During video sharing, the video image URL of the form processing program on the server is not directly from a third-party interface, but is displayed to netizens after the server first calls the third-party video information through the interface, submit the information to the form processing program.
Here, I select an activity:
A user clicks a URL to successfully invite a friend to the activity.
Http://dellcqg.renren.com/redirect.php? U = Mjg2MzI3MDE4 & return_url = http://dellcqg.renren.com/thanksgiving/
In order to fl this traffic, we set this URL as the attack target.
Step 1, share a popular video "Durex SOS App-Emergency express Durex" with URL for http://v.youku.com/v_show/id_XNTA5ODEyODQw.html
Step 2, go to the share page http://share.renren.com /? Origin = 50115 enter the video URL, and a pop-up layer will be displayed. For example, ask the user to enter the reason for sharing.
In this case, use firebug to modify the hidden form to change the pic field to the attack target, and then share
You are done. Go to the home page and check it out.
In this way, if a friend opens his Renren homepage, the invitation is successful.
Solution:
Directly retrieve images