www.kbsec.com.vn
Công ty Cổ phần Chứng khoán KB Việt Nam (KBSV)
Công ty Cổ phần Chứng khoán KB Việt Nam (KBSV)
Industry
- Finance / Investing
Origin
- Vietnam
Global rank
- #506,478
Rank in Vietnam
- #8,934
en
Công ty Cổ phần Chứng khoán KB Việt Nam (KBSV)
Công ty Cổ phần Chứng khoán KB Việt Nam (KBSV)
The score and grade reflect the result recorded at scan time. Review each check and its evidence for the full context.
This report summarizes the security observations recorded for www.kbsec.com.vn at scan time. Review each check and its evidence for the full context.
At assessment time, CyStack did not find www.kbsec.com.vn or related infrastructure on any scam, phishing, or malware warning list after checking 5 online reputation sources. This result reflects external observations; it does not guarantee absolute safety or verify the organization’s legal status or reputation.
Addresses, servers and services that are visible from the Internet.
Data sources
CyStack compiles scan results from its internal cybersecurity monitoring systems, including CyStack VulnScan and CyStack Threat Intelligence, together with publicly available Internet data. The assessment only observes and analyzes information already available; it does not attempt unauthorized access, test passwords, send exploit code, or change or disrupt the assessed system.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the enterprise.
These 3 failed checks or warnings have the greatest impact on the result for www.kbsec.com.vn.
Why it matters
The Secure attribute prevents a browser from sending a cookie over unencrypted HTTP. Without it, session or authentication data may be exposed to someone observing the network.
What to do
Set Secure on every session, authentication, and other sensitive cookie served by the HTTPS application.
Evidence and check scope
Why it matters
Content Security Policy (CSP) limits where scripts, styles, frames, and other browser content may come from. A strong policy reduces the impact if an attacker manages to inject content into a page.
What to do
Define only the sources the application needs, test the policy before activating it, and avoid broad wildcard (*) rules, unsafe-inline, and unsafe-eval where possible.
Why it matters
TLS 1.0 and TLS 1.1 use outdated security designs and are no longer accepted by modern standards. Leaving them enabled allows older, weaker connection methods.
What to do
Disable TLS 1.0 and TLS 1.1, support TLS 1.2 securely, and enable TLS 1.3 where possible.
Evidence and check scope
Each public IP is grouped with its open services, identified products and any CVEs that may apply to the observed version.
Product not identified
Evidence and check scope
References
References
Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.comFancyBox is a tool for displaying images, html content and multi-media in a Mac-style 'lightbox' that floats overtop of web page.
fancyapps.com/fancyboxGoogle Analytics is a free web analytics service that tracks and reports website traffic.
google.com/analyticsGoogle Tag Manager is a tag management system (TMS) that allows you to quickly and easily update measurement codes and related code fragments collectively known as tags on your website or mobile app.
www.google.com/tagmanagerHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org/rfc/rfc6797#section-6.1Insider is the first integrated Growth Management Platform helping digital marketers drive growth across the funnel, from Acquisition to Activation, Retention, and Revenue from a unified platform powered by Artificial Intelligence and Machine Learning.
useinsider.comjQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.comASP.NET is an open-source, server-side web-application framework designed for web development to produce dynamic web pages.
www.asp.netjQuery UI is a collection of GUI widgets, animated visual effects, and themes implemented with jQuery, Cascading Style Sheets, and HTML.
jqueryui.comRecently completed assessments, prioritizing websites with a similar sector, country or security grade for easier comparison.