dedicated to producing articles, methods, documents, tools and technologies in the field of web application security. Every 3.4 years or annually OWASP publishes a list of common and dangerous vulnerabilities encountered. Here is a list of 10 vulnerabilities 2020 Join the channel Telegram of [&#8230;]]]></description>
										<content:encoded><![CDATA[<p></p>
<div id="ftwp-postcontent">
<p><strong>OWASP stands for Open Web Application Security Project, an online community dedicated to producing articles, methods, documents, tools and technologies in the field of web application security.  Every 3.4 years or annually OWASP publishes a list of common and dangerous vulnerabilities encountered.  Here is a list of 10 vulnerabilities 2020</strong></p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> of the <span style="color: #008080;">AnonyViet </span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietchat" class="local-link" rel="noopener">Link</a></span>  👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<p><img post-id="4889" fifu-featured="1" decoding="async" class="aligncenter wp-image-22223 size-full" src="https://anonyviet.com/wp-content/uploads/2020/09/71.png" alt="Top 10 web security vulnerabilities according to OWASP 2020 announcement" title="Top 10 web security vulnerabilities according to OWASP 2020 announcement" width="480" height="320" srcset="https://anonyviet.com/wp-content/uploads/2020/09/71.png 480w, https://anonyviet.com/wp-content/uploads/2020/09/71-300x200.png 300w" sizes="(max-width: 480px) 100vw, 480px" title="Top 10 web security vulnerabilities according to OWASP 2020 announcement 6"/></p>
<h2 id="ftoc-top-10-owasp-la-gi" class="ftwp-heading">What is the OWASP Top 10?</h2>
<p>The OWASP Top 10 is a list of the 10 most common web vulnerabilities.  It also shows the risks, impacts and countermeasures of these vulnerabilities.  Updated every three to four years, <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fowasp.org%2Fwww-project-top-ten%2F" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">Latest OWASP vulnerability list released in 2018</a>.</p>
<h2 id="ftoc-top-10-lo-hong-hang-dau-cua-owasp-vao-nam-2020" class="ftwp-heading">OWASP Top 10 Vulnerabilities in 2020</h2>
<h3 id="ftoc-injection" class="ftwp-heading">Injection</h3>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fcategory%2Fsecurity%2Fsql-injection%2F" rel="noopener noreferrer" class="local-link">Injection</a> allowing attackers to pump malicious code through one application to another.  These attacks exploit the operating system through system calls, the use of external programs via shell commands, as well as calls to the sub-database via SQL (i.e. SQL Injection). ).  Entire scripts can be written in Perl, Python, and other languages ​​that attack poorly designed applications.  Anytime an application uses an interpreter of any kind there is a risk of creating a security hole.  Injection was ranked 1st in OWASP in 2018.</p>
<h3 id="596d" class="ft fu dj bi fv fw fx fy fz ga gb gc gd ge gf gg gh gi gj gk gl aq ftwp-heading">Broken Authentication</h3>
<p>Broken authentication is a protective term for a number of vulnerabilities that attackers exploit to impersonate users to blatantly gain access to the system.  It is roughly understood as impersonating the user&#8217;s identity.  In general, broken authentication refers to weaknesses in two areas: session management and credential management.  Both are classified as broken authentication because attackers use one of two ways to impersonate users: compromised session IDs or stolen credentials.</p>
<p>Attackers use a variety of strategies to take advantage of these weaknesses, ranging from massive credential stuffing attacks to highly targeted conspiracies to gain access to sensitive information. login credentials of a specific person.</p>
<h3 id="d30f" class="ft fu dj bi fv fw fx fy fz ga gb gc gd ge gf gg gh gi gj gk gl aq ftwp-heading">Sensitive Data Exposure</h3>
<p>Sensitive Data Exposure occurs when an application, company or organization inadvertently exposes personal data.  SDE (Sensitive Data Exposure) is different from a data breach, in that an attacker will access and steal your information.</p>
<p>The loss of sensitive data occurs due to inadequate protection of the database where the information is stored.  This can be the result of many reasons such as weak coding, no encryption, software bugs, or when someone mistakenly uploads data to the wrong database.</p>
<p>Different types of data may be displayed in some sensitive data.  Bank account number, credit card number, healthcare data, session key, home address, phone number, date of birth and user account information such as username and password are one number of types of information that may be exposed.  Although the disclosure is by the user, it is still on the OWASP list.</p>
<h3 id="c361" class="ft fu dj bi fv fw fx fy fz ga gb gc gd ge gf gg gh gi gj gk gl aq ftwp-heading">XML External Entities (XXE)</h3>
<p>XML External Entities (also known as XXE) is a security vulnerability that allows an attacker to interfere with an application&#8217;s processing of XML data.  It typically allows an attacker to view files on the application server&#8217;s file system and interact with any third-party back-end or external systems that the application can access.</p>
<p>In some situations, an attacker can escalate a XXE attack to compromise the underlying server or other backend infrastructure, by taking advantage of the XXE vulnerability to perform request spoofing attacks. server-side request (SSRF).</p>
<h3 id="4b28" class="ft fu dj bi fv fw fx fy fz ga gb gc gd ge gf gg gh gi gj gk gl aq ftwp-heading">Broken Access control</h3>
<p>Access control enforces the policy so that users cannot act outside of their authority.  Errors often lead to unauthorized disclosure of information, modification or destruction of all data, or performance of features beyond the user&#8217;s limits.  Common access control vulnerabilities include:</p>
<ul>
<li>Bypass checks access by modifying URLs, internal application state, or HTML pages, or simply using a custom API hack.</li>
<li>Allows to change the primary key to another user&#8217;s record, allows viewing or editing of other people&#8217;s accounts.</li>
<li>Enhanced privileges.  Act as a user without logging in or act as an administrator when logged in as a user.</li>
<li>Manipulating metadata, such as replaying or forging a JSON Web Token (JWT) access control token, or hidden cookies or fields, manipulated to elevate privileges or to abuse JWT disabling.</li>
<li>CORS misconfiguration allows unauthorized API access.</li>
<li>Force browsing to pages authenticated as user or to privileged pages as standard user.  API access with missing access controls for POST, PUT, and DELETE.</li>
</ul>
<h3 id="ftoc-cau-hinh-bao-mat-sai" class="ftwp-heading">Wrong security configuration</h3>
<p>The following security configurations are improperly or unsafely configured security settings that put your system and data at risk.  Essentially, any well-documented configuration changes, default settings, or technical problems on any component of your endpoint lead to misconfiguration.</p>
<p>Misconfiguration can happen due to a multitude of reasons.  Modern network infrastructures are so complex that organizations often overlook important security settings, including new network equipment that is still configured by default.  A developer can write flexible firewall rules and create network shares for his convenience while building software.  Sometimes administrators allow configuration changes for testing or troubleshooting purposes and forget to return the original state resulting in misconfiguration.  Some common security misconfiguration vulnerabilities are login security, user account management, password policy, and legacy protocols.</p>
<h3 id="ftoc-cross-site-scripting-xss" class="ftwp-heading">Cross Site Scripting (XSS)</h3>
<p>Cross-site Scripting (XSS) is a client-side code injection attack.  The attacker aims to execute malicious scripts in the victim&#8217;s web browser by injecting malicious code into a legitimate website or web application.  The actual attack occurs when the victim visits a website or web application that executes malicious code.  The website or web application becomes a vehicle for delivering malicious scripts to the user&#8217;s browser.  Commonly used vulnerable targets for Cross-site Scripting attacks are forums, message boards, and comment-enabled websites.</p>
<p>A website or web application is vulnerable to XSS attacks if it uses unfiltered user input.  User input must be parsed by the browser.  XSS attacks can happen in VBScript, ActiveX, Flash, and even CSS.  However, they are most common in JavaScript, mainly because JavaScript is the foundation for most browsing experiences.  Almost everyone who learns about OWASP knows about this vulnerability.</p>
<h3 id="7e4f" class="ft fu dj bi fv fw fx fy fz ga gb gc gd ge gf gg gh gi gj gk gl aq ftwp-heading">Insecure Deserialization</h3>
<p><strong>Deserialization</strong> is the process of restoring this stream of bytes into a fully functional copy of the original object, in the exact state when it was serialized.  The web logic can then interact with this object, just like any other object.</p>
<p><strong class="hi ir">Serialization (serialization)</strong> is the process of converting complex data structures, such as objects and their fields, into a &#8220;flatter&#8221; format that can be sent and received as a sequential stream of bytes.  The ordering of data lies in the purpose of:</p>
<ul>
<li>Write complex data to inter-process memory, files, or databases.</li>
<li>Send complex data, such as over a network, between different components of an application or within an API call.</li>
</ul>
<p>Importantly, when serializing an object, its state is also maintained.  In other words, the properties of the object are preserved, along with their specified values.</p>
<h3 id="ftoc-su-dung-cac-thanh-phan-co-lo-hong-da-biet" class="ftwp-heading">Using components with known vulnerabilities</h3>
<p>Known vulnerabilities are those that have been discovered in open source components and published in the NVD, security advisor, or issue tracker.  As of the time of publication, a security hole can be exploited by hackers who find documentation related to them.  According to OWASP, the problem of using vulnerable components is very common.  Furthermore, the use of open source components is so widespread that many development leaders don&#8217;t even know what they&#8217;ve accomplished.</p>
<h3 id="ftoc-ghi-nhat-ky-va-giam-sat-khong-day-du" class="ftwp-heading">Inadequate logging and monitoring</h3>
<p>When an organization does not have sufficient logging, detection, monitoring and response capabilities, attackers will rely on these weaknesses to achieve their goals undetected.  The lack of these methods includes things like:</p>
<ul>
<li>Auditable events, such as logins, failed logins, and high value transactions are not logged.</li>
<li>Warnings and errors produce incomplete or ambiguous log messages.</li>
<li>Logs of unmonitored applications and APIs for suspicious activity.</li>
<li>Logs are stored locally only.</li>
<li>Appropriate alarm thresholds and out-of-place or ineffective feedback reporting procedures.</li>
<li>Penetration testing and scanning with DAST tools did not trigger warnings.</li>
<li>Applications cannot detect, report, or warn about active attacks in real time or near real time.</li>
</ul>
<p>Above is a list of Top 10 OWASP Vulnerabilities in 2020.</p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;22221&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;100&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 5\/5 - (100 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;width&quot;:&quot;142.5&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>            The article achieved: 5/5 &#8211; (100 votes)    </p>
</p></div>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/top-10-web-security-vulnerabilities-according-to-owasp-2020-announcement/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2020/09/71.png" medium="image"></media:content>
            	</item>
		<item>
		<title>TryHackMe: OWASP Top 10 Challenge Part 1</title>
		<link>https://en.anonyviet.com/tryhackme-owasp-top-10-challenge-part-1/</link>
					<comments>https://en.anonyviet.com/tryhackme-owasp-top-10-challenge-part-1/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Wed, 25 Jan 2023 18:39:47 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[challenge]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[Part]]></category>
		<category><![CDATA[Top]]></category>
		<category><![CDATA[Tryhackme]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=3211</guid>

					<description><![CDATA[In this article, we will explore the challenge OWASP Top 10 above TryHackMe. Through this challenge, you can also learn and exploit each of the top 10 OWASP vulnerabilities. Those are the 10 most important web security risks, read this paragraph to understand more. Join the channel Telegram of the AnonyViet 👉 Link 👈 Because [&#8230;]]]></description>
										<content:encoded><![CDATA[<p></p>
<div id="ftwp-postcontent">
<p><strong>In this article, we will explore the challenge <a target="_blank" class="dy ix ext-link" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Ftryhackme.com%2Froom%2Fowasptop10" rel="noopener ugc nofollow external" onclick="this.target='_blank';">OWASP Top 10</a> above <a target="_blank" class="dy ix ext-link" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Ftryhackme.com%2F" rel="noopener ugc nofollow external" onclick="this.target='_blank';">TryHackMe.</a> Through this challenge, you can also learn and exploit each of the top 10 OWASP vulnerabilities.  Those are the 10 most important web security risks, read <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Ftop-10-lo-hong-bao-mat-web-theo-cong-bo-owasp-2020%2F" rel="noopener" class="local-link">this paragraph</a> to understand more.</strong></p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> of the <span style="color: #008080;">AnonyViet </span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietchat" class="local-link" rel="noopener">Link</a></span>  👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<p><img post-id="3211" fifu-featured="1" decoding="async" class="aligncenter wp-image-34548 size-full" src="https://anonyviet.com/wp-content/uploads/2021/10/0_2NSPrwCU5nN8bQHP.jpg" alt="TryHackMe: OWASP Top 10 Challenge Part 1" title="TryHackMe: OWASP Top 10 Challenge Part 1" width="525" height="317" srcset="https://anonyviet.com/wp-content/uploads/2021/10/0_2NSPrwCU5nN8bQHP.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/0_2NSPrwCU5nN8bQHP-300x181.jpg 300w" sizes="(max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge Part 1 27"/></p>
<p>Because this challenge is a bit too much, I will divide it into 3 parts for you to follow and also read to be less boring.</p>
<p>I will go straight to the practical part and skip the technical knowledge.  If you want to learn the knowledge or how the vulnerability works, you can go to the room to read it.  And note, the websites I visit in this article are Tryhackme&#8217;s virtual servers.</p>
<h2 id="ftoc-tryhackme-thu-thach-owasp-top-10-phan-1" class="ftwp-heading">TryHackMe: OWASP Top 10 Challenge Part 1</h2>
<h3 id="ftoc-nhiem-vu-5-muc-do-nghiem-trong-1-command-injection" class="ftwp-heading">Mission 5: [Mức độ nghiêm trọng 1] <strong class="ib da"> Command Injection</strong></h3>
<h4 id="ftoc-active-command-injection-la-gi" class="ftwp-heading"><strong> What is Active Command Injection?</strong></h4>
<p>Blind command injection (Bli<span id="rmm">n</span>d command injection) occurs when a system command executed to the server does not return a response to the user in the HTML document.  And ACI (Active command injection) will return the response to the user.  It can be displayed through a number of HTML elements.</p>
<p>See the following script: EvilCorp started developing on the web platform but was accidentally exposed to the Internet.  It&#8217;s incomplete but still contains a command injection vulnerability.  But this time, the response from the system call can be seen on the web page.</p>
<p>Read the sample code from evilhell.php and see what it&#8217;s doing and why it&#8217;s getting ACI.  I will leave the sample code below.</p>
<p><strong class="ib da">EvilShell (evilshell.php)</strong></p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34550 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_HKrEjcxvxXttCYTEcFnkhg.png" alt="TryHackMe: OWASP Top 10 Challenge Part 1 23" width="370" height="219" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_HKrEjcxvxXttCYTEcFnkhg.png 370w, https://anonyviet.com/wp-content/uploads/2021/10/1_HKrEjcxvxXttCYTEcFnkhg-300x178.png 300w" sizes="auto, (max-width: 370px) 100vw, 370px" title="TryHackMe: OWASP Top 10 Challenge Part 1 28"/></p>
<p>Program analysis:</p>
<ol>
<li>Check if the parameter<strong> “commandString”</strong> has been declared.</li>
<li>If so, then the variable <strong>$command_string</strong> get what was passed into the input field.</li>
<li>The program then enters a try block to execute the function <strong class="ib da">passthru($command_string)</strong>.  You can read the documentation for the passthru() function on the PHP website, but in general it will execute what is entered in the input field, then pass the output directly back to the browser.</li>
<li>If it fails, it will give an error.  In general, it won&#8217;t output anything because you can&#8217;t output it <a target="_blank" href="https://en.anonyviet.com/next-link/?url=http%3A%2F%2Fcentos-vn.blogspot.com%2F2013%2F12%2Fstdinstdoutstderr.html%23%3A%7E%3Atext%3DSTDERR%2520l%25C3%25A0%2520d%25C3%25B2ng%2520xu%25E1%25BA%25A5t%2520l%25E1%25BB%2597i%2Cth%25E1%25BB%2591ng%2520s%25E1%25BA%25BD%2520t%25E1%25BB%25B1%2520t%25E1%25BA%25A1o%2520ra%29." rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">stderr.</a></li>
</ol>
<p><strong>Ways to detect Active Command Injection</strong></p>
<p>ACI occurs when you can see a response from a system call.  In the above code, the function <strong class="ib da">passthru()</strong> direct feedback to the document so you can see it.  This command will help you easily view and analyze system errors.</p>
<p><strong>Commands to try</strong></p>
<p id="6bbe" class="hz ia fv ib b ic id ie if ig ih ii ij ik il im in io ip iq ir is it iu iv iw dn gr" data-selectable-paragraph=""><strong class="ib da">Linux</strong></p>
<ul class="">
<li id="c00d" class="hz ia fv ib b ic id ie if ig ih ii ij ik il im in io ip iq ir is it iu iv iw jk jl jm gr" data-selectable-paragraph="">whoami</li>
<li id="5fb5" class="hz ia fv ib b ic jn ie if ig jo ii ij ik jp im in io jq iq ir is jr iu iv iw jk jl jm gr" data-selectable-paragraph="">id</li>
<li id="7720" class="hz ia fv ib b ic jn ie if ig jo ii ij ik jp im in io jq iq ir is jr iu iv iw jk jl jm gr" data-selectable-paragraph="">ifconfig/ip addr</li>
<li id="cb48" class="hz ia fv ib b ic jn ie if ig jo ii ij ik jp im in io jq iq ir is jr iu iv iw jk jl jm gr" data-selectable-paragraph="">uname -a</li>
<li id="5435" class="hz ia fv ib b ic jn ie if ig jo ii ij ik jp im in io jq iq ir is jr iu iv iw jk jl jm gr" data-selectable-paragraph="">ps -ef</li>
</ul>
<p id="05dd" class="hz ia fv ib b ic id ie if ig ih ii ij ik il im in io ip iq ir is it iu iv iw dn gr" data-selectable-paragraph=""><strong class="ib da">Windows</strong></p>
<ul class="">
<li id="d15d" class="hz ia fv ib b ic id ie if ig ih ii ij ik il im in io ip iq ir is it iu iv iw jk jl jm gr" data-selectable-paragraph="">whoami</li>
<li id="0817" class="hz ia fv ib b ic jn ie if ig jo ii ij ik jp im in io jq iq ir is jr iu iv iw jk jl jm gr" data-selectable-paragraph="">ver</li>
<li id="f839" class="hz ia fv ib b ic jn ie if ig jo ii ij ik jp im in io jq iq ir is jr iu iv iw jk jl jm gr" data-selectable-paragraph="">ipconfig</li>
<li id="37fe" class="hz ia fv ib b ic jn ie if ig jo ii ij ik jp im in io jq iq ir is jr iu iv iw jk jl jm gr" data-selectable-paragraph="">tasklist</li>
<li id="c086" class="hz ia fv ib b ic jn ie if ig jo ii ij ik jp im in io jq iq ir is jr iu iv iw jk jl jm gr" data-selectable-paragraph="">nestat -an</li>
</ul>
<p>To answer the questions below you need to navigate to <a target="_blank" href="https://en.anonyviet.com/next-link/?url=http%3A%2F%2F10.10.147.50%2Fevilshell.php" class="ext-link" rel="external nofollow noopener" onclick="this.target='_blank';">http://10.10.147.50/evilshell.php.</a></p>
<h4 id="ftoc-1-tap-tin-van-ban-la-nao-nam-trong-thu-muc-root-cua-trang-web" class="ftwp-heading">#1 What strange text file is in the website root directory?</h4>
<p>We can go to evilhell.php and try the whoami command.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34563 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_8fV_l8QsQya_YZzDL1Vitg.jpg" alt="TryHackMe: OWASP Top 10 Challenge Part 1 24" width="525" height="404" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_8fV_l8QsQya_YZzDL1Vitg.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_8fV_l8QsQya_YZzDL1Vitg-300x231.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge Part 1 29"/></p>
</p>
<p>Try next command <code>uname -a</code>.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34564 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_xwUOsPsRpCPKUOeU99vUPQ.jpg" alt="TryHackMe: OWASP Top 10 Challenge Part 1 25" width="525" height="399" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_xwUOsPsRpCPKUOeU99vUPQ.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_xwUOsPsRpCPKUOeU99vUPQ-300x228.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge Part 1 30"/></p>
<p>Continue to try the command <code>ls</code>.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34561 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_DakOlOzD46OiuE9VfzGQ1g.jpg" alt="TryHackMe: OWASP Top 10 Challenge Part 1 26" width="525" height="392" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_DakOlOzD46OiuE9VfzGQ1g.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_DakOlOzD46OiuE9VfzGQ1g-300x224.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge Part 1 31"/></p>
<p>What do you see?  I found the file drpepper.txt.</p>
<h4 id="ftoc-2-co-bao-nhieu-nguoi-dung-khong-phai-root-non-service-non-daemon" class="ftwp-heading">#2 How many non-root/non-service/non-daemon users are there?</h4>
<p>You can try the command<code> cat /etc/passwd</code></p>
</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34566 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_2Lvbf0U3RwrNxi0lBu0D5A.jpg" alt="TryHackMe: OWASP Top 10 Challenge Part 1 27" width="525" height="558" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_2Lvbf0U3RwrNxi0lBu0D5A.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_2Lvbf0U3RwrNxi0lBu0D5A-282x300.jpg 282w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge Part 1 32"/></p>
<p>Couldn&#8217;t find anything.</p>
<h4 id="ftoc-3-ung-dung-nay-dang-chay-voi-tu-cach-nguoi-dung-nao" class="ftwp-heading">#3 What user is this application running as?</h4>
<p>We found it upstairs, but let&#8217;s rewrite the whoami command.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34563 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_8fV_l8QsQya_YZzDL1Vitg.jpg" alt="TryHackMe: OWASP Top 10 Challenge Part 1 24" width="525" height="404" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_8fV_l8QsQya_YZzDL1Vitg.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_8fV_l8QsQya_YZzDL1Vitg-300x231.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge Part 1 29"/></p>
<p><strong>Answer:</strong> www-data</p>
<h4 id="ftoc-4-shell-cua-nguoi-dung" class="ftwp-heading">#4 User Shell?</h4>
<p>We can find it with the command cat /etc/passwd.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34567 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_1qBRRcXVPtEdEWoRp7uEkA.jpg" alt="TryHackMe: OWASP Top 10 Challenge Part 1 29" width="422" height="69" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_1qBRRcXVPtEdEWoRp7uEkA.jpg 422w, https://anonyviet.com/wp-content/uploads/2021/10/1_1qBRRcXVPtEdEWoRp7uEkA-300x49.jpg 300w" sizes="auto, (max-width: 422px) 100vw, 422px" title="TryHackMe: OWASP Top 10 Challenge Part 1 34"/></p>
<p><strong>Answer:</strong> usr/sbin/nologin</p>
<h4 id="ftoc-5-phien-ban-ubuntu-dang-chay" class="ftwp-heading">#5 What version of Ubuntu is running?</h4>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34568 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_tgRFYDHuo5SJYF2PJZ8_9A.jpg" alt="TryHackMe: OWASP Top 10 Challenge Part 1 30" width="700" height="388" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_tgRFYDHuo5SJYF2PJZ8_9A.jpg 700w, https://anonyviet.com/wp-content/uploads/2021/10/1_tgRFYDHuo5SJYF2PJZ8_9A-300x166.jpg 300w" sizes="auto, (max-width: 700px) 100vw, 700px" title="TryHackMe: OWASP Top 10 Challenge Part 1 35"/></p>
<p>As the picture above, you just need to enter the command<code> lsb_release -a</code> to know the Ubuntu version the application is running.</p>
<p><strong>Answer:</strong> 18.04.4</p>
<h4 id="ftoc-6-xem-motd" class="ftwp-heading">#6 Watch MOTD</h4>
<p>Just do a little search on the internet and you will know the command to show MOTD.  MOTD (Message Of The Day) is the message when you start an application in the terminal.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34569 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_jLfpOm0ZYjCFdb9UEAhHuw.jpg" alt="TryHackMe: OWASP Top 10 Challenge Part 1 31" width="525" height="436" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_jLfpOm0ZYjCFdb9UEAhHuw.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_jLfpOm0ZYjCFdb9UEAhHuw-300x249.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge Part 1 36"/></p>
<div class="TnITTtw-t TnITTtw-inside-layout">
<div class="TnITTtw-t TnITTtw-content">
<div class="TnITTtw-t TnITTtw-help-selected-wrap TnITTtw-hsw-54 TnITTtw-has-bottom-arr0w">
<div class="TnITTtw-t TnITTtw-help-inside-layout TnITTtw-hil-54">
<div id="TnITTtw-trVisibleLayout-54" class="TnITTtw-trVisibleLayout TnITTtw-t">
<div id="TnITTtw-trEntireLayout-54" class="TnITTtw-trEntireLayout TnITTtw-t">
<div class="TnITTtw-t TnITTtw-content-layout TnITTtw-content-layout-54">
<div class="TnITTtw-padded-single-translation TnITTtw-trans-wrap TnITTtw-t">
<p>The path of the MOTD file is /etc/update-motd.d.  I tried, but nothing.  I&#8217;m so confused, I decided to come back to see the suggestion :v.</p>
<div class="TnITTtw-mv-translit TnITTtw-translation-translit TnITTtw-t"><img decoding="async" loading="lazy" class="size-full wp-image-34570 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_-VfWtYoDRwBbUZq9XMbl0g.jpg" alt="TryHackMe: OWASP Top 10 Challenge Part 1 32" width="402" height="97" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_-VfWtYoDRwBbUZq9XMbl0g.jpg 402w, https://anonyviet.com/wp-content/uploads/2021/10/1_-VfWtYoDRwBbUZq9XMbl0g-300x72.jpg 300w" sizes="auto, (max-width: 402px) 100vw, 402px" title="TryHackMe: OWASP Top 10 Challenge Part 1 37"/></div>
<p>cat /etc/update-motd.d/00-header</p>
<div class="TnITTtw-more-butt0n TnITTtw-t iw-mTrigger" data-to="vi"><img decoding="async" loading="lazy" class="size-full wp-image-34565 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_0BrDecJbGLsI4AIVhY1h_w.jpg" alt="TryHackMe: OWASP Top 10 Challenge Part 1 33" width="525" height="518" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_0BrDecJbGLsI4AIVhY1h_w.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_0BrDecJbGLsI4AIVhY1h_w-300x296.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/10/1_0BrDecJbGLsI4AIVhY1h_w-75x75.jpg 75w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge Part 1 38"/></div>
<p>Successful!</p>
<p><strong>Answer:</strong> DR PEPPER</p>
<h3 id="ftoc-nhiem-vu-7-muc-do-nghiem-trong-2-broken-authentication" class="ftwp-heading" data-to="vi">Mission 7: [Mức độ nghiêm trọng 2] Broken Authentication</h3>
<p>For this vulnerability, we will study a logical flaw in the authentication mechanism.</p>
<p>Developers often forget to filter user-provided input (username and password) in their application, which can leave the application vulnerable to SQL injection attacks.  And we&#8217;re going to focus on a security flaw that&#8217;s caused by developer error but is very easy to exploit &#8211; re-registering an existing user.</p>
<p>For example, let&#8217;s say there is an existing user with the name admin and now we want to have access to that account, so what we can do is try to register that username again but there slightly modified.  We will enter “admin” (note the space at the beginning).  Now when you enter that information in username field and enter other required information like email or password and send that data.  It will register a new user but that user will have the same permissions as normal admin.  That new user will also be able to view all of the content presented under the user admin privileges.</p>
<p>To see the demo go to the website http://10.10.147.50:8888 and try to register the username, you will see that user already exists, so try to register a user “darren” and you will see that we are now signed in and will be able to view content that is only available in Darren&#8217;s account, and this is where we exploit this vulnerability.</p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34575 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_Dc_UP6UknviIYh4qR5W4Qw.jpg" alt="TryHackMe: OWASP Top 10 Challenge Part 1 35" width="511" height="468" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_Dc_UP6UknviIYh4qR5W4Qw.jpg 511w, https://anonyviet.com/wp-content/uploads/2021/10/1_Dc_UP6UknviIYh4qR5W4Qw-300x275.jpg 300w" sizes="auto, (max-width: 511px) 100vw, 511px" title="TryHackMe: OWASP Top 10 Challenge Part 1 40"/></p>
<p>I put a space in front of the word darren.</p>
<p>I am logged in as a member.  It&#8217;s successful!</p>
<p>We have found the flag.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34577 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_x7K9YPxkHgz_3I83DfUDnw.jpg" alt="TryHackMe: OWASP Top 10 Challenge Part 1 38" width="525" height="200" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_x7K9YPxkHgz_3I83DfUDnw.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_x7K9YPxkHgz_3I83DfUDnw-300x114.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge Part 1 43"/></p>
</p>
<p><strong>Answer:</strong> fe86079416a21a3c99937fea8874b667</p>
<h4 id="ftoc-2-bay-gio-hay-thu-thuc-hien-thu-thuat-tuong-tu-va-xem-lieu-ban-co-the-dang-nhap-bang-tai-khoan-arthur-hay-khong" class="ftwp-heading">#2 Now try to do the same trick and see if you can login with arthur account.</h4>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34572 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_tmWl4KqK3mM6tZH4itkPUA.jpg" alt="TryHackMe: OWASP Top 10 Challenge Part 1 39" width="525" height="483" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_tmWl4KqK3mM6tZH4itkPUA.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_tmWl4KqK3mM6tZH4itkPUA-300x276.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge Part 1 44"/></p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34573 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_pKME8r2QnCWGB1OV9l7Fqg.jpg" alt="TryHackMe: OWASP Top 10 Challenge Part 1 36" width="525" height="171" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_pKME8r2QnCWGB1OV9l7Fqg.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_pKME8r2QnCWGB1OV9l7Fqg-300x98.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge Part 1 41"/></p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34574 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_TvQuX_RAIZvzEGYh9JpF8g.jpg" alt="TryHackMe: OWASP Top 10 Challenge Part 1 41" width="472" height="360" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_TvQuX_RAIZvzEGYh9JpF8g.jpg 472w, https://anonyviet.com/wp-content/uploads/2021/10/1_TvQuX_RAIZvzEGYh9JpF8g-300x229.jpg 300w" sizes="auto, (max-width: 472px) 100vw, 472px" title="TryHackMe: OWASP Top 10 Challenge Part 1 46"/></p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34571 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_zlVnVTGlMBxj91jBYoKbTg.jpg" alt="TryHackMe: OWASP Top 10 Challenge Part 1 34" width="525" height="207" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_zlVnVTGlMBxj91jBYoKbTg.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_zlVnVTGlMBxj91jBYoKbTg-300x118.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge Part 1 39"/></p>
<h4 id="ftoc-3-flag-ma-ban-tim-thay-trong-tai-khoan-cua-arthur-la-gi" class="ftwp-heading">#3 What&#8217;s the flag you found in Arthur&#8217;s account?</h4>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34576 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_pxP47vPptHfBR71n3ZttaQ.jpg" alt="TryHackMe: OWASP Top 10 Challenge Part 1 43" width="509" height="163" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_pxP47vPptHfBR71n3ZttaQ.jpg 509w, https://anonyviet.com/wp-content/uploads/2021/10/1_pxP47vPptHfBR71n3ZttaQ-300x96.jpg 300w" sizes="auto, (max-width: 509px) 100vw, 509px" title="TryHackMe: OWASP Top 10 Challenge Part 1 48"/></p>
<p><strong>Answer:</strong> d9ac0f7db4fda460ac3edeb75d75e16e</p>
<p>Complete 2 common errors in OWASP 10, Broken Authentication and Command Injection.</p>
<p>The next part will still be exploiting other bugs in OWASP 10.</p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;34547&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;100&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 5\/5 - (100 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;width&quot;:&quot;142.5&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>            The article achieved: 5/5 &#8211; (100 votes)    </p>
</p></div>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/tryhackme-owasp-top-10-challenge-part-1/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2021/10/0_2NSPrwCU5nN8bQHP.jpg" medium="image"></media:content>
            	</item>
		<item>
		<title>TryHackMe: Thử thách OWASP Top 10 [Phần 2]</title>
		<link>https://en.anonyviet.com/tryhackme-thu-thach-owasp-top-10-phan-2/</link>
					<comments>https://en.anonyviet.com/tryhackme-thu-thach-owasp-top-10-phan-2/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Wed, 25 Jan 2023 17:47:07 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[Phần]]></category>
		<category><![CDATA[thách]]></category>
		<category><![CDATA[thử]]></category>
		<category><![CDATA[Top]]></category>
		<category><![CDATA[Tryhackme]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=3168</guid>

					<description><![CDATA[Ở phần 2 này, chúng ta sẽ tiếp tục khai thác các lỗ hổng khác trong OWASP Top 10 trên Tryhackme. Nếu bạn chưa biết OWASP là gì thì có thể đọc tại đây. Tham gia kênh Telegram của AnonyViet  👉 Link 👈 TryHackMe: Thử thách OWASP Top 10 [Phần 2] Nhiệm vụ 11: [Mức [&#8230;]]]></description>
										<content:encoded><![CDATA[<p></p>
<div id="ftwp-postcontent">
<p><strong>Ở phần 2 này, chúng ta sẽ tiếp tục khai thác các lỗ hổng khác trong OWASP Top 10 trên Tryhackme. Nếu bạn chưa biết OWASP là gì thì có thể đọc<a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Ftop-10-lo-hong-bao-mat-web-theo-cong-bo-owasp-2020%2F" rel="noopener" class="local-link"> tại đây</a>.</strong></p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Tham gia kênh <span style="color: #0000ff;">Telegram</span> của <span style="color: #008080;">AnonyViet </span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietchat" class="local-link" rel="noopener">Link</a></span> 👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<p><img alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2]" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2]" post-id="3168" fifu-featured="1" decoding="async" class="aligncenter wp-image-34580 size-full" src="https://anonyviet.com/wp-content/uploads/2021/10/1__o9kgTkh_63l51skO0hGcQ.jpg" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2]" width="687" height="384" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1__o9kgTkh_63l51skO0hGcQ.jpg 687w, https://anonyviet.com/wp-content/uploads/2021/10/1__o9kgTkh_63l51skO0hGcQ-300x168.jpg 300w" sizes="(max-width: 687px) 100vw, 687px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 37"/></p>
<h2 id="ftoc-tryhackme-thu-thach-owasp-top-10-phan-2" class="ftwp-heading">TryHackMe: Thử thách OWASP Top 10 [Phần 2]</h2>
<h3 id="ftoc-nhiem-vu-11-muc-do-nghiem-trong-3-ro-ri-du-lieu-nhay-cam" class="ftwp-heading">Nhiệm vụ 11: [Mức độ nghiêm trọng 3] Rò rỉ dữ liệu nhạy cảm</h3>
<p>Đã đến lúc áp dụng những gì bạn đã học được vào thực tế rồi.</p>
<h4 id="ftoc-1-dev-co-de-lai-mot-ghi-chu-chi-ra-rang-co-du-lieu-nhay-cam-trong-mot-thu-muc-nao-do" class="ftwp-heading"># 1 Dev có để lại một ghi chú chỉ ra rằng có dữ liệu nhạy cảm trong một thư mục nào đó.</h4>
<p><strong>Tên của thư mục đó là gì?</strong></p>
<p>Truy cập vào trang web và bạn sẽ thấy mục đăng nhập.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34581 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_aOOMEfFxHUYZBeZO57zFrw.jpg" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 33" width="525" height="386" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_aOOMEfFxHUYZBeZO57zFrw.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_aOOMEfFxHUYZBeZO57zFrw-300x221.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 38"/></p>
<p>Vào trang đăng nhập.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34582 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_3Ol11TfBZQglfuX7G7nEPA.jpg" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 34" width="525" height="362" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_3Ol11TfBZQglfuX7G7nEPA.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_3Ol11TfBZQglfuX7G7nEPA-300x207.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 39"/></p>
<p>Kiểm tra mã nguồn của web.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34583 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_CUxt_NkfB5L_hPYK684YBA.jpg" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 35" width="525" height="267" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_CUxt_NkfB5L_hPYK684YBA.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_CUxt_NkfB5L_hPYK684YBA-300x153.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 40"/></p>
<p>Các bạn có thấy cái mà mình đang thấy không :v.</p>
<p><strong>Đáp án:</strong> /assets</p>
<h4 id="ftoc-2-truy-cap-den-thu-muc-ban-da-tim-thay-va-tim-file-co-kha-nang-chua-du-lieu-nhay-cam" class="ftwp-heading"># 2 Truy cập đến thư mục bạn đã tìm thấy. Và tìm file có khả năng chứa dữ liệu nhạy cảm</h4>
<p>Truy cập vào thư mục assets.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34584 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_ZC4e3K8opyf5pejy2o60RQ.jpg" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 36" width="525" height="284" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_ZC4e3K8opyf5pejy2o60RQ.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_ZC4e3K8opyf5pejy2o60RQ-300x162.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 41"/></p>
<p>Thành công rồi đó.</p>
<p><strong>Đáp án:</strong> webapp.db</p>
<h4 id="ftoc-3-khai-thac-file-chua-du-lieu-nhay-cam-va-tim-ma-bam-mat-khau" class="ftwp-heading"># 3 Khai thác file chứa dữ liệu nhạy cảm và tìm mã băm mật khẩu</h4>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34585 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_K5GwAupErjrryC1FZkbQog.png" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 37" width="639" height="75" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_K5GwAupErjrryC1FZkbQog.png 639w, https://anonyviet.com/wp-content/uploads/2021/10/1_K5GwAupErjrryC1FZkbQog-300x35.png 300w" sizes="auto, (max-width: 639px) 100vw, 639px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 42"/></p>
<p>Chúng ta có thể thấy rằng có một cơ sở dữ liệu SQlite trong thư mục hiện tại.</p>
<p>Để truy cập nó, mình sử dụng lệnh <code>sqlite3 &lt;database-name&gt;</code></p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34586 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_JZaGRHZn5FBuP91npO7j5Q.png" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 38" width="539" height="132" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_JZaGRHZn5FBuP91npO7j5Q.png 539w, https://anonyviet.com/wp-content/uploads/2021/10/1_JZaGRHZn5FBuP91npO7j5Q-300x73.png 300w" sizes="auto, (max-width: 539px) 100vw, 539px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 43"/></p>
<p>Từ đây, chúng ta có thể xem các bảng trong cơ sở dữ liệu bằng cách sử dụng lệnh .tables:</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34587 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_SenjtNQskPp_iUOeOZY_FA.png" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 39" width="324" height="87" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_SenjtNQskPp_iUOeOZY_FA.png 324w, https://anonyviet.com/wp-content/uploads/2021/10/1_SenjtNQskPp_iUOeOZY_FA-300x81.png 300w" sizes="auto, (max-width: 324px) 100vw, 324px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 44"/></p>
<p>Mình có thể kết xuất tất cả dữ liệu ra khỏi bảng, nhưng mình sẽ không biết ý nghĩa của mỗi cột trừ khi xem thông tin bảng. Trước tiên, hãy sử dụng lệnh <code>PRAGMA table_info(customers);</code> để xem thông tin bảng, sau đó sử dụng lệnh <code>SELECT * FROM customers;</code> để kết xuất thông tin khỏi bảng:</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34588 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_K1CTkSNBFmre_AiJCH3-FQ.png" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 40" width="387" height="111" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_K1CTkSNBFmre_AiJCH3-FQ.png 387w, https://anonyviet.com/wp-content/uploads/2021/10/1_K1CTkSNBFmre_AiJCH3-FQ-300x86.png 300w" sizes="auto, (max-width: 387px) 100vw, 387px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 45"/></p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34589 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_7clRJ1vlb1L2N8XXgdTTRg.png" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 41" width="619" height="106" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_7clRJ1vlb1L2N8XXgdTTRg.png 619w, https://anonyviet.com/wp-content/uploads/2021/10/1_7clRJ1vlb1L2N8XXgdTTRg-300x51.png 300w" sizes="auto, (max-width: 619px) 100vw, 619px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 46"/></p>
<p>Giờ chúng ta đã tìm ra được mã băm rồi đó.</p>
<p><strong>Đáp án:</strong> 6eea9b7ef19179a06954edd0f6c05ceb</p>
<h4 id="ftoc-4-be-khoa-ma-bam" class="ftwp-heading">#4 Bẻ khóa mã băm</h4>
<p>Để tìm ra mật khẩu dưới dạng văn bản thuần thì các bạn truy cập vào trang crackstation<a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fcrackstation.net%2F" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';"> tại đây</a>.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34590 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_HUKMNp46GAqLCZWjZimZgw.png" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 42" width="700" height="282" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_HUKMNp46GAqLCZWjZimZgw.png 700w, https://anonyviet.com/wp-content/uploads/2021/10/1_HUKMNp46GAqLCZWjZimZgw-300x121.png 300w" sizes="auto, (max-width: 700px) 100vw, 700px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 47"/></p>
<p>Crackstation hoạt động bằng cách sử dụng một danh sách từ điển lớn. Nếu mật khẩu không có trong danh sách từ thì Crackstation sẽ không thể bẻ khóa mã băm.</p>
<p>Nếu Crackstation không bẻ khóa được mã băm này, thì hàm băm đó đã được thiết kế đặc biệt để không thể bẻ khóa được.</p>
<p><strong>Đáp án: </strong>qwertyuiop</p>
<h4 id="ftoc-5-dang-nhap-voi-tu-cach-la-admin-va-tim-flag" class="ftwp-heading">#5 Đăng nhập với tư cách là admin và tìm flag</h4>
<p>Sử dụng tài khoản và mật khẩu đã tìm được để đăng nhập vào tài khoản admin.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34591 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_V6p5UuXOXTDA5pWEJyaCrQ.png" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 43" width="700" height="305" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_V6p5UuXOXTDA5pWEJyaCrQ.png 700w, https://anonyviet.com/wp-content/uploads/2021/10/1_V6p5UuXOXTDA5pWEJyaCrQ-300x131.png 300w" sizes="auto, (max-width: 700px) 100vw, 700px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 48"/></p>
<p><strong>Đáp án:</strong> THM{Yzc2YjdkMjE5N2VjMzNhOTE3NjdiMjdl}</p>
<h3 id="ftoc-nhiem-vu-13-muc-do-nghiem-trong-4-xml-external-entity" class="ftwp-heading">Nhiệm vụ 13: [Mức độ nghiêm trọng 4] XML External Entity</h3>
<h4 id="f8c4" class="hz ia fv ib b ic id ie if ig ih ii ij ik il im in io ip iq ir is it iu iv iw dn gr ftwp-heading">#1 XML là viết tắt của từ gì?</h4>
<p id="608d" class="hz ia fv ib b ic id ie if ig ih ii ij ik il im in io ip iq ir is it iu iv iw dn gr" data-selectable-paragraph=""><strong class="ib da">Đáp án :</strong> Extensible Markup Language.</p>
<h4 id="a6db" class="hz ia fv ib b ic id ie if ig ih ii ij ik il im in io ip iq ir is it iu iv iw dn gr ftwp-heading">#2 Có bắt buộc phải mở đầu XML trong các tài liệu XML không?</h4>
<p id="eef8" class="hz ia fv ib b ic id ie if ig ih ii ij ik il im in io ip iq ir is it iu iv iw dn gr" data-selectable-paragraph=""><strong class="ib da">Đáp án :</strong> Không</p>
<h4 id="079e" class="hz ia fv ib b ic id ie if ig ih ii ij ik il im in io ip iq ir is it iu iv iw dn gr ftwp-heading">#3 Chúng ta có thể xác thực các tài liệu XML dựa trên một lược đồ không?</h4>
<p id="97f8" class="hz ia fv ib b ic id ie if ig ih ii ij ik il im in io ip iq ir is it iu iv iw dn gr" data-selectable-paragraph=""><strong class="ib da">Đáp án :</strong> Có</p>
<h4 id="0e07" class="hz ia fv ib b ic id ie if ig ih ii ij ik il im in io ip iq ir is it iu iv iw dn gr ftwp-heading">#4 Làm thế nào để chỉ định phiên bản XML và cách mã hóa trong tài liệu XML?</h4>
<p id="7aa1" class="hz ia fv ib b ic id ie if ig ih ii ij ik il im in io ip iq ir is it iu iv iw dn gr" data-selectable-paragraph=""><strong class="ib da">Đáp án : </strong>XML Prolog</p>
<h3 id="ftoc-nhiem-vu-14-muc-do-nghiem-trong-4-xml-external-entity-dtd" class="ftwp-heading">Nhiệm vụ 14: [Mức độ nghiêm trọng 4] XML External Entity — DTD</h3>
<p>Trước khi bắt đầu tìm hiểu về XXE, chúng ta sẽ phải hiểu DTD trong XML là gì.</p>
<p>Đầu tiên tìm hiêu cách DTD xác thực XML. Đây là ý nghĩa của tất cả các thuật ngữ được sử dụng trong note.dtd</p>
<p>!DOCTYPE note – Xác định phần tử gốc của tài liệu có tên note</p>
<p>!ELEMENT note – Xác định phần tử note phải chứa các thành phần: “to, from, heading, body”</p>
<p>!ELEMENT to – Xác định phần tử thuộc loại “#PCDATA”</p>
<p>!ELEMENT from – Xác định phần tử có kiểu “#PCDATA”</p>
<p>!ELEMENT heading – Xác định phần tử tiêu đề thuộc loại “#PCDATA”</p>
<p>!ELEMENT body – Xác định phần tử nội dung thuộc loại “#PCDATA”</p>
<p>LƯU Ý: #PCDATA có nghĩa là parseable character data (dữ liệu ký tự có thể phân tích cú pháp).</p>
<h4 id="ftoc-1-lam-the-nao-de-xac-dinh-mot-root-element" class="ftwp-heading"># 1 Làm thế nào để xác định một <strong class="ib da">ROOT element</strong>?</h4>
<p><strong>Đáp án:</strong> !ELEMENT</p>
<h4 id="ftoc-2-xac-dinh-root-element-nhu-the-nao" class="ftwp-heading"># 2 Xác định ROOT element như thế nào?</h4>
<p><strong>Đáp án: </strong>!DOCTYPE</p>
<h4 id="ftoc-3-xac-dinh-entity-moi-nhu-the-nao" class="ftwp-heading"># 3 Xác định ENTITY mới như thế nào?</h4>
<p><strong>Đáp án: </strong>!ENTITY</p>
<h3 id="ftoc-nhiem-vu-15-muc-do-nghiem-trong-4-xml-external-entity-xxe-payload" class="ftwp-heading">Nhiệm vụ 15 [Mức độ nghiêm trọng 4] XML External Entity — XXE Payload</h3>
<p>1) Payload đầu tiên mà chúng ta sẽ thấy rất đơn giản. Nếu bạn đã đọc những nhiệm vụ trước đó thì bạn sẽ payload này.</p>
<pre class="EnlighterJSRAW" data-enlighter-language="generic">&lt;!DOCTYPE replace [&lt;!ENTITY name “feast”&gt; ]&gt;&#13;
&lt;userInfo&gt;&#13;
&lt;firstName&gt;falcon&lt;/firstName&gt;&#13;
&lt;lastName&gt;&amp;name;&lt;/lastName&gt;&#13;
&lt;/userInfo&gt;</pre>
<p>Chúng ta đang xác định một ENTITY và gán cho nó giá trị feast. Tiếp, chúng ta sẽ sử dụng ENTITY đó trong code.</p>
<p>2) Chúng ta cũng có thể sử dụng XXE để đọc một số tệp từ hệ thống bằng cách xác định ENTITY và sử dụng từ khóa SYSTEM</p>
<pre class="EnlighterJSRAW" data-enlighter-language="generic">&lt;?xml version=”1.0"?&gt;&#13;
&lt;!DOCTYPE root [&lt;!ENTITY read SYSTEM ‘file:////cat /etc/passwd&gt;]&gt;&#13;
&lt;root&gt;&amp;read;&lt;/root&gt;&#13;
</pre>
<p>Chúng ta xác định ENTITY với giá trị là `SYSTEM` và đường dẫn của tệp.</p>
<p>Nếu mình sử dụng payload này thì một trang web dễ bị tấn công bởi XXE (thông thường) sẽ hiển thị nội dung của tệp /etc/passwd.</p>
<p>Theo cách tương tự, chúng ta có thể sử dụng loại payload này để đọc các tệp khác.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34596 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_tEnItBPE8PjGIzjTtdY_bg.jpg" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 44" width="525" height="244" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_tEnItBPE8PjGIzjTtdY_bg.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_tEnItBPE8PjGIzjTtdY_bg-300x139.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 49"/></p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34595 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_tcF335F1mphsE131r0tcHA.jpg" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 45" width="525" height="236" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_tcF335F1mphsE131r0tcHA.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_tcF335F1mphsE131r0tcHA-300x135.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 50"/></p>
<h3 id="ftoc-nhiem-vu-16-muc-do-nghiem-trong-4-doi-tuong-ben-ngoai-xml-exploiting" class="ftwp-heading">Nhiệm vụ 16: [Mức độ nghiêm trọng 4] Đối tượng bên ngoài XML – Exploiting</h3>
<h4 id="ftoc-3-ten-cua-nguoi-dung-trong-etc-passwd-la-gi" class="ftwp-heading">#3 Tên của người dùng trong /etc/passwd là gì?</h4>
<pre class="EnlighterJSRAW" data-enlighter-language="generic">&lt;?xml version="1.0"?&gt;&#13;
&lt;!DOCTYPE root [&lt;!ENTITY read SYSTEM 'file:///etc/passwd'&gt;]&gt;&#13;
&lt;root&gt;&amp;read;&lt;/root&gt;&#13;
</pre>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34597 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_U88cjPGRANT_izAp7sP2hg.png" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 46" width="500" height="74" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_U88cjPGRANT_izAp7sP2hg.png 500w, https://anonyviet.com/wp-content/uploads/2021/10/1_U88cjPGRANT_izAp7sP2hg-300x44.png 300w" sizes="auto, (max-width: 500px) 100vw, 500px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 51"/></p>
<p><strong>Đáp án:</strong> falcon</p>
<h4 id="ftoc-4-khoa-ssh-cua-falcon-nam-o-dau" class="ftwp-heading">#4 Khóa SSH của falcon nằm ở đâu?</h4>
<p>Tìm kiếm trên mạng xem khóa SSH được lưu ở đâu.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34598 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_s68WbEf_PAX1Vs7bIaLmEA.png" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 47" width="700" height="111" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_s68WbEf_PAX1Vs7bIaLmEA.png 700w, https://anonyviet.com/wp-content/uploads/2021/10/1_s68WbEf_PAX1Vs7bIaLmEA-300x48.png 300w" sizes="auto, (max-width: 700px) 100vw, 700px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 52"/></p>
<p><strong>Đáp án:</strong> /home/falcon/.ssh/id_rsa</p>
<h4 id="ftoc-5-18-ky-tu-dau-tien-trong-private-key-cua-falcon-la-gi" class="ftwp-heading">#5 18 ký tự đầu tiên trong private key của falcon là gì?</h4>
<pre class="EnlighterJSRAW" data-enlighter-language="generic">&lt;?xml version=”1.0"?&gt;&#13;
&lt;!DOCTYPE root [&lt;!ENTITY read SYSTEM ‘file:////home/falcon/.ssh/id_rsa&gt;]&gt;&#13;
&lt;root&gt;&amp;read;&lt;/root&gt;&#13;
</pre>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34599 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_hBqJmlaXB9UeiBbgJDsuaQ-1.jpg" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 48" width="525" height="187" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_hBqJmlaXB9UeiBbgJDsuaQ-1.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_hBqJmlaXB9UeiBbgJDsuaQ-1-300x107.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 53"/></p>
<p><strong>Đáp án: </strong>MIIEogIBAAKCAQEA7b</p>
<h3 id="ftoc-nhiem-vu-18-muc-do-nghiem-trong-5-broken-access-control-thu-thach-idor" class="ftwp-heading">Nhiệm vụ 18: [Mức độ nghiêm trọng 5] Broken Access Control (Thử thách IDOR)</h3>
<p>IDOR, hoặc Insecure Direct Object Reference (tham chiếu đối tượng trực tiếp không an toàn), là hành động khai thác cấu hình sai trong cách xử lý đầu vào của người dùng, để truy cập vào các tài nguyên mà thông thường bạn không thể truy cập. IDOR là một loại lỗ hổng kiểm soát truy cập.</p>
<p>Ví dụ: giả sử chúng ta đang đăng nhập vào tài khoản ngân hàng của mình và sau khi tự xác thực chính xác, chúng ta sẽ được đưa đến một URL như sau https://example.com/bank?account_number=1234. Trên trang đó, mình có thể xem tất cả các chi tiết ngân hàng quan trọng của bả thân và người dùng sẽ làm bất cứ điều gì họ cần làm và suy nghĩ không có gì sai.</p>
<p>Tuy nhiên, có một vấn đề lớn tiềm ẩn ở đây, một tin tặc có thể thay đổi thông số account_number thành một số khác như 1235 và nếu trang web được định cấu hình không chính xác, thì hacker sẽ có quyền truy cập vào thông tin ngân hàng của người khác (như <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fwww.techrum.vn%2Fthreads%2Fd%25E1%25BB%25AF-li%25E1%25BB%2587u-c%25E1%25BB%25A7a-3-000-ng%25C6%25B0%25E1%25BB%259Di-d%25C3%25B9ng-metap-vn-c%25E1%25BB%25A7a-ti%25E1%25BA%25BFn-s%25E1%25BB%25B9-%25C3%259Ac-%25C4%2591ang-b%25E1%25BB%258B-rao-b%25C3%25A1n-%25E1%25BB%259F-tr%25C3%25AAn-di%25E1%25BB%2585n-%25C4%2591%25C3%25A0n-hacker.471410%2F" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">vụ metap</a>).</p>
<h4 id="ftoc-1-doc-va-hieu-cach-idor-hoat-dong" class="ftwp-heading">#1 Đọc và hiểu cách IDOR hoạt động.</h4>
<h4 id="ftoc-2-trien-khai-va-truy-cap-http-10-10-220-97-dang-nhap-voi-ten-nguoi-dung-la-noot-va-mat-khau-la-test1234" class="ftwp-heading">#2 Triển khai và truy cập http://10.10.220.97 – Đăng nhập với tên người dùng là noot và mật khẩu là test1234.</h4>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34600 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_UhozwNrgn6sPPeD1GFFksw.png" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 49" width="700" height="244" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_UhozwNrgn6sPPeD1GFFksw.png 700w, https://anonyviet.com/wp-content/uploads/2021/10/1_UhozwNrgn6sPPeD1GFFksw-300x105.png 300w" sizes="auto, (max-width: 700px) 100vw, 700px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 54"/></p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34602 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_33AdyeWQZqBu8ni9r_eZ1A.png" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 50" width="700" height="113" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_33AdyeWQZqBu8ni9r_eZ1A.png 700w, https://anonyviet.com/wp-content/uploads/2021/10/1_33AdyeWQZqBu8ni9r_eZ1A-300x48.png 300w" sizes="auto, (max-width: 700px) 100vw, 700px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 55"/></p>
<p>Mình đã thử tăng dần số sau note = 1 theo thứ tự, nhưng nó không xảy ra. Nhưng khi thử số 0 thì lại có kết quả.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34601 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_cSmXDYEUZ674x2FlAVspDw.png" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 51" width="700" height="142" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_cSmXDYEUZ674x2FlAVspDw.png 700w, https://anonyviet.com/wp-content/uploads/2021/10/1_cSmXDYEUZ674x2FlAVspDw-300x61.png 300w" sizes="auto, (max-width: 700px) 100vw, 700px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 56"/></p>
<p><strong>Đáp án:</strong> flag{fivefourthree}</p>
<h3 id="ftoc-nhiem-vu-19-muc-do-nghiem-trong-6-cau-hinh-sai-bao-mat" class="ftwp-heading">Nhiệm vụ 19: [Mức độ nghiêm trọng 6] Cấu hình sai bảo mật</h3>
<h4 id="ftoc-cau-hinh-sai-bao-mat-security-misconfiguration" class="ftwp-heading"><strong>Cấu hình sai bảo mật (<strong class="ib da">Security Misconfiguration</strong>)</strong></h4>
<p>Cấu hình sai bảo mật khác với 10 lỗ hổng OWASP hàng đầu khác, bởi vì lỗi này chỉ xảy ra khi bạn cấu hình sai bảo mật hệ thống.</p>
<h4 id="ftoc-cau-hinh-sai-bao-mat-bao-gom" class="ftwp-heading"><strong>Cấu hình sai bảo mật bao gồm:</strong></h4>
<p>Các quyền được cấu hình kém trên các dịch vụ đám mây, chẳng hạn như nhóm S3 bật các tính năng không cần thiết, như dịch vụ, trang, tài khoản hoặc đặc quyền của tài khoản mặc định với mật khẩu không thay đổi, thông báo lỗi quá chi tiết và cho phép kẻ tấn công tìm hiểu thêm về hệ thống, không sử dụng <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fviblo.asia%2Fp%2Fhttp-security-headers-ByEZkwwWZQ0" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">HTTP security headers</a> hoặc tiết lộ quá nhiều chi tiết trong Server: HTTP header.</p>
<p>Lỗ hổng này thường có thể dẫn đến nhiều lỗ hổng khác hơn, chẳng hạn như thông tin xác thực mặc định cho phép bạn truy cập vào dữ liệu nhạy cảm, XXE hoặc chèn lệnh trên các trang quản trị.</p>
<p>Máy ảo trong nhiệm vụ này tập trung vào mật khẩu mặc định. Đây là một ví dụ cụ thể về cấu hình sai bảo mật. Bạn nên thay đổi bất kỳ mật khẩu mặc định nào trong hệ thống.</p>
<p>Mật khẩu mặc định rất phổ biến trong các thiết bị nhúng và Internet of Things, và phần lớn các chủ sở hữu thiết bị không thay đổi các mật khẩu này.</p>
<p>Mức độ rủi ro về thông tin xác thực mặc định còn tùy theo quan điểm của kẻ tấn công. Chúng có thể truy cập vào trang quản trị, các dịch vụ được thiết kế cho quản trị viên hệ thống hoặc nhà sản xuất, hoặc thậm chí cơ sở hạ tầng mạng cũng có thể vô cùng hữu ích trong việc tấn công doanh nghiệp. Từ việc tiếp xúc dữ liệu đến RCE dễ dàng, ảnh hưởng của thông tin xác thực mặc định có thể rất nghiêm trọng.</p>
<p>Vào tháng 10 năm 2016, Dyn (một nhà cung cấp DNS) đã bị DDoS bởi một trong những cuộc tấn công DDoS đáng nhớ nhất trong 10 năm qua. Lưu lượng truy cập chủ yếu đến từ Internet of Things và các thiết bị mạng như bộ định tuyến và modem, bị nhiễm phần mềm độc hại Mirai.</p>
<p>Phần mềm độc hại đã xâm nhập vào hệ thống như thế nào? Bằng mật khẩu mặc định. Phần mềm độc hại có danh sách chứa 63 cặp username/password và tin tặc sẽ cố gắng đăng nhập vào các dịch vụ telnet bị lộ.</p>
<p>Các cuộc tấn công DDoS rất đáng chú ý vì nó đã khiến nhiều trang web và dịch vụ lớn bị gián đoạn. Amazon, Twitter, Netflix, GitHub, Xbox Live, PlayStation Network và nhiều dịch vụ khác đã offline trong vài giờ trong 3 đợt tấn công DDoS vào Dyn.</p>
<p>Ví dụ thực tế: Máy ảo này bị cấu hình sai bảo mật, như một lỗi của danh sách 10 lỗ hổng hàng đầu của OWASP.</p>
<p>Triển khai VM và xâm nhập bằng cách khai thác cấu hình sai bảo mật (Security Misconfiguration)!</p>
<p><strong>#1 Triển khai VM (Máy ảo)</strong></p>
<p><strong># 2 Xâm nhập vào ứng dụng web và tìm flag</strong></p>
<p>Chúng ta có thể nghiên cứu username và mật khẩu mặc định là gì của pensive notes.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34682 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_QS5leBfmI1ruCa9jiZ24aw.jpg" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 52" width="525" height="211" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_QS5leBfmI1ruCa9jiZ24aw.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_QS5leBfmI1ruCa9jiZ24aw-300x121.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 57"/></p>
<p>Xem mình tìm thấy gì nào.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34683 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_6w_FFnGE8_VJlf4hfvuHGQ.png" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 53" width="700" height="130" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_6w_FFnGE8_VJlf4hfvuHGQ.png 700w, https://anonyviet.com/wp-content/uploads/2021/10/1_6w_FFnGE8_VJlf4hfvuHGQ-300x56.png 300w" sizes="auto, (max-width: 700px) 100vw, 700px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 58"/></p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34684 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_9KHf2XpT5_dPNhejAwKdpg.png" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 54" width="700" height="300" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_9KHf2XpT5_dPNhejAwKdpg.png 700w, https://anonyviet.com/wp-content/uploads/2021/10/1_9KHf2XpT5_dPNhejAwKdpg-300x129.png 300w" sizes="auto, (max-width: 700px) 100vw, 700px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 59"/></p>
<p><strong>Đáp án:</strong></p>
<p id="19cc" class="hz ia fv ib b ic id ie if ig ih ii ij ik il im in io ip iq ir is it iu iv iw dn gr" data-selectable-paragraph="">thm{4b9513968fd564a87b28aa1f9d672e17}</p>
<h3 id="ftoc-nhiem-vu-20-muc-do-nghiem-trong-7-cross-site-scripting-xss" class="ftwp-heading">Nhiệm vụ 20: [Mức độ nghiêm trọng 7] Cross-site Scripting (XSS)</h3>
<h4 id="ftoc-giai-thich-xss" class="ftwp-heading">Giải thích XSS</h4>
<p>Cross-site scripting, còn được gọi là XSS là một lỗ hổng bảo mật thường thấy trong các ứng dụng web. Đây là một kiểu tiêm code có thể cho phép kẻ tấn công thực thi các tập lệnh độc hại và khiến nó thực thi trên máy của nạn nhân.</p>
<p>Một ứng dụng web dễ bị tấn công bởi XSS nếu nó sử dụng đầu vào của người dùng mà chưa được lọc. XSS có thể sử dụng trong Javascript, VBScript, Flash và CSS. Có ba loại XSS web chính:</p>
<p><strong class="ib da">Stored XSS: </strong>Là loại XSS nguy hiểm nhất. Đây là nơi bắt nguồn một chuỗi mã độc từ cơ sở dữ liệu của trang web. Điều này thường xảy ra khi một trang web lấy đầu vào từ người dùng mà chưa được lọc (loại bỏ “các ký tự đặc biệt” của người dùng nhập) khi được chèn vào cơ sở dữ liệu.</p>
<p><strong class="ib da">Reflected XSS: </strong>Payload độc hại là một phần request của victims đối với trang web. Trang web bao gồm payload này để phản hồi lại người dùng. Tóm lại, kẻ tấn công cần lừa nạn nhân nhấp vào URL để thực thi payload độc hại.</p>
<p><strong class="ib da">DOM-Based XSS: </strong>DOM là viết tắt của Document Object Model và là một giao diện lập trình cho các tài liệu HTML và XML. Nó giúp các chương trình có thể thay đổi cấu trúc, kiểu và nội dung tài liệu. Trang web là một tài liệu và tài liệu này có thể được hiển thị trong cửa sổ trình duyệt hoặc dưới dạng mã nguồn HTML.</p>
<p>Để biết thêm các giải thích và bài tập XSS, hãy <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2F10-website-giup-ban-thuc-hanh-ky-nang-hack-xss%2F" rel="noopener" class="local-link">đọc bài viết này.</a></p>
<h4 id="ftoc-xss-payloads" class="ftwp-heading"><strong class="ib da">XSS Payloads</strong></h4>
<p>Hãy nhớ rằng, XSS là một lỗ hổng có thể bị lợi dụng để thực thi Javascript độc hại trên máy của nạn nhân. Một số loại payload phổ biến được sử dụng:</p>
<p>XSS-Payloads.com (http://www.xss-payloads.com/) là một trang web có payload, công cụ, tài liệu liên quan đến XSS nhiều thứ khác nữa. Bạn có thể tải các payload XSS chụp ảnh nhanh từ webcam hoặc thậm chí port scanner.</p>
<h4 id="ftoc-cac-thu-thach-xss" class="ftwp-heading"><strong>Các thử thách XSS</strong></h4>
<p>Máy ảo đi kèm với nhiệm vụ này dựa trên DOM, có Reflected và Stored XSS. Giờ hãy triển khai máy ảo và bắt đầu khai thác lỗ hổng XSS nào.</p>
<p><strong>#1 Triển khai VM (Máy ảo)</strong></p>
<p><strong>#2 Truy cập http://10.10.193.134/reflected và tạo một payload <strong class="ib da">reflected</strong> XSS để tạo cửa sổ popup “<strong class="ib da">Hello</strong>“.</strong></p>
<p>Viết Script:</p>
<p><code>&lt;script&gt;alert(“hello”)&lt;/script&gt;</code></p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34686 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_6-04EfkkK5zquG2jnJKhSA.jpg" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 55" width="525" height="254" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_6-04EfkkK5zquG2jnJKhSA.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_6-04EfkkK5zquG2jnJKhSA-300x145.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 60"/></p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34687 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_pwPyAvOMvQ6efse4af2nCg.jpg" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 56" width="525" height="331" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_pwPyAvOMvQ6efse4af2nCg.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_pwPyAvOMvQ6efse4af2nCg-300x189.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 61"/></p>
<p><strong>Đáp án:</strong> ThereIsMoreToXSSThanYouThink</p>
<p><strong>#3 Trên cùng một trang <strong class="ib da">reflective</strong>, tạo một payload XSS bật cửa sổ popup chứa địa chỉ IP của bạn.</strong></p>
<p id="4d1f" class="hz ia fv ib b ic id ie if ig ih ii ij ik il im in io ip iq ir is it iu iv iw dn gr" data-selectable-paragraph="">&lt;script&gt;alert(window.location.hostname)&lt;/script&gt;</p>
<p data-selectable-paragraph=""><img decoding="async" loading="lazy" class="size-full wp-image-34688 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_GQdJAhQQo6WEcp6RrcSfXg.png" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 57" width="700" height="190" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_GQdJAhQQo6WEcp6RrcSfXg.png 700w, https://anonyviet.com/wp-content/uploads/2021/10/1_GQdJAhQQo6WEcp6RrcSfXg-300x81.png 300w" sizes="auto, (max-width: 700px) 100vw, 700px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 62"/></p>
<p data-selectable-paragraph=""><img decoding="async" loading="lazy" class="size-full wp-image-34689 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_eHFGTTbS5XU8bbe8u1zf7Q.png" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 58" width="662" height="254" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_eHFGTTbS5XU8bbe8u1zf7Q.png 662w, https://anonyviet.com/wp-content/uploads/2021/10/1_eHFGTTbS5XU8bbe8u1zf7Q-300x115.png 300w" sizes="auto, (max-width: 662px) 100vw, 662px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 63"/></p>
<p data-selectable-paragraph=""><strong>Đáp án:</strong> ReflectiveXss4TheWin</p>
<div class="TnITTtw-t TnITTtw-help-inside-layout TnITTtw-hil-14">
<div id="TnITTtw-trVisibleLayout-14" class="TnITTtw-trVisibleLayout TnITTtw-t">
<div id="TnITTtw-trEntireLayout-14" class="TnITTtw-trEntireLayout TnITTtw-t">
<div class="TnITTtw-t TnITTtw-content-layout TnITTtw-content-layout-14">
<div class="TnITTtw-padded-single-translation TnITTtw-trans-wrap TnITTtw-t">
<p><strong>#4 Truy cập đến http://10.10.193.134/stored và tạo tài khoản.</strong></p>
<p>Sau đó, thêm bình luận và xem liệu bạn có thể chèn code HTML hay không.</p>
<p><code>&lt;html&gt;&lt;body&gt;&lt;p&gt;I am a emre&lt;/p&gt;&lt;/body&gt;&lt;/html&gt;</code></p>
<div class="TnITTtw-ico-listen TnITTtw-listen-butt0n TnITTtw-listen-translation TnITTtw-t" data-to="en"><img decoding="async" loading="lazy" class="size-full wp-image-34690 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_Wz0R4YSqwLTQY6eCR_Z-QA.png" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 59" width="700" height="218" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_Wz0R4YSqwLTQY6eCR_Z-QA.png 700w, https://anonyviet.com/wp-content/uploads/2021/10/1_Wz0R4YSqwLTQY6eCR_Z-QA-300x93.png 300w" sizes="auto, (max-width: 700px) 100vw, 700px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 64"/></div>
<div data-to="en"><img decoding="async" loading="lazy" class="size-full wp-image-34691 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_sUATI3UMA1spt04QaZlQ6A.png" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 60" width="700" height="173" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_sUATI3UMA1spt04QaZlQ6A.png 700w, https://anonyviet.com/wp-content/uploads/2021/10/1_sUATI3UMA1spt04QaZlQ6A-300x74.png 300w" sizes="auto, (max-width: 700px) 100vw, 700px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 65"/></div>
</div>
</div>
</div>
</div>
</div>
<p><strong>#5 Trên cùng một trang, hãy tạo một cửa sổ popup chứa cookie của bạn.</strong></p>
<p><code>&lt;script&gt;alert(document.cookie)&lt;/script&gt;</code></p>
<div><img decoding="async" loading="lazy" class="size-full wp-image-34692 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_ZhYeauKp7I37YM3VB5mnDA.png" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 61" width="700" height="267" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_ZhYeauKp7I37YM3VB5mnDA.png 700w, https://anonyviet.com/wp-content/uploads/2021/10/1_ZhYeauKp7I37YM3VB5mnDA-300x114.png 300w" sizes="auto, (max-width: 700px) 100vw, 700px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 66"/></div>
<div><img decoding="async" loading="lazy" class="size-full wp-image-34693 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_x1aoTA_p7kMLrklB4vsLGA.png" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 62" width="601" height="248" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_x1aoTA_p7kMLrklB4vsLGA.png 601w, https://anonyviet.com/wp-content/uploads/2021/10/1_x1aoTA_p7kMLrklB4vsLGA-300x124.png 300w" sizes="auto, (max-width: 601px) 100vw, 601px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 67"/></div>
<p><strong>Đáp án:</strong> W3LL_D0N3_LVL2</p>
<p><strong>#6 Thay đổi “<strong class="ib da">XSS Playground</strong>” thành “<strong class="ib da">I am a hacker</strong>” bằng cách thêm bình luận và sử dụng Javascript.</strong></p>
<p><code>&lt;script&gt;document.querySelector(‘#thm-title’).textContent = ‘I am a hacker’&lt;/script&gt;</code></p>
<div><img decoding="async" loading="lazy" class="size-full wp-image-34694 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_sZc6XOzp2eRYrShI1iyd1A.jpg" alt="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 63" width="525" height="172" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_sZc6XOzp2eRYrShI1iyd1A.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_sZc6XOzp2eRYrShI1iyd1A-300x98.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: Thử thách OWASP Top 10 [Phần 2] 68"/></div>
<p><strong>Đáp án:</strong> websites_can_be_easily_defaced_with_xss</p>
<p>Trong bài viết này chúng ta đã hoàn thành khai thác các lỗi như Sensitive Data Exposure (Rò rỉ dữ liệu nhạy cảm), XML External Entity, Broken Access Control, Security Misconfiguration (Cấu hình sai hệ thống) and Cross-site Scripting (XSS).</p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;34579&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;100&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 5\/5 - (100 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;width&quot;:&quot;142.5&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>
            Bài viết đạt: 5/5 &#8211; (100 bình chọn)    </p>
</p></div>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/tryhackme-thu-thach-owasp-top-10-phan-2/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2021/10/1__o9kgTkh_63l51skO0hGcQ.jpg" medium="image"></media:content>
            	</item>
		<item>
		<title>TryHackMe: OWASP Top 10 Challenge [Phần 3]</title>
		<link>https://en.anonyviet.com/tryhackme-owasp-top-10-challenge-phan-3/</link>
					<comments>https://en.anonyviet.com/tryhackme-owasp-top-10-challenge-phan-3/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Wed, 25 Jan 2023 16:30:08 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[challenge]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[Phần]]></category>
		<category><![CDATA[Top]]></category>
		<category><![CDATA[Tryhackme]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=3111</guid>

					<description><![CDATA[Continuing with part 2, in this article I will guide you to exploit OWASP vulnerabilities such as Insecure Deserialization, Components With Known Vulnerabilities, and Insufficient Logging &#038; Monitoring in challenge OWASP Top 10. Join the channel Telegram of the AnonyViet 👉 Link 👈 TryHackMe: OWASP Top 10 Challenge [Phần 3] Mission 21: [Mức độ nghiêm [&#8230;]]]></description>
										<content:encoded><![CDATA[<p></p>
<div id="ftwp-postcontent">
<p><strong>Continuing with part 2, in this article I will guide you to exploit OWASP vulnerabilities such as <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Ftoan9.com%2Ftim-hieu-ve-loi-insecure-deserialization-trong-ung-dung-web%2F%23%3A%7E%3Atext%3DInsecure%2520Deserialization%2520l%25C3%25A0%2520l%25E1%25BB%2597i%2520x%25E1%25BA%25A3y%2C%25C3%25BD%2520c%25E1%25BB%25A7a%2520ng%25C6%25B0%25E1%25BB%259Di%2520khai%2520th%25C3%25A1c." rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">Insecure Deserialization</a>, <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fwebsitehcm.com%2Ftop-10-lo-hong-bao-mat-theo-owasp%2F" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">Components With Known Vulnerabilities, and Insufficient Logging &#038; Monitoring</a> in challenge <a target="_blank" class="dy ix ext-link" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Ftryhackme.com%2Froom%2Fowasptop10" rel="noopener ugc nofollow external" onclick="this.target='_blank';">OWASP Top 10.</a></strong></p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> of the <span style="color: #008080;">AnonyViet </span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietchat" class="local-link" rel="noopener">Link</a></span>  👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<p><img alt="TryHackMe: OWASP Top 10 Challenge [Phần 3]" title="TryHackMe: OWASP Top 10 Challenge [Phần 3]" post-id="3111" fifu-featured="1" decoding="async" class="aligncenter wp-image-34826 size-full" src="https://anonyviet.com/wp-content/uploads/2021/10/1_TPtoIN4c4bLgS8fCGCU8Wg.jpg" alt="TryHackMe: OWASP Top 10 Challenge [Phần 3]" width="525" height="318" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_TPtoIN4c4bLgS8fCGCU8Wg.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_TPtoIN4c4bLgS8fCGCU8Wg-300x182.jpg 300w" sizes="(max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge [Phần 3] 27"/></p>
<h2 id="ftoc-tryhackme-thu-thach-owasp-top-10-phan-3" class="ftwp-heading"><strong>TryHackMe: OWASP Top 10 Challenge [Phần 3]</strong></h2>
<h3 id="ftoc-nhiem-vu-21-muc-do-nghiem-trong-8-insecure-deserialization" class="ftwp-heading"><strong>Mission 21: [Mức độ nghiêm trọng 8] Insecure Deserialization</strong></h3>
<p>What applications are vulnerable?</p>
<p>Any application that stores or fetches data for which no authentication or integrity check is applied to the queried or stored data.  Some examples of applications of this nature are:</p>
<ul>
<li>E-commerce website</li>
<li>Forum</li>
<li>API</li>
<li>Runtimes applications (Tomcat, Jenkins, Jboss, &#8230;)</li>
</ul>
<p>You can learn more about Insecure Deserialization <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Ftoan9.com%2Ftim-hieu-ve-loi-insecure-deserialization-trong-ung-dung-web%2F%23%3A%7E%3Atext%3DInsecure%2520Deserialization%2520l%25C3%25A0%2520l%25E1%25BB%2597i%2520x%25E1%25BA%25A3y%2C%25C3%25BD%2520c%25E1%25BB%25A7a%2520ng%25C6%25B0%25E1%25BB%259Di%2520khai%2520th%25C3%25A1c." rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">here</a>.</p>
<h4 id="ftoc-1-ai-da-phat-trien-ung-dung-tomcat" class="ftwp-heading">#1 Who developed the Tomcat application?</h4>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34827 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_2sPpIM33C09WPkdrOMuLYg.jpg" alt="TryHackMe: OWASP Top 10 Challenge [Phần 3] 25" width="254" height="311" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_2sPpIM33C09WPkdrOMuLYg.jpg 254w, https://anonyviet.com/wp-content/uploads/2021/10/1_2sPpIM33C09WPkdrOMuLYg-245x300.jpg 245w" sizes="auto, (max-width: 254px) 100vw, 254px" title="TryHackMe: OWASP Top 10 Challenge [Phần 3] 28"/></p>
<p><strong>Answer:</strong> Apache Software Foundation</p>
<h4 id="ftoc-2-loai-tan-cong-nao-lam-hong-cac-dich-vu-co-the-duoc-thuc-hien-voi-tinh-nang-giai-ma-khong-an-toan" class="ftwp-heading">#2 What kind of attacks that crash services can be done with insecure decryption?</h4>
<p>This definition is still quite broad.  But can be understood like this, unsafe decryption is replacing the data processed by the application with malicious code;  allows anything from DoS (Denial of Service) to RCE (Remote Malware Execution) that an attacker can use to gain a foothold in pentesting.</p>
<p><strong>Answer: </strong>Denial of Service</p>
<h3 id="ftoc-nhiem-vu-22-muc-do-nghiem-trong-8-giai-ma-khong-an-toan-doi-tuong" class="ftwp-heading"><strong>Mission 22 [Mức độ nghiêm trọng 8] Unsecure Decryption – Object</strong></h3>
<h4 id="ftoc-1-chon-thuat-ngu-dung-cua-cau-sau" class="ftwp-heading">#1 Choose the correct term of the following sentence:</h4>
<p id="67cc" class="hz ia fv ib b ic id ie if ig ih ii ij ik il im in io ip iq ir is it iu iv iw dn gr" data-selectable-paragraph=""><strong class="ib da">if a dog was sleeping, would this be:</strong></p>
<p id="9336" class="hz ia fv ib b ic id ie if ig ih ii ij ik il im in io ip iq ir is it iu iv iw dn gr" data-selectable-paragraph="">A) A State<br />B) A Behaviour</p>
<p data-selectable-paragraph=""><strong>Answer:</strong> A Behaviour</p>
<h3 id="ftoc-nhiem-vu-23-muc-do-nghiem-trong-8-insecure-deserialization-deserialization" class="ftwp-heading"><strong>Mission 23: [Mức độ nghiêm trọng 8]</strong> <strong class="ib da">Insecure Deserialization — Deserialization</strong></h3>
<p>Suppose you have a password “password123” from a program that needs to be stored in a database on another system.  To move across a network, this string/output needs to be converted to binary.  Of course, the password needs to be stored as “password123” and not its binary string.  When it reaches the database, it will be converted or <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fqastack.vn%2Fprogramming%2F3316762%2Fwhat-is-deserialize-and-serialize-in-json" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">deserialised</a> back to “password123” to be stored.</p>
<h4 id="ftoc-1-ten-cua-dinh-dang-co-so-2-ma-du-lieu-duoc-gui-qua-mang-la-gi" class="ftwp-heading">#1 What is the name of the base 2 format in which data is sent over the network?</h4>
<p><strong>Answer:</strong> binary</p>
<h3 id="ftoc-nhiem-vu-24-muc-do-nghiem-trong-8-insecure-deserialization-cookies" class="ftwp-heading"><strong>Mission 24 [Mức độ nghiêm trọng 8]</strong> <strong class="ib da">Insecure Deserialization — Cookies</strong></h3>
<h4 id="ftoc-1-neu-cookie-co-duong-dan-la-webapp-com-login-thi-url-ma-nguoi-dung-phai-truy-cap-se-la-gi" class="ftwp-heading">#1 If the cookie has a path of webapp.com/login, what is the URL the user has to visit?</h4>
<p><strong>Answer:</strong> webapp.com/login</p>
<h4 id="ftoc-2-tu-viet-tat-cua-cong-nghe-web-ma-secure-cookies-hoat-dong-tren-do-la-gi" class="ftwp-heading">#2 What is the acronym for the web technology that Secure cookies work on?</h4>
<p><strong>Answer:</strong> Https</p>
<h3 id="ftoc-nhiem-vu-25-muc-do-nghiem-trong-8-insecure-deserialization-cookies-practical" class="ftwp-heading"><strong>Mission 25: [Mức độ nghiêm trọng 8] <strong class="ib da">Insecure Deserialization — Cookies Practical</strong></strong></h3>
<p>I will log in to a website like the one below.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34829 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_sH1S2h0l_gOtdcitAtAgQw.jpg" alt="TryHackMe: OWASP Top 10 Challenge [Phần 3] 26" width="525" height="350" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_sH1S2h0l_gOtdcitAtAgQw.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_sH1S2h0l_gOtdcitAtAgQw-300x200.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge [Phần 3] 29"/></p>
<p>Create an account.  No need to enter details, you can enter what you like.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34830 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_Dh33Tsl6f2TOEn3HD760Ug.jpg" alt="TryHackMe: OWASP Top 10 Challenge [Phần 3] 27" width="525" height="281" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_Dh33Tsl6f2TOEn3HD760Ug.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_Dh33Tsl6f2TOEn3HD760Ug-300x161.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge [Phần 3] 30"/></p>
<p>Notice on the right, you have your details.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34832 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_Y0gvcqZ27yn1yOMCarypyg.jpg" alt="TryHackMe: OWASP Top 10 Challenge [Phần 3] 28" width="525" height="219" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_Y0gvcqZ27yn1yOMCarypyg.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_Y0gvcqZ27yn1yOMCarypyg-300x125.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge [Phần 3] thirty first"/></p>
<p>Right click on the page and hit “Inspect Element” then go to the “Storage” tab.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34835 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_t6Hfq9McMutemExQlsyI3w.jpg" alt="TryHackMe: OWASP Top 10 Challenge [Phần 3] 29" width="525" height="124" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_t6Hfq9McMutemExQlsyI3w.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_t6Hfq9McMutemExQlsyI3w-300x71.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge [Phần 3] 32"/></p>
<h4 id="ftoc-kiem-tra-du-lieu-duoc-ma-hoa" class="ftwp-heading">Check Encrypted Data</h4>
<p>You will see here that there are both plaintext and base64 encoded cookies.  The first flag will be found in one of these cookies.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34836 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_MK8-Z7XHP1p3vgfGoUkmDg.jpg" alt="TryHackMe: OWASP Top 10 Challenge [Phần 3] 30" width="525" height="353" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_MK8-Z7XHP1p3vgfGoUkmDg.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_MK8-Z7XHP1p3vgfGoUkmDg-300x202.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge [Phần 3] 33"/></p>
<p><strong>Answer:</strong> THM{good_old_base64_huh}</p>
<h4 id="ftoc-sua-doi-gia-tri-cookie" class="ftwp-heading">Modify cookie value</h4>
<p>Notice here that you have a cookie named “userType”.  You are now a user, as confirmed by your information on the “myprofile” page.</p>
<p>This application defines what you can and cannot see by your userType.  What if you want to be an administrator?</p>
<p>Double left click on the “Value” column of “userType” to modify the content.  Let&#8217;s change our userType to &#8220;admin&#8221; and navigate to http://10.10.83.1/admin to get the second flag.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34837 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_IzyUyY0UlbXr9QDqjUxlkA.jpg" alt="TryHackMe: OWASP Top 10 Challenge [Phần 3] thirty first" width="525" height="215" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_IzyUyY0UlbXr9QDqjUxlkA.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_IzyUyY0UlbXr9QDqjUxlkA-300x123.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge [Phần 3] 34"/></p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34838 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_HMlS5RidzVvaughfWQUfEQ.jpg" alt="TryHackMe: OWASP Top 10 Challenge [Phần 3] 32" width="525" height="344" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_HMlS5RidzVvaughfWQUfEQ.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_HMlS5RidzVvaughfWQUfEQ-300x197.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge [Phần 3] 35"/></p>
<p><strong>Answer:</strong> THM{heres_the_admin_flag}</p>
<h3 id="ftoc-nhiem-vu-26-muc-do-nghiem-trong-8-insecure-deserialization-code-execution" class="ftwp-heading"><strong>Mission 26: [Mức độ nghiêm trọng 8]</strong> <strong class="ic fw">Insecure Deserialization — Code Execution</strong></h3>
<p>1. First, change the value of the userType cookie from “admin” to “user” and back to http://10.10.83.1/myprofile.</p>
<p>2. Then left click on the URL under “Exhange your vim” in the screenshot below.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34839 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_EEYwgX5BHZUMzI6K0iPDhA.jpg" alt="TryHackMe: OWASP Top 10 Challenge [Phần 3] 33" width="525" height="284" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_EEYwgX5BHZUMzI6K0iPDhA.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_EEYwgX5BHZUMzI6K0iPDhA-300x162.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge [Phần 3] 36"/></p>
<p>3. Next left click on the URL under “Provide your feedback!”  to a page like this:</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34840 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_pwtT5NXo0ugwOq6CAT_SNA.jpg" alt="TryHackMe: OWASP Top 10 Challenge [Phần 3] 34" width="525" height="269" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_pwtT5NXo0ugwOq6CAT_SNA.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_pwtT5NXo0ugwOq6CAT_SNA-300x154.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge [Phần 3] 37"/></p>
<h4 id="ftoc-1-flag-txt" class="ftwp-heading">#1 flag.txt</h4>
<p>Change netcat ip.</p>
<p>Use command <code>nano rce.py</code></p>
<p>Swap tryhackmyIP to the IP of that website.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34841 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_9V77__vCew4fh1DYX3Hr7A.jpg" alt="TryHackMe: OWASP Top 10 Challenge [Phần 3] 35" width="700" height="236" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_9V77__vCew4fh1DYX3Hr7A.jpg 700w, https://anonyviet.com/wp-content/uploads/2021/10/1_9V77__vCew4fh1DYX3Hr7A-300x101.jpg 300w" sizes="auto, (max-width: 700px) 100vw, 700px" title="TryHackMe: OWASP Top 10 Challenge [Phần 3] 38"/> <img decoding="async" loading="lazy" class="size-full wp-image-34842 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_x8U0Kc3WlmklPKiKMOwUJQ.jpg" alt="TryHackMe: OWASP Top 10 Challenge [Phần 3] 36" width="700" height="68" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_x8U0Kc3WlmklPKiKMOwUJQ.jpg 700w, https://anonyviet.com/wp-content/uploads/2021/10/1_x8U0Kc3WlmklPKiKMOwUJQ-300x29.jpg 300w" sizes="auto, (max-width: 700px) 100vw, 700px" title="TryHackMe: OWASP Top 10 Challenge [Phần 3] 39"/></p>
<p>Paste this into the “encodedPayload” cookie in your browser:</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34843 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_T1K36ev-PGuhao2xzC3J9Q.jpg" alt="TryHackMe: OWASP Top 10 Challenge [Phần 3] 37" width="525" height="266" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_T1K36ev-PGuhao2xzC3J9Q.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_T1K36ev-PGuhao2xzC3J9Q-300x152.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge [Phần 3] 40"/></p>
<p>7. Make sure netcat is still running:</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34844 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_J0JZqUTMtFxWA0JwhlyrJw.jpg" alt="TryHackMe: OWASP Top 10 Challenge [Phần 3] 38" width="700" height="187" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_J0JZqUTMtFxWA0JwhlyrJw.jpg 700w, https://anonyviet.com/wp-content/uploads/2021/10/1_J0JZqUTMtFxWA0JwhlyrJw-300x80.jpg 300w" sizes="auto, (max-width: 700px) 100vw, 700px" title="TryHackMe: OWASP Top 10 Challenge [Phần 3] 41"/></p>
<p>8. Refresh the page.  It will hang, go back to netcat:</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34845 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_-dFodSJWPDeLQjPcXgYetg.jpg" alt="TryHackMe: OWASP Top 10 Challenge [Phần 3] 39" width="648" height="185" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_-dFodSJWPDeLQjPcXgYetg.jpg 648w, https://anonyviet.com/wp-content/uploads/2021/10/1_-dFodSJWPDeLQjPcXgYetg-300x86.jpg 300w" sizes="auto, (max-width: 648px) 100vw, 648px" title="TryHackMe: OWASP Top 10 Challenge [Phần 3] 42"/></p>
<p><strong>Answer:</strong> 4a69a7ff9fd68</p>
<h3 id="ftoc-nhiem-vu-29-muc-do-nghiem-trong-9-components-with-known-vulnerabilities-lab" class="ftwp-heading"><strong>Mission 29: [Mức độ nghiêm trọng 9]</strong> <strong class="ic fw">Components With Known Vulnerabilities — Lab</strong></h3>
<h4 id="ftoc-1-co-bao-nhieu-ky-tu-trong-etc-passwd-su-dung-wc-c-etc-passwd-de-co-cau-tra-loi" class="ftwp-heading">#1 How many characters are in /etc/passwd (using <strong class="ic fw">WC </strong>-c /etc/passwd for the answer)</h4>
<p>Visit the website, as we see this is a normal book website.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34846 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_TRi9V-3tW6L0zf2x8Fccow.jpg" alt="TryHackMe: OWASP Top 10 Challenge [Phần 3] 40" width="525" height="373" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_TRi9V-3tW6L0zf2x8Fccow.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_TRi9V-3tW6L0zf2x8Fccow-300x213.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/10/1_TRi9V-3tW6L0zf2x8Fccow-120x86.jpg 120w, https://anonyviet.com/wp-content/uploads/2021/10/1_TRi9V-3tW6L0zf2x8Fccow-350x250.jpg 350w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge [Phần 3] 43"/></p>
<p>Did a bit of research on vulnerabilities found in online bookstore sites and I found this.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34847 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_A3V1TD8v0bAzwBYZDlqmXg.jpg" alt="TryHackMe: OWASP Top 10 Challenge [Phần 3] 41" width="525" height="293" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_A3V1TD8v0bAzwBYZDlqmXg.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_A3V1TD8v0bAzwBYZDlqmXg-300x167.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge [Phần 3] 44"/></p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34848 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_-ced-BSJK0y-7FcZAbzFdw.jpg" alt="TryHackMe: OWASP Top 10 Challenge [Phần 3] 42" width="656" height="198" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_-ced-BSJK0y-7FcZAbzFdw.jpg 656w, https://anonyviet.com/wp-content/uploads/2021/10/1_-ced-BSJK0y-7FcZAbzFdw-300x91.jpg 300w" sizes="auto, (max-width: 656px) 100vw, 656px" title="TryHackMe: OWASP Top 10 Challenge [Phần 3] 45"/></p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34849 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_B4p4BKvh7jglZ4HLdmKZTA.jpg" alt="TryHackMe: OWASP Top 10 Challenge [Phần 3] 43" width="662" height="99" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_B4p4BKvh7jglZ4HLdmKZTA.jpg 662w, https://anonyviet.com/wp-content/uploads/2021/10/1_B4p4BKvh7jglZ4HLdmKZTA-300x45.jpg 300w" sizes="auto, (max-width: 662px) 100vw, 662px" title="TryHackMe: OWASP Top 10 Challenge [Phần 3] forty six"/></p>
<p><strong>Answer:</strong> 1611</p>
<h3 id="ftoc-nhiem-vu-30-muc-do-nghiem-trong-10-insufficient-logging-monitoring" class="ftwp-heading"><strong>Mission 30: [Mức độ nghiêm trọng 10] Insufficient Logging &#038; Monitoring</strong></h3>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34850 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_kC5SlBCSDe1D0cPpCs48-Q.jpg" alt="TryHackMe: OWASP Top 10 Challenge [Phần 3] 44" width="525" height="142" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_kC5SlBCSDe1D0cPpCs48-Q.jpg 525w, https://anonyviet.com/wp-content/uploads/2021/10/1_kC5SlBCSDe1D0cPpCs48-Q-300x81.jpg 300w" sizes="auto, (max-width: 525px) 100vw, 525px" title="TryHackMe: OWASP Top 10 Challenge [Phần 3] 47"/></p>
<p>We have to download the login-logs.txt file.  Click download and save the file.</p>
<h4 id="ftoc-1-ke-tan-cong-dang-su-dung-dia-chi-ip-nao" class="ftwp-heading">#1 What IP address is the attacker using?</h4>
<p>We can use cat login-logs.txt and see all the frontends.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-34851 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/10/1_cEGS52wUfC0ra_Xo33FI1w.jpg" alt="TryHackMe: OWASP Top 10 Challenge [Phần 3] 45" width="652" height="219" srcset="https://anonyviet.com/wp-content/uploads/2021/10/1_cEGS52wUfC0ra_Xo33FI1w.jpg 652w, https://anonyviet.com/wp-content/uploads/2021/10/1_cEGS52wUfC0ra_Xo33FI1w-300x101.jpg 300w" sizes="auto, (max-width: 652px) 100vw, 652px" title="TryHackMe: OWASP Top 10 Challenge [Phần 3] 48"/></p>
<p>There is one person constantly accessing the system with different usernames.</p>
<p><strong>Answer:</strong> 49.99.13.16</p>
<h4 id="ftoc-2-loai-tan-cong-nao-dang-duoc-thuc-hien" class="ftwp-heading">#2 What kind of attack is being performed?</h4>
<p>HTTP 401 indicates that the request has not been applied because it lacks valid credentials for the target resource.</p>
<p>So I think it&#8217;s a brute force attack because we see that someone is repeatedly trying a password with a different username.</p>
<p><strong>Answer:</strong> Brute Force</p>
<p>So this series is done.  Are you looking forward to other series?  In addition, you can also see more challenges on tryhackme <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Ftag%2Ftryhackme%2F" rel="noopener" class="local-link">here</a>.</p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;34822&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;100&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 5\/5 - (100 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;width&quot;:&quot;142.5&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>            The article achieved: 5/5 &#8211; (100 votes)    </p>
</p></div>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/tryhackme-owasp-top-10-challenge-phan-3/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2021/10/1_TPtoIN4c4bLgS8fCGCU8Wg.jpg" medium="image"></media:content>
            	</item>
		<item>
		<title>How to find Website security holes with OWASP ZAP</title>
		<link>https://en.anonyviet.com/how-to-find-website-security-holes-with-owasp-zap/</link>
					<comments>https://en.anonyviet.com/how-to-find-website-security-holes-with-owasp-zap/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Wed, 25 Jan 2023 10:01:57 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Find]]></category>
		<category><![CDATA[holes]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[ZAP]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=2808</guid>

					<description><![CDATA[Website security is always a necessary issue before operating on the Internet. If you want to check if your Website has security holes, use OWASP ZAP &#8211; Zed Attack Proxy software to scan for errors. Join the channel Telegram of the AnonyViet 👉 Link 👈 OWASP ZAP – Zed Attack Proxy is an open source [&#8230;]]]></description>
										<content:encoded><![CDATA[<p></p>
<div id="ftwp-postcontent">
<p><strong>Website security is always a necessary issue before operating on the Internet.  If you want to check if your Website has security holes, use OWASP ZAP &#8211; Zed Attack Proxy software to scan for errors.</strong></p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> of the <span style="color: #008080;">AnonyViet </span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietchat" class="local-link" rel="noopener">Link</a></span>  👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<p>OWASP ZAP – Zed Attack Proxy is an open source tool that allows you to test the robustness of your application against security vulnerabilities.  But what exactly is OWASP ZAP?</p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2021%2F11%2Fcach-su-dung-zap-quet-lo-hong-bao-mat.jpg" rel="noopener" class="local-link"><img post-id="2808" fifu-featured="1" decoding="async" class="aligncenter wp-image-36635 size-full" src="https://anonyviet.com/wp-content/uploads/2021/11/cach-su-dung-zap-quet-lo-hong-bao-mat.jpg" alt="How to find Website security holes with OWASP ZAP" title="How to find Website security holes with OWASP ZAP" width="600" height="338" srcset="https://anonyviet.com/wp-content/uploads/2021/11/cach-su-dung-zap-quet-lo-hong-bao-mat.jpg 600w, https://anonyviet.com/wp-content/uploads/2021/11/cach-su-dung-zap-quet-lo-hong-bao-mat-300x169.jpg 300w" sizes="(max-width: 600px) 100vw, 600px" title="How to find Website security holes with OWASP ZAP 20"/></a></p>
<p>In a nutshell, this is a vulnerability testing tool that helps programmers and security professionals discover website vulnerabilities.  You can perform a variety of tasks through OWASP ZAP, including scanning web requests, using dictionary lists to find files and folders on the web server, and crawling websites to find all the files and folders on the web server. link and URL.  In addition, you can intercept, view, modify, and forward web requests between the browser and the web application using OWASP ZAP.</p>
<p>OWASP ZAP scanning can reveal problems related to <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fsql-injection-la-gi-lam-the-nao-de-ngan-chan-lo-hong-sql-injection%2F" rel="noopener" class="local-link">SQL injection</a>broken authentication, exposed sensitive data, broken access control, security misconfiguration, <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2F10-website-giup-ban-thuc-hanh-ky-nang-hack-xss%2F" rel="noopener" class="local-link">Cross-Site Scripting (XSS)</a>insecure decryption, components with known vulnerabilities, and any missing security headers.</p>
<p>In this article, we will see how OWASP ZAP works, how to set up ZAP, how to create our own crawlers to scan for vulnerabilities.</p>
<h2 id="ftoc-owasp-zap-hoat-dong-nhu-the-nao" class="ftwp-heading">How does OWASP ZAP work?</h2>
<p>OWASP ZAP is a proxy server that scans all traffic running through it.  This proxy server includes automated tools that allow you to block security holes on your website and generate reports from its findings.  Here&#8217;s a quick diagram of how ZAP works.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-36617 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/11/01.jpg" alt="How to find Website security holes with OWASP ZAP 16" width="528" height="352" srcset="https://anonyviet.com/wp-content/uploads/2021/11/01.jpg 528w, https://anonyviet.com/wp-content/uploads/2021/11/01-300x200.jpg 300w" sizes="auto, (max-width: 528px) 100vw, 528px" title="How to find Website security holes with OWASP ZAP 21"/></p>
<p>ZAP creates its attacks by running the ZAP browser on a URL.  During this process, ZAP will use its crawlers to gather information about a target application, scan all available pages, and then run the active scanner on it.  The active scanner will accurately identify any vulnerabilities using known attack methods on the targets it receives from the scan.  Alerts will be issued if potential vulnerabilities are detected and flagged from high to low based on the level of risk.</p>
<h2 id="ftoc-thiet-lap-zap-zed-attack-proxy" class="ftwp-heading">Setting up ZAP – Zed Attack Proxy</h2>
<p><strong>Step 1:</strong> To set up OWASP ZAP, you need to install it first.  You can access: <a target="_blank" href="https://en.anonyviet.com/next-link/?url=http%3A%2F%2Fzaproxy.org%2Fdownload" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">zaproxy.org/download</a> to select an installer that is compatible with your operating system.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-36618 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/11/02-1-768x525-1.jpg" alt="How to find Website security holes with OWASP ZAP 17" width="768" height="525" srcset="https://anonyviet.com/wp-content/uploads/2021/11/02-1-768x525-1.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/11/02-1-768x525-1-300x205.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/11/02-1-768x525-1-750x513.jpg 750w" sizes="auto, (max-width: 768px) 100vw, 768px" title="How to find Website security holes with OWASP ZAP 22"/></p>
<p><strong>Step 2: </strong>Once downloaded, run the installer.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-36619 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/11/03.png" alt="How to find Website security holes with OWASP ZAP 18" width="510" height="510" srcset="https://anonyviet.com/wp-content/uploads/2021/11/03.png 510w, https://anonyviet.com/wp-content/uploads/2021/11/03-300x300.png 300w, https://anonyviet.com/wp-content/uploads/2021/11/03-150x150.png 150w, https://anonyviet.com/wp-content/uploads/2021/11/03-75x75.png 75w, https://anonyviet.com/wp-content/uploads/2021/11/03-350x350.png 350w" sizes="auto, (max-width: 510px) 100vw, 510px" title="How to find Website security holes with OWASP ZAP 23"/></p>
<p><strong>Step 3:</strong> Read and accept the terms and conditions to continue.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-36620 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/11/04-2.png" alt="How to find Website security holes with OWASP ZAP 19" width="510" height="510" srcset="https://anonyviet.com/wp-content/uploads/2021/11/04-2.png 510w, https://anonyviet.com/wp-content/uploads/2021/11/04-2-300x300.png 300w, https://anonyviet.com/wp-content/uploads/2021/11/04-2-150x150.png 150w, https://anonyviet.com/wp-content/uploads/2021/11/04-2-75x75.png 75w, https://anonyviet.com/wp-content/uploads/2021/11/04-2-350x350.png 350w" sizes="auto, (max-width: 510px) 100vw, 510px" title="How to find Website security holes with OWASP ZAP 24"/></p>
<p><strong>Step 4:</strong> Select &#8216;Standard installation&#8217; and click &#8216;Next&#8217;.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-36621 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/11/05-1.png" alt="How to find Website security holes with OWASP ZAP 20" width="510" height="510" srcset="https://anonyviet.com/wp-content/uploads/2021/11/05-1.png 510w, https://anonyviet.com/wp-content/uploads/2021/11/05-1-300x300.png 300w, https://anonyviet.com/wp-content/uploads/2021/11/05-1-150x150.png 150w, https://anonyviet.com/wp-content/uploads/2021/11/05-1-75x75.png 75w, https://anonyviet.com/wp-content/uploads/2021/11/05-1-350x350.png 350w" sizes="auto, (max-width: 510px) 100vw, 510px" title="How to find Website security holes with OWASP ZAP 25"/></p>
<p><strong>Step 5:</strong> Click &#8216;Install&#8217; to finish.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-36622 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/11/06-1.jpg" alt="How to find Website security holes with OWASP ZAP 21" width="510" height="510" srcset="https://anonyviet.com/wp-content/uploads/2021/11/06-1.jpg 510w, https://anonyviet.com/wp-content/uploads/2021/11/06-1-300x300.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/11/06-1-150x150.jpg 150w, https://anonyviet.com/wp-content/uploads/2021/11/06-1-75x75.jpg 75w, https://anonyviet.com/wp-content/uploads/2021/11/06-1-350x350.jpg 350w" sizes="auto, (max-width: 510px) 100vw, 510px" title="How to find Website security holes with OWASP ZAP 26"/></p>
<p><strong>Step 6:</strong> Wait a moment for the program to finish installing.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-36623 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/11/07-1.png" alt="How to find Website security holes with OWASP ZAP 22" width="510" height="510" srcset="https://anonyviet.com/wp-content/uploads/2021/11/07-1.png 510w, https://anonyviet.com/wp-content/uploads/2021/11/07-1-300x300.png 300w, https://anonyviet.com/wp-content/uploads/2021/11/07-1-150x150.png 150w, https://anonyviet.com/wp-content/uploads/2021/11/07-1-75x75.png 75w, https://anonyviet.com/wp-content/uploads/2021/11/07-1-350x350.png 350w" sizes="auto, (max-width: 510px) 100vw, 510px" title="How to find Website security holes with OWASP ZAP 27"/></p>
<p><strong>Step 7:</strong> Once done, you will be directed to a screen that looks something like this.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-36624 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/11/08-1.png" alt="How to find Website security holes with OWASP ZAP 23" width="510" height="510" srcset="https://anonyviet.com/wp-content/uploads/2021/11/08-1.png 510w, https://anonyviet.com/wp-content/uploads/2021/11/08-1-300x300.png 300w, https://anonyviet.com/wp-content/uploads/2021/11/08-1-150x150.png 150w, https://anonyviet.com/wp-content/uploads/2021/11/08-1-75x75.png 75w, https://anonyviet.com/wp-content/uploads/2021/11/08-1-350x350.png 350w" sizes="auto, (max-width: 510px) 100vw, 510px" title="How to find Website security holes with OWASP ZAP 28"/></p>
<h2 id="ftoc-tao-zap-spider" class="ftwp-heading">Create ZAP Spider</h2>
<p>To run the first scan, run the newly installed OWASP ZAP.  You will be greeted with a screen that looks like this:</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-36625 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/11/09-2.png" alt="How to find Website security holes with OWASP ZAP 24" width="510" height="510" srcset="https://anonyviet.com/wp-content/uploads/2021/11/09-2.png 510w, https://anonyviet.com/wp-content/uploads/2021/11/09-2-300x300.png 300w, https://anonyviet.com/wp-content/uploads/2021/11/09-2-150x150.png 150w, https://anonyviet.com/wp-content/uploads/2021/11/09-2-75x75.png 75w, https://anonyviet.com/wp-content/uploads/2021/11/09-2-350x350.png 350w" sizes="auto, (max-width: 510px) 100vw, 510px" title="How to find Website security holes with OWASP ZAP 29"/></p>
<p>Once the download is complete, you will get a screen that looks like the image below.  In the main &#8216;Quick Start&#8217; view, you can choose between &#8216;Automated Scan&#8217; and &#8216;Manual Explore&#8221;.  For this tutorial, select &#8216;Automated Scan&#8217;.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-36626 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/11/10.jpg" alt="How to find Website security holes with OWASP ZAP 25" width="1046" height="825" srcset="https://anonyviet.com/wp-content/uploads/2021/11/10.jpg 1046w, https://anonyviet.com/wp-content/uploads/2021/11/10-300x237.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/11/10-1024x808.jpg 1024w, https://anonyviet.com/wp-content/uploads/2021/11/10-768x606.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/11/10-750x592.jpg 750w" sizes="auto, (max-width: 1046px) 100vw, 1046px" title="How to find Website security holes with OWASP ZAP 30"/>This option will give you a page like the image below.  You can run it on your application by pointing the destination URL to the localhost your application is currently running on.</p>
<p>This is an example of when in the scan phase.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-36627 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/11/11-2-768x439-1.jpg" alt="How to find Website security holes with OWASP ZAP 26" width="768" height="439" srcset="https://anonyviet.com/wp-content/uploads/2021/11/11-2-768x439-1.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/11/11-2-768x439-1-300x171.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/11/11-2-768x439-1-750x429.jpg 750w" sizes="auto, (max-width: 768px) 100vw, 768px" title="How to find Website security holes with OWASP ZAP 31"/></p>
<p>Once done, you can click on the &#8216;Alerts&#8217; tab to see all the potential vulnerabilities.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-36628 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/11/12-768x290-1.jpg" alt="How to find Website security holes with OWASP ZAP 27" width="768" height="290" srcset="https://anonyviet.com/wp-content/uploads/2021/11/12-768x290-1.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/11/12-768x290-1-300x113.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/11/12-768x290-1-750x283.jpg 750w" sizes="auto, (max-width: 768px) 100vw, 768px" title="How to find Website security holes with OWASP ZAP 32"/></p>
<p>Based on the example and scan results above, we can see that the issues detected are not serious and can be easily remedied, such as X-Frame-Options and Anti-CSRF Tokens.</p>
<p>The impact of a vulnerability can be assessed by the number of specific alerts.  For example, cross-domain JavaScript source file inclusion seems to be a bug of some sort.  However, if we dig deeper, we find that the risk is classified as low because of the reliable source.</p>
<p>Here&#8217;s a screenshot of one of the flagged warnings and reports generated for the cross-domain JavaScript source file inclusion error.  Right below is a solution on how to reduce this vulnerability based on this bug.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-36629 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/11/13-768x345-1.jpg" alt="How to find Website security holes with OWASP ZAP 28" width="768" height="345" srcset="https://anonyviet.com/wp-content/uploads/2021/11/13-768x345-1.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/11/13-768x345-1-300x135.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/11/13-768x345-1-750x337.jpg 750w" sizes="auto, (max-width: 768px) 100vw, 768px" title="How to find Website security holes with OWASP ZAP 33"/></p>
<p>Conversely, if we want to start vulnerability testing based on severity, OWASP ZAP will automatically rank from highest to lowest in the &#8216;Alerts&#8217; file list.  The top warning on the list is &#8216;Vulnerable JS Library&#8217;.  The report is marked as medium risk because the jQuery used is not the latest version.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-36630 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/11/14-768x345-1.jpg" alt="How to find Website security holes with OWASP ZAP 29" width="768" height="345" srcset="https://anonyviet.com/wp-content/uploads/2021/11/14-768x345-1.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/11/14-768x345-1-300x135.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/11/14-768x345-1-750x337.jpg 750w" sizes="auto, (max-width: 768px) 100vw, 768px" title="How to find Website security holes with OWASP ZAP 34"/></p>
<p>A little more digging into jquery-2.1.4 tells us that this target site is vulnerable to Cross-site Scripting (XSS) attacks via elements from untrusted sources.  This is because in the JQuery version, DOM manipulation methods can execute untrusted code.</p>
<h2 id="ftoc-ket-luan" class="ftwp-heading">Conclusion</h2>
<p>The Quick Scan function of OWASP ZAP &#8211; Zed Attack Proxy will not &#8220;hack&#8221; your Web.  However, it will give you an overview of the security issues and vulnerabilities your website is facing.</p>
<p>Using OWASP ZAP during the programming phase can also help us improve our security processes by identifying problems before they grow too large over time.  It is easier to fix a potential vulnerability when it is small than when it is large and affects the entire developed application.</p>
<p>One thing to keep in mind is that if you run OWASP ZAP on a more mature application with lots of legacy code, you may get a large number of warnings.  This is normal, especially if security is not part of the growth mindset at first.  As long as you prioritize your vulnerabilities and find ways to address them, it will increase the security of your application.</p>
<p>In addition to running the function <strong>Quick Scan</strong> manually every time, you can also automate it into your workflow via Docker Packaged Scans, GitHub Actions or automation frameworks.</p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;36615&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;100&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 5\/5 - (100 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;width&quot;:&quot;142.5&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>            The article achieved: 5/5 &#8211; (100 votes)    </p>
</p></div>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/how-to-find-website-security-holes-with-owasp-zap/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2021/11/cach-su-dung-zap-quet-lo-hong-bao-mat.jpg" medium="image"></media:content>
            	</item>
	</channel>
</rss>
