Defect logic, mobile phone verification code to retrieve the password, the verification code is too simple 6 digits. After a large number of tests, it is found that the verification code is 6 digits for the first time. If the verification code is sent too frequently, a combination of five digits and letter a appears, I don't know what it is (strange) to add a clerk, but at most it is to change the arrangement and combination of 10 characters into 11 characters, in addition, it only appears when you click to send the verification code too frequently. The first time you click to send the verification code, it does not appear (You have registered several small numbers to test the results ). The verification code is not verified when the mobile phone verification code is submitted, resulting in brute force cracking. For the test certificate of the Verification Code received (up to three text messages can be sent at a time, token), two smaller accounts are selected to reset the password. The numbers of the returned error data are different when they are found in the process (I don't know what the situation is). However, it is easy to differentiate the numbers of the correct verification codes. 1. Two small accounts were cracked. 2. logon certificate.
Solution:
1. When you submit the mobile phone verification code, add a verification code input box. 2. Change the verification code to 26 letters (preferably case sensitive) and 10 numbers and combinations.