Credential stuffing caused by an improper design of an osscmd Interface
Credential stuffing caused by an improper design of an osscmd Interface
Detailed description:
Http://www.aoshitang.com/login.actionthe local code was not verified at the beginning:
After a certain number of errors, the verification code is displayed, but the verification code can be bypassed. I will not describe it here.
Username and password in plaintext:
Some successful account proofs are posted here:
Code Region
615815361581538189qweqweaqweqwe8189749023944004468189666890066689008189733458012345681896546564123456818912345551234568189w1234561234568189643968264396828189zhumama123456818934345451234568189592252159225218189guiyangguiyang8189124558512345681892145678123456818926880326812903818911865171186517818911234561234568189asdasdsasdasd8189321321312345681891122331123456818913145201314520818912121211234568189hnsqjjmfyhjjm1981894545655123456818946464641234568189123512312345681899829768123450818913100131231230818965165451234568189guodiyu1234568189wenchaowenchao8189yhc8042351955648818913245641234568189dfasfas123456818932145671234568189259876555748812818912345621234568189snakewxzhanglu81895615611123456818921321321234568189hjc5437120143612818923213121234568189zy1812913141298189luo0607823162858189122245612345681891234656123456818913019932536353818912356451234568189s480065648006568192234234231234568192afcxj00312662068192lixiyuanlixiyuan8192afcxj0031266206819219911016199110168192sd521272111111819261866657701112868192658822975845208192200005252000052581922946487019864158192wdtxwslszhanquan8192123123121231238192newbahua86891784819212345644123456819226866810singer8192123456ds1234568192341646461234567898192779420083971123819289075527yaohu1986120981921988031119880311819230907407lurong0018192sunyujunsunyujun81922525132525251325819212345790123456819219910620199106208192newhacke123123819265882297584520819280264094caonima8192123123121231238192zhyashui1597538192zousihou346297280819277782736665966028192yejinhua123456819212312312123123819219851208198512088192531936361234568192564654651234568192ouyangbb12345681921111111Q1111118192yinenhuiyinenhui8192chairmanchairman819215347190198311781928495970331164781922009010120090101819212345689123456819285031365330204581921987050619870506819242210898zuochuan8192baimizhu101409018192rinconal57523750819242539656425396568192123123121231238192nokia219chl2195208192123123121231238192123456961234567898192zzc1234568125608192156456411234568192wangsibowangsibo8192
Logon account proof:
Proof of vulnerability:
Http://www.aoshitang.com/login.actionthe local code was not verified at the beginning:
After a certain number of errors, the verification code is displayed, but the verification code can be bypassed. I will not describe it here.
Username and password in plaintext:
Some successful account proofs are posted here:
Code Region
615815361581538189qweqweaqweqwe8189749023944004468189666890066689008189733458012345681896546564123456818912345551234568189w1234561234568189643968264396828189zhumama123456818934345451234568189592252159225218189guiyangguiyang8189124558512345681892145678123456818926880326812903818911865171186517818911234561234568189asdasdsasdasd8189321321312345681891122331123456818913145201314520818912121211234568189hnsqjjmfyhjjm1981894545655123456818946464641234568189123512312345681899829768123450818913100131231230818965165451234568189guodiyu1234568189wenchaowenchao8189yhc8042351955648818913245641234568189dfasfas123456818932145671234568189259876555748812818912345621234568189snakewxzhanglu81895615611123456818921321321234568189hjc5437120143612818923213121234568189zy1812913141298189luo0607823162858189122245612345681891234656123456818913019932536353818912356451234568189s480065648006568192234234231234568192afcxj00312662068192lixiyuanlixiyuan8192afcxj0031266206819219911016199110168192sd521272111111819261866657701112868192658822975845208192200005252000052581922946487019864158192wdtxwslszhanquan8192123123121231238192newbahua86891784819212345644123456819226866810singer8192123456ds1234568192341646461234567898192779420083971123819289075527yaohu1986120981921988031119880311819230907407lurong0018192sunyujunsunyujun81922525132525251325819212345790123456819219910620199106208192newhacke123123819265882297584520819280264094caonima8192123123121231238192zhyashui1597538192zousihou346297280819277782736665966028192yejinhua123456819212312312123123819219851208198512088192531936361234568192564654651234568192ouyangbb12345681921111111Q1111118192yinenhuiyinenhui8192chairmanchairman819215347190198311781928495970331164781922009010120090101819212345689123456819285031365330204581921987050619870506819242210898zuochuan8192baimizhu101409018192rinconal57523750819242539656425396568192123123121231238192nokia219chl2195208192123123121231238192123456961234567898192zzc1234568125608192156456411234568192wangsibowangsibo8192
Logon account proof:
Solution:
Fixed the verification code issue.