1 + 1 large online games in China are severely unauthorized, and all of their financial and user privacy services are in a hurry.

Source: Internet
Author: User

1 + 1 large online games in China are severely unauthorized, and all of their financial and user privacy services are in a hurry.

1 + 1 large online games in China are severely unauthorized, and all of their financial and user privacy services are in a hurry.




Allows you to reset the password, information, ID card, and other information of any player and log on to the game. This seriously affects the game order and allows you to steal accounts, involving financial and privacy services. It is China's No. 1 online game platform.



Over 150 gamers



Serious emergency. Please handle it !!

#1 excessive permissions, million user privacy leaks





URL:


 

http://www.dajiawan.com/admin.php?module=HuiYuan&action=Detail&uid=





Uid can be traversed, 1-1500000,150 W user uid



Direct unauthorized access to user Members for various viewing and operations



For example:


 

http://www.dajiawan.com/admin.php?module=HuiYuan&action=Detail&uid=33086





This user has spent more than RMB, and all mobile phones, QQ, ID card, name, email, and IP addresses are leaked.






 




 







#2 second excessive authorization, 1 + 1 reset any User Password



Under the first excessive view, the second excessive permission can modify the user's mailbox without administrator cookie Verification


 





Of course, you can also visit the following URL to traverse all the UIDs and directly modify and save the mailbox


 

http://www.dajiawan.com/admin.php?module=HuiYuan&action=ChangeEmail&uid=





Both methods are supported.



After modification, you can see that a user mailbox is successfully modified to 123@qq.com


 





Then select "forgot password" at the home page logon"



Enter the new email address to retrieve the password, and enter the user name and email address. The user name can be viewed in the first excessive authority. The email address is your own email address in the second excessive authority, then, you can reset the password of any user by email.


 




 




 





Successfully logged on to the user, with a balance of more than RMB


 






The above test is not malicious. the user's original email address has been changed after the test!

 

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.