The problem still appears in the password retrieval page, the verification code unlimited can be cracked... login, forget the password to the password retrieval page... http://sso.hc360.com/VerifyLoginName.html
Enter the target username, next to password retrieval... http://sso.hc360.com/security/VerifyIdentity.html? Operate = 2 password retrieval method whether it is mailbox retrieval or mobile phone retrieval, the system sends a 6-digit verification code to the registered mailbox or mobile phone... the verification code is not restricted, causing brute-force cracking. After cracking, You can reset the user password... here, select "Mailbox retrieval" and enter a verification code to capture packets when submitting... then crack the verification code parameter emailVerifyCode... the verification code does not limit the number of valid times. You can enter the verification code to reset the user password...Solution:
The number of verification code attempts is limited, or an image verification code is added when the verification code is submitted...