[{"data":1,"prerenderedAt":241},["ShallowReactive",2],{"post-top10owasp":3},{"id":4,"title":5,"body":6,"description":227,"extension":228,"meta":229,"navigation":236,"path":237,"seo":238,"stem":239,"__hash__":240,"dateDisplay":234,"image":235,"tags":231,"badge":230,"readingTime":205},"posts\u002Fposts\u002FTop10OWASP.md","OWASP Top 10",{"type":7,"value":8,"toc":203},"minimark",[9,18,31,39,50,57,73,80,91,98,109,116,127,134,145,152,163,170,181,188],[10,11,13,14],"h2",{"id":12},"_1-broken-access-control","1. ",[15,16,17],"strong",{},"Broken Access Control",[19,20,21,25,28],"ul",{},[22,23,24],"li",{},"Lỗi khi ứng dụng không kiểm soát quyền đúng cách, cho phép user truy cập dữ liệu\u002Fchức năng vượt quá quyền hạn.",[22,26,27],{},"Ví dụ: người dùng thường truy cập được trang admin chỉ bằng đổi URL.",[22,29,30],{},"Cách phòng tránh: kiểm tra quyền ở server-side, áp dụng nguyên tắc least privilege.",[10,32,34,35,38],{"id":33},"_2-cryptographic-failures-trước-gọi-là-sensitive-data-exposure","2. ",[15,36,37],{},"Cryptographic Failures"," (trước gọi là Sensitive Data Exposure)",[19,40,41,44,47],{},[22,42,43],{},"Lỗi liên quan đến mã hóa, dẫn đến rò rỉ dữ liệu nhạy cảm.",[22,45,46],{},"Ví dụ: lưu mật khẩu dạng plaintext, dùng HTTP thay vì HTTPS.",[22,48,49],{},"Cách phòng tránh: dùng HTTPS, hashing với salt (bcrypt, Argon2), không tự viết thuật toán crypto.",[10,51,53,54],{"id":52},"_3-injection","3. ",[15,55,56],{},"Injection",[19,58,59,62,70],{},[22,60,61],{},"Xảy ra khi dữ liệu đầu vào không được lọc, chèn thẳng vào câu lệnh (SQL, NoSQL, OS command…).",[22,63,64,65,69],{},"Ví dụ: SQL Injection (",[66,67,68],"code",{},"' OR '1'='1",").",[22,71,72],{},"Cách phòng tránh: dùng prepared statement, ORM, validate input.",[10,74,76,77],{"id":75},"_4-insecure-design","4. ",[15,78,79],{},"Insecure Design",[19,81,82,85,88],{},[22,83,84],{},"Vấn đề từ giai đoạn thiết kế hệ thống (chưa triển khai nhưng đã nguy hiểm).",[22,86,87],{},"Ví dụ: không có kế hoạch chống brute-force, không thiết kế rate-limit.",[22,89,90],{},"Giải pháp: threat modeling, security-by-design.",[10,92,94,95],{"id":93},"_5-security-misconfiguration","5. ",[15,96,97],{},"Security Misconfiguration",[19,99,100,103,106],{},[22,101,102],{},"Lỗi cấu hình không an toàn (nguyên nhân rất phổ biến).",[22,104,105],{},"Ví dụ: bật directory listing, để default account, lộ banner server.",[22,107,108],{},"Cách phòng tránh: hardening, disable default, patching thường xuyên.",[10,110,112,113],{"id":111},"_6-vulnerable-and-outdated-components","6. ",[15,114,115],{},"Vulnerable and Outdated Components",[19,117,118,121,124],{},[22,119,120],{},"Sử dụng thư viện\u002Fframework\u002Fsoftware lỗi thời chứa lỗ hổng đã biết.",[22,122,123],{},"Ví dụ: dùng jQuery version cũ có XSS.",[22,125,126],{},"Giải pháp: kiểm tra dependency (OWASP Dependency-Check, Snyk), update thường xuyên.",[10,128,130,131],{"id":129},"_7-identification-and-authentication-failures","7. ",[15,132,133],{},"Identification and Authentication Failures",[19,135,136,139,142],{},[22,137,138],{},"Lỗi trong xác thực, dẫn đến bypass hoặc chiếm quyền tài khoản.",[22,140,141],{},"Ví dụ: brute-force login, JWT không hết hạn, session ID dự đoán được.",[22,143,144],{},"Cách phòng tránh: MFA, session timeout, rate limiting.",[10,146,148,149],{"id":147},"_8-software-and-data-integrity-failures","8. ",[15,150,151],{},"Software and Data Integrity Failures",[19,153,154,157,160],{},[22,155,156],{},"Liên quan đến việc không đảm bảo tính toàn vẹn phần mềm\u002Fdữ liệu.",[22,158,159],{},"Ví dụ: update từ nguồn không tin cậy, không kiểm tra chữ ký file.",[22,161,162],{},"Giải pháp: dùng ký số, kiểm soát CI\u002FCD pipeline.",[10,164,166,167],{"id":165},"_9-security-logging-and-monitoring-failures","9. ",[15,168,169],{},"Security Logging and Monitoring Failures",[19,171,172,175,178],{},[22,173,174],{},"Thiếu log hoặc giám sát, khiến không phát hiện được tấn công.",[22,176,177],{},"Ví dụ: brute-force password mà không bị cảnh báo.",[22,179,180],{},"Cách phòng tránh: log đủ (auth, error), giám sát SIEM\u002FSOC, alert khi có bất thường.",[10,182,184,185],{"id":183},"_10-server-side-request-forgery-ssrf","10. ",[15,186,187],{},"Server-Side Request Forgery (SSRF)",[19,189,190,193,200],{},[22,191,192],{},"Attacker ép server gửi request đến domain khác (nội bộ hoặc bên ngoài).",[22,194,195,196,199],{},"Ví dụ: attacker nhập URL payload, server gọi nội bộ ",[66,197,198],{},"http:\u002F\u002Flocalhost:8080\u002Fadmin",".",[22,201,202],{},"Cách phòng tránh: validate URL đầu vào, chặn internal IP, dùng allowlist.",{"title":204,"searchDepth":205,"depth":205,"links":206},"",2,[207,209,211,213,215,217,219,221,223,225],{"id":12,"depth":205,"text":208},"1. Broken Access Control",{"id":33,"depth":205,"text":210},"2. Cryptographic Failures (trước gọi là Sensitive Data Exposure)",{"id":52,"depth":205,"text":212},"3. Injection",{"id":75,"depth":205,"text":214},"4. Insecure Design",{"id":93,"depth":205,"text":216},"5. Security Misconfiguration",{"id":111,"depth":205,"text":218},"6. Vulnerable and Outdated Components",{"id":129,"depth":205,"text":220},"7. Identification and Authentication Failures",{"id":147,"depth":205,"text":222},"8. Software and Data Integrity Failures",{"id":165,"depth":205,"text":224},"9. Security Logging and Monitoring Failures",{"id":183,"depth":205,"text":226},"10. Server-Side Request Forgery (SSRF)","Tóm tắt OWASP Top 10 (2021) — định nghĩa từng mục, ví dụ thực tế và cách khắc phục ngắn gọn; cheat-sheet tiện ôn phỏng vấn cho pentester\u002Fdev-sec.","md",{"badge":230,"tags":231,"date":233,"dateDisplay":234,"image":235},"Web Security",[232],"Web","2025-06-20","Jun 20, 2025","\u002Fthumbnails\u002Fowasp-top-ten-1000.png",true,"\u002Fposts\u002Ftop10owasp",{"title":5,"description":227},"posts\u002FTop10OWASP","tUSeET8WkeKI7qABYGwtX_T_j1f9vQwg9Y5YBwknpLY",1787385494364]