When the domain name Management Panel jumps to any modification, other domain names are controlled.

Source: Internet
Author: User

In fact, this time it was accidentally discovered that a friend's domain name was registered in an IDC and encountered a problem during point management. He had a link for redirect, but this link could be changed at will, the following Links

Http://www.bkjia.com/apilogin. asp? D_name = [hide] & act = domainlogincontrolpanel & u_name = [hide] & checkTime = [hide] & checkSum = [hide]

The d_name can be changed at will, resulting in a vulnerability. As long as this link exists, domain names registered with this agent will suffer.

For example, my friend hijacked a website today ....

The cause of this vulnerability is also complex.

Because there must be a transmission when you log on to the console, and the user md5str in it is also transmitted. This vulnerability should be considered by developers and may be difficult to fix.

Solution:

Put all kinds of content on the server for internal processing, just like this transfer.

Now the server obtains the data internally (depending on id = xxx), then determines the owner of the id, and finally obtains the content returned by the server for determination. If the result is true, generate a temporary code (only once) and jump to the dns console. This requires a good integration between the dns Control Platform and the idc platform.

Source: network security technology blog (www.safe121.com)

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.