Hiển thị các bài đăng có nhãn b?o m?t. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn b?o m?t. Hiển thị tất cả bài đăng

Chủ Nhật, 8 tháng 4, 2012

L?i nh?n nh? Ng�n Lu?ng ch?m Vi en

Ch�o ng�n lu?ng ! t�i y�u qu� ng�n lu?ng l�u l�u ro�i , v� l� ngu?i di d?u n�n ng�n lu?ng d� sao cung c� nhi?u kinh nghi?m hon nh?ng b?n di sau t�t t?t n�y , nhung n�i th?t ni?m tin c?a t�i ng�y c�ng b? s�i m�n, m?t d?n r?i...

H�nh nhu c�ng ty c? ph?n h�a b�nh dang h?t ti?n mua t�n mi?n n�n config c? ng�n lu?ng l�m trang mua b�n , n�i th?t c�c v? dang  m?t d?n th? tru?ng v� ngu?i d�ng nghi:
N?u d? ti?n v�o ng�n lu?ng an to�n ch? ? ?a sao c� c? shoping nh?ng nh?t tr�n n�y ? an to�n h�ng ? shoping b? hack th� ti?n c?a tui th? n�o ?
Th?m ch� th?i gian tru?c Ng�n lu?ng c�n d? trang ch? l� NON - SSL n?a , o?ch ! tui th?m ch� kh�ng d�m dang nh?p v� s? th?ng h�ng x�m n� o�nh m?t t�i kho?n ...




V� h�nh nhu PEACESOFT kh�ng hi?u ngu?i d�ng l� c�i g� ?y nh? ?

 + Nh?ng ngu?i bi?t d�ng ti?n tr?c tuy?n da s? s? l� nh?ng ngu?i pro tr�n m?ng , m� h? th� 60% th�ch s? don gi?n v� h? quen v?i facebook, quen v?i PAYPAL, quen v?i google anh n�o cung don gi?n, nhung Pi s?p(d�nh m?i c? tay) trang n�o cung l�e lo?t ki?u thi?u thi?u t�nh chuy�n nghi?p ( ch?c th?ng cha gi�m d?c c� h?n th� v?i v?t gi� n�n d� theo ) ... m� n�i th?t c? th?ng v?t gi� m�nh cung ch?ng th�m v�o nh�m n� bao gi? ....

N?u PEACESOFT h?t ti?n mua t�n mi?n m?i th� b?o tui c�u, d?ng t�ch h?p mua s?m v�o trong c?ng thanh to�n nghe n� ng?a tai ng?a m?t qu�, ho?c t�i chuy?n qu�ch sang PAYPAL ho?c B?o Kim c�n d? gh�t ...

B�i bai Ng�n Lu?ng gi� nua ...

Chủ Nhật, 4 tháng 3, 2012

SSL in Wamp server

I have tried to enable SSL on localhost . I found a solution on wampserver forum . You can try this :)
****************
****Step1****** -> Create SSL Certificate and Key
****************

1a) Open the DOS command window and change directory to bin directory of wamp apache directory by using the DOS command without quotes: �cd /d c:\� and then �cd wamp\bin\apache\apache2.2.8\bin�. apache2.2.8 should be changed to what apache folder your wamp server has.
After done, the DOS prompt should look like: C:\wamp\bin\apache\apache2.2.8\bin>
1b) Create a server key with 1024 bits encryption. You should enter this command without quotes:
�openssl genrsa -des3 -out server.key 1024?. It�ll ask you a pass phrase, just enter it. �
1c) Remove the pass phrase from the RSA private key (while keeping a backup copy of the original file). Enter this command without quotes: �copy server.key server.key.org� and then �openssl rsa -in server.key.org -out server.key�. It�ll ask you the pass phrase, just type it.
1d) Create a self-signed Certificate (X509 structure) with the RSA key you just created. Enter the command without quotes: �openssl req -new -x509 -nodes -sha1 -days 365 -key server.key -out server.crt -config C:\wamp\bin\apache\apache2.2.8\conf\openssl.cnf�.
You�ll fill in the information after entering this command. The correct location of config file, openssl.cnf may need to be changed. In windows, you won�t see �.cnf� extension of the file openssl, but in DOS you�ll see the full name openssl.cnf.
****************
***** Step2***** -> Copy the server.key and server.crt files.
****************
2a) In the conf folder of apache2.2.8 folder, create two folders named as ssl.key and ssl.crt
2b) copy the server.key file to ssl.key folder and server.crt file to ssl.crt
****************
****Step3****** -> Edit the httpd.conf file and php.ini
****************
3a) In httpd.conf file, remove the comment �#� at the line which says: LoadModule ssl_module
modules/mod_ssl.so
3b) In httpd.conf, remove the comment �#� at the line which says: Include
conf/extra/httpd_ssl.conf
Then move that line after this block <IfModule ssl_module>�. </IfModule>
3c) open the php.ini file located in apache2.2�.\bin folder, remove the comment �;� at the line
which says: extension=php_openssl.dll
***************
****Step4***** -> Edit the httpd_ssl.conf file in the folder name, extra
***************
4a) Find the line which says �SSLMutex �.� and change it to �SSLMutex default� without quotes
4b) Find the line which says: <VirtualHost _default_:443>. Right after it, change the line which says �DocumentRoot �� to DocumentRoot �C:/wamp/www/� with quotes. Change the line �ErrorLog�.� to Errorlog logs/sslerror_log. Change the line �TransferLog �.� to TransferLog logs/sslaccess_log
4c) SSL crt file: Change the line �SSLCertificateFile �.� to SSLCertificateFile �conf/ssl.crt/server.crt�
4d) SSL key file: Change the line �SSLCertificateKeyFile �.� to SSLCertificateKeyFile �conf/ssl.key/server.key�
4e) Change the line which says <Directory �C:/Program Files/Apache Software Foundation/Apache2.2/cgi-bin�> or something similar to <Directory �C:/wamp/www/�> and add the following lines inside those <Directory � >�</Directory> tags:
Options Indexes FollowSymLinks MultiViews
AllowOverride All
Order allow,deny
allow from all
4f) Make sure the line CustomLog �logs/ssl_request_log� \
is uncommented (remove the #). This step is suggested by wmorse1.
**************
****Step5**** In the previous DOS Command windows, enter httpd -t . If it displays Sysntax is OK, then
************** go to Step 6. If not, then correct the wrong syntax and redo step 5.
**************
****Step6***** -> Restart the Apache server
***************
**************
****Step7**** -> if restart is successful, then open the browser and enter �https://localhost� without
************** quotes.
*************************
****Step8 (Optional)**** -> If you want to allow world wide web access to your HTTPS secure server, then
************** ********** in the httpd_ssl.conf file, change the line which says �ServerName localhost:443' to �ServerName www.yourwebsitename.com:443' without quotes. yourwebsitename is your registered internet domain name. If you don�t have it, then just use your WAN IP address. For example �ServerName 99.238.53.105:443'. Make sure these setups are correct to allow outside access to secured www server.
8.a The DocumentRoot you modified in step 4b points to the correct website folder on your
computer.
8.b If your computer�s connected to the router, setup the router to allow port 443 forwarding to your
computer.
8.c If your computer has a firewall enabled or behind a network firewall, set up the firewall to allow
incoming port 443 connection
And finally

Thứ Bảy, 3 tháng 3, 2012

Cache trong php - c�ch vi?t code cache trong php

 M?t trang php co b?n th�ng thu?ng kh�gn c?n cache nhung n?u m?t trang c� luu lu?ng truy c?p l?n ho?c m?t CMS m� ngu?n n�o cung ?ng d?ng cache , sau d�y m�nh s? ch? cho c�c b?n c�ch cache don gi?n nh?t gi�p tang kh? nang c?a server v� tang t?c trang c?a b?n.

Client s? g?i request t?i server, thu?ng th� ch? l� m?t url, l�n t?i bu?c n�y th� kh�ng t?n th?i gian. Ti?p d� server s? parse request, g?i t?i DB, v� l?y d? li?u t? DB tr? v?, parse d? li?u v� tr? l?i cho Browser, vi?c query t?i DB s? t?n r?t nhi?u th?i gian, th�m n?a d? li?u response thu?ng l?n, d�y ch�nh l� nguy�n nh�n l�m cho ?ng d?ng c?a ta ch?m di.

T?o cache s? gi�p cho site ch?y nhanh v� gi?m truy c?p tr?c ti?p v�o database, v?i php vi?c t?o cache ch? ? m?c genarate ra file, thu?ng l� html. ��y l� gi?i ph�p r?t hay n?u l�m t?t, c� th? tang t?c d? lu?t web l�n h�ng ch?c l?n. Tu? v�o m?c d�ch c?a ?ng d?ng d? cache, cung nhu k?t h?p c�c phuong ph�p cho hi?u qu?:

1. Cache to�n b? page: Nguy�n c? page ?ng v?i url nh?t d?nh du?c luu v�o cache, c�c truy c?p ti?p theo d?n c�ng url n�y s? include ngay l?p t?c file cache du?c t?o ra tru?c d�, do d� s? gi?m t?i da v? th?i gian do server kh�ng ph?i x? l� g� c? (k? c? truy c?p DB). C�ch n�y don gi?n nhung kh�ng linh ho?t, v� kh� th?c thi v� d? li?u tr�n c�c trang l� dynamic.

2. Cache t?ng ph?n c?a page: Ta s? ch? cache m?t ph?n c?a page m� t?i d� d? li?u �t b? thay d?i. �i?u n�y d?m b?o client s? nh?n du?c d? li?u tr? v? l� ch�nh x�c m� kh�ng ph?i d? li?u cu t? file cache.

3. Cache SQL: Khi c�ng c�u l?nh SQL du?c g?i di g?i l?i, th� ch? l?nh d?u ti�n du?c g?i d?n DB server, trong c�c Framework d?u c� cache SQL.

�? b?t d?u th� ta ph?i t?o m?t thu m?c cache d? ch?a c�c file cache cho ?ng d?ng c?a ta, kh�ng l�n d? c�c file cache lung tung v� d? c� th? cache file ta c?n chmod cho thu m?c ph?i c� quy?n ghi v� d?c, do d� d? d? chmod v� b?o m?t ta c?n t?o ri�ng thu m?c cache, vi?c d?t cache key cung c?n ch� � d? d? ph�n bi?t. Sau d�y l� m?t v� d? don gi?n cache d? li?u:

CODE

$cacheFile = 'cache/name_file_cache.php';
if ( (file_exists($cacheFile)) && ((fileatime($cacheFile) + 600) > time()) ){
$content = file_get_contents($cacheFile);
echo $content;
} else{
ob_start();
echo '

Hello world to cache

';
$content = ob_get_contents();
ob_end_clean();
file_put_contents($cacheFile,$content);
echo $content;
}
?>


SQL cache:

CODE

$file = 'sql_cache.txt';
$expire = 86400; // 24 hours
if (file_exists($file) &&
filemtime($file) > (time() - $expire)) {
$records = unserialize(file_get_contents($file));
} else {
$link = mysql_connect('localhost','username','password')
or die (mysql_error());
mysql_select_db('shop')
or die (mysql_error());
/* form SQL query */
$query = "SELECT * FROM categories";
$result = mysql_query($query)
or die (mysql_error());
while ($record = mysql_fetch_array($result) ) {
$records[] = $record;
}
$OUTPUT = serialize($records);
$fp = fopen($file,"w");
fputs($fp, $OUTPUT);
fclose($fp);
} // end else

// Query results are in $records array
foreach ($records as $id=>$row) {
if ($row['category_id'] == $_REQUEST['category_id']) {
// category selected - print bold
print ''.$row['category_name'].'
';
} else {
// other category - print regular
print $row['category_name'].'
';
}
} // end foreach


D? li?u out put s? ch?a ki?u v� size, c� d?ng:

CODE

a:1:{i:0;a:6:{i:0;s:1:"1";s:11:"category_id";s:1:"1";i:1;s:9:"Computers";s:13:"category_name";s:9:
"Computers" ;i:2;s:25:"Description for computers";s:20:"category_description"
;s:25:"Description for computers";}}


Ch�c c�c b?n th�nh c�ng !

Thứ Hai, 20 tháng 2, 2012

Update wordpress l?i - show ra trang tr?ng ?

�ang update th� b�o l?i ! b?m n�t back quay l?i th� th�i r?i ! tr?ng te lu�n , n?u b?n n�o g?p l?i tuong t? m�nh ch? cho :

C�ch duy nh?t:
1.log v�o FTP
2. T?i b?n d?y d? m?i nh?t
3.N�m h?t ch�ng v�o core v� cho ph�p ghi d�
4. Xong ! d�nh v�o address .../wp-admin/upgrade.php cho ch?y ph?n c�n l?i
5. XONG ! h?t l?i, n?u b?n c�n l?i l�m ti?p nhu sau:


a. Rename folder plugin.
b. log v�o admin v� ftp,
c. qu?ng t?ng c�i v�o folder plugin , refresh trang admin d?n khi n�o b? l?i, d?ng l?i plugin d� v� x�a n� di !
d. N?u v?n b? : call me !

Chủ Nhật, 19 tháng 2, 2012

Null vs Empty (Zero Length) stringNull vs Empty (Zero Length) string

Not many end users understand the difference between an empty string of zero length (�) vs Null. We have seen that at times, the end users put in an empty string in a field and there are no checks in the system to prevent them from being able to get that data into the database.  An empty string of zero length is not the same as a Null value in SQL Server. A string of zero length is still a string with no characters � a Null on the other hand can mean more than just denoting an absence of data.  Maybe the data is not applicable or the data is missing or it is just not present yet.  A classic analogy given in this case is that of a blank CD with nothing on it vs no CD.  A lot of debate is there about the usefulness of Null and the design patterns but that is not what we want to cover here today.  We will provide some links in the Resources section which cover that topic as well.  What we want to mention in this post today are the differences between a Null value vs a zero length string and how the behavior is also different between different RDBMS.  We will cover this for a couple of different data types besides the string data type.
We have blogged about the side effects of using a zero length string for an integer  data type column before � here.  Today, we saw a similar issue at a client site � this time with a datetime data type column.  Here is an example (using SQL Server here):
declare @table table (col1 datetime)
insert into @table values ('');
select * from @table
��������
1900-01-01 00:00:00.000
The empty string gets converted to the default datetime value of 1900-01-01 00:00:00.000 as shown above.  Not really what the end user was expecting.  And why do we get that particular date?  Because datetime is internally stored as two integers (hence the 8 bytes per datetime value) � the first integer stores the number for computing dates before or after the base date of 1900-01-01 and the second integer has the number of clock ticks post midnight with each tick being 1/300th of a second.
So, what could be some other issues that this can result into besides silently corrupting the data?
a) Your SQL code that would otherwise expect to work like the IS NULL or IS NOT NULL checks won�t work anymore,
b) In case you were doing this for a number column, the aggregate functions like AVG() which otherwise would be ignoring the Null value will now count the record,
c) The SQL code which uses functions like ISNULL(), COALESCE() etc. will not function as expected since these fields will not have a Null value.
d) The sorts won�t work as expected since Null and the empty string (and the subsequent default value that actually gets inserted) are not the same thing.
e) If you have this column as part of the foreign key, you will get an error at the time of the insert itself since instead of a Null value, the code will try to insert another default value in and it will violate the FK constraint.
f) Any concatenation operations or MAX(), MIN() functions can lead to un-desired results.
As always, there is no substitute for good design and good code.  A good design can put checks in place both at the application level (validations � either at the client side or application layer) as well as the DB level (check constraint) to prevent such scenarios from happening.
Do note that if you enter in an empty string of more than zero length, in SQL Server, the result would be the same.  ANSI_PADDING does effect the storage but the comparison rules remain the same.  You can read more on that in one of our previous blog posts here.
And if we were to use a varchar or a char column, the behavior is the same with the difference of course being that it is string of length 1 in the case of a CHAR data-type column.
declare @table table (col1 char(1), col2 varchar(1))
insert into @table values ('', '');
select col1, datalength(col1) char_str_length, col2, datalength(col2) varchar_str_length from @table where col1 = ''
col1 char_str_length col2 varchar_str_length
---- --------------- ---- ------------------
     1                    0
Also, if you are a developer who has worked in both SQL Server and Oracle, then you would know that the behavior in Oracle is a bit different.  It treats Null and an empty string of zero length, the same way.  And it treats an empty string of more than a zero length different than a Null value.  This is different than the ANSI (and SQL Server behavior).  So, in Oracle:
a) A zero length variable length string (varchar2 data type) is treated as a NULL.
b) A string of more than zero length is not treated as a NULL.
c) A zero length fixed length string (char data type) is not treated as a NULL since CHAR data types are blank padded strings.
Here is an example:
SQL> select 1 as col1,length('') LEN  from dual where '' is null
col1        LEN
���- ���-
1 NULL
SQL> select 1 as col1,length('') LEN  from dual where to_char('') is null
col1        LEN
���- ���-
1 NULL
This shows that an empty string is treated as a null in Oracle and the default data type of an empty string is varchar2 since if it were char, then automatically its length would have been one as stated above.
It is always better to check for such issues and in order to follow the same guidelines across RDBMS, check for empty strings via client side logic or application layer logic or check constraints at the DB level and ensure that you are going to put in NULL if that is what your design intention was rather than having such side effects of the empty string.

LOcal attack v� c�ch t?n c�ng !

Local  Attack l� m?t trong nhung phuong th?c hack kh�ng du?c khuy�n d�ng v� l� do d?o d?c. Tuy nhi�n t�m hi?u v� d? ph�ng local attack l?i l� m?t chuy?n th� v? r?t du?c quan t�m.
Define:
�?i v?i m?t web server th�ng thu?ng.
Khi c�c b?n host site c?a m�nh tr�n server, th�ng thu?ng b?n du?c c?p 1 account tr�n server d� v� m?t thu m?c d? qu?n l� sai c?a m�nh. V� d? l� /user/username1. Tuong t? nhu v?y cung c� 1 thu m?c l� /user/username2. Gi? s? /user/username2 b? hacker chi?m gi?, b?ng c�c script th�ng thu?ng, hacker c� th? truy c?p d?n c�c file c?a b?n ? /user/username1. C�c t?n c�ng d?a tr�n nh?ng script ? user n�y t?n c�ng v�o host c?a user kh�c tr�n c�ng server g?i l� Local Attack.
More:
Th�ng thu?ng nh?t, Local Attack du?c s? d?ng d? d?c l?y th�ng tin config t? victim, sau d� d?a v�o th�ng tin config n�y d? ph� ho?i website.
T? phuong th?c c?a Local Attack, c�ch ph�ng ch?ng Local Attack ch? y?u d?a tr�n 3 m?c:
Config c?a server: c?u h�nh server c?a super admin, t�y v�o c�ch c?u h�nh m� kh? nang tr�nh local attack s? tang or gi?m:D
Source code c?a website: thu?ng c�c website khi ch?y tr�n m?ng kh�ng dc zend ( encode php ) ho?c m� h�a. Khi d� local attack s? d?  d�ng hon. Ngo�i ra t�y v�o source c?a t?ng website v� t�y ch?nh c?a developer m� c� th? ho?c kh�ng th? tr�nh local attack.
Chuong tr�nh b?o v? tr�n server: nh?ng chuong tr�nh nhu NAV ho?c KPS c� th? ch?n du?c nh?ng scrip d?c h?i -> disable local attack :D
N�i so qua v? c�ch t?n c�ng: nhu d� n�i trong phuong th?c, ch? y?u l� hacker ph?i d?c du?c config c?a website d? ti?n h�nh c�ch bu?c ti?p theo ( :�> ). Vi?c x�c d?nh file config n?m ? d�u v� l�m th? n�o d? d?c du?c n� d�i h?i c? tr�nh d? l?n kinh nghi?m. Sau khi x�c d?nh du?c file config, hacker s? s? d?ng c�c l?nh kh�c nhau d? c? g?ng l?y n?i dung c?a file nay. ? d�y dua m?t s? v� d? v? v�i v? tr� file config
VBB: <root>/includes/config.php
Joomla <root>/configuration.php



C� nhi?u c�ch t?n c�ng v�ng v�o nh?m qua m?t co ch? b?o m?t c?a server, song d?u qua c�c bu?c tuong t? nhu sau:
Bu?c 1: T?n c�ng site b? l?i b?o m?t n?m c�ng server v?i website c?n t?n c�ng th�ng qua c�c bug v� upload Shell n�n website n�y. c� r?t nhi?u lo?i shell cho 1 v� nhi?u ng�n ng? nhu : php shell , asp shell, aspx shell, jps shell...t�y thu?c v�o server h? tr? lo?i ng�n ng?  n�o v� d�i khi l� s? k?t h?p nhi?u shell trong l�c t?n c�ng .
khi upload l�n ta c� d?ng: http://a.com/shell.php v� con shell n�y d� n?m c�ng server v?i website c?n t?n c�ng b.com
Bu?c 2:  t?n c�ng.T?i Shell Command ta b?t d?u g� l?nh: 

 
1.cat /etc/passwd

s? cho ra du?c k?t qu? nhi?u d�ng d?n nhu sau:
1.tphats:33217:33218::/home/tphats:/usr/local/cpanel/bin/noshell
 
b?n th?y user ch�nh l�  tphats. ti?p theo b?n ki?m tra domain c?a site c?n t?n c�ng.
1.cat /etc/userdomains

nh�n k?t qu? th?y user domain 
v?y l� d�ng tphats l� user c?a tanphat.net
ti?p t?c d�ng l?nh d? xem trong th? m?c www c?a tanphat.net c� nh?ng file g�?
1.dir /home/<strong>tphats</strong>/public_html/

ta c� 1 list file v� thu m?c:
1.admin
2.include
3.image
4.template
5.index.php
6.config.php
7.footer.php

d? d?c file d? xem file n�o ch?a li�n k?t v?i database. nh�n v�o d�y d�ch th? l� config.php. ta d?c fie n�y th?:
1.cat / home/tphats/public_html/config.php
2.{code}
3.ta th?y k?t qu? nhu sau:
4.{code}


Nhu v?y d� d� c� du?c user + pass c?a mysql, c�ng vi?c c�n l?i c?a b?n l� g�? k?t n?i data update user + pass v� b?t d?u dang nh?p: http://tanphat.net/admin
 
b�i vi?t n�y du?c m� ph�ng tr�n m�i tru?ng linux v?i vi?c config server y?u. Th?c t? kh�ng d? d�ng nhu v?y, c� nh?ng website kh�ng cho upload file php, asp... th�ng qua browse hay khi upload l�n th�nh c�ng th� anti virus c?a server x�a m?t. v� v?y c�c hacker thuong link d�ng trong t?n c�ng. V� d?: zend code , hay base64 code shell d? server kh�ng ph�t hi?n. n?u kh�a h�m cat th� ch?y h�m read, less... 
 ����.
N�i v? v�i c�ch m� t�i bi?t:
V? server: Jail Apache : t? host c?a user n�y kh�ng th? truy c?p t?i file ? host c?a user kh�c
V? web source code: Zend -> encode source d? hacker ko th? d?c du?c n?i dung d� d� t�m ra file, chmod file d? ko th? d?c t? b�n ngo�i �
V? security app: NAV -> t?t dc nhung script nhu Shell r57 r59 �
Nh�n chung, d?i v?i t?t c? c�c website th� local attack l� �c m?ng v� g?n nhu n?u b? local attack th� s? die trong nh�y m?t. Tuy nhi�n nh?ng hacker th?c s? s? kh�ng s? d?ng c�ch n�y tr? khi b? khi�u kh�ch. Cho n�n n?u b?n l� web master, h�y ngoan ngo�n v� d? ph�ng. N?u b?n l� server admin, ph?i b?o v? cho ngu?i d�ng. N?u b?n l� hacker, l�m on d?ng s? d?ng c�ch n�y. C�n n?u b?n nhu tui nghi, kh�ng c?n lo nhi?u v? n�.

Nhu d� n�i, local attack l� t?n c�ng t? user c�ng server v?i nhau. V?y l�m sao c� th? s? d?ng m?t user n�y d? t?n c�ng m?t user kh�c? Th�ng thu?ng c� 2 c�ch:
1. C�ch n�y t?n kh� nhi?u th? qu� gi� : ti?n. L?y  ti?n mua m?t c�i host tr�n server d� r?i local -> ch?c 100% th�nh c�ng.
2. T?n c�ng v�o website c�ng server c� d? b?o m?t th?p hon. Sau d� local.

Th�ng thu?ng hacker s? d?ng c�ch th? 2, ch?c ai cung hi?u l� do. V?y l�m sao d? t?n c�ng v�o nh?ng m?c ti�u b�n c?nh? C� m?y bu?c sau:
1. T�m xem tr�n server c� nh?ng website n�o? C�ch hi?n t?i du?c d�ng nhi?u nh?t l� Reverse IP domain d�. Hi?n t?i c� kh� nhi?u website cung c?p d?ch v? n�y.
2. Sau khi t�m du?c danh s�ch website, l?n lu?t check xem website n�o c� kh? nang t?n c�ng th�nh c�ng v� c� th? s? d?ng local.
3. TI?p theo d� t?n c�ng website d� ch?n.
4. Sau khi attack th�nh c�ng, b?t d?u local attack.
5. Local attack th�nh c�ng hay th?t b?i c�n l� chuy?n sau n�y.
Quan tr?ng nh?t ? 5 bu?c n�y l� t�m xem website n�o c� d? b?o m?t k�m hon v� c� th? b? hack. Thu?ng nhung website nhu th? l�:
1. Nh?ng website t? l�m, kh? nang m?c l?i thu?ng cao.
2. Nh?ng source code ph? th�ng nhung version d� l?i th?i.
N?u t�m th?y tru?ng h?p s? 1, t? t? check l?i v� hack.
N?u t�m th?y tru?ng h?p s? 2, c� th? check xem version hi?n t?i c� l�i g� kh�ng t?i trang web milw0rm.com
T? d�, c�c b?n c� th? th?y ra du?c khi n�o m�nh x�i local. �� l� nh?ng website c� d? b?o m?t cao, kh�ng th? t?n c�ng qua l?i l?p tr�nh, d?ng th?i server config kh� an to�n kh�ng th? t?n c�ng chi?m root, b?t bu?c ph?i local.. Nh?ng website nhu th? thu?ng l� nh?ng website du?c update thu?ng xuy�n n?u nhu l� c�i source th�ng d?ng ho?c nh?ng website v?i coder pro :D.
N�i t? d?u t?i h, ch?c c�c b?n cung nh?n ra d� mu?n hay kh�ng, n?u kh�ng th? chi?m server b?ng c�ch n�y hay c�ch kh�c, hacker v?n b? b?t bu?c ph?i t?n c�ng tr?c ti?p th�nh c�ng m?t website kh�c. N�i nhu v?y, nghia l� mu?n local, hacker ph?i luy?n m?y c�i kh�c tru?c d�. V� quan di?m n�y cho n�n trong m?t s? tru?ng h?p, c� th? s? d?ng local :D.
Nghi d?n chuy?n t?n c�ng tr?c ti?p m?t website n�o d� v?i m?c d�ch up shell / local, hacker ph?i l?i d?ng nh?ng l?i/l? h?ng d? can thi?p v�o c?u tr�c c?a website. N?u c�c b?n d� bi?t, c� nh?ng l?i c?c k� co b?n m� ai tham gia security zone d?u bi?t nhu:
1.L?i Sql Injection
2.L?i XSS
3.L?i zero-length string (c� c? chuy�n gia chuy�n khai th�c l?i n�y lu�n n�). -> b?a trc Joomla b? l?i n�y n�.
4. v� c�n nhi?u nhi?u n?a� m� tui hok bi?t.
M?i l?i c� m?c d? nguy hi?m , c�ch ki?m tra, v� c? c�ch ph�ng ch?ng kh�c nhau. C�n hacker l�m sao bi?t n�n khai th�c l?i n�o, c�u tr? l?i ch? c� th? l� t? kinh nghi?m -> test c�c l?i xem d�nh c�i n�o th� l�m vi?c v?i c�i ?y th�i�..

Nh�n chung, mu?n t?n c�ng nh?ng website d?ng nhu vbb thu?n ho?c joomla thu?n hay d?i lo?i gi?ng v?y, c�ch duy nh?t l� local :D. C� v�i hacker t? nh?n m�nh l� Hacker Mu B?c (d?p), d? tho�t ra c�i v�ng tr?ng den nhung th?c ch?t d� ch?nh l� hacker mu x�m :D hay th?m ch� c� khi t? hon l� script kiddies gi? danh, s? d?ng nh?ng chi�u local th? n�y d? n?i danh. Th?c ch?t kh�ng d�ng n�i l?m.
B�i vi?t n�y ch? nh?m d?n ngu?i d?c d?n con du?ng ch�nh d?o m� th�i. :D

(B�I VI?T �U?C SUU T?M)