Problem site is: http://qing.weibo.com now my Weibo fans only 5 people ha! 3. I am looking for my personal attention. Pay attention to packet capture at this time! The post request is as follows: POST/blog/api/attentionpost. php HTTP/1.1 rialog = A0012 & uid = [Fan id] & aid = [Object id of interest] & name = [Optional] & is_follower = [Optional] the preceding two parameters the most important thing is uid, it is the fan's id. By default, it is the account id of this request. aid is the object of interest, that is, the target account that needs to be refreshed! 4. to demonstrate the effect of vulnerabilities, I flushed my wooyun account to my fans. at the beginning, the POST request is constructed as follows. uid is used to write the account of wooyun, and aid is used to write my own account. Other requests remain unchanged. Check and return! 6. Let's take a look at the actual effect and capture the dark clouds to become my fans:
7. If I send this POST request to the intruder module of burpsuite and set uid to 10 digits for traversal, will I brush tens of millions of fans every day?Solution:
How many failed attempts have I discovered this time!