Logging of APP security is tiring for any user login (major broadcasters lay down their guns)
I watched douyu live broadcast last night and saw a wave of ads for this APP. Then let's test the logic.
Attackers can log on to major broadcasters (mainly LOL broadcasters)
Any user logs on, and the host has a gun.
First of all, you need to download the APP and register an account to log on. Use the Burp to capture the logon package and the returned information.
-------- My mobile phone number is exposed with a 0.0-digit code. Thank you for your attention. member_id ": "2041879" because the GET request of the next package in subsequent tests has this parameter, modify this ID to a broadcaster ID 728499 and find that the ID in GET changes accordingly. Then, directly forward.
It is too easy to find the host ID. You can directly find the anchor ID by directly capturing packets and clicking to follow the anchor's news. Here, several anchor IDs are used as verification items: 1 5264322 9646793 524745.