Brief description: when entering the enterprise mailbox from the QQ panel or QQ mailbox, bypass entering the enterprise mailbox password protection.
For details, anyone who has used QQ enterprise mailbox and bound QQ/associated QQ mailbox settings knows that when entering enterprise mailbox from QQ mailbox panel, you can set a password for entering enterprise mail from QQ or QQ mail. After obtaining the QQ password, you cannot enter enterprise mail, you can use the new email reminder function of the QQ client to bypass password protection when entering the enterprise mailbox.
Vulnerability proof: first, log on to the other party's QQ, go to system settings-status and reminder-message reminder-enable the new email reminder
Then, send an email to the recipient's enterprise email account.
Then, the QQ client immediately prompts you to receive a new email reminder.
Click "Reminder" to enter the email address and view the email address directly beyond the enterprise email password protection.
Click the enterprise mail logo in the upper left corner and return to the enterprise mail directly. No Password is required.
Solution: Apply the independent password function in QQ mail to enterprise mail password access protection.
You can use QQ to directly process new emails. You only need to enter your enterprise email password when entering your mailbox, or always need to enter your enterprise email password.
Author wdlei @ wooyun