China Mobile mailbox system weak password can enter
I entered the Mailbox System and saw a lot of sensitive information.
I found a page without a verification code, so I came to a burp dictionary brute-force attack (I will not crack it with a verification code. Who will ask me to learn privately ),
A large wave of weak passwords were found, all of which were abcd1234.
Next, I did not expect this to happen. I had a text message for secondary verification )/~~
Although I cannot enter OA, can I use the same password to access the mailbox system? You have a good plan. I have a wall ladder.
The welfare of state-owned enterprises is really good. In, the vacation fee is.
Above
From the weak password mailbox, the default password of trustpass is also written into the mailbox content...
Solution:
1. Avoid weak passwords
2. Enhance the authentication of the mailbox system.