First, register a 126 email test account.
Then a security prompt bound to a mobile phone is displayed.
Note that there is a uid in the parameter. Change the uid to the Netease email account to be hacked.
Enter a mobile phone number that you can control and send the confirmation code back.
Www.2cto.com
Click "OK" and enter the email address. At this time, the target Netease email address has been denied permission to be bound to a secret protection mobile phone.
Then, go through the normal password retrieval process and find that this mailbox has another retrieval method through the mobile phone. This mobile phone number is the mobile phone I just bound!
Password Reset successful !!
Improper permission judgment exists. The interface for unauthorized operations is:
Http://security.mail.126.com/mobileserv/mbp.do? Uid = [write the account you want to modify] & backurl =
Solution: Correct the program logic or directly Delete and modify the program.
Author: saviour