Modify any user password for a website on Sina

Source: Internet
Author: User

1. the url is not encrypted, so you can see the real mobile phone number of any user. 2. You can use the url to change the password to any mobile phone number. 3. After logging in, anyone's information, including the mobile phone number, can be changed to the real estate network. The information is very valuable. Problem URL cause: http://j.esf.sina.com.cn/login/retrievepsd below I use admin as an example, as we go to the next step as required, as we can see: the phone number on the page in the middle of the 4 digits was, the url is not encrypted, but directly displayed. Next, you can change the mobile phone number on the url to your mobile phone number (to receive the text message for password retrieval, we get the following page: OK. Next, click "Get Verification Code". Let's receive the verification code on our mobile phone. The verification code is sent to the mobile phone, let's enter the verification code to modify the 'admin' password. We can see this figure. I think everyone knows that it has been more than half done. Why can't we say it was half done? Because we are not sure whether the 'admin' password is modified, we can change it: wooyun (changing the password is to change the password to the one you want to change. Everyone knows this). The password has been changed and the password has been changed, then, we can try to see if the modified 'admin' can be logged on (the password is wooyun) OK. The following example shows that the 186 mobile phone number is the same as that of admin:
 Solution:

1. url encryption 2 to prevent burp packet capture

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.