China Resources Shuanghe roaming from mailbox to Group intranet

Source: Internet
Author: User

China Resources Shuanghe roaming from mailbox to Group intranet

Account Design Problems

Detailed description:

The problem started with: https://webmail.dcpc.com/owa/ (China Resources Shuanghe Mail System)

Outlook mailbox, can be cracked, get more than ten weak passwords

[email protected]P@ssw0rd[email protected]P@ssw0rd[email protected]P@ssw0rd     [email protected]P@ssw0rd[email protected]        P@ssw0rd[email protected]        P@ssw0rd[email protected]P@ssw0rd[email protected]P@ssw0rd[email protected]        P@ssw0rd[email protected]P@ssw0rd[email protected]        P@ssw0rd[email protected]       P@ssw0rd[email protected]P@ssw0rd[email protected]P@ssw0rd[email protected]P@ssw0rd  [email protected]P@ssw0rd[email protected]P@ssw0rd[email protected]P@ssw0rd[email protected]P@ssw0rd  [email protected]P@ssw0rd

All are default passwords. This is found in account [email protected] P @ ssw0rd.
 


Collect the following URLs and


Show that the account and password of the learning platform are both 11143130. log on to the Learning Platform


Zhou Yong's employee ID is 11143130. I have noted it down now. China Resources uses the password of the LDAP-managed information system account. If the password is not found in the email, you can change the password of the website on the internet as shown in the first figure.

Https://mima.crc.com.cn/OIMPWD/, found that it has retrieval password function, but need the ID card number after 4 digits, and the previous collection of information is not, then try to retrieve the user name, here, select the employee ID for the authentication method (11143130 we collected previously)

Next, select the email address for verification (the email address is controllable)


After obtaining the verification code in the mailbox, next step
 

You can change the password (this can be done where the account name is retrieved, but I don't fully trust it)

Modify

The password for ZHOUYONG31 is admin123! @ #, Connect directly to the vpn

Https://vpn.crc.com.cn/

Unified Authentication Platform

Information Management Department

China Resources Information Portal

Hrms System

China Resources University
 


Knowledge Base


JiRa

Proof of vulnerability:

Solution:

Modify weak passwords.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.