Suning Tesco an SSL interface can use the security trust relationship to successfully hit the database (you can indirectly log on to the entire site system)

Source: Internet
Author: User

Suning Tesco an SSL interface can use the security trust relationship to successfully hit the database (you can indirectly log on to the entire site system)

Suning Tesco an SSL interface can use the security trust relationship to successfully hit the database (you can indirectly log on to the entire site system)

Https://open.suning.com/api/toLogin.action Suning open Service Platform




The login site does not have a verification code. You can directly test whether the credential stuffing is successful.



Take another 100 accounts for testing





The burp hit database shows that the returned http content contains three Set-cookies: JSESSIONID, OS _login_userName, and osusernamekey, with these three parameters, you can log on to the Suning Tesco system, such as the main site, efu Bao, Suning cloud, and Forum.



The returned http response is 302 and contains three Set-Cookie values.


 

HTTP/1.1 302 FoundServer: nginxDate: Thu, 22 Jan 2015 13:46:40 GMTContent-Length: 0Connection: keep-aliveLocation: https://open.suning.com/api/toDevCenter.actionExpires: Thu, 01 Jan 1970 00:00:00 GMTCache-Control: no-cacheSet-Cookie: JSESSIONID=XUcEimoST0q0xxxxxx.slave104:fserver2; path=/apiSet-Cookie: os_login_userName=xxxxxx.com.cn; path=/; domain=.suning.comSet-Cookie: osusernamekey=91695d7xxxxx9b29d4ee37; path=/; domain=.suning.comPragma: No-cacheContent-Language: zh-CN




 







If the logon fails, the http response value is 200, which contains the JSESSIONID in one Set-Cookie parameter. If there are no other two parameters, You Can preliminarily determine that the logon fails.


 

HTTP/1.1 200 OKServer: nginxDate: Thu, 22 Jan 2015 13:46:38 GMTContent-Type: text/html;charset=utf-8Connection: keep-aliveVary: Accept-EncodingExpires: Thu, 01 Jan 1970 00:00:00 GMTCache-Control: no-cacheSet-Cookie: JSESSIONID=3voH9xxxxxx2qC2hj0QQA.master:fserver1; path=/apiPragma: No-cacheContent-Language: zh-CNContent-Length: 13371







Log on to the Suning Open Platform and log on to the main site of Suning Tesco



Find several accounts to log on and test the function.


 






 






 







Forum


 




 




 





Cloud Platform vendor self-check, all under the suning.com subdomain can log on

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.