Weak password + unauthorized access + svn source code leakage in a business system of China Unicom
Www.10655123.com is China Unicom, so I tried it and registered it on my mobile phone.
Just after registration, I got a text message. Emma scared me to death. Will I be charged ?? Originally hold casually look at the psychological he gave me the whole text message that can not casually look at who knows he will buckle I spent first look for background http://admin.10655123.com/
Without a verification code, the first thing that comes to mind is that the brute-force admin account does not exist. test has tested some dictionaries and has no results ...... It seems that the brute-force command cannot scan the directory ...... Make sure you have a new one: http://admin.10655123.com/common/left.jsp. you can directly view the source code.
According to the source code, we found some accounts, hntjcrplushenancaiwuhljtjebuptkadminmusicadminclientadmin, and then used these accounts to crack them.
Emma finally succeeded in cracking operatorName = clientadmin & password = abc123
I did not have the required permissions. My goal is to delete my mobile phone number ...... I was a diaosi if the service charge this can be worse, 0.0 I am looking for Ah found the main site and a directory in the background svn vulnerability http://www.10655123.com/images/.svn/entries
Http://admin.10655123.com/client/.svn/entries
Emma's goal has not been reached ..... cool has two ways to achieve its goal: 1. Elevation of Privilege To improve the permissions of this account. 2. Excessive permission may also be due to the fact that the cms is the most serious cool with no cancellation function. terrible soon the Sao years dug a privilege escalation vulnerability http://admin.10655123.com/mngr/privilege/getPrivilegeListByGroupId.action? OperGroupLevel = 0
I'm just sure there's no permission to modify it. I should be back soon http://admin.10655123.com/mngr/user/deleteUser.jsp.
Isn't that what I want?
Solution:
Enhance filtering. Enhance verification.