The MI account vulnerability allows you to bypass the lock screen and change the password of your mi account to obtain account information when the miui adds a password lock screen.
If you lose your miui system and bind your Xiaomi account's mobile phone, you may be at risk of data leakage if you fail to exploit this vulnerability, in addition, your Xiaomi account will be obtained by others, and data cannot be retrieved or cleared, resulting in data leakage.
Many people think that it is safe to add a Lock password to the mobile phone. Even if you lose the Lock password, you can clear data and retrieve the Mobile Phone Based on the Xiaomi cloud service. But is it really safe? View my cracking experiences.
I,
First, I picked up a mobile phone. I can switch the SIM card to another mobile phone, get the mobile phone number, and then
Open https:// I .mi.com/click forgot password? "
Enter mobile phone number
Click Next and you will receive the SMS verification code. Enter the verification code to change the password of your Xiaomi account. Now, this account is yours.
II,
If you happen to know the phone number and do not want to install sim on another phone or cannot, you can do the same.
This is the screen lock Interface
Call this phone with another number.
Slide the circle and send a text message
Select the "Custom SMS" at the bottom
Enter the text message Writing Page
Click the plus sign in the lower left corner of the page.
Select "image" on the page.
Log onto the https:// I .mi.com/click "forgot password? "
Enter mobile phone number
Click Next.
Enter the verification code to change the password of your Xiaomi account. Now, this account is yours.
Solution:
I feel that it is too insecure to change the password of a mobile phone when I cancel receiving the verification code or combine it with my mailbox.