This problem depends on the business of various companies. It is not common. If xss is used, it should be used to refresh points. But it is definitely a big vulnerability for e-commerce companies. If you can see the vulnerability score, to help enterprises fix vulnerabilities, 1. Let's talk about a bug first. After the mobile phone of the client desk is registered and incomplete information is obtained, buy something directly and click buy now. An error is reported. 2. http, get plaintext transmission username and password. If there are too many clients, we will take a screenshot. The interfaces are three traversal username verification keys found on the client. A maximum of five passwords can be verified in one hour, because of this, I just need to traverse the user name. If I get the user name of many users, it will make them unable to log on. This is also a big problem. Where can I find the specific user name, csdn and many other http://m.happigo.com/datai/bus.php? Fid = as0010 & username = ****** & pwd = ****** & cps_id = 0 4 violent registration is a big problem for e-commerce companies, even if it is not e-commerce, sina meager, penguin meager is also, harm Party A certainly understand the http://m.happigo.com/datai/bus.php? & Fid = as0008 & username = Z ******* & pwd = ******** & email = ********* @ qq.com & cps_id = 0
Solution:1. Use https or other encrypted post transmission to enable mobile phone login. The registration interface must be fixed. The verification code required by the client is not acceptable. You can decide the specific policy, the key is not to be bypassed again. Test it well.