Suning Tesco an SSL interface can use the security trust relationship to successfully hit the database (you can indirectly log on to the entire site system)
Suning Tesco an SSL interface can use the security trust relationship to successfully hit the database (you can indirectly log on to the entire site system)
Https://open.suning.com/api/toLogin.action Suning open Service Platform
The login site does not have a verification code. You can directly test whether the credential stuffing is successful.
Take another 100 accounts for testing
The burp hit database shows that the returned http content contains three Set-cookies: JSESSIONID, OS _login_userName, and osusernamekey, with these three parameters, you can log on to the Suning Tesco system, such as the main site, efu Bao, Suning cloud, and Forum.
The returned http response is 302 and contains three Set-Cookie values.
HTTP/1.1 302 FoundServer: nginxDate: Thu, 22 Jan 2015 13:46:40 GMTContent-Length: 0Connection: keep-aliveLocation: https://open.suning.com/api/toDevCenter.actionExpires: Thu, 01 Jan 1970 00:00:00 GMTCache-Control: no-cacheSet-Cookie: JSESSIONID=XUcEimoST0q0xxxxxx.slave104:fserver2; path=/apiSet-Cookie: os_login_userName=xxxxxx.com.cn; path=/; domain=.suning.comSet-Cookie: osusernamekey=91695d7xxxxx9b29d4ee37; path=/; domain=.suning.comPragma: No-cacheContent-Language: zh-CN
If the logon fails, the http response value is 200, which contains the JSESSIONID in one Set-Cookie parameter. If there are no other two parameters, You Can preliminarily determine that the logon fails.
HTTP/1.1 200 OKServer: nginxDate: Thu, 22 Jan 2015 13:46:38 GMTContent-Type: text/html;charset=utf-8Connection: keep-aliveVary: Accept-EncodingExpires: Thu, 01 Jan 1970 00:00:00 GMTCache-Control: no-cacheSet-Cookie: JSESSIONID=3voH9xxxxxx2qC2hj0QQA.master:fserver1; path=/apiPragma: No-cacheContent-Language: zh-CNContent-Length: 13371
Log on to the Suning Open Platform and log on to the main site of Suning Tesco
Find several accounts to log on and test the function.
Forum
Cloud Platform vendor self-check, all under the suning.com subdomain can log on