WHITEHAT ACADEMY V10.1 · MANUAL QA EDITION

Học hacker mũ trắng từ số 0

558 bài tiếng Việt chuyên sâu, gồm 414 scenario lab tương tác + 144 tool chuyên nghiệp + 128 bài tự viết mini-tool + 28-tool CTF toolkit + 8 Business Logic Lab + AI-assisted Bug Bounty Workspace + 105 challenge. Thực hành tích hợp ưu tiên synthetic/local và scope được phép.

0%khóa lý thuyết
43module
558bài chuyên sâu
105challenge
100%local/synthetic
00

144 tool · Tool Mastery

144 tool chuyên nghiệp theo workflow + 128 bài tự viết mini-tool, có tìm kiếm, evidence, lỗi hay mắc và lời giải mở dần.

01

Bug Bounty Hunter

8 business-logic lab, request budget, evidence diff/redaction, source/sink review, AI prompt guardrails và report quality gate.

02

Competition Prep

Checklist 9 track, tool chain, timed rounds 30–120 phút và roadmap tool chuyên nghiệp để luyện theo kiểu đi thi.

03

28-tool CTF Toolkit

Encode/decode, crypto math, XOR analyzer, PNG/ELF/PCAP triage, JWT, HTTP, subnet, regex và file inspector.

04

CTF Beginner → Mystery

10 category: Web, API, Crypto, Forensics, OSINT synthetic, Reverse, Network, Linux, Mobile, Blue Team.

05

Pentest & Bug Bounty

Scope, validation, evidence, report builder, impact, remediation và retest.

06

Attack-Defense Simulator

Uptime, inspect, patch, harden, restore và verify dưới action budget.

07

239 thuật ngữ + phát âm

Tên chuẩn tiếng Anh + giải thích ngắn bằng tiếng Việt để đọc tài liệu quốc tế.

Luật số 1 của white-hat

Chỉ kiểm thử localhost, lab/CTF hoặc hệ thống mà ông có quyền rõ ràng và nằm trong scope. Bug bounty không có nghĩa là được thử mọi website của công ty.

LEARNING PATH

43 module · học theo thứ tự

Module dài được thu gọn để giao diện không thành một bức tường 558 bài.

00

Đạo đức & cách học

Scope, authorization, tư duy bằng chứng và cách học security không đi tắt.

0/5
01

Máy tính & hệ điều hành

Phần cứng, process, file system, terminal và môi trường lab.

0/5
02

Mạng máy tính

OSI/TCP-IP, địa chỉ, subnet, DNS, TCP/UDP, HTTP và TLS.

0/8
03

Linux & shell

File, quyền, process, log, pipeline và Bash cho người làm security.

0/12
04

Windows & scripting

Windows internals căn bản, PowerShell và tự động hóa an toàn.

0/5
05

Web, HTTP & lập trình

DOM, JavaScript, request/response, cookie/session, API và Python.

0/7
06

Nền tảng bảo mật & crypto

CIA, threat model, authn/authz, hash, mã hóa và quản lý secret.

0/7
07

Bộ công cụ white-hat

DevTools, curl, Wireshark, Burp, Nmap và ghi chép trong lab.

0/7
08

Web Security Core

Access control, auth, SQLi, XSS, CSRF, SSRF, upload, traversal và logic.

0/12
09

API & web hiện đại

REST, JWT, OAuth/OIDC, CORS, GraphQL, race condition và cache.

0/7
10

CTF Foundations

Web, crypto, forensics, OSINT, reverse và pwn ở mức beginner.

0/7
11

Pentest & Bug Bounty

Từ scope tới methodology, evidence, report, retest và hunting có tổ chức.

0/6
12

Blue Team, Attack-Defense & Capstone

Log triage, incident response, defend service và bài thi tổng hợp.

0/7
13

Advanced Web Exploitation

XXE, deserialization, prototype pollution, request smuggling, WebSocket và SAML/OIDC ở mức lab.

0/6
14

Active Directory & Enterprise Identity

Domain, Kerberos, LDAP, Group Policy và tư duy phân tích quyền trong enterprise lab.

0/6
15

Reverse Engineering & Binary Exploitation

Assembly, ELF/PE, GDB/Ghidra, stack, mitigations, ROP và crash triage trong CTF.

0/6
16

Cloud, Containers & Kubernetes Security

Cloud IAM, metadata, storage policy, container boundary, Kubernetes RBAC và evidence.

0/6
17

Vulnerability Research & Elite Capstone

Source audit, fuzzing, crash triage, exploitability reasoning và capstone không walkthrough.

0/6
18

Competition Mastery & Tournament Prep

Tool workflow, triage, timebox, write-up, teamwork và mô phỏng thi CTF nhiều category.

0/8
19

Bug Bounty Hunter & AI-Assisted Research

Business logic, invariant, multi-account, low-impact testing, AI human-in-the-loop, evidence và report quality.

0/11
20

Scenario Lab · Web Access & Session

18 tình huống access control, session, upload, cache và browser-facing security trong safe lab.

0/18
21

Scenario Lab · Authentication, OAuth & Identity

18 tình huống login, MFA, reset, OAuth/OIDC, SSO và lifecycle identity trong môi trường mô phỏng.

0/18
22

Scenario Lab · API, GraphQL & WebSocket

18 case REST, GraphQL, WebSocket, JWT, CORS, webhook, idempotency và authorization theo object/action.

0/18
23

Scenario Lab · Business Logic & Payments

18 case business logic, payment, coupon, refund, inventory, quota và state-machine dùng account/dữ liệu giả.

0/18
24

Scenario Lab · Browser, Frontend & Supply Chain

18 case DOM, postMessage, iframe, storage, service worker, dependency và frontend supply-chain.

0/18
25

Scenario Lab · Network, DNS & TLS

18 tình huống packet/pcap synthetic, DNS, TLS, proxy, firewall, routing và service exposure.

0/18
26

Scenario Lab · Linux & Windows Operations

18 case permission, service, task, logs, process, secret handling và hardening trên dataset/VM lab.

0/18
27

Scenario Lab · Active Directory & Enterprise

18 case identity graph, group/ACL, Kerberos/LDAP, GPO và enterprise hardening theo dữ liệu synthetic.

0/18
28

Scenario Lab · Cloud, Containers & Kubernetes

18 case IAM, storage, secret, metadata, container image và Kubernetes RBAC/network trong lab.

0/18
29

Scenario Lab · Mobile Android/iOS

18 tình huống mobile storage, deep link, IPC, TLS, WebView và reverse artifact theo app lab.

0/18
30

Scenario Lab · Forensics & Incident Response

18 case disk/memory/log/pcap/email/timeline và incident response trên artifact synthetic.

0/18
31

Scenario Lab · Blue Team & Detection Engineering

18 case SIEM, alert triage, detection logic, containment, hardening và purple-team synthetic.

0/18
32

Scenario Lab · Reverse Engineering

18 case static/dynamic analysis, ELF/PE, assembly, Java/Android và behavior recovery trên binary challenge local.

0/18
33

Scenario Lab · Binary Exploitation & Pwn

18 case crash triage, memory safety, mitigations, format string và ROP concepts trên binary CTF local.

0/18
34

Scenario Lab · Crypto, Encoding & Data Formats

18 case encoding, hashes, symmetric/asymmetric concepts, randomness, signatures và protocol data handling.

0/18
35

Scenario Lab · OSINT, Research, AI & Reporting

18 case OSINT synthetic, source validation, AI-assisted research, vulnerability triage và report/handoff.

0/18
36

Scenario Lab · Wireless, Wi-Fi & Local Radio

18 case Wi-Fi/EAP/BLE/DHCP/ARP/MQTT và wireless incident analysis bằng capture/config/sandbox riêng.

0/18
37

Scenario Lab · IoT, Firmware & Embedded

18 case firmware/update/debug interface/device identity/storage/protocol bằng image, emulator và dev-board lab.

0/18
1Firmware partition triage từ magic bytes35–50 phút · Dễ · Research2Hardcoded test credential trong firmware fixture35–50 phút · Dễ · Research3Secret nằm trong config image35–50 phút · Dễ · Research4Debug interface còn bật ở production profile35–50 phút · Dễ · Research5Firmware update thiếu signature verification35–50 phút · Dễ · Research6Rollback protection không giữ version floor35–50 phút · Trung bình · Research7Boot chain trust bị cấu hình sai35–50 phút · Trung bình · Research8Local web admin authorization thiếu object/action check35–50 phút · Trung bình · Research9MQTT topic ACL quá rộng35–50 phút · Trung bình · Research10Local device API token dùng chung mọi thiết bị35–50 phút · Trung bình · Research11Certificate identity reuse giữa device35–50 phút · Khó · Research12Sensitive data lưu plaintext trên flash image35–50 phút · Khó · Research13Diagnostic log ghi quá nhiều dữ liệu cá nhân35–50 phút · Khó · Research14Default service exposure trong emulator35–50 phút · Khó · Research15SBOM chỉ ra component firmware lỗi thời35–50 phút · Khó · Research16Parser memory bug trên file/protocol toy35–50 phút · Expert · Research17Factory reset không xóa state nhạy cảm trong image lab35–50 phút · Expert · Research18Firmware provenance không truy được build35–50 phút · Expert · Research
38

Scenario Lab · CI/CD & Software Supply Chain

18 case pipeline, runner, artifact, dependency, provenance, signing và deployment controls trong repo/registry lab.

0/18
39

Scenario Lab · Database & Data Security

18 case tenant isolation, DB privilege, query safety, backup/export, encryption, audit và retention trong database lab.

0/18
40

Scenario Lab · Email, SaaS & Collaboration

18 case mail auth, OAuth consent, sharing, forwarding, SaaS audit, helpdesk identity và collaboration controls.

0/18
41

Scenario Lab · GenAI, LLM & Agent Security

18 case prompt injection, RAG, tool permission, memory isolation, output handling, model/data supply chain và human approval.

0/18
42

Scenario Lab · Threat Modeling, Architecture & Secure Design

18 case trust boundary, fail-safe design, multi-tenant isolation, recovery, feature flag, secrets và abuse-case modeling.

0/18
1Data-flow diagram thiếu trust boundary35–50 phút · Dễ · Foundation2Asset/invariant không được viết trước implementation35–50 phút · Dễ · Foundation3Exceptional condition fail-open35–50 phút · Dễ · Foundation4Feature flag bỏ qua security control35–50 phút · Dễ · Foundation5Multi-tenant isolation chỉ nằm ở UI routing35–50 phút · Dễ · Foundation6Default configuration không secure35–50 phút · Trung bình · Foundation7Secret lifecycle không có owner/rotation35–50 phút · Trung bình · Foundation8Backup restore thiếu authorization design35–50 phút · Trung bình · Foundation9Disaster recovery bỏ quên security controls35–50 phút · Trung bình · Foundation10Logging design thu quá nhiều sensitive data35–50 phút · Trung bình · Foundation11Privacy requirement không map vào data flow35–50 phút · Khó · Foundation12Quota/abuse case không được threat-model35–50 phút · Khó · Foundation13TOCTOU trong design workflow35–50 phút · Khó · Foundation14Third-party trust mặc định quá cao35–50 phút · Khó · Foundation15Privileged admin workflow thiếu separation of duties35–50 phút · Khó · Foundation16Schema/data migration bỏ qua backward security invariant35–50 phút · Expert · Foundation17Security control không có observable success metric35–50 phút · Expert · Foundation18Architecture capstone với unknown system35–50 phút · Expert · Foundation