Activity row design defects can be logged on to other user accounts
Sign up for the meeting of tangscan. It is easy to use the activity line, so I simply read it...
The title is obviously too vague for others to directly discover problems. The problem occurs in the app's password retrieval (app security seems to be often overlooked). Enter the mobile phone number and click get verification code. The verification code is displayed before receiving the text message.
I thought this 90% was returned directly from the interface. I captured the packet and read it.
My first thought was to log on with the mobile phone number 18888888888, but the verification code was returned. When I changed the password, I was prompted that the verification code was incorrect. At that time, I still wanted to get the local number, the phone number that must be filled in to retrieve the Password Matches the phone number of the local machine. Later, I thought it was unlikely. So I found a colleague and found the password, I don't know if I have taken special care of mobile phone numbers such as 18888888888 and 13333333333. The process is as simple as above, because the results will be directly displayed in the app, saving even packet capture, the previous one successfully logged on to the colleague account.
Solution:
Modify the interface logic. Do not display the Verification Code directly on the interface.