Ocai aviation design defects can cause (sensitive information leakage + unconditional 1 second admin reset)

Source: Internet
Author: User

Ocai aviation design defects can cause (sensitive information leakage + unconditional 1 second admin reset)

Kill admin directly

Retrieve the homepage

Site:
 

Http://bk.travelsky.com/when the main site is open, it will jump to this station. This is how the main man directly finds the password
Http://bk.travelsky.com/bkair/page/users/front/userlogin.jspuse abc123as an example.


If you find any answers, enter them as needed to see how I can bypass them.
 


Capture packets here to leak the plaintext mobile phone number and email address (both can be used to retrieve the password)
 

 


Then, of course, modify the returned package.
 


Check whether the password is successfully reset. You just don't know the password.
 


Don't worry. Just change the phone number above and change it to your own phone number. Then the password will be sent to your phone,


Let's see how to kill admin in 3 seconds.
 


Try logging on
 


I have nothing to say.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.