China Resources Shuanghe roaming from mailbox to Group intranet
Account Design Problems
Detailed description:
The problem started with: https://webmail.dcpc.com/owa/ (China Resources Shuanghe Mail System)
Outlook mailbox, can be cracked, get more than ten weak passwords
[email protected]P@ssw0rd[email protected]P@ssw0rd[email protected]P@ssw0rd [email protected]P@ssw0rd[email protected] P@ssw0rd[email protected] P@ssw0rd[email protected]P@ssw0rd[email protected]P@ssw0rd[email protected] P@ssw0rd[email protected]P@ssw0rd[email protected] P@ssw0rd[email protected] P@ssw0rd[email protected]P@ssw0rd[email protected]P@ssw0rd[email protected]P@ssw0rd [email protected]P@ssw0rd[email protected]P@ssw0rd[email protected]P@ssw0rd[email protected]P@ssw0rd [email protected]P@ssw0rd
All are default passwords. This is found in account [email protected] P @ ssw0rd.
Collect the following URLs and
Show that the account and password of the learning platform are both 11143130. log on to the Learning Platform
Zhou Yong's employee ID is 11143130. I have noted it down now. China Resources uses the password of the LDAP-managed information system account. If the password is not found in the email, you can change the password of the website on the internet as shown in the first figure.
Https://mima.crc.com.cn/OIMPWD/, found that it has retrieval password function, but need the ID card number after 4 digits, and the previous collection of information is not, then try to retrieve the user name, here, select the employee ID for the authentication method (11143130 we collected previously)
Next, select the email address for verification (the email address is controllable)
After obtaining the verification code in the mailbox, next step
You can change the password (this can be done where the account name is retrieved, but I don't fully trust it)
Modify
The password for ZHOUYONG31 is admin123! @ #, Connect directly to the vpn
Https://vpn.crc.com.cn/
Unified Authentication Platform
Information Management Department
China Resources Information Portal
Hrms System
China Resources University
Knowledge Base
JiRa
Proof of vulnerability:
Solution:
Modify weak passwords.