Zhihu's permission control is very strict, but it is very confidential. Keyword: modify any user permission. Impact: it can affect the communication between all users under all topics. In other places, the token and hash are all very powerful, but the token in this place does not take effect! 1. Find comments from any person on any topic and view the user's message aid = 1794719 based on his attribute values. This is the target of the attack. 2. Attackers can modify the aid value of packet capture when they operate on their own message permissions. This allows all users to comment and view the user's message permission status, open to everyone (if other permissions are set for the user) 3. The other two methods are only open to people who follow me and not open comments to view results.Solution:
If attackers write a program and execute this request in batches
Is it possible to achieve the 'Ban 'effect on the entire website? -0-