Đang mở báo cáo bảo mật của www.calbandalumni.berkeley.edu
www.calbandalumni.berkeley.edu
Đang tải báo cáo bảo mật của www.calbandalumni.berkeley.edu
www.calbandalumni.berkeley.edu
www.calbandalumni.berkeley.edu có an toàn không? Điểm bảo mật 69,7/100 | CyStack
www.calbandalumni.berkeley.edu
Cal Band Alumni Association
This is the Home Page of the Cal Band Alumni Association. The Cal Band Alumni Association (CBAA) is an organization made up principally of former members of the University of California Marching Band. It is dedicated to furthering the interests of the Cal Band and encouraging fellowship among its me
Lĩnh vực
Khoa học và Giáo dục / Đại học và Cao đẳng
Nguồn gốc
Hoa Kỳ
Xếp hạng toàn cầu
#3.455
Xếp hạng tại Hoa Kỳ
#846
Cập nhật lúc
D69,7/100
Mức an toàn
Cần cải thiện
Độ tin cậy dữ liệu
Cao
Phạm vi đã kiểm tra
94,5%
Điểm càng cao, hệ thống càng ghi nhận được nhiều biện pháp bảo vệ quan sát từ bên ngoài. Trang này không nhằm chứng nhận website uy tín, hợp pháp hay hoàn toàn không có lỗ hổng.
Trang web “www.calbandalumni.berkeley.edu” có an toàn không?
Tính đến 00:15 ngày 9/9/2026, www.calbandalumni.berkeley.edu đạt 69,7/100 điểm an toàn (đạt hạng D: “Cần cải thiện”). Hệ thống quét tự động của CyStack ghi nhận 16 vấn đề cần xem xét sau khi kiểm tra 94,5% hạng mục. Chủ sở hữu website nên ưu tiên khắc phục “Mức độ công khai của dịch vụ quản trị”, sau đó rà soát các mục còn lại theo mức độ ảnh hưởng.
Có dấu hiệu lừa đảo, phishing hoặc mã độc nào liên quan đến www.calbandalumni.berkeley.edu không?
CyStack chưa ghi nhận www.calbandalumni.berkeley.edu hay hạ tầng liên quan trong bất kỳ danh sách cảnh báo lừa đảo, phishing hoặc mã độc nào tại thời điểm quét, sau khi đối chiếu 5 nguồn danh tiếng trực tuyến. Kết quả này phản ánh quan sát từ bên ngoài, không đảm bảo website an toàn tuyệt đối và không xác nhận tư cách pháp lý hay uy tín của tổ chức.
Điều gì đang ảnh hưởng đến độ an toàn của www.calbandalumni.berkeley.edu?
Chứng thư SSL hợp lệ vẫn chưa đủ để khẳng định www.calbandalumni.berkeley.edu là website an toàn, uy tín hay không có dấu hiệu lừa đảo. Để đánh giá toàn diện hơn, báo cáo còn kiểm tra phishing và mã độc, email lộ lọt, IP và cổng mở, tên miền phụ, công nghệ cùng các CVE có thể liên quan đến phiên bản ghi nhận được.
www.calbandalumni.berkeley.edu có dùng HTTPS và chứng thư SSL còn hợp lệ không?
www.calbandalumni.berkeley.edu đang dùng chứng thư SSL hợp lệ tại thời điểm đánh giá, có hiệu lực đến ngày 26 tháng 10, 2026. Trạng thái này có thể thay đổi khi chứng thư hết hạn hoặc máy chủ đổi cấu hình.
Dữ liệu được tổng hợp từ các hệ thống giám sát an ninh mạng của CyStack
CyStack tổng hợp kết quả quét từ các hệ thống giám sát an ninh mạng nội bộ, bao gồm CyStack VulnScan và CyStack Threat Intelligence, cùng các nguồn dữ liệu công khai trên Internet. Quá trình đánh giá chỉ quan sát và phân tích thông tin sẵn có, không đăng nhập trái phép, thử mật khẩu, gửi mã khai thác hay làm thay đổi, gián đoạn hệ thống được đánh giá.
Có 3 tiêu chí không đạt hoặc cảnh báo có ảnh hưởng lớn nhất tới kết quả của www.calbandalumni.berkeley.edu.
Mức độ công khai của dịch vụ quản trịPhát hiện dịch vụ quản trị công khai đã được xác nhận qua phản hồi dịch vụ: 67.205.5.50:22 (ssh).Cao
Vì sao cần quan tâm
Dịch vụ quản trị từ xa như RDP, VNC, Docker, Kubernetes và bảng điều khiển là mục tiêu có giá trị cao. Khi mở công khai, bất kỳ ai trên Internet cũng có thể thử mật khẩu hoặc khai thác dịch vụ chưa được vá.
Nên làm gì
Loại bỏ truy cập trực tiếp từ Internet và yêu cầu VPN, cổng truy cập được bảo vệ chặt hoặc mạng nguồn tin cậy; đồng thời bật MFA khi dịch vụ hỗ trợ.
Bằng chứng và phạm vi kiểm tra
Hoàn tất:
Có
Các cổng đã kiểm tra:
21, 22, 23, 25, 53, 80, 110, 111, 139, 143… và 48 giá trị khác
Dịch vụ mở phù hợp:
67.205.5.50:22, ssh OpenSSH 9.6p1
Số dịch vụ được chọn để nhận diện:
5
Số dịch vụ đã nhận diện:
5
Đã hoàn tất nhận diện dịch vụ:
Không
Dịch vụ cũ không mã hóaPhát hiện dịch vụ plaintext lỗi thời công khai đã được xác nhận qua phản hồi dịch vụ: 67.205.5.50:21 (ftp).Cao
Vì sao cần quan tâm
Các dịch vụ cũ như Telnet, FTP và giao thức email hoặc thư mục không mã hóa có thể gửi mật khẩu, dữ liệu ở dạng đọc được. Bên quan sát đường truyền có thể thu thập các thông tin này.
Nên làm gì
Tắt dịch vụ cũ hoặc thay bằng lựa chọn có mã hóa như SSH, SFTP, HTTPS hay phiên bản bảo mật của giao thức email.
Cookie phiên được bảo vệ khỏi script (HttpOnly)Có 1/1 cookie giống cookie phiên quan sát được trên phản hồi trang gốc không dùng HttpOnly.Cao
Vì sao cần quan tâm
HttpOnly ngăn script trong trình duyệt đọc trực tiếp cookie. Thuộc tính này không khắc phục lỗi chèn script nhưng khiến việc đánh cắp cookie phiên và xác thực khó hơn.
Nên làm gì
Đặt HttpOnly cho cookie phiên và xác thực, trừ khi ứng dụng có nhu cầu rõ ràng và được ghi nhận để đọc chúng bằng mã trong trình duyệt.
Nhà cung cấp hạ tầng hoặc mạngChưa xác định được nhà cung cấp
Vị trí mạng–
ASN–
21FtpChưa nhận diện được sản phẩm
Chưa nhận diện được sản phẩm
22SshOpenssh18 CVE có thể liên quan
Email @berkeley.edu có xuất hiện trong dữ liệu lộ lọt hoặc nhật ký của phần mềm đánh cắp thông tin (infostealer) không?
Hiện ghi nhận 1.743 bản ghi email lộ lọt khớp tên miền berkeley.edu. Các bản ghi này có thể đã cũ hoặc đã được xử lý. Chủ sở hữu website nên xác minh trước khi đổi mật khẩu hoặc khóa các tài khoản liên quan.
www.calbandalumni.berkeley.edu dùng công nghệ nào và có CVE (lỗ hổng bảo mật) nào có khả năng liên quan?
Đã nhận diện 18 công nghệ trên www.calbandalumni.berkeley.edu. Trong đó chỉ 5 công nghệ xác định được phiên bản đủ tin cậy để đối chiếu chính xác với CVE.
www.calbandalumni.berkeley.edu đang công khai những IP, dịch vụ và cổng nào?
Ghi nhận được 1 IP công khai và 5 cổng đang mở của www.calbandalumni.berkeley.edu. Cổng mở không tương đương với việc có lỗ hổng, nhưng chủ sở hữu website nên cập nhật thường xuyên và giới hạn truy cập cho từng dịch vụ công khai.
Đã phát hiện được bao nhiêu tên miền phụ của berkeley.edu?
Ghi nhận 993+ tên miền phụ công khai của berkeley.edu. Danh sách này giúp nhận biết thêm các cổng vào như API, hệ thống quản trị hay môi trường thử nghiệm, nhưng không có nghĩa tên miền phụ nào cũng có rủi ro.
21, 22, 23, 25, 53, 80, 110, 111, 139, 143… và 48 giá trị khác
Dịch vụ mở phù hợp:
67.205.5.50:21, ftp
Số dịch vụ được chọn để nhận diện:
5
Số dịch vụ đã nhận diện:
5
Đã hoàn tất nhận diện dịch vụ:
Không
Phạm vi của tiêu chí
Tiêu chí này chỉ đánh giá phản hồi và nội dung của trang chủ mà hệ thống truy cập được; các trang hoặc luồng đăng nhập khác có thể có cấu hình khác.
Bằng chứng và phạm vi kiểm tra
Cookie có dấu hiệu phiên đăng nhập:
1
Cookie phiên có thuộc tính HttpOnly:
0
Phản hồi đã kiểm tra:
Phản hồi trang chủ
Host được yêu cầu:
www.calbandalumni.berkeley.edu
Host quan sát được:
calbandalumni.berkeley.edu
Sản phẩmPhiên bảnLỗ hổng có thể liên quan
Openssh9.6p19.6p118 CVE có thể liên quanCVSS 9,4
Định danh CPEcpe:2.3:a:openbsd:openssh:9.6p1:*:*:*:*:*:*:*
Độ tin cậyCao
CVE tiềm năng của sản phẩm này
CVE-2026-60002OpenSSH 9.6p1CVSS 9,4
Sản phẩm đối chiếu: OpenSSH 9.6p1 Độ tin cậy: Cao
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).
OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.
sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.
OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms.
sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.
In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.
Định danh CPEcpe:2.3:a:apache:http_server:-:*:*:*:*:*:*:*
Độ tin cậyTrung bình
443HTTPSĐã xác minh TLSWordPressApache HTTP Servercdnjs+135 CVE có thể liên quan
Sản phẩmPhiên bảnLỗ hổng có thể liên quan
WordPress6.2.2Blogs · CMS6.2.25 CVE có thể liên quanCVSS 8,8
Định danh CPEcpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*
Độ tin cậyTrung bình
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.
Sản phẩm đối chiếu: WordPress 6.2.2 Độ tin cậy: Trung bình
WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted as a new plugin by an administrative user on the Plugins -> Add New -> Upload Plugin screen in WordPress. If FTP credentials are requested for installation (in order to move the file into place outside of the `uploads` directory) then the uploaded file remains temporary available in the Media Library despite it not being allowed. If the `DISALLOW_FILE_EDIT` constant is set to `true` on the site _and_ FTP credentials are required when uploading a new theme or plugin, then this technically allows an RCE when the user would otherwise have no means of executing arbitrary PHP code. This issue _only_ affects Administrator level users on single site installations, and Super Admin level users on Multisite installations where it's otherwise expected that the user does not have permission to upload or execute arbitrary PHP code. Lower level users are not affected. Sites where the `DISALLOW_FILE_MODS` constant is set to `true` are not affected. Sites where an administrative user either does not need to enter FTP credentials or they have access to the valid FTP credentials, are not affected. The issue was fixed in WordPress 6.4.3 on January 30, 2024 and backported to versions 6.3.3, 6.2.4, 6.1.5, 6.0.7, 5.9.9, 5.8.9, 5.7.11, 5.6.13, 5.5.14, 5.4.15, 5.3.17, 5.2.20, 5.1.18, 5.0.21, 4.9.25, 2.8.24, 4.7.28, 4.6.28, 4.5.31, 4.4.32, 4.3.33, 4.2.37, and 4.1.40. A workaround is available. If the `DISALLOW_FILE_MODS` constant is defined as `true` then it will not be possible for any user to upload a plugin and therefore this issue will not be exploitable.
Sản phẩm đối chiếu: WordPress 6.2.2 Độ tin cậy: Trung bình
WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due to insufficient output escaping on the display name. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. In addition, it also makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that have the comment block present and display the comment author's avatar.
Sản phẩm đối chiếu: WordPress 6.2.2 Độ tin cậy: Trung bình
Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.1.3, from 6.0 through 6.0.5, from 5.9 through 5.9.7 and Gutenberg plugin <= 16.8.0 versions.
Sản phẩm đối chiếu: WordPress 6.2.2 Độ tin cậy: Trung bình
WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack
Sản phẩm đối chiếu: WordPress 6.2.2 Độ tin cậy: Trung bình
Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9, from 5.6 through 5.6.11, from 5.5 through 5.5.12, from 5.4 through 5.4.13, from 5.3 through 5.3.15, from 5.2 through 5.2.18, from 5.1 through 5.1.16, from 5.0 through 5.0.19, from 4.9 through 4.9.23, from 4.8 through 4.8.22, from 4.7 through 4.7.26, from 4.6 through 4.6.26, from 4.5 through 4.5.29, from 4.4 through 4.4.30, from 4.3 through 4.3.31, from 4.2 through 4.2.35, from 4.1 through 4.1.38.
CloudflareChưa thấy phiên bảnCDNChưa thấy phiên bản
Độ tin cậyTrung bình
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
DataTablesChưa thấy phiên bảnJavaScript LibrariesChưa thấy phiên bản
Định danh CPEcpe:2.3:a:datatables:datatables.net:*:*:*:*:*:*:*:*
Độ tin cậyTrung bình
DataTables is a plug-in for the jQuery Javascript library adding advanced features like pagination, instant search, themes, and more to any HTML table.
jQueryChưa thấy phiên bảnJavaScript LibrariesChưa thấy phiên bản
Định danh CPEcpe:2.3:a:jquery:jquery:*:*:*:*:*:*:*:*
Độ tin cậyTrung bình
jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
Query Migrate is a javascript library that allows you to preserve the compatibility of your jQuery code developed for versions of jQuery older than 1.9.