Suning's manufacturers are very reliable and pay more and more attention to security.
1. The website is:
Htttp: // tuan.suning.com is actually a payment bug. During group buying, the quantity and amount are stored on the client and not verified on the server. Therefore, you can capture packets to modify the amount, so that you can use 1 yuan to buy anything.
2. Select the purchased item as needed. Here, we chose a 358 yuan accommodation:
3. After filling in your personal information, click Submit to capture and modify POST Data
SaleCount = 1 & contactName = % E4 % B8 % 81% E7 % 8E % B2 % E6 % 98% 8E & contactPhone = 15821852469 & contactEmail = & price = 358 & Region ID = 15592 & ourId = 154658 & singleLimit = 99 The saleCount here is the purchased quantity, change to 5, and the price must be the price. Change it to 1 yuan.
4. The order is submitted successfully. The displayed amount is 5 RMB:
5. Select the bank to pay and check whether the payment amount is 5 RMB:
All the tests are finished after the above steps. I didn't buy anything!
Solution:
Attitude determines everything. Suning will do better!