Obi dị anyị ụtọ ịkpọsa nke ahụ AhaSlides anabatala Greybox Pentest nke Viettel Cyber Security na-elekọta. Nnyocha nchekwa miri emi lekwasịrị anya na nyiwe ọkọlọtọ abụọ anyị dị n'ịntanetị: ngwa Presenter (presenter.ahaslides.com) na ngwa ndị na-ege ntị (ndị na-ege ntị.ahaslides.com).
Nnwale nchekwa ahụ, nke sitere na Disemba 20 ruo Disemba 27, 2023, gụnyere nyocha nke ọma maka adịghị ike nchekwa dị iche iche. Ndị otu sitere na Viettel Cyber Security mere nyocha miri emi wee gosipụta ọtụtụ mpaghara maka mmelite n'ime sistemụ anyị.
Isi ihe:
- Oge ule: Disemba 20-27, 2023
- Oke: Nyocha miri emi nke adịghị ike nchekwa dị iche iche nwere ike ime
- Nsonaazụ: AhaSlides gafere ule ahụ ka o kwuchara ihe adịghị ike achọpụtara
- Mmetụta: Nchekwa na ntụkwasị obi emelitere maka ndị ọrụ anyị
Kedu ihe bụ Pentest Viettel Security?
Pentest, dị mkpụmkpụ maka ule penetration, bụ n'ezie cyberattack na-akpa ọchị na sistemụ gị iji kpughee mperi ndị na-erigbu. N'ihe gbasara ngwa webụ, Pentest bụ nlebanya na-agwụ agwụ iji tụọ, nyochaa, na kọọ ntụpọ nchekwa dị n'ime ngwa. Chee ya dị ka ule nrụgide maka nchekwa sistemụ gị - ọ na-egosi ebe ndị nwere ike ịdaba.
Ndị ọkachamara nwere ahụmahụ na Viettel Cyber Security mere, nkịta kachasị elu na oghere cybersecurity, ule a bụ akụkụ nke nnukwu ụlọ ọrụ nchekwa ha. Usoro ule Greybox eji na ntule anyị gụnyere akụkụ nke ma igbe ojii na ule igbe ọcha. Ndị na-anwale nwere ụfọdụ intel na arụ ọrụ dị n'ime nke ikpo okwu anyị, na-eṅomi mwakpo nke onye ọchụnta ego nwere mmekọrịta tupu ya na sistemụ.
Site n'iji usoro dị iche iche nke akụrụngwa webụ anyị eme ihe, site na nhazi ihe nkesa na ịde ederede saịtị ruo na nyocha agbajiri agbaji yana mkpughe data, Pentest na-enye foto ziri ezi nke ihe iyi egwu. Ọ bụ nke ọma, gụnyere vectors ọgụ dị iche iche, a na-eme ya na gburugburu ebe a na-achịkwa iji hụ na ọ nweghị mmerụ ahụ na sistemu ndị metụtara ya.
Akụkọ ikpeazụ abụghị naanị na-achọpụta adịghị ike mana ọ na-ebutekwa ha ụzọ site n'ịdị njọ yana gụnye ndụmọdụ maka idozi ha. Ịgafe ụdị ule zuru oke na nke siri ike na-emesi ike nke nchekwa cyber nke otu ụlọ ọrụ ma bụrụkwa ihe mgbochi dị mkpa maka ntụkwasị obi na afọ dijitalụ.
Achọpụtara adịghị ike na ndozi
N'oge ule a, ahụrụ ọtụtụ ihe adịghị ike, sitere na Cross-Site Scripting (XSS) ruo nsogbu njikwa ohere gbajiri (BAC). Iji kọwaa kpọmkwem, ule ahụ ekpughere adịghị ike dị ka XSS echekwara n'ofe ọtụtụ atụmatụ, Ntụle Ihe Ntụkwasị Obi Na-adịghị Anya (IDOR) na ọrụ nhichapụ ngosi, yana nkwalite ihe ùgwù gafee ọrụ dị iche iche.
The AhaSlides otu teknụzụ, na-arụ ọrụ aka na Viettel Cyber Security, ekwupụtala okwu niile achọpụtara. Usoro dị ka nzacha data ntinye, ntinye ntinye data, ojiji nke nkụnye eji isi mee nzaghachi kwesịrị ekwesị, na nnabata nke amụma nchekwa ọdịnaya siri ike (CSP) ka emejuputala iji kwalite nchekwa anyị.
AhaSlides Gafere ule penetration nke Viettel Security nke ọma
Ma ngwa ihe ngosi na ndị na-ege ntị agabigala ule nnabata zuru oke nke Viettel Security mere. Ntụle siri ike a na-emesi mkpebi anyị siri ike na omume nchekwa na nchekwa data onye ọrụ.
Nnwale ahụ, emere na Disemba 2023, jiri usoro Greybox mee ihe, na-eme ka ọnọdụ mwakpo ụwa n'ezie. Ndị ọkachamara nchekwa nke Viettel nyochachara nke ọma ikpo okwu anyị maka adịghị ike, na-achọpụta mpaghara maka imelite.
Ndị ahụ lebara ihe adịghị ike ndị ahụ anya AhaSlides ndị otu injinia na mmekorita ya na Viettel Security. Usoro etinyere gụnyere nzacha data ntinye, ntinye data mmepụta, amụma nchekwa ọdịnaya siri ike (CSP), yana ndị nkụnye eji isi mee nzaghachi kwesịrị ekwesị iji mee ka ikpo okwu sie ike.
AhaSlides etinyewokwa ego na ngwaọrụ nleba anya dị elu maka nchọpụta na nzaghachi ihe iyi egwu n'ezie. Na mgbakwunye, a nụcharala usoro nzaghachi ihe omume anyị iji hụ na emee ngwa ngwa na nke dị irè ma ọ bụrụ na enwere mmebi nchekwa.
Platform echekwara ma chekwaa
Ndị ọrụ nwere ike inwe obi ike na echekwara data ha yana ahụmịhe mmekọrịta ha na-echekwa. Site na ntule nchekwa na-aga n'ihu na nkwalite na-aga n'ihu, anyị na-agba mbọ wulite ikpo okwu a pụrụ ịdabere na ya na nchekwa maka ndị ọrụ anyị.