Sunshine Insurance sensitive information leakage led to the successful access to the internal network system (straight board more than one operation and maintenance host)

Source: Internet
Author: User
Tags access accounts application desktop download host http information

Waited for so long or result ah.

Before the certificate problems encountered to solve another burst of several accounts

He uploaded the latest May 31 certificate and saw him upload a certificate every 1 presumably the certificate is limited by the server

http://pan.baidu.com/share/home?uk=3257785095#category/type=0

# 1 Import the certificate into a trusted root certificate

Download citrix xenapp application

Link: http://pan.baidu.com/s/1cFRWJk Password: 67k9

# 1 Into the network OA

This Baidu cloud address to figure out who is it

Blasting ideas:

First of all, if you want to enter the end of the desktop operation and maintenance finance must ghq

Use of current resources ygbx and his own name can be used as one of the password conditions before the combination of loopholes

Back to 339 is successful

login = yangli-ghq & passwd = ygbx321! - By the dealer system

login = zhangjianmin-ghq & passwd = ygbx123 # - Finance Mobile Office

Operation and maintenance host

login = lijing-ghq & passwd = lijing123!

login = zhouwei-ghq & passwd = zhouwei123!

login = wangdan-ghq & passwd = wangdan123!

login = xieli-ghq & passwd = xieli123!

Financial desktop

login = zhangdan-ghq & passwd = zhangdan321!

login = liyun-ghq & passwd = liyun123!

No permission number

login = chenwei-ghq & passwd = ygbx123 @

login = lidandan-ghq & passwd = ygbx123 @

login = zhaowei-ghq & passwd = ygbx123 #

Login to major systems

Log in to the financial desktop

login = zhangdan-ghq & passwd = zhangdan321!

Log in to an O & M desktop

login = lijing-ghq & passwd = lijing123!

oralce database does not matter

solution:

1. Staff safety awareness issues

2 weak password problem (do not set and user name, company name and other simple password combination)

3. Remote computer database and other operations under the machine off

4. This infiltration, did not move any host data

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.