APP Security douyu live broadcast arbitrary user login (it is a broadcaster with a gun)
I watched douyu live broadcast last night and saw a wave of ads for this APP. Then let's test the logic.
Attackers can log on to major broadcasters (mainly LOL broadcasters)
Any user logs on, and the host has a gun.
First, download the APP
Then register an account
Use Burp to capture packets during logon
Capture the logon package and its returned information
-------- My mobile phone number has been exposed, and I have sent a code of 0.0. Thank you.
Note: member_id ":" 2041879 "because this parameter is available in GET requests for the next package in subsequent tests
Modify the ID to a host ID 728499.
Find that the ID in GET changes accordingly, and then directly forward.
It is too easy to find the host ID.
You can directly find the anchor ID by directly capturing packets and clicking pay attention to the anchor or clicking the anchor's dynamics.
Here are several broadcaster IDs for verification.
1 526432
2 964679
3 524745
Solution:
You know