{"id":477284,"date":"2023-08-09T09:10:23","date_gmt":"2023-08-09T09:10:23","guid":{"rendered":""},"modified":"2023-09-05T11:14:25","modified_gmt":"2023-09-05T11:14:25","slug":"formjacking","status":"publish","type":"wiki","link":"https:\/\/oneproxy.pro\/vn\/wiki\/formjacking\/","title":{"rendered":"\u0110\u1ecbnh h\u00ecnh"},"content":{"rendered":"<p>Formjacking l\u00e0 m\u1ed9t cu\u1ed9c t\u1ea5n c\u00f4ng m\u1ea1ng tinh vi li\u00ean quan \u0111\u1ebfn vi\u1ec7c tr\u00edch xu\u1ea5t tr\u00e1i ph\u00e9p d\u1eef li\u1ec7u nh\u1ea1y c\u1ea3m t\u1eeb c\u00e1c bi\u1ec3u m\u1eabu web tr\u00ean c\u00e1c trang web. N\u00f3 nh\u1eafm m\u1ee5c ti\u00eau v\u00e0o c\u00e1c n\u1ec1n t\u1ea3ng th\u01b0\u01a1ng m\u1ea1i \u0111i\u1ec7n t\u1eed v\u00e0 c\u00e1c trang web kh\u00e1c thu th\u1eadp th\u00f4ng tin c\u00e1 nh\u00e2n v\u00e0 t\u00e0i ch\u00ednh t\u1eeb ng\u01b0\u1eddi d\u00f9ng. H\u00ecnh th\u1ee9c tr\u1ed9m c\u1eafp k\u1ef9 thu\u1eadt s\u1ed1 x\u1ea3o quy\u1ec7t n\u00e0y \u0111\u00e3 thu h\u00fat \u0111\u01b0\u1ee3c s\u1ef1 ch\u00fa \u00fd c\u1ee7a t\u1ed9i ph\u1ea1m m\u1ea1ng do ti\u1ec1m n\u0103ng thu \u0111\u01b0\u1ee3c l\u1ee3i nhu\u1eadn t\u00e0i ch\u00ednh \u0111\u00e1ng k\u1ec3 v\u00e0 kh\u00f3 ph\u00e1t hi\u1ec7n. Trong b\u00e0i vi\u1ebft n\u00e0y, ch\u00fang t\u00f4i s\u1ebd \u0111i s\u00e2u v\u00e0o l\u1ecbch s\u1eed, ho\u1ea1t \u0111\u1ed9ng, lo\u1ea1i h\u00ecnh v\u00e0 tri\u1ec3n v\u1ecdng trong t\u01b0\u01a1ng lai c\u1ee7a Formjacking, c\u00f9ng v\u1edbi s\u1ef1 li\u00ean k\u1ebft c\u1ee7a n\u00f3 v\u1edbi c\u00e1c m\u00e1y ch\u1ee7 proxy.<\/p>\n<h2>L\u1ecbch s\u1eed ngu\u1ed3n g\u1ed1c c\u1ee7a Formjacking v\u00e0 l\u1ea7n \u0111\u1ea7u ti\u00ean \u0111\u1ec1 c\u1eadp \u0111\u1ebfn n\u00f3<\/h2>\n<p>Formjacking l\u1ea7n \u0111\u1ea7u ti\u00ean \u0111\u01b0\u1ee3c ch\u00fa \u00fd v\u00e0o kho\u1ea3ng n\u0103m 2018 khi n\u00f3 \u1ea3nh h\u01b0\u1edfng \u0111\u1ebfn m\u1ed9t s\u1ed1 trang web n\u1ed5i ti\u1ebfng. Tuy nhi\u00ean, ngu\u1ed3n g\u1ed1c c\u1ee7a n\u00f3 c\u00f3 th\u1ec3 b\u1eaft ngu\u1ed3n t\u1eeb c\u00e1c k\u1ef9 thu\u1eadt tr\u01b0\u1edbc \u0111\u00f3 nh\u01b0 ghi nh\u1eadt k\u00fd b\u00e0n ph\u00edm v\u00e0 \u0111\u1ecdc l\u01b0\u1edbt th\u1ebb t\u00edn d\u1ee5ng. Tr\u01b0\u1eddng h\u1ee3p Formjacking \u0111\u01b0\u1ee3c ghi nh\u1eadn \u0111\u1ea7u ti\u00ean c\u00f3 th\u1ec3 \u0111\u01b0\u1ee3c quy cho nh\u00f3m Magecart, m\u1ed9t t\u1eadp th\u1ec3 t\u1ed9i ph\u1ea1m m\u1ea1ng kh\u00e9t ti\u1ebfng ch\u1ecbu tr\u00e1ch nhi\u1ec7m v\u1ec1 nhi\u1ec1u v\u1ee5 vi ph\u1ea1m d\u1eef li\u1ec7u b\u1eb1ng c\u00e1ch ti\u00eam m\u00e3 \u0111\u1ed9c v\u00e0o c\u00e1c trang web th\u01b0\u01a1ng m\u1ea1i \u0111i\u1ec7n t\u1eed.<\/p>\n<h2>Th\u00f4ng tin chi ti\u1ebft v\u1ec1 Formjacking<\/h2>\n<p>Formjacking l\u00e0 m\u1ed9t k\u1ef9 thu\u1eadt \u0111\u1ed9c h\u1ea1i th\u01b0\u1eddng li\u00ean quan \u0111\u1ebfn vi\u1ec7c ch\u00e8n m\u00e3 JavaScript \u0111\u1ed9c h\u1ea1i v\u00e0o trang thanh to\u00e1n c\u1ee7a trang web. M\u00e3 n\u00e0y ho\u1ea1t \u0111\u1ed9ng l\u00e9n l\u00fat, ch\u1eb7n v\u00e0 \u0111\u00e1nh c\u1eafp th\u00f4ng tin do ng\u01b0\u1eddi d\u00f9ng g\u1eedi, ch\u1eb3ng h\u1ea1n nh\u01b0 chi ti\u1ebft th\u1ebb t\u00edn d\u1ee5ng, m\u1eadt kh\u1ea9u, t\u00ean, \u0111\u1ecba ch\u1ec9, v.v. m\u00e0 ng\u01b0\u1eddi d\u00f9ng kh\u00f4ng bi\u1ebft ho\u1eb7c kh\u00f4ng \u0111\u1ed3ng \u00fd. D\u1eef li\u1ec7u b\u1ecb \u0111\u00e1nh c\u1eafp sau \u0111\u00f3 s\u1ebd \u0111\u01b0\u1ee3c truy\u1ec1n \u0111\u1ebfn m\u00e1y ch\u1ee7 c\u1ee7a k\u1ebb t\u1ea5n c\u00f4ng, n\u01a1i d\u1eef li\u1ec7u c\u00f3 th\u1ec3 \u0111\u01b0\u1ee3c s\u1eed d\u1ee5ng \u0111\u1ec3 \u0111\u00e1nh c\u1eafp danh t\u00ednh, gian l\u1eadn t\u00e0i ch\u00ednh ho\u1eb7c b\u00e1n tr\u00ean web \u0111en.<\/p>\n<h2>C\u1ea5u tr\u00fac b\u00ean trong c\u1ee7a Formjacking: Formjacking ho\u1ea1t \u0111\u1ed9ng nh\u01b0 th\u1ebf n\u00e0o<\/h2>\n<p>Formjacking ho\u1ea1t \u0111\u1ed9ng l\u00e9n l\u00fat, khi\u1ebfn vi\u1ec7c ph\u00e1t hi\u1ec7n tr\u1edf n\u00ean kh\u00f3 kh\u0103n. C\u00e1c b\u01b0\u1edbc ch\u00ednh li\u00ean quan \u0111\u1ebfn m\u1ed9t cu\u1ed9c t\u1ea5n c\u00f4ng Formjacking \u0111i\u1ec3n h\u00ecnh nh\u01b0 sau:<\/p>\n<ol>\n<li>\n<p><strong>M\u0169i ti\u00eam<\/strong>: K\u1ebb t\u1ea5n c\u00f4ng ch\u00e8n m\u00e3 JavaScript \u0111\u1ed9c h\u1ea1i v\u00e0o trang thanh to\u00e1n c\u1ee7a trang web m\u1ee5c ti\u00eau ho\u1eb7c c\u00e1c h\u00ecnh th\u1ee9c quan tr\u1ecdng kh\u00e1c.<\/p>\n<\/li>\n<li>\n<p><strong>Thu th\u1eadp d\u1eef li\u1ec7u<\/strong>: Khi ng\u01b0\u1eddi d\u00f9ng g\u1eedi th\u00f4ng tin c\u1ee7a h\u1ecd th\u00f4ng qua bi\u1ec3u m\u1eabu b\u1ecb x\u00e2m ph\u1ea1m, m\u00e3 \u0111\u01b0\u1ee3c ch\u00e8n s\u1ebd thu th\u1eadp d\u1eef li\u1ec7u tr\u01b0\u1edbc khi g\u1eedi \u0111\u1ebfn m\u00e1y ch\u1ee7 c\u1ee7a trang web.<\/p>\n<\/li>\n<li>\n<p><strong>Truy\u1ec1n d\u1eef li\u1ec7u<\/strong>: D\u1eef li\u1ec7u b\u1ecb \u0111\u00e1nh c\u1eafp \u0111\u01b0\u1ee3c g\u1eedi \u0111\u1ebfn m\u1ed9t m\u00e1y ch\u1ee7 t\u1eeb xa do k\u1ebb t\u1ea5n c\u00f4ng ki\u1ec3m so\u00e1t, n\u01a1i d\u1eef li\u1ec7u c\u00f3 th\u1ec3 b\u1ecb truy c\u1eadp v\u00e0 s\u1eed d\u1ee5ng sai m\u1ee5c \u0111\u00edch.<\/p>\n<\/li>\n<li>\n<p><strong>B\u00e0i h\u00e1t che ph\u1ee7<\/strong>: \u0110\u1ec3 tr\u00e1nh b\u1ecb ph\u00e1t hi\u1ec7n, k\u1ebb t\u1ea5n c\u00f4ng c\u00f3 th\u1ec3 s\u1eed d\u1ee5ng m\u00e3 h\u00f3a v\u00e0 c\u00e1c k\u1ef9 thu\u1eadt che gi\u1ea5u kh\u00e1c nhau \u0111\u1ec3 \u1ea9n m\u00e3 v\u00e0 d\u1eef li\u1ec7u b\u1ecb \u0111\u00e1nh c\u1eafp.<\/p>\n<\/li>\n<\/ol>\n<h2>Ph\u00e2n t\u00edch c\u00e1c t\u00ednh n\u0103ng ch\u00ednh c\u1ee7a Formjacking<\/h2>\n<p>Formjacking th\u1ec3 hi\u1ec7n m\u1ed9t s\u1ed1 t\u00ednh n\u0103ng ch\u00ednh khi\u1ebfn n\u00f3 tr\u1edf th\u00e0nh m\u1ed1i \u0111e d\u1ecda ti\u1ec1m t\u00e0ng:<\/p>\n<ol>\n<li>\n<p><strong>T\u1ea5n c\u00f4ng ng\u1ee5y trang<\/strong>: C\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng Formjacking h\u00f2a tr\u1ed9n v\u1edbi trang web h\u1ee3p ph\u00e1p, khi\u1ebfn c\u1ea3 ng\u01b0\u1eddi d\u00f9ng v\u00e0 qu\u1ea3n tr\u1ecb vi\u00ean trang web kh\u00f3 ph\u00e1t hi\u1ec7n.<\/p>\n<\/li>\n<li>\n<p><strong>Ph\u1ea1m vi to\u00e0n c\u1ea7u<\/strong>: V\u00ec Formjacking nh\u1eafm m\u1ee5c ti\u00eau v\u00e0o c\u00e1c trang web thu h\u00fat l\u01b0\u1ee3ng l\u1edbn ng\u01b0\u1eddi d\u00f9ng n\u00ean m\u1ed9t cu\u1ed9c t\u1ea5n c\u00f4ng duy nh\u1ea5t c\u00f3 th\u1ec3 mang l\u1ea1i m\u1ed9t l\u01b0\u1ee3ng l\u1edbn d\u1eef li\u1ec7u b\u1ecb \u0111\u00e1nh c\u1eafp.<\/p>\n<\/li>\n<li>\n<p><strong>Ti\u1ebfp t\u1ee5c \u0111e d\u1ecda<\/strong>: C\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng Formjacking c\u00f3 th\u1ec3 t\u1ed3n t\u1ea1i trong th\u1eddi gian d\u00e0i, cho ph\u00e9p k\u1ebb t\u1ea5n c\u00f4ng thu th\u1eadp d\u1eef li\u1ec7u li\u00ean t\u1ee5c.<\/p>\n<\/li>\n<li>\n<p><strong>D\u1ec5 tri\u1ec3n khai<\/strong>: Nh\u1eefng k\u1ebb t\u1ea5n c\u00f4ng c\u00f3 th\u1ec3 th\u1ef1c hi\u1ec7n c\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng Formjacking b\u1eb1ng c\u00e1c k\u1ef9 thu\u1eadt t\u01b0\u01a1ng \u0111\u1ed1i \u0111\u01a1n gi\u1ea3n, th\u01b0\u1eddng l\u1ee3i d\u1ee5ng c\u00e1c l\u1ed7 h\u1ed5ng b\u1ea3o m\u1eadt trong m\u00e3 c\u1ee7a trang web.<\/p>\n<\/li>\n<\/ol>\n<h2>C\u00e1c lo\u1ea1i h\u00ecnh th\u1ee9c<\/h2>\n<p>C\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng Formjacking c\u00f3 th\u1ec3 \u0111\u01b0\u1ee3c ph\u00e2n lo\u1ea1i d\u1ef1a tr\u00ean ph\u1ea1m vi v\u00e0 c\u00e1ch ti\u1ebfp c\u1eadn c\u1ee7a ch\u00fang. D\u01b0\u1edbi \u0111\u00e2y l\u00e0 m\u1ed9t s\u1ed1 lo\u1ea1i t\u1ea5n c\u00f4ng Formjacking ph\u1ed5 bi\u1ebfn:<\/p>\n<table>\n<thead>\n<tr>\n<th>Ki\u1ec3u<\/th>\n<th>S\u1ef1 mi\u00eau t\u1ea3<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Nh\u1eafm m\u1ee5c ti\u00eau c\u1ee5 th\u1ec3<\/td>\n<td>C\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng nh\u1eafm v\u00e0o m\u1ed9t trang web ho\u1eb7c t\u1ed5 ch\u1ee9c c\u1ee5 th\u1ec3.<\/td>\n<\/tr>\n<tr>\n<td>t\u1ef1 \u0111\u1ed9ng<\/td>\n<td>C\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng nh\u1eafm v\u00e0o nhi\u1ec1u trang web c\u00f9ng m\u1ed9t l\u00fac.<\/td>\n<\/tr>\n<tr>\n<td>L\u01b0\u1edbt web<\/td>\n<td>M\u1ed9t h\u00ecnh th\u1ee9c Formjacking t\u1eadp trung v\u00e0o vi\u1ec7c \u0111\u00e1nh c\u1eafp d\u1eef li\u1ec7u t\u1eeb c\u00e1c h\u00ecnh th\u1ee9c thanh to\u00e1n tr\u1ef1c tuy\u1ebfn.<\/td>\n<\/tr>\n<tr>\n<td>B\u00ean th\u1ee9 ba<\/td>\n<td>T\u1ea5n c\u00f4ng v\u00e0o c\u00e1c t\u1eadp l\u1ec7nh c\u1ee7a b\u00ean th\u1ee9 ba \u0111\u01b0\u1ee3c nhi\u1ec1u trang web s\u1eed d\u1ee5ng.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>C\u00e1ch s\u1eed d\u1ee5ng Formjacking, c\u00e1c v\u1ea5n \u0111\u1ec1 v\u00e0 gi\u1ea3i ph\u00e1p li\u00ean quan \u0111\u1ebfn vi\u1ec7c s\u1eed d\u1ee5ng<\/h2>\n<p>Formjacking g\u00e2y ra r\u1ee7i ro nghi\u00eam tr\u1ecdng cho c\u1ea3 ng\u01b0\u1eddi d\u00f9ng v\u00e0 doanh nghi\u1ec7p. M\u1ed9t s\u1ed1 c\u00e1ch c\u00f3 th\u1ec3 khai th\u00e1c Formjacking bao g\u1ed3m:<\/p>\n<ol>\n<li>\n<p><strong>Gian l\u1eadn t\u00e0i ch\u00ednh<\/strong>: Th\u00f4ng tin th\u1ebb t\u00edn d\u1ee5ng b\u1ecb \u0111\u00e1nh c\u1eafp c\u00f3 th\u1ec3 \u0111\u01b0\u1ee3c s\u1eed d\u1ee5ng \u0111\u1ec3 mua h\u00e0ng tr\u00e1i ph\u00e9p, d\u1eabn \u0111\u1ebfn t\u1ed5n th\u1ea5t t\u00e0i ch\u00ednh cho ng\u01b0\u1eddi d\u00f9ng.<\/p>\n<\/li>\n<li>\n<p><strong>H\u00e0nh vi tr\u1ed9m c\u1eafp danh t\u00ednh<\/strong>: Th\u00f4ng tin c\u00e1 nh\u00e2n c\u00f3 th\u1ec3 \u0111\u01b0\u1ee3c s\u1eed d\u1ee5ng \u0111\u1ec3 \u0111\u00e1nh c\u1eafp danh t\u00ednh, g\u00e2y t\u1ed5n h\u1ea1i \u0111\u00e1ng k\u1ec3 cho n\u1ea1n nh\u00e2n.<\/p>\n<\/li>\n<li>\n<p><strong>Thi\u1ec7t h\u1ea1i danh ti\u1ebfng<\/strong>: C\u00e1c doanh nghi\u1ec7p tr\u1edf th\u00e0nh n\u1ea1n nh\u00e2n c\u1ee7a c\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng Formjacking c\u00f3 th\u1ec3 b\u1ecb thi\u1ec7t h\u1ea1i v\u1ec1 danh ti\u1ebfng v\u00e0 m\u1ea5t ni\u1ec1m tin c\u1ee7a kh\u00e1ch h\u00e0ng.<\/p>\n<\/li>\n<\/ol>\n<h3>Gi\u1ea3i ph\u00e1p v\u00e0 gi\u1ea3m nh\u1eb9:<\/h3>\n<ol>\n<li>\n<p><strong>B\u1ea3o m\u1eadt \u1ee9ng d\u1ee5ng web<\/strong>: S\u1eed d\u1ee5ng c\u00e1c bi\u1ec7n ph\u00e1p b\u1ea3o m\u1eadt m\u1ea1nh m\u1ebd, ch\u1eb3ng h\u1ea1n nh\u01b0 \u0111\u00e1nh gi\u00e1 m\u00e3 v\u00e0 t\u01b0\u1eddng l\u1eeda \u1ee9ng d\u1ee5ng web, \u0111\u1ec3 x\u00e1c \u0111\u1ecbnh v\u00e0 ng\u0103n ch\u1eb7n c\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng Formjacking.<\/p>\n<\/li>\n<li>\n<p><strong>Gi\u00e1m s\u00e1t v\u00e0 ph\u00e1t hi\u1ec7n<\/strong>: Li\u00ean t\u1ee5c theo d\u00f5i l\u01b0u l\u01b0\u1ee3ng truy c\u1eadp v\u00e0 h\u00e0nh vi c\u1ee7a trang web \u0111\u1ec3 ph\u00e1t hi\u1ec7n b\u1ea5t k\u1ef3 ho\u1ea1t \u0111\u1ed9ng \u0111\u00e1ng ng\u1edd n\u00e0o cho th\u1ea5y Formjacking.<\/p>\n<\/li>\n<li>\n<p><strong>M\u00e3 h\u00f3a<\/strong>: S\u1eed d\u1ee5ng m\u00e3 h\u00f3a \u0111\u1ec3 b\u1ea3o v\u1ec7 d\u1eef li\u1ec7u nh\u1ea1y c\u1ea3m \u0111\u01b0\u1ee3c truy\u1ec1n gi\u1eefa ng\u01b0\u1eddi d\u00f9ng v\u00e0 m\u00e1y ch\u1ee7, khi\u1ebfn k\u1ebb t\u1ea5n c\u00f4ng kh\u00f3 \u0111\u00e1nh ch\u1eb7n h\u01a1n.<\/p>\n<\/li>\n<li>\n<p><strong>Ki\u1ec3m to\u00e1n th\u01b0\u1eddng xuy\u00ean<\/strong>: Th\u01b0\u1eddng xuy\u00ean ki\u1ec3m tra v\u00e0 c\u1eadp nh\u1eadt m\u00e3 trang web \u0111\u1ec3 \u0111\u00f3ng c\u00e1c l\u1ed7 h\u1ed5ng ti\u1ec1m \u1ea9n.<\/p>\n<\/li>\n<\/ol>\n<h2>C\u00e1c \u0111\u1eb7c \u0111i\u1ec3m ch\u00ednh v\u00e0 so s\u00e1nh kh\u00e1c v\u1edbi c\u00e1c thu\u1eadt ng\u1eef t\u01b0\u01a1ng t\u1ef1<\/h2>\n<p>D\u01b0\u1edbi \u0111\u00e2y l\u00e0 so s\u00e1nh gi\u1eefa Formjacking v\u00e0 c\u00e1c m\u1ed1i \u0111e d\u1ecda m\u1ea1ng t\u01b0\u01a1ng t\u1ef1 kh\u00e1c:<\/p>\n<table>\n<thead>\n<tr>\n<th>M\u1ed1i \u0111e d\u1ecda<\/th>\n<th>S\u1ef1 mi\u00eau t\u1ea3<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>L\u1eeba \u0111\u1ea3o<\/td>\n<td>C\u00e1c ph\u01b0\u01a1ng ph\u00e1p l\u1eeba \u0111\u1ea3o \u0111\u1ec3 l\u1eeba ng\u01b0\u1eddi d\u00f9ng ti\u1ebft l\u1ed9 d\u1eef li\u1ec7u.<\/td>\n<\/tr>\n<tr>\n<td>\u0110\u1ecdc l\u01b0\u1edbt<\/td>\n<td>Thu th\u1eadp d\u1eef li\u1ec7u t\u1eeb th\u1ebb thanh to\u00e1n t\u1ea1i c\u00e1c thi\u1ebft b\u1ecb v\u1eadt l\u00fd.<\/td>\n<\/tr>\n<tr>\n<td>ghi nh\u1eadt k\u00fd b\u00e0n ph\u00edm<\/td>\n<td>Ghi l\u1ea1i c\u00e1c l\u1ea7n g\u00f5 ph\u00edm \u0111\u1ec3 n\u1eafm b\u1eaft th\u00f4ng tin nh\u1ea1y c\u1ea3m.<\/td>\n<\/tr>\n<tr>\n<td>Ph\u1ea7n m\u1ec1m t\u1ed1ng ti\u1ec1n<\/td>\n<td>Ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i m\u00e3 h\u00f3a d\u1eef li\u1ec7u, y\u00eau c\u1ea7u ti\u1ec1n chu\u1ed9c \u0111\u1ec3 m\u1edf kh\u00f3a.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Trong khi L\u1eeba \u0111\u1ea3o v\u00e0 \u0110\u1ecdc l\u01b0\u1edbt l\u00e0 nh\u1eefng m\u1ed1i \u0111e d\u1ecda n\u1ed5i b\u1eadt v\u00e0 d\u1ec5 th\u1ea5y h\u01a1n th\u00ec Formjacking ho\u1ea1t \u0111\u1ed9ng \u00e2m th\u1ea7m, khi\u1ebfn vi\u1ec7c ph\u00e1t hi\u1ec7n tr\u1edf n\u00ean kh\u00f3 kh\u0103n h\u01a1n cho \u0111\u1ebfn khi thi\u1ec7t h\u1ea1i x\u1ea3y ra. Keylogging v\u00e0 Ransomware kh\u00e1c nhau v\u1ec1 b\u1ea3n ch\u1ea5t nh\u01b0ng c\u00f3 chung m\u1ee5c \u0111\u00edch l\u00e0 \u0111\u00e1nh c\u1eafp d\u1eef li\u1ec7u nh\u1ea1y c\u1ea3m.<\/p>\n<h2>Quan \u0111i\u1ec3m v\u00e0 c\u00f4ng ngh\u1ec7 c\u1ee7a t\u01b0\u01a1ng lai li\u00ean quan \u0111\u1ebfn Formjacking<\/h2>\n<p>T\u01b0\u01a1ng lai c\u1ee7a Formjacking c\u00f3 th\u1ec3 s\u1ebd ch\u1ee9ng ki\u1ebfn m\u1ed9t tr\u00f2 ch\u01a1i m\u00e8o v\u1eddn chu\u1ed9t kh\u00f4ng ng\u1eebng ngh\u1ec9 gi\u1eefa t\u1ed9i ph\u1ea1m m\u1ea1ng v\u00e0 c\u00e1c chuy\u00ean gia an ninh m\u1ea1ng. Khi c\u00f4ng ngh\u1ec7 ti\u1ebfn b\u1ed9, k\u1ebb t\u1ea5n c\u00f4ng c\u00f3 th\u1ec3 ph\u00e1t tri\u1ec3n c\u00e1c k\u1ef9 thu\u1eadt tr\u1ed1n tr\u00e1nh tinh vi h\u01a1n. Ng\u01b0\u1ee3c l\u1ea1i, nh\u1eefng ng\u01b0\u1eddi b\u1ea3o v\u1ec7 c\u0169ng s\u1ebd t\u1eadn d\u1ee5ng c\u00e1c thu\u1eadt to\u00e1n AI v\u00e0 m\u00e1y h\u1ecdc ti\u00ean ti\u1ebfn \u0111\u1ec3 ph\u00e1t hi\u1ec7n v\u00e0 ng\u0103n ch\u1eb7n c\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng Formjacking hi\u1ec7u qu\u1ea3 h\u01a1n.<\/p>\n<h2>C\u00e1ch s\u1eed d\u1ee5ng ho\u1eb7c li\u00ean k\u1ebft m\u00e1y ch\u1ee7 proxy v\u1edbi Formjacking<\/h2>\n<p>M\u00e1y ch\u1ee7 proxy c\u00f3 th\u1ec3 v\u00f4 t\u00ecnh \u0111\u00f3ng m\u1ed9t vai tr\u00f2 trong c\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng Formjacking. T\u1ed9i ph\u1ea1m m\u1ea1ng c\u00f3 th\u1ec3 s\u1eed d\u1ee5ng m\u00e1y ch\u1ee7 proxy \u0111\u1ec3 \u1ea9n danh t\u00ednh v\u00e0 v\u1ecb tr\u00ed c\u1ee7a ch\u00fang, khi\u1ebfn c\u01a1 quan ch\u1ee9c n\u0103ng g\u1eb7p kh\u00f3 kh\u0103n trong vi\u1ec7c truy t\u00ecm ngu\u1ed3n g\u1ed1c c\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng. Ngo\u00e0i ra, k\u1ebb t\u1ea5n c\u00f4ng c\u00f3 th\u1ec3 s\u1eed d\u1ee5ng proxy \u0111\u1ec3 truy c\u1eadp c\u00e1c trang web m\u1ee5c ti\u00eau t\u1eeb c\u00e1c v\u1ecb tr\u00ed \u0111\u1ecba l\u00fd kh\u00e1c nhau, tr\u00e1nh c\u00e1c c\u01a1 ch\u1ebf ph\u00e1t hi\u1ec7n v\u00e0 gi\u1edbi h\u1ea1n t\u1ed1c \u0111\u1ed9.<\/p>\n<p>M\u1eb7c d\u00f9 b\u1ea3n th\u00e2n c\u00e1c m\u00e1y ch\u1ee7 proxy l\u00e0 c\u00f4ng c\u1ee5 h\u1ee3p ph\u00e1p \u0111\u01b0\u1ee3c s\u1eed d\u1ee5ng \u0111\u1ec3 \u1ea9n danh, b\u1ea3o m\u1eadt v\u00e0 v\u01b0\u1ee3t qua c\u00e1c gi\u1edbi h\u1ea1n \u0111\u1ecba l\u00fd, nh\u01b0ng ch\u00fang c\u00f3 th\u1ec3 v\u00f4 t\u00ecnh t\u1ea1o v\u1ecf b\u1ecdc cho c\u00e1c ho\u1ea1t \u0111\u1ed9ng \u0111\u1ed9c h\u1ea1i nh\u01b0 Formjacking. \u0110i\u1ec1u c\u1ea7n thi\u1ebft l\u00e0 c\u00e1c nh\u00e0 cung c\u1ea5p m\u00e1y ch\u1ee7 proxy nh\u01b0 OneProxy ph\u1ea3i th\u1ef1c hi\u1ec7n c\u00e1c bi\u1ec7n ph\u00e1p b\u1ea3o m\u1eadt nghi\u00eam ng\u1eb7t \u0111\u1ec3 ng\u0103n ch\u1eb7n vi\u1ec7c l\u1ea1m d\u1ee5ng d\u1ecbch v\u1ee5 c\u1ee7a h\u1ecd cho m\u1ee5c \u0111\u00edch t\u1ed9i ph\u1ea1m.<\/p>\n<h2>Li\u00ean k\u1ebft li\u00ean quan<\/h2>\n<p>\u0110\u1ec3 t\u00ecm hi\u1ec3u th\u00eam v\u1ec1 Formjacking, b\u1ea1n c\u00f3 th\u1ec3 kh\u00e1m ph\u00e1 c\u00e1c t\u00e0i nguy\u00ean sau:<\/p>\n<ol>\n<li><a href=\"https:\/\/owasp.org\/www-community\/attacks\/Formjacking\" target=\"_new\" rel=\"noopener nofollow\">H\u01b0\u1edbng d\u1eabn \u0111\u1ecbnh d\u1ea1ng OWASP<\/a><\/li>\n<li><a href=\"https:\/\/www.riskiq.com\/research\/magecart\/\" target=\"_new\" rel=\"noopener nofollow\">Nghi\u00ean c\u1ee9u m\u1ed1i \u0111e d\u1ecda Magecart<\/a><\/li>\n<li><a href=\"https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/formjacking-attacks-rise\" target=\"_new\" rel=\"noopener nofollow\">C\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng Formjacking \u0111ang gia t\u0103ng \u2013 Symantec<\/a><\/li>\n<\/ol>\n<p>H\u00e3y nh\u1edb r\u1eb1ng, vi\u1ec7c c\u1eadp nh\u1eadt th\u00f4ng tin v\u00e0 th\u1ef1c hi\u1ec7n c\u00e1c bi\u1ec7n ph\u00e1p b\u1ea3o m\u1eadt m\u1ea1nh m\u1ebd l\u00e0 r\u1ea5t quan tr\u1ecdng \u0111\u1ec3 b\u1ea3o v\u1ec7 b\u1ea3n th\u00e2n v\u00e0 doanh nghi\u1ec7p c\u1ee7a b\u1ea1n kh\u1ecfi m\u1ed1i \u0111e d\u1ecda ng\u00e0y c\u00e0ng gia t\u0103ng c\u1ee7a Formjacking.<\/p>","protected":false},"featured_media":477285,"menu_order":0,"template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"class_list":["post-477284","wiki","type-wiki","status-publish","has-post-thumbnail","hentry"],"acf":{"faq_title":"Frequently Asked Questions about <mark>Formjacking: A Stealthy Cyber Threat<\/mark>","faq_items":[{"question":"<strong>What is Formjacking?<\/strong>","answer":"<p>Formjacking is a malicious cyber attack where hackers insert code into websites to steal sensitive information submitted through online forms, such as credit card details and personal data.<\/p>"},{"question":"<strong>When did Formjacking first emerge, and who was responsible for its origin?<\/strong>","answer":"<p>Formjacking gained prominence around 2018, with the Magecart group being one of the first known perpetrators of this type of attack.<\/p>"},{"question":"<strong>How does Formjacking work?<\/strong>","answer":"<p>Formjacking involves injecting malicious JavaScript code into websites' payment pages. This code captures user-submitted data before it reaches the website's server and sends it to the attacker's remote server.<\/p>"},{"question":"<strong>What are the key features of Formjacking?<\/strong>","answer":"<p>Formjacking operates stealthily, affecting websites with significant user bases, allows attackers to collect data continuously, and is relatively easy to deploy due to security flaws in website code.<\/p>"},{"question":"<strong>What types of Formjacking attacks exist?<\/strong>","answer":"<p>Formjacking attacks can be specific, automated, focus on web skimming, or target third-party scripts used by multiple websites.<\/p>"},{"question":"<strong>What are the risks associated with Formjacking?<\/strong>","answer":"<p>Formjacking poses risks like financial fraud, identity theft, and reputational damage to businesses falling victim to these attacks.<\/p>"},{"question":"<strong>How can Formjacking be mitigated and prevented?<\/strong>","answer":"<p>Mitigation involves employing web application security, monitoring and detection, encryption, and regular code auditing to close potential vulnerabilities.<\/p>"},{"question":"<strong>How does Formjacking compare to other cyber threats like phishing and ransomware?<\/strong>","answer":"<p>Formjacking is stealthier compared to phishing and ransomware, but it shares the aim of stealing sensitive data with keylogging and ransomware.<\/p>"},{"question":"<strong>What can we expect in the future of Formjacking?<\/strong>","answer":"<p>The future may witness more sophisticated evasion techniques from cybercriminals, countered by advanced AI and machine learning solutions from cybersecurity experts.<\/p>"},{"question":"<strong>How are proxy servers associated with Formjacking?<\/strong>","answer":"<p>Proxy servers can unintentionally facilitate Formjacking attacks by providing cover for attackers, hiding their identity and location.<\/p>"}]},"_links":{"self":[{"href":"https:\/\/oneproxy.pro\/vn\/wp-json\/wp\/v2\/wiki\/477284","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oneproxy.pro\/vn\/wp-json\/wp\/v2\/wiki"}],"about":[{"href":"https:\/\/oneproxy.pro\/vn\/wp-json\/wp\/v2\/types\/wiki"}],"version-history":[{"count":0,"href":"https:\/\/oneproxy.pro\/vn\/wp-json\/wp\/v2\/wiki\/477284\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oneproxy.pro\/vn\/wp-json\/wp\/v2\/media\/477285"}],"wp:attachment":[{"href":"https:\/\/oneproxy.pro\/vn\/wp-json\/wp\/v2\/media?parent=477284"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}