The Eastern Airlines registration page forces weak user passwords to leak sensitive user information.
I don't know if I have been mentioned.
The registration page of Eastern Airlines does not allow the password to be entered
http://easternmiles.ceair.com/mpf/#/sign/register
After registration, you will be forced to use your date of birth as the query and login password. After logging in, the password is not changed. Later, you will notice this sentence in the login window, "To modify your key information, use the consumption password to log on ".
https://passport.ceair.com/cesso/login.html?redirectUrl=http%3A%2F%2Fwww.ceair.com%2F<v=1&local=zh_CN
How can I set the consumption password? Log on to the personal center and apply for activation.
I don't know if I can change the query password after I log on with the consumption password. I'm so lazy, I didn't try it. I thought, I'm so lazy, so most Chinese people are also lazy, baidu gave me the "ID card number ".
The second one has a real ID card number.
Then I tried using the ID card number here. As a result, most of them can log on directly to view personal information, phone number, email address, address, and so on. Let's take three examples. You may have a lot of ID card numbers and other things.
At the same time, information about your friends or company colleagues may be leaked, including the phone number, ID card, and ID card. You can log on again.
The registration page of Eastern Airlines does not allow the password to be entered
http://easternmiles.ceair.com/mpf/#/sign/register
After registration, you will be forced to use your date of birth as the query and login password. After logging in, the password is not changed. Later, you will notice this sentence in the login window, "To modify your key information, use the consumption password to log on ".
https://passport.ceair.com/cesso/login.html?redirectUrl=http%3A%2F%2Fwww.ceair.com%2F<v=1&local=zh_CN
How can I set the consumption password? Log on to the personal center and apply for activation.
I don't know if I can change the query password after I log on with the consumption password. I'm so lazy, I didn't try it. I thought, I'm so lazy, so most Chinese people are also lazy, baidu gave me the "ID card number ".
The second one has a real ID card number.
Then I tried using the ID card number here. As a result, most of them can log on directly to view personal information, phone number, email address, address, and so on. Let's take three examples. You may have a lot of ID card numbers and other things.
At the same time, information about your friends or company colleagues may be leaked, including the phone number, ID card, and ID card. You can log on again.
Solution:
Even if the password is weak, can you use a registered mobile phone number as the password.
Can users set their own passwords to force password complexity.
However, all of China Eastern Airlines are experts.