Ocai aviation design defects can cause (sensitive information leakage + unconditional 1 second admin reset)
Kill admin directly
Retrieve the homepage
Site:
Http://bk.travelsky.com/when the main site is open, it will jump to this station. This is how the main man directly finds the password
Http://bk.travelsky.com/bkair/page/users/front/userlogin.jspuse abc123as an example.
If you find any answers, enter them as needed to see how I can bypass them.
Capture packets here to leak the plaintext mobile phone number and email address (both can be used to retrieve the password)
Then, of course, modify the returned package.
Check whether the password is successfully reset. You just don't know the password.
Don't worry. Just change the phone number above and change it to your own phone number. Then the password will be sent to your phone,
Let's see how to kill admin in 3 seconds.
Try logging on
I have nothing to say.