Thứ Năm, 8 tháng 10, 2026

How to tracing processes using audit logs

 Một buổi sáng đẹp trời bạn nhận được cảnh báo từ SIEM:

Ghi nhận hành vi thực thi lệnh bất thường trên hệ thống

Log Source: SIEM @ a.b.c.d

Source IP: a.b.c.d

Command: "grep" a1="-qE" a2="209\.59\.141\.49|50\.28\.104\.57" a3="/root/.ssh/authorized_keys" a4="/root/.ssh/authorized_keys2"

Time: 15:30:05 8 thg 10, 2026

Rồi, xong.

Bước 1 : Lấy  full log theo ID


cat /var/log/cmdlog.log | grep 1580306382

Oct  8 01:30:01 a.b.c.d audispd: type=SYSCALL msg=audit(1791397801.256:1580306382): arch=c000003e syscall=59 success=yes exit=0 a0=5595e7630c40 a1=5595e76303c0 a2=5595e7603700 a3=1b6 items=2 ppid=1498460 pid=1498463 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4090958 comm="grep" exe="/usr/bin/grep" key="T1081_Credentials_In_Files" ARCH=x86_64 SYSCALL=execve AUID="root" UID="root" GID="root" EUID="root" SUID="root" FSUID="root" EGID="root" SGID="root" FSGID="root"

Oct  8 01:30:01 a.b.c.d audispd: type=EXECVE msg=audit(1791397801.256:1580306382): argc=5 a0="grep" a1="-qE" a2="209\.59\.141\.49|50\.28\.104\.57" a3="/root/.ssh/authorized_keys" a4="/root/.ssh/authorized_keys2"

Oct  8 01:30:01 a.b.c.d audispd: type=PATH msg=audit(1791397801.256:1580306382): item=0 name="/usr/bin/grep" inode=693 dev=fc:02 mode=0100755 ouid=0 ogid=0 rdev=00:00 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0 OUID="root" OGID="root"

Oct  8 01:30:01 a.b.c.d audispd: type=PATH msg=audit(1791397801.256:1580306382): item=1 name="/lib64/ld-linux-x86-64.so.2" inode=2034 dev=fc:02 mode=0100755 ouid=0 ogid=0 rdev=00:00 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0 OUID="root" OGID="root"

Oct  8 01:30:01 a.b.c.d audispd: type=PROCTITLE msg=audit(1791397801.256:1580306382): proctitle=67726570002D7145003230395C2E35395C2E3134315C2E34397C35305C2E32385C2E3130345C2E3537002F726F6F742F2E7373682F617574686F72697A65645F6B657973002F726F6F742F2E7373682F617574686F72697A65645F6B65797332


Bước 2: Lấy log theo process ID :

grep -nHE 'pid=1498460|ppid=1498460|ses=4090958' /var/log/cmdlog.log

grep -nE 'pid=1498460|ppid=1498460' /var/log/cmdlog.log


/var/log/cmd.log:181790:Oct  8 01:30:01 a.b.c.d audispd: type=LOGIN msg=audit(1791397801.184:1580305632): pid=1498388 uid=0 old-auid=4294967295 auid=0 tty=(none) old-ses=4294967295 ses=4090958 res=1 UID="root" OLD-AUID="unset" AUID="root"

/var/log/cmd.log:181791:Oct  8 01:30:01 a.b.c.d audispd: type=SYSCALL msg=audit(1791397801.184:1580305632): arch=c000003e syscall=1 success=yes exit=1 a0=7 a1=7ffeb0b7b050 a2=1 a3=7f0c21b9d371 items=0 ppid=2962086 pid=1498388 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4090958 comm="cron" exe="/usr/sbin/cron" key=(null) ARCH=x86_64 SYSCALL=write AUID="root" UID="root" GID="root" EUID="root" SUID="root" FSUID="root" EGID="root" SGID="root" FSGID="root"

/var/log/cmd.log:181794:Oct  8 01:30:01 a.b.c.d audispd: type=USER_START msg=audit(1791397801.184:1580305634): pid=1498388 uid=0 auid=0 ses=4090958 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_env,pam_permit,pam_umask,pam_unix,pam_limits acct="root" exe="/usr/sbin/cron" hostname=? addr=? terminal=cron res=success' UID="root" AUID="root"

/var/log/cmd.log:181809:Oct  8 01:30:01 a.b.c.d audispd: type=SYSCALL msg=audit(1791397801.184:1580305643): arch=c000003e syscall=59 success=yes exit=0 a0=55d1cc9f3fc6 a1=7ffeb0b7b0d0 a2=55d1cc9f3fe0 a3=7ffeb0b7b0d0 items=2 ppid=1498388 pid=1498397 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4090958 comm="sh" exe="/usr/bin/dash" key="susp_shell" ARCH=x86_64 SYSCALL=execve AUID="root" UID="root" GID="root" EUID="root" SUID="root" FSUID="root" EGID="root" SGID="root" FSGID="root"

/var/log/cmd.log:181825:Oct  8 01:30:01 a.b.c.d audispd: type=SYSCALL msg=audit(1791397801.188:1580305647): arch=c000003e syscall=59 success=yes exit=0 a0=7ffc0b0b0ed0 a1=7ffc0b0b10f0 a2=7ffc0b0b1110 a3=7f15598c0640 items=2 ppid=1498397 pid=1498400 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4090958 comm="bash" exe="/usr/bin/bash" key="susp_shell" ARCH=x86_64 SYSCALL=execve AUID="root" UID="root" GID="root" EUID="root" SUID="root" FSUID="root" EGID="root" SGID="root" FSGID="root"

/var/log/cmd.log:182082:Oct  8 01:30:01 a.b.c.d audispd: type=SYSCALL msg=audit(1791397801.196:1580305791): arch=c000003e syscall=59 success=yes exit=0 a0=5595e76042f0 a1=5595e76045f0 a2=5595e76043c0 a3=8 items=2 ppid=1498400 pid=1498412 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4090958 comm="whoami" exe="/usr/bin/whoami" key="recon" ARCH=x86_64 SYSCALL=execve AUID="root" UID="root" GID="root" EUID="root" SUID="root" FSUID="root" EGID="root" SGID="root" FSGID="root"

/var/log/cmd.log:182294:Oct  8 01:30:01 a.b.c.d audispd: type=SYSCALL msg=audit(1791397801.252:1580306378): arch=c000003e syscall=59 success=yes exit=0 a0=5595e7630760 a1=5595e7631c00 a2=5595e7603700 a3=1b6 items=2 ppid=1498460 pid=1498461 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4090958 comm="grep" exe="/usr/bin/grep" key="T1081_Credentials_In_Files" ARCH=x86_64 SYSCALL=execve AUID="root" UID="root" GID="root" EUID="root" SUID="root" FSUID="root" EGID="root" SGID="root" FSGID="root"

/var/log/cmd.log:182295:Oct  8 01:30:01 a.b.c.d audispd: type=SYSCALL msg=audit(1791397801.252:1580306379): arch=c000003e syscall=59 success=yes exit=0 a0=5595e7630400 a1=5595e7631c00 a2=5595e7603700 a3=1b6 items=2 ppid=1498460 pid=1498462 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4090958 comm="grep" exe="/usr/bin/grep" key="T1081_Credentials_In_Files" ARCH=x86_64 SYSCALL=execve AUID="root" UID="root" GID="root" EUID="root" SUID="root" FSUID="root" EGID="root" SGID="root" FSGID="root"

/var/log/cmd.log:182302:Oct  8 01:30:01 a.b.c.d audispd: type=SYSCALL msg=audit(1791397801.256:1580306382): arch=c000003e syscall=59 success=yes exit=0 a0=5595e7630c40 a1=5595e76303c0 a2=5595e7603700 a3=1b6 items=2 ppid=1498460 pid=1498463 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4090958 comm="grep" exe="/usr/bin/grep" key="T1081_Credentials_In_Files" ARCH=x86_64 SYSCALL=execve AUID="root" UID="root" GID="root" EUID="root" SUID="root" FSUID="root" EGID="root" SGID="root" FSGID="root"

/var/log/cmd.log:182317:Oct  8 01:30:01 a.b.c.d audispd: type=SYSCALL msg=audit(1791397801.820:1580306389): arch=c000003e syscall=59 success=yes exit=0 a0=5595e7632590 a1=5595e7636470 a2=5595e7632040 a3=8 items=2 ppid=1498460 pid=1499143 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4090958 comm="grep" exe="/usr/bin/grep" key="T1081_Credentials_In_Files" ARCH=x86_64 SYSCALL=execve AUID="root" UID="root" GID="root" EUID="root" SUID="root" FSUID="root" EGID="root" SGID="root" FSGID="root"

/var/log/cmd.log:182322:Oct  8 01:30:01 a.b.c.d audispd: type=SYSCALL msg=audit(1791397801.832:1580306390): arch=c000003e syscall=59 success=yes exit=0 a0=5595e7630000 a1=5595e7636770 a2=5595e7632040 a3=8 items=2 ppid=1498460 pid=1499145 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4090958 comm="grep" exe="/usr/bin/grep" key="T1081_Credentials_In_Files" ARCH=x86_64 SYSCALL=execve AUID="root" UID="root" GID="root" EUID="root" SUID="root" FSUID="root" EGID="root" SGID="root" FSGID="root"

/var/log/cmd.log:182327:Oct  8 01:30:01 a.b.c.d audispd: type=SYSCALL msg=audit(1791397801.848:1580306391): arch=c000003e syscall=59 success=yes exit=0 a0=5595e76192e0 a1=5595e7616c40 a2=5595e76154b0 a3=8 items=2 ppid=1498400 pid=1499151 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4090958 comm="hostname" exe="/usr/bin/hostname" key="recon" ARCH=x86_64 SYSCALL=execve AUID="root" UID="root" GID="root" EUID="root" SUID="root" FSUID="root" EGID="root" SGID="root" FSGID="root"

/var/log/cmd.log:182332:Oct  8 01:30:01 a.b.c.d audispd: type=SYSCALL msg=audit(1791397801.860:1580306392): arch=c000003e syscall=59 success=yes exit=0 a0=5595e75fc3e0 a1=5595e75fcea0 a2=5595e75fc480 a3=5595e75f2010 items=2 ppid=1498400 pid=1499153 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4090958 comm="whoami" exe="/usr/bin/whoami" key="recon" ARCH=x86_64 SYSCALL=execve AUID="root" UID="root" GID="root" EUID="root" SUID="root" FSUID="root" EGID="root" SGID="root" FSGID="root"

/var/log/cmd.log:182337:Oct  8 01:30:01 a.b.c.d audispd: type=CRED_DISP msg=audit(1791397801.868:1580306393): pid=1498388 uid=0 auid=0 ses=4090958 msg='op=PAM:setcred grantors=pam_hulk,pam_permit acct="root" exe="/usr/sbin/cron" hostname=? addr=? terminal=cron res=success' UID="root" AUID="root"

/var/log/cmd.log:182338:Oct  8 01:30:01 a.b.c.d audispd: type=USER_END msg=audit(1791397801.868:1580306394): pid=1498388 uid=0 auid=0 ses=4090958 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_env,pam_permit,pam_umask,pam_unix,pam_limits acct="root" exe="/usr/sbin/cron" hostname=? addr=? terminal=cron res=success' UID="root" AUID="root"


182294:Oct  8 01:30:01 a.b.c.d audispd: type=SYSCALL msg=audit(1791397801.252:1580306378): arch=c000003e syscall=59 success=yes exit=0 a0=5595e7630760 a1=5595e7631c00 a2=5595e7603700 a3=1b6 items=2 ppid=1498460 pid=1498461 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4090958 comm="grep" exe="/usr/bin/grep" key="T1081_Credentials_In_Files" ARCH=x86_64 SYSCALL=execve AUID="root" UID="root" GID="root" EUID="root" SUID="root" FSUID="root" EGID="root" SGID="root" FSGID="root"

182295:Oct  8 01:30:01 a.b.c.d audispd: type=SYSCALL msg=audit(1791397801.252:1580306379): arch=c000003e syscall=59 success=yes exit=0 a0=5595e7630400 a1=5595e7631c00 a2=5595e7603700 a3=1b6 items=2 ppid=1498460 pid=1498462 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4090958 comm="grep" exe="/usr/bin/grep" key="T1081_Credentials_In_Files" ARCH=x86_64 SYSCALL=execve AUID="root" UID="root" GID="root" EUID="root" SUID="root" FSUID="root" EGID="root" SGID="root" FSGID="root"

182302:Oct  8 01:30:01 a.b.c.d audispd: type=SYSCALL msg=audit(1791397801.256:1580306382): arch=c000003e syscall=59 success=yes exit=0 a0=5595e7630c40 a1=5595e76303c0 a2=5595e7603700 a3=1b6 items=2 ppid=1498460 pid=1498463 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4090958 comm="grep" exe="/usr/bin/grep" key="T1081_Credentials_In_Files" ARCH=x86_64 SYSCALL=execve AUID="root" UID="root" GID="root" EUID="root" SUID="root" FSUID="root" EGID="root" SGID="root" FSGID="root"

182317:Oct  8 01:30:01 a.b.c.d audispd: type=SYSCALL msg=audit(1791397801.820:1580306389): arch=c000003e syscall=59 success=yes exit=0 a0=5595e7632590 a1=5595e7636470 a2=5595e7632040 a3=8 items=2 ppid=1498460 pid=1499143 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4090958 comm="grep" exe="/usr/bin/grep" key="T1081_Credentials_In_Files" ARCH=x86_64 SYSCALL=execve AUID="root" UID="root" GID="root" EUID="root" SUID="root" FSUID="root" EGID="root" SGID="root" FSGID="root"

182322:Oct  8 01:30:01 a.b.c.d audispd: type=SYSCALL msg=audit(1791397801.832:1580306390): arch=c000003e syscall=59 success=yes exit=0 a0=5595e7630000 a1=5595e7636770 a2=5595e7632040 a3=8 items=2 ppid=1498460 pid=1499145 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4090958 comm="grep" exe="/usr/bin/grep" key="T1081_Credentials_In_Files" ARCH=x86_64 SYSCALL=execve AUID="root" UID="root" GID="root" EUID="root" SUID="root" FSUID="root" EGID="root" SGID="root" FSGID="root"


181809:Oct  8 01:30:01 a.b.c.d audispd: type=SYSCALL msg=audit(1791397801.184:1580305643): arch=c000003e syscall=59 success=yes exit=0 a0=55d1cc9f3fc6 a1=7ffeb0b7b0d0 a2=55d1cc9f3fe0 a3=7ffeb0b7b0d0 items=2 ppid=1498388 pid=1498397 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4090958 comm="sh" exe="/usr/bin/dash" key="susp_shell" ARCH=x86_64 SYSCALL=execve AUID="root" UID="root" GID="root" EUID="root" SUID="root" FSUID="root" EGID="root" SGID="root" FSGID="root"

181825:Oct  8 01:30:01 a.b.c.d audispd: type=SYSCALL msg=audit(1791397801.188:1580305647): arch=c000003e syscall=59 success=yes exit=0 a0=7ffc0b0b0ed0 a1=7ffc0b0b10f0 a2=7ffc0b0b1110 a3=7f15598c0640 items=2 ppid=1498397 pid=1498400 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4090958 comm="bash" exe="/usr/bin/bash" key="susp_shell" ARCH=x86_64 SYSCALL=execve AUID="root" UID="root" GID="root" EUID="root" SUID="root" FSUID="root" EGID="root" SGID="root" FSGID="root"

182082:Oct  8 01:30:01 a.b.c.d audispd: type=SYSCALL msg=audit(1791397801.196:1580305791): arch=c000003e syscall=59 success=yes exit=0 a0=5595e76042f0 a1=5595e76045f0 a2=5595e76043c0 a3=8 items=2 ppid=1498400 pid=1498412 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4090958 comm="whoami" exe="/usr/bin/whoami" key="recon" ARCH=x86_64 SYSCALL=execve AUID="root" UID="root" GID="root" EUID="root" SUID="root" FSUID="root" EGID="root" SGID="root" FSGID="root"

182327:Oct  8 01:30:01 a.b.c.d audispd: type=SYSCALL msg=audit(1791397801.848:1580306391): arch=c000003e syscall=59 success=yes exit=0 a0=5595e76192e0 a1=5595e7616c40 a2=5595e76154b0 a3=8 items=2 ppid=1498400 pid=1499151 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4090958 comm="hostname" exe="/usr/bin/hostname" key="recon" ARCH=x86_64 SYSCALL=execve AUID="root" UID="root" GID="root" EUID="root" SUID="root" FSUID="root" EGID="root" SGID="root" FSGID="root"

182332:Oct  8 01:30:01 a.b.c.d audispd: type=SYSCALL msg=audit(1791397801.860:1580306392): arch=c000003e syscall=59 success=yes exit=0 a0=5595e75fc3e0 a1=5595e75fcea0 a2=5595e75fc480 a3=5595e75f2010 items=2 ppid=1498400 pid=1499153 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4090958 comm="whoami" exe="/usr/bin/whoami" key="recon" ARCH=x86_64 SYSCALL=execve AUID="root" UID="root" GID="root" EUID="root" SUID="root" FSUID="root" EGID="root" SGID="root" FSGID="root"


Bước 3: Đã xác định được Cron, lấy log Cron 

grep -hE 'Oct  8 01:30:0[01].*CRON'   /var/log/syslog* /var/log/cron* 2>/dev/null


Oct  8 01:30:01 a.b.c.d CRON[1498397]: (root) CMD (/usr/local/maldetect/maldet --mkpubpaths >> /dev/null 2>&1)

Oct  8 01:30:01 a.b.c.d CRON[1498396]: (root) CMD (   bash -c "sleep $((RANDOM % 60))" ; /opt/imunify360/venv/share/imunify360/scripts/check-detached.py > /dev/null 2>&1 || :)

Oct  8 01:30:01 a.b.c.d CRON[1498398]: (root) CMD (/usr/sbin/imunify-notifier -update-cron)

Oct  8 01:30:01 a.b.c.d CRON[1498399]: (cicocom) CMD (/usr/local/bin/php/home/cicocom/public_html/artisan queue:work >/dev/null 2>&1)

Oct  8 01:30:01 a.b.c.d CRON[1498401]: (root) CMD (/usr/local/cpanel/scripts/dcpumon-wrapper >/dev/null 2>&1)

Oct  8 01:30:01 a.b.c.d CRON[1498397]: (root) CMD (/usr/local/maldetect/maldet --mkpubpaths >> /dev/null 2>&1)

Oct  8 01:30:01 a.b.c.d CRON[1498396]: (root) CMD (   bash -c "sleep $((RANDOM % 60))" ; /opt/imunify360/venv/share/imunify360/scripts/check-detached.py > /dev/null 2>&1 || :)

Oct  8 01:30:01 a.b.c.d CRON[1498398]: (root) CMD (/usr/sbin/imunify-notifier -update-cron)

Oct  8 01:30:01 a.b.c.d CRON[1498399]: (cicocom) CMD (/usr/local/bin/php/home/cicocom/public_html/artisan queue:work >/dev/null 2>&1)

Oct  8 01:30:01 a.b.c.d CRON[1498401]: (root) CMD (/usr/local/cpanel/scripts/dcpumon-wrapper >/dev/null 2>&1)


Xác định được ID : 1498397 thực thi là maldet

Thở phào nhẹ nhõm

Lệnh thực thi trong maldet 


    # G ?~@~T SSH keys carrying known-attacker IP labels. Broader Pattern G

    # (forged-mtime detection) has customer-paste FP risk; left to ioc-scan.

    grep -qE '209\.59\.141\.49|50\.28\.104\.57' \

        /root/.ssh/authorized_keys /root/.ssh/authorized_keys2 2>/dev/null \

        && h="$h G"

Mission Completed

Read More

Thứ Ba, 24 tháng 2, 2026

Sửa Lỗi 508 Resource Limit Is Reached

 Khi Quý khách truy cập website mà nhận được thông báo Resource Limit Is Reached The website is temporarily unable to service your request as it exceeded resource limit. Please try again later."Thì có nghĩa là Quý khách đã sử dụng hết tài nguyên của Hosting. Thông báo lỗi "508 Resource Limit Is Reached" xuất hiện khi tài khoản hosting đột ngột sử dụng quá lượng tài nguyên được ấn định trước đó, tài nguyên mà hosting được ấn định bao gồm %CPU, lượng RAM được phép sử dụng, I/O, Processes được phép tối đa. 

Nguyên nhân gây ra lỗi

Dưới đây là một vài lý do thường dẫn đến lỗi 508 Resource Limit Is Reached trên website :

1. Nguyên nhân phổ biến nhất là các website Quý khách sử dụng trên Hosting có tổng lượng truy cập lớn hơn mức được ấn định.

2. Do website "nặng" (Có thể do code chưa tối ưu, plugin nặng sử dụng nhiều tài nguyên)

3. Do nhiễm mã độc. Ở VN phổ biến nhất tình trạng website nhiễm mã độc và hacker sử dụng để phát tán thư rác bằng hàm mail php.

4. Nguyên nhân khác


Cách xử lý 

1. Đối với trường hợp đầu tiên khách hàng có thể kiểm tra và khắc phục bằng cách truy cập cpanel, chọn " Thống kê truy cập sử dụng" => "Hệ thống thống kê awstats " => "Robots/Spiders visitors" tại đây nếu khách hàng thấy lượng hits và bandwith cao so với gói hosting, khách hàng có thể tự cấu hình trong file robot.txt tại thư mục public_html như sau để giảm lượng request :

User-agent: <tên của bot >

Crawl-delay: < thời gian giản cách giữa 2 lần Crawl tính bằng giây >

2. Đối với trường hợp thứ 2 khách hàng có thể kiểm tra tương tự như cách xử lý trên, nhưng tại "Hệ thống thống kê awstats " => "Days of month" khách hàng sẽ thống kê xem lưu lượng bandwidth cũng như lượng hits sẽ có 2 trướng hợp xảy ra :

+ bandwidth và hit tăng cao đột biến trong 1 ngày lúc này khách hàng tiếp tục truy cập vào " Host top " để xác định IP có bandwith và hits cao đột biến tiến hành chặn ip tại mục " công cụ quản lý khác " => "chặn IP "

+ bandwidth và hit tăng dần theo các ngày trong tháng trường hợp này khách hàng nên tiến hành nâng cấp vps.

3. Khách hàng nên tối ưu lại mã nguồn, đối với các website sử dụng mã nguồn mở như wordpress,joomla khách hàng nên kiểm tra và tắt các plugin không cần thiết, hạn chế sử các plugin, themes không rõ nguồn gốc đế tránh tình trạng bị dính mã độc dẫn đến việc chiếm dụng, vượt quá tài nguyên cho phép.

Read More

Thứ Năm, 5 tháng 2, 2026

Roleplay có thực sự tác dụng với ChatGPT?

Roleplay (đặt vai trò) thực sự có tác dụng rõ rệt với ChatGPT. Ví dụ như câu: “Bạn là một chuyên gia…” thường giúp câu trả lời sát ngữ cảnh, sâu hơn và đúng phong cách mong muốn.

✅ Vì sao roleplay hiệu quả

1. Giúp định hướng góc nhìn

ChatGPT có thể trả lời theo nhiều mức độ: phổ thông, kỹ thuật, học thuật, marketing, pháp lý…
Khi bạn đặt vai trò, bạn đang chọn góc nhìn chuyên môn.

👉 Ví dụ:

  • ❌ Không roleplay

    Giải thích backup Oracle là gì
    → Trả lời thường khá tổng quát

  • ✅ Có roleplay

    Bạn là DBA Oracle 15 năm kinh nghiệm, hãy giải thích backup Oracle cho junior
    → Thường sẽ:

    • Thực tế hơn

    • Có best practice

    • Có kinh nghiệm vận hành


2. Điều chỉnh phong cách trình bày

Roleplay giúp thay đổi:

  • Độ sâu kỹ thuật

  • Cách dùng thuật ngữ

  • Cách giải thích (dễ hiểu / chuyên sâu / mang tính đào tạo)

  • Cách tổ chức nội dung


3. Tăng độ phù hợp với mục tiêu

Ví dụ cùng 1 chủ đề nhưng khác vai:

RoleKết quả
Giáo viênGiải thích dễ hiểu, có ví dụ
Chuyên gia doanh nghiệpPhân tích ROI, rủi ro
Hacker pentestPhân tích lỗ hổng
DevHướng code / implement

✅ Khi nào roleplay phát huy tác dụng mạnh nhất

Roleplay đặc biệt hữu ích khi:

  • Nội dung chuyên môn sâu

  • Nội dung cần kinh nghiệm thực tế

  • Nội dung cần style viết cụ thể

  • Nội dung cần mindset của 1 nghề


⚠️ Nhưng roleplay KHÔNG phải "buff sức mạnh AI"

Nó chỉ giúp:

  • Điều chỉnh cách suy luận

  • Điều chỉnh cách trình bày

  • Tập trung domain knowledge

Nó không làm AI biết thêm kiến thức ngoài training.


✅ Cách viết roleplay hiệu quả (Prompt Pattern)

Công thức hay dùng:

Bạn là [vai trò] với [kinh nghiệm / bối cảnh]. Mục tiêu: [bạn muốn gì] Yêu cầu: - ... - ... - ...

🔥 Ví dụ prompt tốt

Bạn là Senior SysAdmin quản lý hệ thống hosting 100+ VPS. Hãy hướng dẫn checklist kiểm tra server Linux hàng ngày. Ưu tiên thực tế production.

❌ Ví dụ prompt yếu

Explain Linux monitoring

💡 Tip nâng cao

Bạn có thể combine nhiều yếu tố:

  • Role

  • Audience

  • Output format

  • Constraint

Ví dụ:

Bạn là DBA Oracle enterprise. Giải thích RMAN backup cho người mới. Output dạng checklist + ví dụ SQL.
Read More