A problem in the CCN Forum involves million user information including passwords.
This question is interesting.
The problem is that port 11211 is enabled on memcache.
Default connection 182.92.192.240: 11211 total number of records: 1407685 because memcached Source Code limits the cachedump command, a maximum of 2 MB of keys can be traversed.
Connect.
Find the account and use the Administrator email address:
User: my500wbz password: 100800 email: [email protected to enter
Here, you only need to find a managed login record, and I will not find the rest. This vulnerability allows you to obtain the logon passwords of all users.
If there are no IP addresses in the cache, you only need to regularly refresh them. Wait for the Administrator to log on and list all user information.
You can drag the database directly, which is too convenient. (I have not dragged the database to check records)
Solution:
IP address Restriction