A large number of users in the giant's network can log on to multiple systems with their default passwords
A large number of users in the giant's network can log on to multiple systems with their default passwords
Http://wooyun.org/bugs/wooyun-2010-0165622
After this vulnerability, I guess the default password is ztgame @ 123.
Test the first 100 usernames.
Actually succeeded several times...
Logon Allowed:
Http://haoce.ztgame.com/view/user.html
Http://zhichi.ztgame.com: 9000/login.html
It seems that there are other such domain passwords.
Mask Region
1.: // **. **. ** // Why **********?? 12 ***************** 2.: // **. **. ** // Why? * ***** 3. ://**. **. ** // open.weixin.qq.com _ ****** 19848 @ 1 ************ ztgam *************** * *** public? * ***** 4. ://**. **. ** // mp.weixin.qq.com _ ****** nhao @ ztg ************ ztgam *************** *****?? * ***** 5.: // **. **. ** // www.jpush.cn /_*****?? M1 *********** ztgam ********************?? * 6.: // *. */op.open.qq.com? _ ****** 10767 (************ tgame @******************** * ***** 7. http ://**. **. **/Project/ProjectInfo/20558 _ ****** om password: hu *********** cod *****
Http://wooyun.org/bugs/wooyun-2010-0165622
After this vulnerability, I guess the default password is ztgame @ 123.
Test the first 100 usernames.
Actually succeeded several times...
Logon Allowed:
Http://haoce.ztgame.com/view/user.html
Http://zhichi.ztgame.com: 9000/login.html
It seems that there are other such domain passwords.
Mask Region
1.: // **. **. ** // Why **********?? 12 ***************** 2.: // **. **. ** // Why? * ***** 3. ://**. **. ** // open.weixin.qq.com _ ****** 19848 @ 1 ************ ztgam *************** * *** public? * ***** 4. ://**. **. ** // mp.weixin.qq.com _ ****** nhao @ ztg ************ ztgam *************** *****?? * ***** 5.: // **. **. ** // www.jpush.cn /_*****?? M1 *********** ztgam ********************?? * 6.: // *. */op.open.qq.com? _ ****** 10767 (************ tgame @******************** * ***** 7. http ://**. **. **/Project/ProjectInfo/20558 _ ****** om password: hu *********** cod *****