Đang mở báo cáo bảo mật của www.rceee2016.hust.edu.vn
www.rceee2016.hust.edu.vn
Đang tải báo cáo bảo mật của www.rceee2016.hust.edu.vn
www.rceee2016.hust.edu.vn
www.rceee2016.hust.edu.vn có an toàn không? Điểm bảo mật 58,7/100 | CyStack
www.rceee2016.hust.edu.vn
Câu lạc bộ sinh viên
Câu lạc bộ sinh viên - Detail - Sinh viên - https://hust.edu.vn/vi/sinh-vien/hoat-dong-cua-sinh-vien/cau-lac-bo-sinh-vien-654597.html
Lĩnh vực
Khoa học và Giáo dục / Giáo dục
Nguồn gốc
Việt Nam
Xếp hạng toàn cầu
#19.578
Xếp hạng tại Việt Nam
#321
Cập nhật lúc
F58,7/100
Mức an toàn
Thấp
Độ tin cậy dữ liệu
Cao
Phạm vi đã kiểm tra
92,9%
Điểm càng cao, hệ thống càng ghi nhận được nhiều biện pháp bảo vệ quan sát từ bên ngoài. Trang này không nhằm chứng nhận website uy tín, hợp pháp hay hoàn toàn không có lỗ hổng.
Trang web “www.rceee2016.hust.edu.vn” có an toàn không?
Tính đến 14:16 ngày 12/9/2026, www.rceee2016.hust.edu.vn đạt 58,7/100 điểm an toàn (đạt hạng F – “Thấp”). Hệ thống quét tự động của CyStack ghi nhận 20 vấn đề cần xem xét sau khi kiểm tra 92,9% hạng mục. Chủ sở hữu website nên ưu tiên khắc phục “Chứng thư khớp với website”, sau đó rà soát các mục còn lại theo mức độ ảnh hưởng.
Có dấu hiệu lừa đảo, phishing hoặc mã độc nào liên quan đến www.rceee2016.hust.edu.vn không?
CyStack chưa ghi nhận www.rceee2016.hust.edu.vn hay hạ tầng liên quan trong bất kỳ danh sách cảnh báo lừa đảo, phishing hoặc mã độc nào tại thời điểm quét, sau khi đối chiếu 5 nguồn danh tiếng trực tuyến. Kết quả này phản ánh quan sát từ bên ngoài, không đảm bảo website an toàn tuyệt đối và không xác nhận tư cách pháp lý hay uy tín của tổ chức.
Điều gì đang ảnh hưởng đến độ an toàn của www.rceee2016.hust.edu.vn?
Chứng thư SSL hợp lệ vẫn chưa đủ để khẳng định www.rceee2016.hust.edu.vn là website an toàn, uy tín hay không có dấu hiệu lừa đảo. Để đánh giá toàn diện hơn, báo cáo còn kiểm tra phishing và mã độc, email lộ lọt, IP và cổng mở, tên miền phụ, công nghệ cùng các CVE có thể liên quan đến phiên bản ghi nhận được.
www.rceee2016.hust.edu.vn có dùng HTTPS và chứng thư SSL còn hợp lệ không?
HTTPS của www.rceee2016.hust.edu.vn có chứng thư không hợp lệ hoặc không vượt qua bước xác minh. Người vận hành nên kiểm tra ngày hiệu lực, tên miền trên chứng thư và chuỗi tin cậy.
Email @hust.edu.vn có xuất hiện trong dữ liệu lộ lọt hoặc nhật ký của phần mềm đánh cắp thông tin (infostealer) không?
Nguồn dữ liệu
Dữ liệu được tổng hợp từ các hệ thống giám sát an ninh mạng của CyStack
CyStack tổng hợp kết quả quét từ các hệ thống giám sát an ninh mạng nội bộ, bao gồm CyStack VulnScan và CyStack Threat Intelligence, cùng các nguồn dữ liệu công khai trên Internet. Quá trình đánh giá chỉ quan sát và phân tích thông tin sẵn có, không đăng nhập trái phép, thử mật khẩu, gửi mã khai thác hay làm thay đổi, gián đoạn hệ thống được đánh giá.
Có 3 tiêu chí không đạt hoặc cảnh báo có ảnh hưởng lớn nhất tới kết quả của www.rceee2016.hust.edu.vn.
Chứng thư khớp với websiteChứng thư không khớp với mục tiêu được yêu cầu.Nghiêm trọng
Vì sao cần quan tâm
Chứng thư phải liệt kê chính xác tên miền người dùng truy cập trong trường Subject Alternative Names (SAN). Nếu không khớp, trình duyệt sẽ cảnh báo vì chứng thư có thể thuộc về một dịch vụ khác.
Nên làm gì
Cấp và triển khai chứng thư có danh sách SAN bao gồm mọi tên miền công khai được địa chỉ website này phục vụ.
Thông tin chẩn đoán
Bằng chứng chứng thư hiện có chưa đủ để kết luận yêu cầu chứng thư này.
Chứng thư được trình duyệt tin cậyKhông thể xác thực chuỗi chứng thư tới gốc đáng tin cậy trong kho tin cậy của trình quét.Nghiêm trọng
Vì sao cần quan tâm
Trình duyệt chỉ tin cậy website khi chứng thư có thể được xác minh tới một nhà cung cấp được công nhận. Chứng thư không đáng tin cậy gây cảnh báo và khiến người dùng không thể xác nhận chắc chắn danh tính website.
Nên làm gì
Cài chứng thư từ nhà cung cấp được các trình duyệt phổ biến tin cậy và cấu hình máy chủ gửi đầy đủ các chứng thư trung gian cần thiết.
Mức độ công khai của dịch vụ quản trịPhát hiện dịch vụ quản trị công khai đã được xác nhận qua phản hồi dịch vụ: 166.62.10.47:22 (ssh).Cao
Vì sao cần quan tâm
Dịch vụ quản trị từ xa như RDP, VNC, Docker, Kubernetes và bảng điều khiển là mục tiêu có giá trị cao. Khi mở công khai, bất kỳ ai trên Internet cũng có thể thử mật khẩu hoặc khai thác dịch vụ chưa được vá.
Nên làm gì
Loại bỏ truy cập trực tiếp từ Internet và yêu cầu VPN, cổng truy cập được bảo vệ chặt hoặc mạng nguồn tin cậy; đồng thời bật MFA khi dịch vụ hỗ trợ.
Hệ điều hành
Hạ tầng công khai và phần mềm có thể quan sát
Mỗi địa chỉ IP công khai được nhóm cùng dịch vụ đang mở, sản phẩm đã nhận diện và các CVE có khả năng liên quan đến phiên bản quan sát được.
58 cổng tcp đã thử · Hoàn tất
166.62.10.4747.10.62.166.host.secureserver.net
12 dịch vụ đang mở8 sản phẩm đã nhận diện
Nhà cung cấp hạ tầng hoặc mạngChưa xác định được nhà cung cấp
Vị trí mạng—
ASN—
21FtpPPure Ftpd
Sản phẩmPhiên bảnLỗ hổng có thể liên quan
PPure FtpdChưa thấy phiên bảnChưa thấy phiên bản
Công nghệ khác quan sát được ở cấp websiteCác sản phẩm này được quan sát từ website công khai, nhưng chưa có đủ bằng chứng để gắn an toàn với một địa chỉ IP và cổng cụ thể.
DDovecotChưa thấy phiên bảnChưa thấy phiên bản
Độ tin cậyThấp
Hiện ghi nhận 563 bản ghi email lộ lọt khớp tên miền hust.edu.vn. Các bản ghi này có thể đã cũ hoặc đã được xử lý. Chủ sở hữu website nên xác minh trước khi đổi mật khẩu hoặc khóa các tài khoản liên quan.
www.rceee2016.hust.edu.vn đang công khai những IP, dịch vụ và cổng nào?
Ghi nhận được 1 IP công khai và 12 cổng đang mở của www.rceee2016.hust.edu.vn. Cổng mở không tương đương với việc có lỗ hổng, nhưng chủ sở hữu website nên cập nhật thường xuyên và giới hạn truy cập cho từng dịch vụ công khai.
Đã phát hiện được bao nhiêu tên miền phụ của hust.edu.vn?
Ghi nhận 465+ tên miền phụ công khai của hust.edu.vn. Danh sách này giúp nhận biết thêm các cổng vào như API, hệ thống quản trị hay môi trường thử nghiệm, nhưng không có nghĩa tên miền phụ nào cũng có rủi ro.
Bằng chứng chứng thư hiện có chưa đủ để kết luận yêu cầu chứng thư này.
Bằng chứng và phạm vi kiểm tra
Đơn vị cấp chứng thư:
CN=accomplicemediakraft.com
Host được yêu cầu:
www.rceee2016.hust.edu.vn
Địa chỉ IP đã thử kết nối:
166.62.10.47
Địa chỉ IP trả về kết quả quan sát:
166.62.10.47
Bằng chứng và phạm vi kiểm tra
Hoàn tất:
Có
Các cổng đã kiểm tra:
21, 22, 23, 25, 53, 80, 110, 111, 139, 143… và 48 giá trị khác
Dịch vụ mở phù hợp:
166.62.10.47:22 — ssh OpenSSH 8.0
Số dịch vụ được chọn để nhận diện:
12
Số dịch vụ đã nhận diện:
11
Đã hoàn tất nhận diện dịch vụ:
Không
Định danh CPEcpe:2.3:a:pureftpd:pure-ftpd:*:*:*:*:*:*:*:*
Độ tin cậyTrung bình
22SshOOpenssh26 CVE có thể liên quan
Sản phẩmPhiên bảnLỗ hổng có thể liên quan
OOpenssh8.08.026 CVE có thể liên quanCVSS 9,8
Định danh CPEcpe:2.3:a:openbsd:openssh:8.0:*:*:*:*:*:*:*
Độ tin cậyCao
CVE tiềm năng của sản phẩm này
CVE-2023-38408OpenSSH 8.0CVSS 9,8
Sản phẩm đối chiếu: OpenSSH 8.0 Độ tin cậy: Cao
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.
465SmtpCổng này thường sử dụng TLSChưa nhận diện được sản phẩm
Chưa nhận diện được sản phẩm
587SmtpChưa nhận diện được sản phẩm
Chưa nhận diện được sản phẩm
993ImapsĐã xác minh TLSChưa nhận diện được sản phẩm
Chưa nhận diện được sản phẩm
995Pop3Đã xác minh TLSDDovecot
Sản phẩmPhiên bảnLỗ hổng có thể liên quan
DDovecotChưa thấy phiên bảnChưa thấy phiên bản
Độ tin cậyThấp
3306MysqlMMariadb1 CVE có thể liên quan
Sản phẩmPhiên bảnLỗ hổng có thể liên quan
MMariadb10.11.1810.11.181 CVE có thể liên quanCVSS 6,5
Định danh CPEcpe:2.3:a:mariadb:mariadb:10.11.18:*:*:*:*:*:*:*
Độ tin cậyCao
CVE tiềm năng của sản phẩm này
CVE-2026-35549MariaDB 10.11.18CVSS 6,5
Sản phẩm đối chiếu: MariaDB 10.11.18 Độ tin cậy: Cao
An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. If the caching_sha2_password authentication plugin is installed, and some user accounts are configured to use it, a large packet can crash the server because sha256_crypt_r uses alloca.
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).
OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.
OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This leads to memory corruption and local code execution because of an error in the XMSS key parsing algorithm. NOTE: the XMSS implementation is considered experimental in all released OpenSSH versions, and there is no supported way to enable it when building portable OpenSSH.
sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user.
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.
In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.
OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms.
sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6 are also affected.
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305@openssh.com and (if CBC is used) the -etm@openssh.com MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before 1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230101, trilead-ssh2 6401, LANCOM LCOS and LANconfig, FileZilla before 3.66.4, Nova before 11.8, PKIX-SSH before 14.4, SecureCRT before 9.4.3, Transmit5 before 5.10.4, Win32-OpenSSH before 9.5.0.0p1-Beta, WinSCP before 6.2.2, Bitvise SSH Server before 9.32, Bitvise SSH Client before 9.33, KiTTY through 0.76.1.13, the net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for Node.js, the thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust.
sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.
OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product
In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.
An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=verbose, and an attacker has silently modified the server to support the None authentication option, then the user cannot determine whether FIDO authentication is going to confirm that the user wishes to connect to that server, or that the user wishes to allow that server to connect to a different server on the user's behalf. NOTE: the vendor's position is "this is not an authentication bypass, since nothing is being bypassed.
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.
Hệ thống tìm thấy 26 kết quả tiềm năng cho sản phẩm này, nhưng báo cáo chỉ lưu một phần chi tiết đại diện.
CVE-2024-3566PHP 7.4.33CVSS 9,8
Sản phẩm đối chiếu: PHP 7.4.33 Độ tin cậy: Trung bình
A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.
Sản phẩm đối chiếu: PHP 7.4.33 Độ tin cậy: Trung bình
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.