<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:media="http://search.yahoo.com/mrss/"><channel><title><![CDATA[dungbv - ARROW Technologies Blog]]></title><description><![CDATA[Trang tổng hợp các kiến thức về lập trình]]></description><link>https://blog.arrow-tech.vn/</link><image><url>https://blog.arrow-tech.vn/favicon.png</url><title>dungbv - ARROW Technologies Blog</title><link>https://blog.arrow-tech.vn/</link></image><generator>Ghost 5.81</generator><lastBuildDate>Mon, 06 Apr 2026 21:40:40 GMT</lastBuildDate><atom:link href="https://blog.arrow-tech.vn/author/dungbv/rss/" rel="self" type="application/rss+xml"/><ttl>60</ttl><item><title><![CDATA[Hướng dẫn sử dụng công cụ Vuls để quét lỗ hổng bảo mật trên hệ điều hành nhân *nix (Ubuntu, Debian, RHEL, Oracle Linux, CentOS..)]]></title><description><![CDATA[<!--kg-card-begin: markdown--><h1 id="nidungtrnhby">N&#x1ED9;i dung tr&#xEC;nh b&#xE0;y:</h1>
<ul>
<li>Gi&#x1EDB;i thi&#x1EC7;u</li>
<li>C&#xE0;i &#x111;&#x1EB7;t</li>
<li>Qu&#xE9;t h&#x1EC7; th&#x1ED1;ng</li>
<li>K&#x1EBF;t qu&#x1EA3; qu&#xE9;t</li>
</ul>
<h1 id="giithiu">Gi&#x1EDB;i thi&#x1EC7;u</h1>
<ul>
<li>L&#xE0; c&#xF4;ng c&</li></ul>]]></description><link>https://blog.arrow-tech.vn/vuls/</link><guid isPermaLink="false">63915acd7a2f410001205db1</guid><category><![CDATA[Security]]></category><category><![CDATA[Linux]]></category><dc:creator><![CDATA[dungbv]]></dc:creator><pubDate>Fri, 25 May 2018 08:41:55 GMT</pubDate><content:encoded><![CDATA[<!--kg-card-begin: markdown--><h1 id="nidungtrnhby">N&#x1ED9;i dung tr&#xEC;nh b&#xE0;y:</h1>
<ul>
<li>Gi&#x1EDB;i thi&#x1EC7;u</li>
<li>C&#xE0;i &#x111;&#x1EB7;t</li>
<li>Qu&#xE9;t h&#x1EC7; th&#x1ED1;ng</li>
<li>K&#x1EBF;t qu&#x1EA3; qu&#xE9;t</li>
</ul>
<h1 id="giithiu">Gi&#x1EDB;i thi&#x1EC7;u</h1>
<ul>
<li>L&#xE0; c&#xF4;ng c&#x1EE5; m&#xE3; ngu&#x1ED3;n m&#x1EDF;, qu&#xE9;t l&#x1ED7; h&#x1ED5;ng b&#x1EA3;o m&#x1EAD;t tr&#xEA;n c&#xE1;c g&#xF3;i ph&#x1EA7;n m&#x1EC1;m &#x111;&#xE3; &#x111;&#x1B0;&#x1EE3;c c&#xE0;i &#x111;&#x1EB7;t tr&#xEA;n OS.</li>
<li>Vuls qu&#xE9;t d&#x1EF1;a tr&#xEA;n th&#xF4;ng tin t&#x1EEB; NVD, OVAL, &#x2026;</li>
<li>Nh&#x1EEF;ng OS &#x111;&#x1B0;&#x1EE3;c support: Alpine, Ubuntu, Debian, RHEL, Oracle Linux, CentOS, SUSE Enterprise, &#x2026;</li>
<li>K&#x1EBF;t qu&#x1EA3; qu&#xE9;t c&#xF3; th&#x1EC3; xem v&#x1EDB;i Terminal Based Viewer ho&#x1EB7;c VulsRepo (Web UI).</li>
<li>Th&#xF4;ng b&#xE1;o k&#x1EBF;t qu&#x1EA3; qu&#xE9;t qua email, slack.<br>
<img src="https://blog.arrow-tech.vn/content/images/2018/05/Screen-Shot-2018-05-25-at-10.56.17-AM.png" alt="Screen-Shot-2018-05-25-at-10.56.17-AM" loading="lazy"></li>
</ul>
<h1 id="cit">C&#xE0;i &#x111;&#x1EB7;t</h1>
<p>Sau &#x111;&#xE2;y l&#xE0; c&#xE1;c b&#x1B0;&#x1EDB;c c&#xE0;i &#x111;&#x1EB7;t tr&#xEA;n Ubuntu</p>
<h2 id="citccyucu">C&#xE0;i &#x111;&#x1EB7;t c&#xE1;c y&#xEA;u c&#x1EA7;u</h2>
<h3 id="package">Package</h3>
<pre><code>$ sudo apt-get install sqlite git gcc make wget
$ wget https://dl.google.com/go/go1.10.2.linux-amd64.tar.gz
$ sudo tar -C /usr/local -xzf go1.10.2.linux-amd64.tar.gz
$ mkdir $HOME/go
</code></pre>
<h3 id="thmexportvoetcprofiledgoenvsh">Th&#xEA;m export v&#xE0;o <code>/etc/profile.d/goenv.sh</code></h3>
<pre><code>export GOROOT=/usr/local/go
export GOPATH=$HOME/go
export PATH=$PATH:$GOROOT/bin:$GOPATH/bin
</code></pre>
<h3 id="setbinmitrngtrnvoshellhinti">Set bi&#x1EBF;n m&#xF4;i tr&#x1B0;&#x1EDD;ng &#x1EDF; tr&#xEA;n v&#xE0;o shell hi&#x1EC7;n t&#x1EA1;i</h3>
<pre><code>$ source /etc/profile.d/goenv.sh
</code></pre>
<h2 id="deploygocvedictionary">Deploy go-cve-dictionary</h2>
<h3 id="buildktquctdigopathbin">Build, k&#x1EBF;t qu&#x1EA3; &#x111;&#x1B0;&#x1EE3;c &#x111;&#x1EB7;t d&#x1B0;&#x1EDB;i <code>$GOPATH/bin</code></h3>
<pre><code>$ sudo mkdir /var/log/vuls
$ sudo chown user_name /var/log/vuls
$ sudo chmod 700 /var/log/vuls

$ mkdir -p $GOPATH/src/github.com/kotakanbe
$ cd $GOPATH/src/github.com/kotakanbe
$ git clone https://github.com/kotakanbe/go-cve-dictionary.git
$ cd go-cve-dictionary
$ make install
</code></pre>
<h3 id="fetchdliutnvd">Fetch d&#x1EEF; li&#x1EC7;u t&#x1EEB; NVD</h3>
<pre><code>$ mkdir $HOME/vuls
$ cd $HOME/vuls
$ for i in `seq 2002 $(date +&quot;%Y&quot;)`; do go-cve-dictionary fetchnvd -years $i; done
</code></pre>
<h2 id="deploygovaldictionary">Deploy goval-dictionary</h2>
<h3 id="buildktquctdigopathbin">Build, k&#x1EBF;t qu&#x1EA3; &#x111;&#x1B0;&#x1EE3;c &#x111;&#x1EB7;t d&#x1B0;&#x1EDB;i <code>$GOPATH/bin</code></h3>
<pre><code>$ mkdir -p $GOPATH/src/github.com/kotakanbe
$ cd $GOPATH/src/github.com/kotakanbe
$ git clone https://github.com/kotakanbe/goval-dictionary.git
$ cd goval-dictionary
$ make install
</code></pre>
<h3 id="fetchdliuoval">Fetch d&#x1EEF; li&#x1EC7;u OVAL</h3>
<p>Ph&#x1EE5; thu&#x1ED9;c v&#xE0;o OS c&#x1EA7;n qu&#xE9;t, chi ti&#x1EBF;t: <a href="https://github.com/kotakanbe/goval-dictionary?ref=blog.arrow-tech.vn">https://github.com/kotakanbe/goval-dictionary</a></p>
<pre><code>$ cd $HOME/vuls
$ goval-dictionary fetch-ubuntu 12 14 16 18 #Ubuntu
</code></pre>
<h2 id="deployvuls">Deploy Vuls</h2>
<pre><code>$ mkdir -p $GOPATH/src/github.com/future-architect
$ cd $GOPATH/src/github.com/future-architect
$ git clone https://github.com/future-architect/vuls.git
$ cd vuls
$ make install
</code></pre>
<h1 id="quththng">Qu&#xE9;t h&#x1EC7; th&#x1ED1;ng</h1>
<p>Vuls h&#x1ED7; tr&#x1EE3; local scan v&#xE0; remote scan. D&#x1B0;&#x1EDB;i &#x111;&#xE2;y l&#xE0; h&#x1B0;&#x1EDB;ng d&#x1EAB;n scan localhost</p>
<pre><code>$ cd $HOME/vuls
# T&#x1EA1;o file config.toml nh&#x1B0; sau:
[servers]
[servers.localhost]
host = &quot;localhost&quot;
port = &quot;local&quot;
</code></pre>
<h3 id="kimtra">Ki&#x1EC3;m tra</h3>
<p>Ki&#x1EC3;m tra config.toml v&#xE0; setting tr&#xEA;n server tr&#x1B0;&#x1EDB;c khi scan</p>
<pre><code>$ vuls configtest
</code></pre>
<p><img src="https://blog.arrow-tech.vn/content/images/2018/05/Screen-Shot-2018-05-25-at-11.52.49-AM.png" alt="Screen-Shot-2018-05-25-at-11.52.49-AM" loading="lazy"></p>
<h3 id="scan">Scan</h3>
<pre><code>$ vuls scan
</code></pre>
<p><img src="https://blog.arrow-tech.vn/content/images/2018/05/Screen-Shot-2018-05-25-at-11.56.29-AM.png" alt="Screen-Shot-2018-05-25-at-11.56.29-AM" loading="lazy"></p>
<h3 id="report">Report</h3>
<pre><code>$ vuls report -format-one-line-text
</code></pre>
<p><img src="https://blog.arrow-tech.vn/content/images/2018/05/Screen-Shot-2018-05-25-at-1.12.12-PM.png" alt="Screen-Shot-2018-05-25-at-1.12.12-PM" loading="lazy"></p>
<pre><code>$ vuls report -format-short-text
$ vuls report -format-full-text | less
</code></pre>
<h1 id="ktququt">K&#x1EBF;t qu&#x1EA3; qu&#xE9;t</h1>
<h2 id="terminalbaseduserinterface">Terminal-Based User Interface</h2>
<pre><code>$ vuls tui
</code></pre>
<p><img src="https://blog.arrow-tech.vn/content/images/2018/05/Screen-Shot-2018-05-25-at-1.18.36-PM.png" alt="Screen-Shot-2018-05-25-at-1.18.36-PM" loading="lazy"></p>
<h2 id="webui">Web UI</h2>
<p>VulsRepo cung c&#x1EA5;p giao di&#x1EC7;n web &#x111;&#x1EC3; th&#x1ECB; k&#x1EBF;t qu&#x1EA3; m&#x1ED9;t c&#xE1;ch tr&#x1EF1;c quan h&#x1A1;n</p>
<h3 id="tomtjsonreportcavulsvclonevulsrepo">T&#x1EA1;o m&#x1ED9;t json report c&#x1EE7;a vuls v&#xE0; clone vulsrepo</h3>
<pre><code>$ cd $HOME/vuls
$ vuls scan 
$ vuls report -format-json 

$ git clone https://github.com/usiusi360/vulsrepo.git
$ cd vulsrepo/server
$ cp vulsrepo-config.toml.sample vulsrepo-config.toml

# N&#x1ED9;i dung file vulsrepo-config.toml
[Server]
rootPath = &#x201C;/home/user_name/vuls/vusrepo&#x201D;
resultsPath = &#x201C;/home/user_name/vuls/results&#x201D;
serverPort = &#x201C;5111&#x201D;
</code></pre>
<h3 id="startvulsreposerver">Start vulsrepo-server</h3>
<pre><code>$ ./vulsrepo-server
</code></pre>
<p><img src="https://blog.arrow-tech.vn/content/images/2018/05/Screen-Shot-2018-05-25-at-1.55.57-PM.png" alt="Screen-Shot-2018-05-25-at-1.55.57-PM" loading="lazy"></p>
<h3 id="mtshnhnhcavulsrepo">M&#x1ED9;t s&#x1ED1; h&#xEC;nh &#x1EA3;nh c&#x1EE7;a vulsrepo</h3>
<p><img src="https://blog.arrow-tech.vn/content/images/2018/05/Screen-Shot-2018-05-25-at-2.00.41-PM.png" alt="Screen-Shot-2018-05-25-at-2.00.41-PM" loading="lazy"></p>
<p><img src="https://blog.arrow-tech.vn/content/images/2018/05/Screen-Shot-2018-05-25-at-2.02.16-PM.png" alt="Screen-Shot-2018-05-25-at-2.02.16-PM" loading="lazy"></p>
<p><img src="https://blog.arrow-tech.vn/content/images/2018/05/Screen-Shot-2018-05-25-at-2.03.26-PM.png" alt="Screen-Shot-2018-05-25-at-2.03.26-PM" loading="lazy"></p>
<h1 id="thngtinchititxemtihttpsvulsio">Th&#xF4;ng tin chi ti&#x1EBF;t xem t&#x1EA1;i: <a href="https://vuls.io/?ref=blog.arrow-tech.vn">https://vuls.io/</a></h1>
<!--kg-card-end: markdown-->]]></content:encoded></item><item><title><![CDATA[Hướng dẫn sử dụng công cụ OWASP ZAP để quét lỗ hổng bảo mật ứng dụng web]]></title><description><![CDATA[<!--kg-card-begin: markdown--><h1 id="nidungtrnhby">N&#x1ED9;i dung tr&#xEC;nh b&#xE0;y:</h1>
<ol>
<li>OWASP ZAP l&#xE0; g&#xEC;</li>
<li>C&#xE0;i &#x111;&#x1EB7;t</li>
<li>S&#x1EED; d&#x1EE5;ng nh&#x1B0; th&#x1EBF; n&#xE0;o</li>
</ol>
<h1 id="owaspzaplg">OWASP ZAP l&#xE0; g&#xEC;</h1>
<ul>
<li>L&#xE0; c&#xF4;ng c&#x1EE5; qu&#xE9;t</li></ul>]]></description><link>https://blog.arrow-tech.vn/owasp-zap/</link><guid isPermaLink="false">63915acd7a2f410001205daf</guid><category><![CDATA[Security]]></category><category><![CDATA[Testing]]></category><dc:creator><![CDATA[dungbv]]></dc:creator><pubDate>Thu, 24 May 2018 07:10:12 GMT</pubDate><content:encoded><![CDATA[<!--kg-card-begin: markdown--><h1 id="nidungtrnhby">N&#x1ED9;i dung tr&#xEC;nh b&#xE0;y:</h1>
<ol>
<li>OWASP ZAP l&#xE0; g&#xEC;</li>
<li>C&#xE0;i &#x111;&#x1EB7;t</li>
<li>S&#x1EED; d&#x1EE5;ng nh&#x1B0; th&#x1EBF; n&#xE0;o</li>
</ol>
<h1 id="owaspzaplg">OWASP ZAP l&#xE0; g&#xEC;</h1>
<ul>
<li>L&#xE0; c&#xF4;ng c&#x1EE5; qu&#xE9;t l&#x1ED7;i b&#x1EA3;o m&#x1EAD;t c&#x1EE7;a &#x1EE9;ng d&#x1EE5;ng web, m&#xE3; ngu&#x1ED3;n m&#x1EDF;.</li>
<li>C&#xE1;c t&#xED;nh n&#x103;ng c&#x1EE7;a ZAP:
<ul>
<li>Zap nh&#x1B0; m&#x1ED9;t proxy gi&#x1EEF;a tr&#xEC;nh duy&#x1EC7;t v&#xE0; web app, do &#x111;&#xF3; ta c&#xF3; th&#x1EC3; inspect, modify nh&#x1EEF;ng request &#x111;&#x1B0;&#x1EE3;c g&#x1EED;i &#x111;&#x1EBF;n app.<br>
<img src="https://blog.arrow-tech.vn/content/images/2018/05/zap0.png" alt="zap0" loading="lazy"></li>
<li>Spider: l&#xE0; t&#xED;nh n&#x103;ng &#x111;&#x1B0;&#x1EE3;c s&#x1EED; d&#x1EE5;ng &#x111;&#x1EC3; t&#x1EF1; &#x111;&#x1ED9;ng kh&#xE1;m ph&#xE1; ra nh&#x1EEF;ng URL tr&#xEA;n website. N&#xF3; b&#x1EAF;t &#x111;&#x1EA7;u v&#x1EDB;i m&#x1ED9;t danh s&#xE1;ch URL, sau &#x111;&#xF3; x&#xE1;c &#x111;&#x1ECB;nh t&#x1EA5;t c&#x1EA3; c&#xE1;c URL c&#xF3; tr&#xEA;n c&#xE1;c trang v&#xE0; th&#xEA;m ch&#xFA;ng v&#xE0;o danh s&#xE1;ch URL c&#x1EA7;n th&#x103;m ti&#x1EBF;p theo, &#x111;&#x1EC7; quy ti&#x1EBF;p t&#x1EE5;c &#x111;&#x1EC3; t&#xEC;m &#x111;&#x1B0;&#x1EE3;c URL m&#x1EDB;i.</li>
<li>Active scan: l&#xE0; t&#xED;nh n&#x103;ng t&#x1EF1; &#x111;&#x1ED9;ng scan &#x111;&#x1EC3; t&#xEC;m nh&#x1EEF;ng l&#x1ED7;i &#x111;&#xE3; &#x111;&#x1B0;&#x1EE3;c bi&#x1EBF;t tr&#x1B0;&#x1EDB;c.</li>
<li>Passive scan: khi Zap &#x111;&#x1B0;&#x1EE3;c &#x111;&#x1EB7;t l&#xE0;m proxy cho tr&#xEC;nh duy&#x1EC7;t, n&#xF3; s&#x1EBD; scan t&#x1EA5;t c&#x1EA3; HTTP message (request v&#xE0; response) &#x111;&#x1B0;&#x1EE3;c g&#x1EED;i &#x111;&#x1EBF;n web app &#x111;&#x1EC3; x&#xE1;c &#x111;&#x1ECB;nh l&#x1ED7;i. Passive scan kh&#xF4;ng thay &#x111;&#x1ED5;i request v&#xE0; response.</li>
<li>Fuzzing: l&#xE0; t&#xED;nh n&#x103;ng cho ph&#xE9;p submit nhi&#x1EC1;u d&#x1EEF; li&#x1EC7;u kh&#xF4;ng h&#x1EE3;p l&#x1EC7; l&#xEA;n server.</li>
<li>....</li>
</ul>
</li>
</ul>
<h1 id="cit">C&#xE0;i &#x111;&#x1EB7;t</h1>
<ul>
<li>Download v&#xE0; c&#xE0;i &#x111;&#x1EB7;t theo h&#x1B0;&#x1EDB;ng d&#x1EAB;n t&#x1EA1;i &#x111;&#xE2;y:<br>
<a href="http://">https://github.com/zaproxy/zaproxy/wiki/Downloads<br>
</a></li>
</ul>
<h1 id="sdng">S&#x1EED; d&#x1EE5;ng</h1>
<h2 id="khito">Kh&#x1EDF;i t&#x1EA1;o</h2>
<ol>
<li>
<p>Explore app th&#x1EE7; c&#xF4;ng</p>
<ul>
<li>Sau khi start Zap, b&#x1B0;&#x1EDB;c &#x111;&#x1EA7;u ti&#xEA;n ta n&#xEA;n explore app th&#x1EE7; c&#xF4;ng, s&#x1EED; d&#x1EE5;ng t&#x1ED1;i &#x111;a c&#xE1;c ch&#x1EE9;c n&#x103;ng m&#xE0; web app cung c&#x1EA5;p, b&#x1EDF;i c&#xF3; nh&#x1EEF;ng t&#xED;nh n&#x103;ng c&#x1EA7;n d&#x1EEF; li&#x1EC7;u h&#x1EE3;p l&#x1EC7; &#x111;&#x1EC3; c&#xF3; th&#x1EC3; ti&#x1EBF;p t&#x1EE5;c.</li>
<li>&#x110;&#x1EC3; explore, ta Launch Browser &#x1EDF; tab Quick Start ho&#x1EB7;c &#x111;&#x1EB7;t Zap l&#xE0; proxy cho tr&#xEC;nh duy&#x1EC7;t (Preference --&gt; Local Proxy)</li>
</ul>
</li>
<li>
<p>Sau khi &#x111;&#xE3; explore, ta n&#xEA;n l&#x1B0;u session &#x111;&#x1EC3; t&#xE1;i s&#x1EED; d&#x1EE5;ng l&#x1EA7;n sau</p>
</li>
<li>
<p>T&#x1EA1;o Context</p>
<ul>
<li>Context l&#xE0; m&#x1ED9;t t&#x1EAD;p url, th&#x1B0;&#x1EDD;ng l&#xE0; m&#x1ED9;t web app</li>
<li>Context cung c&#x1EA5;p c&#xE1;c t&#xED;nh n&#x103;ng quan tr&#x1ECD;ng nh&#x1B0;: Authentication, Users, Session Management&#x2026;</li>
<li>N&#x1EBF;u web app cung c&#x1EA5;p nhi&#x1EC1;u role, ta n&#xEA;n l&#x1B0;u m&#x1ED7;i role v&#xE0;o m&#x1ED9;t Zap session.</li>
<li>C&#xE1;c b&#x1B0;&#x1EDB;c t&#x1EA1;o context:
<ul>
<li>Trong ph&#x1EA7;n Sites, click icon New Context, sau &#x111;&#xF3; t&#x1EA1;o context m&#x1EDB;i</li>
<li>Double click v&#xE0;o context v&#x1EEB;a t&#x1EA1;o<br>
<img src="https://blog.arrow-tech.vn/content/images/2018/05/Screen-Shot-2018-05-24-at-10.05.42-AM.png" alt="Screen-Shot-2018-05-24-at-10.05.42-AM" loading="lazy"></li>
<li>M&#x1EE5;c Authencitation: ch&#x1ECD;n Authentication mehtod ph&#xF9; h&#x1EE3;p<br>
<img src="https://blog.arrow-tech.vn/content/images/2018/05/Screen-Shot-2018-05-24-at-10.23.14-AM.png" alt="Screen-Shot-2018-05-24-at-10.23.14-AM" loading="lazy"></li>
<li>M&#x1EE5;c Users: click Add &#x111;&#x1EC3; th&#xEA;m m&#x1EDB;i m&#x1ED9;t user<br>
<img src="https://blog.arrow-tech.vn/content/images/2018/05/Screen-Shot-2018-05-24-at-10.26.04-AM.png" alt="Screen-Shot-2018-05-24-at-10.26.04-AM" loading="lazy"></li>
</ul>
</li>
</ul>
</li>
<li>
<p>Include web app v&#xE0;o context v&#x1EEB;a t&#x1EA1;o<br>
<img src="https://blog.arrow-tech.vn/content/images/2018/05/Screen-Shot-2018-05-24-at-10.37.55-AM.png" alt="Screen-Shot-2018-05-24-at-10.37.55-AM" loading="lazy"></p>
</li>
<li>
<p>Th&#xEA;m nh&#x1EEF;ng context c&#x1EA7;n quan t&#xE2;m v&#xE0; lo&#x1EA1;i nh&#x1EEF;ng context kh&#xE1;c t&#x1EEB; Scope b&#x1EB1;ng c&#xE1;ch chu&#x1ED9;t ph&#x1EA3;i v&#xE0;o m&#x1ED7;i context, sau &#x111;&#xF3; click icon Show only URL in Scope<br>
<img src="https://blog.arrow-tech.vn/content/images/2018/05/Screen-Shot-2018-05-24-at-10.43.28-AM.png" alt="Screen-Shot-2018-05-24-at-10.43.28-AM" loading="lazy"></p>
</li>
</ol>
<h2 id="tnhnngspidervactivescan">T&#xED;nh n&#x103;ng Spider v&#xE0; Active Scan</h2>
<ol>
<li>
<p>Ch&#x1ECD;n Attack --&gt; Spider<br>
<img src="https://blog.arrow-tech.vn/content/images/2018/05/Screen-Shot-2018-05-24-at-10.55.21-AM.png" alt="Screen-Shot-2018-05-24-at-10.55.21-AM" loading="lazy"></p>
</li>
<li>
<p>Ch&#x1ECD;n Context, User, sau &#x111;&#xF3; Start Scan<br>
<img src="https://blog.arrow-tech.vn/content/images/2018/05/Screen-Shot-2018-05-24-at-10.56.53-AM.png" alt="Screen-Shot-2018-05-24-at-10.56.53-AM" loading="lazy"></p>
</li>
<li>
<p>Active Scan c&#x169;ng t&#x1B0;&#x1A1;ng t&#x1EF1;, k&#x1EBF;t qu&#x1EA3; s&#x1EBD; &#x111;&#x1B0;&#x1EE3;c show trong tab Alert</p>
</li>
</ol>
<h2 id="tnhnngfuzzing">T&#xED;nh n&#x103;ng Fuzzing</h2>
<ol>
<li>Ch&#x1ECD;n m&#x1ED9;t submit request t&#x1EEB; ph&#x1EA7;n Sites c&#x1EA7;n test, sau &#x111;&#xF3; ch&#x1ECD;n Fuzz t&#x1EEB; menu Attack</li>
<li>Double click m&#x1ED9;t tham s&#x1ED1; c&#x1EA7;n g&#xE1;n nhi&#x1EC1;u gi&#xE1; tr&#x1ECB;, t&#x1EA1;i m&#x1EE5;c Fuzz Locations --&gt; Add --&gt; Add --&gt; Ch&#x1ECD;n payload type c&#x1EA7;n test --&gt; Add --&gt; Start Fuzzer<br>
<img src="https://blog.arrow-tech.vn/content/images/2018/05/Screen-Shot-2018-05-24-at-11.10.05-AM.png" alt="Screen-Shot-2018-05-24-at-11.10.05-AM" loading="lazy"></li>
</ol>
<h1 id="more">More</h1>
<p>&#x110;&#x1EC3; t&#xEC;m hi&#x1EC3;u chi ti&#x1EBF;t, ch&#x1ECD;n Help --&gt; OWASP ZAP User Guide</p>
<!--kg-card-end: markdown-->]]></content:encoded></item></channel></rss>