Ele. Me mobile phone verification can be used as phone bombing (killing you)

Source: Internet
Author: User

Ele. Me mobile phone verification can be used as phone bombing (killing you)

Now, the food on campus is filled with little brother and sister who often send takeaways. I can't resist the temptation to start using ELE. Me, too, but what makes me angry is that there is a restaurant that looks so good that it actually increases the take-out fee, and I am very dissatisfied with this. Far away... As a result, the detection of ELE. Me mobile terminals has been launched. Various possible problems may be that I have no technical skills, and security measures have been well performed. The hacker did not find a valuable vulnerability, only find the mobile phone bombing. After a meal, if the take-out mobile phone number is new, the system will prompt for phone verification if you are hungry, and then call the verification code to intercept the data packet during the process as follows:


Obviously, the checkpoint sig exists here, so it is troublesome to modify the data, so I will not modify it. I will directly enter the target mobile phone number for replay attacks. It is tested that the interval is only 30 seconds, but there is no limit on the number of times. That is to say, a script is used to replay the data. The target mobile phone will receive a verification code call every thirty seconds. If you don't shut down, what should you do ....



There is a time difference between them because I went out for a meal.

Solution:

This vulnerability can be exploited to increase the number of phone numbers. I am a programmer and I have a suggestion. Ele. Me's current ticket list can only be made by friends. We recommend that you add a function to list orders between strangers, scan the users who buy the same seller around according to the positioning information, and then submit the ticket together. This will attract users who want to get takeout but cannot afford to pay for it, and sellers will also send it once, so that each win is mutually beneficial.
 

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.