!"#$%&'() *"
&+(,&%- .")- /"
"012304&5
&'()-6"
789:;<=>?
Nội Dung Báo Cáo
& ."%@"A05
& ."%B& ."&CDC-E& FGH-IJ5KK
& ."%&LB"&M(B& ."&C FG-IJ5KK
& ."%#
!&M0
Xây dựng nền tảng về công nghệ thông tin, cũng như phát triển các ứng
dụng máy tính trong sản xuất, kinh doanh, khoa học, giáo dục, xã hội.
Sử dụng các bức tường lửa (Firewall) để bảo vệ mạng nội bộ (Intranet),
tránh sự tấn công.
Lập Trình Vượt Firewall Phần I: Tổng Quan
Firewall
-IJ5KKKN&MG&O"")B&PQMBG-01&DCG-C&RCGST"NQN
('"BU"& &V"WXGOW&Y"&FCKMGSTG-"-5Z-IJ5KKG&LB
&MQMBK6BT[&V"\]5B&^W&Y"&FCKM_L5G&IBB`01GaB&51B&^
G0\]&
G- !BZ
&bB)"B&c&
&bB)"B&c&Bd5-IJ5KKKNWe(fGK0g"G&Y"GGS"V5G-5IG
QNGI-IGZ&XGKDCB.B&X\h0W&e_i"G&Y"G"V5('"TG-"
jG-5IGkQN('"GI-IGZlG&eKN%
9&C&RC&PBBm(&V"_]B&QlG-01&DC-5"NjGSG-5IG-5
GI-IGk
9&C&RC&PBBm(&V"_]B&QlC&RCG-01&DCQNG-"jGSGI-IG
QNG-5IGkZ
9<e(fG\]5B&^G-01&DCnBm(\]5B&^G-01&DCZ
9<e(fG" /fo_l"QNQMBG-01&DCBd5" /fo_l"Z<e(fG
p_0"G&Y"GK 0B&01eG-('"Z
DC-E& FG-IJ5KK&q%@"A05
Nguyên lý
-IJ5KKWe(G-5GNTp\'_VKM0\e`01XG\]&rI(\'_VKM0
\+B+G&s(t(pGG-"fOBBK0DGKMBd5K6BC5BWIG&51W&Y"ZB
K0DGKMK6BC5BWIGN1KN_L5G-BBG&Y"G*\q0(uC5BWIGjC5BWIG
&I5_I-kn_v"\eB&C&RCG-01hBBC5BWIG\+*G-('"%
9w]5B&^.r0mGC&Gj,0-BI5__-Iffk
9w]5B&^.&Dj#IfG5G5__-Iffk
9&V"G&dGlBG-01hGjn>#nnG0IKk
9@"x>#.r0mGC&Gjx>#f0-BIC-Gk
9@"x>#.&Djx>#_IfG5GC-Gk
9#'"G&Y"Tj(Iff5"IG1CIk
95_MC5BWIG\XjB(("GI-H5BIHC5BWIGk
95_MC5BWIG\j0GB(("GI-H5BIHC5BWIGk
MBWe(fGBBB@"KN(B&-IJ5KKB&^B&C&RC(pGfOK'WXG
O QN BB K' (1B&d &PB &V" _]B& Ql N \+ jIKIGn ,n
ZZZk\ FBC&RCB&'1\ FBG-&MG&O"Z
DC-E& FG-IJ5KK&q%@"A05
Các dạng firewall
-IJ5KKBb"
N&V"H-IJ5KK\ FBGcB&&FCG-BBG&XGT]&'G\p"*Gq"G&mCjq"IGJ-W
QNGq"-5fC-GkZ-IJ5KKBb"W&Y"G&eWe(G-5\ FBpG_0"Bd5"+GZ
c_l-IJ5KKBb"%jIGJ-W__-Iff-5fK5GIkZ
DC-E& FG-IJ5KK&q%@"A05
Các dạng firewall
-IJ5KK(h(
&q(h(B+B&bB)"H-IJ5KK\eBNG-(1Gc&nBU"B+G&eBH"\ FBZ-IJ5KK
(h(B+G&eKm10fI-G-"_(5BG-KKI-\eBm(&51B&C&RC0fI-jQc_l,kZ
B-IJ5KK5CCKB5GBU"KN(Yy_'"-IJ5KK(h(Z
DC-E& FG-IJ5KK&q%@"A05
Một số mô hình Firewall
5BWIG9KGI-"0GI-
GI-IG H-IJ5KK C&@ TX &mG B&^ T5 "g( (pG C5BWIG9HKGI-" -0GI- \PG
"V5 ('"pTp QNGI-IGZpG C5BWIG9HKGI-"-0GI- B+&5 B&bB)"%
B&01eGXCG-01hG&Y""V5&5('"QNfo_l"BB`01K0DGQhK6B"+\e
B&C&RC&51GSB&OG-01hG&Y"Z
& FB\e(%
9#2T]GmBY"QNBBTpK6B(NBm0&E&W&Y"&N&sn&PBKNT]Gm
BY""q(_ !&V"_]B&Ql\t\ FBC&RC
9X0(pGC5BWIG9HKGI-"-0GI-_(pGfLBON\+"S"&'G\p"nGmG
Bs&MG&O"G-('"pTpB+G&eT]GmBY"Z
DC-E& FG-IJ5KK&q%@"A05
Mô hình Single-Homed Bastion Host
MG&O"N1T5"g((pGC5BWIG9HKGI-"-0GI-QN(pGT5fG&fG
Z&V"0fI-pTp\ FBG&LB&MTz"BB&\PGBm0&E&TpK6BBd5-0GI-
f5B&B&^B&mC&D&V"G-01hG&Y"pTpr0mGC&GGST5fG&fGZ
DC-E& FG-IJ5KK&q%@"A05
Mô hình Dual-Homed Bastion Host
MG&O"T5"g(&5C5BWIG9HKGI-"-0GI-QN(pGT5fG&fGZM
B+\p5GNB5&mGQE+B0"BmCBs(bBTs(DGIGJ-WQN
5CCKB5GZMG&O"B&^B&C&RCT"NG-01&DCQNT5fG
&fGZ0GI-G-"B0"BmCfLTsQMTz"BB&\h0W&e#{
G-01&DC('"pTpTaG\q0GST5fG&fGZ&V"G&Y"G\n
-0GI-G-"\h0W&e('"pTpG-01&DCG!#{B&C&RCT
G-"G-01&DCT5fG&fGZ
DC-E& FG-IJ5KK&q%@"
A05
Proxy Server
N(pGGI-IGfI-QI-KN(&M(QlB&01eGXCG&Y"GQNWe(fGG'fL5GNB&QMBG-01BDCGI-IGZ
pB& ."G-E&C-r1\ FBG&XGWXB&(pGfOBm0&E&H-IJ5KKnG&IBB_'"B.Ts%_05K9&(I"5GIJ51nfB-III_&fG"5GIJ51nQNfB-III_f0TIG"5GIJ51Z
&N&C&q5fG&fGG-"-IJ5KKn\+"Q5G-i& (pG" /B&01eGXCG&Y"Gn"&&DGW|G-01hG&Y"nQNB0"BmCBB_]B&Qln\i&[\p5GNB5Z
DC-E& FG-IJ5KK&q%@"A05
CÁC PHƯƠNG PHÁP LẬP TRÌNH VƯỢT
FIREWALL
FGH-IJ5KKKNQ FG`05fLG-01BsBd5BBB& ."G-E&Ts
(DGj-IJ5KKk\eB+G&eG-01BDC\X\ FB\cB&("Z
DC-E& FG-IJ5KK&q%& ."&CDC-E& FG
-IJ5KK
Phương pháp HTTP Proxy
NC& ."C&C(NfI-QI-fo_l"(pGB@"N\+\eG-0"B&01eBB
10Bq0nBBfI-QI-N1G& /"\ FB"6KNJITC-r1fI-QI-&51&GGCC-r1
fI-QI-Z
<&BB10Bq0Bd5BKIGT]GSB&OT*" /`0sG-]" /fo_l"fo
_l"BBC-r1fI-QI-\eB&01eGXCBB10Bq0(NG-"\+n
C-r1fI-QI-KN(pG\]5B&^\ FBB&C&RCWXGO\XZ
DC-E& FG-IJ5KK&q%& ."&CDC-E& FG-IJ5KK
Phương pháp HTTP Tunneling
N(pGW}G&0DG\+""+_VKM0Bd5BB"5G&bBW&B
jxkG-"(pG"+G\eB+G&eQ FG`05G /"Ko5\ FB
G-eW&5_ !&E&G&bBBKIG9fI-QI-Z
DC-E& FG-IJ5KK&q%& ."&CDC-E& FG
-IJ5KK
Web base proxy
IT9T5fI_1(0f-r1KN_'"W&BBd5IT-r1,I-QI-n
& "\ FBr41_L"_ !_'"G-5"JITjG'("6KNIT9T5fI_-r1
kZ
<&\ FBBBBKIG10Bq0nf~Km1BBG&Y"GjIf0-BIkGSJIT
fI-QI-\cB&nf50\+r41_L"K'G&N&G-5"JIT&NB&^&-g\•1GN
Tpp_0"G-5"JIT&NB&^&N1QhB&G-E&_01MGBd5KIGZ
-E&_01MGC&c5KIGf~&D\ FBG-5"JIT(E&10Bq0B+\c&W€(
G&IC&qG0\hBd5Z
DC-E& FG-IJ5KK&q%& ."&CDC-E& FG-IJ5KK
Sử dụng phần mềm vượt tường lửa
#v"BBC&q(h(G-(1W&B&G-01B4yCQN(1\cB&W&Y"T]fL")
BsBd5-IJ5KKZ
V d :
>KG-5,0-H
-r1,JGB&I--
-rHI-,G5_5-__G
DC-E& FG-IJ5KK&q%&LB"&M(& ."&C FG-IJ5KK
Những kết quả đạt được
E(&e0QNG-eW&5G&N&BY"•C& ."C&C%-r1,I-QI-QN
IT9T5fI_-r1Z
E(&e0f40G&(QhBBC& ."C&CKDCG-E&b"_l"('"_L5G-Tp
G& QMfBWBd5_JfZ
E(&e0\ FBC& ."C&Cr41_L"QNG-eW&5,I-QBIb"_l"G-
_Jf
E(&e0BB&r41_L"QNG-eW&5b"_l"K0"B&G-E&_01MG
GI-IGrCK-I-Z
w FB&e0\ FBBB&r41_L"QNC&GG-eb"_l"_L5G-(YG- /"
j(CIGT‚IBG_IKkZ
DC-E& FG-IJ5KK&q%@"<XG
Hướng phát triển
"&Bb0GXCC& ."C&C&GGCG0IK"Z
-eW&5b"_l"(&&65B&C& ."C&C&GGCG0IK"Z
NG&M&.V5K0"9QN,I-QBI\e\'G&M0`0sGO 0Z
-eW&5G&N&BY"(_0KIB&O"Q FG-IJ5KKTz"C& ."C&C
0IK"Z
-eW&5\hGNG&N&fsC&•(&NB&^&\eC_l"QNG&LB
G2Z
DC-E& FG-IJ5KK&q%@"<XG
Demo
#I(& ."C&C-r1
DC-E& FG-IJ5KK&q%
#
Lời Cảm Ơn
&ƒ"I(rBs(.&NG- /"+B&0"QN<&5+
-"\t\I(K'B&B&ƒ"I("0gWXG&bBQYBv"`0|"
\eB&ƒ"I(B+\dWXG&bB&NG&N&\hGNBU"& KN(
&N&G-5"T !BQN\/Z
&ƒ"I(rBs(.BBG&q1BYG&0pBTp(Yn\PBTMGKN
G&q1&'() *"„"Q& !"_$Bd5B&ƒ"I(\t
GDGE&& !"_$QN"ƒC\…B&ƒ"I((uW&B&ƒ"I(B+
W&+W&)G-"`0G-E&&6BGDCBU"& G-"`0G-E&KN(
TBZ
3Bs(.GmGBsBBT'T€G&410\t\p"Qn"ƒC\…
B&ƒ"I(G-"f0OG`0G-E&&6BGDCBU"& KN(\hGNZ