1. Do you still remember the oau2's question? Why can't anyone spread this idea! Let's take a look at how I reset my sister account! 2. to test whether there is a problem with the thunder Security Center, I have registered a new account and log on to the thunder Security Center. 3. Bind a security email address! I in order to test, prepared to bind a QQ mailbox, click [send mail], pay attention to set up proxy, intercept requests do not really send: 3. I wipe, the original is a GET request: http://dynamic.aq.xunlei.com/interface/mail? M = set_send & mail = *********** @ qq.com & jsoncallback = jsonp1356855966584 proof of vulnerability: 4. Yes, the GET request bound to the mailbox is not protected against CSRF. The mail parameter must be bound to a specified email address. Is the jsoncallback value temporarily generated? To solve this problem, I registered and logged on to another account, and then accessed the above link directly! Yes, let's see the returned result. The json callback parameter can still be used even if it is not set. 5. Check your mailbox again and send me an email "Dear leiyou! 6. Click it! Successfully bound and activated!