A well-known beverage company's weak VPN password causes internal information leakage

Source: Internet
Author: User

A well-known beverage company's weak VPN password causes internal information leakage

No verification code. weak passwords can be cracked.

Shenzhen Dongpeng Beverage Industry Co., Ltd. ssl vpn login Port
 

https://app.szeastroc.com



Weak passwords can be cracked because of poor design and no verification code.

Burpsite packet capture, top500 name as user name, 123456 as password, run out of weak password.
 



Zhangyong

123456

Log on to the ssl vpn
 



After connecting, you can log on to FTP, mail, and other systems.
 


 



No verification code for the internal mailbox logon Port

Export the logged-on email address book as the user name and run out several accounts.
 



There are still a lot of sensitive things in the mailbox, including various reports, accounts, passwords, company address book, OA ......
 


 


 


 





OA login Port

You can directly log on to the OA system using the account and password of your mailbox.
 

http://oa.szeastroc.com:89/login.do


 




 

Proof of vulnerability:

 


 


 


 


 

 

Solution:

For ssl vpn and mail, I only use some usernames to test weak passwords. If all the passwords are tested, it is estimated that there will be more,

The tested accounts are sufficient to indicate hazards. All accounts should be checked when fixing vulnerabilities.

1. Add the verification code.

2. Change the password. Do not use weak passwords.

3. Do not use the same password and account easily for multiple systems.

4. strengthen employees' information security awareness.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.