fui.vn
Xây dựng ứng dụng web nhanh và hiệu quả | FastProject
Xây dựng ứng dụng web nhanh và hiệu quả.
Industry
- —
Origin
- —
Global rank
- —
Rank in
- —
en
Xây dựng ứng dụng web nhanh và hiệu quả | FastProject
Xây dựng ứng dụng web nhanh và hiệu quả.
The score and grade reflect the result recorded at scan time. Review each check and its evidence for the full context.
This report summarizes the security observations recorded for fui.vn at scan time. Review each check and its evidence for the full context.
At assessment time, CyStack did not find fui.vn or related infrastructure on any scam, phishing, or malware warning list after checking 5 online reputation sources. This result reflects external observations; it does not guarantee absolute safety or verify the organization’s legal status or reputation.
Addresses, servers and services that are visible from the Internet.
Data sources
CyStack compiles scan results from its internal cybersecurity monitoring systems, including CyStack VulnScan and CyStack Threat Intelligence, together with publicly available Internet data. The assessment only observes and analyzes information already available; it does not attempt unauthorized access, test passwords, send exploit code, or change or disrupt the assessed system.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the enterprise.
These 3 failed checks or warnings have the greatest impact on the result for fui.vn.
Why it matters
The Secure attribute prevents a browser from sending a cookie over unencrypted HTTP. Without it, session or authentication data may be exposed to someone observing the network.
What to do
Set Secure on every session, authentication, and other sensitive cookie served by the HTTPS application.
Evidence and check scope
Why it matters
Content Security Policy (CSP) limits where scripts, styles, frames, and other browser content may come from. A strong policy reduces the impact if an attacker manages to inject content into a page.
What to do
Define only the sources the application needs, test the policy before activating it, and avoid broad wildcard (*) rules, unsafe-inline, and unsafe-eval where possible.
Why it matters
TLS 1.0 and TLS 1.1 use outdated security designs and are no longer accepted by modern standards. Leaving them enabled allows older, weaker connection methods.
What to do
Disable TLS 1.0 and TLS 1.1, support TLS 1.2 securely, and enable TLS 1.3 where possible.
Evidence and check scope
Each public IP is grouped with its open services, identified products and any CVEs that may apply to the observed version.
Evidence and check scope
References
References
Internet Information Services (IIS) is an extensible web server software created by Microsoft for use with the Windows NT family.
www.iis.netJSDelivr is a free public CDN for open-source projects. It can serve web files directly from the npm registry and GitHub repositories without any configuration.
www.jsdelivr.comLottieFiles is an open-source animation file format that's tiny, high quality, interactive, and can be manipulated at runtime.
lottiefiles.comUnpkg is a content delivery network for everything on npm.
unpkg.comWindows Server is a brand name for a group of server operating systems.
microsoft.com/windowsserverBootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.comInternet Information Services (IIS) is an extensible web server software created by Microsoft for use with the Windows NT family.
www.iis.netASP.NET is an open-source, server-side web-application framework designed for web development to produce dynamic web pages.
www.asp.netRecently completed assessments, prioritizing websites with a similar sector, country or security grade for easier comparison.