当前位置:网站首页>Possible problems with password retrieval function (supplementary)
Possible problems with password retrieval function (supplementary)
2022-06-11 04:05:00 【Sword-heart】
0x00 Background introduction
I have seen a summary of password recovery vulnerabilities before , Now we see some new situations , Write it out to add .
link : Possible problems with password retrieval function
0x01 review
Already in the last article 7 Here's the point :
1 2 3 4 5 6 7 8 |
|
0x02 Add
One . Skip the validation step 、 Ways to retrieve , Go directly to the set new password page
Two . When retrieving the password, the authentication code is sent without verifying whether the user name matches the mailbox on the server
http://www.zhaojin97.cn/read-196.html
3、 ... and . Returned when resetting the password token It is not bound to the account and verification code
Or the above Meizu password reset problem
Four . The server only verifies whether the corresponding verification information exists , Failed to verify whether it matches the account number
WooYun: OPPO The mobile phone resets any account password (3)
WooYun: Second reset OPPO Any account password on the mobile official website ( Second change )
WooYun: OPPO Change any account password
5、 ... and . Verify the server's return information locally , Determine whether to perform password reset , But its return information is controllable , Or what you can get
WooYun: oppo Reset arbitrary user password vulnerability (4)
6、 ... and . Sending SMS and other verification information is carried out locally , It can be controlled by modifying the return package
WooYun: OPPO Change any account password -3
WooYun: OPPO Change any account password -2
7、 ... and . When submitting a new password , Only partially controllable information is verified to match
WooYun: AA Find any password of carpool network 2
8、 ... and . There is an injection vulnerability in retrieving the password
0x03 Repair plan
Retrieving password credentials is complex and unpredictable , Any action is performed on the server side , The transmitted verification parameters shall be encrypted , At the same time, filter the parameters
This article comes from the dark cloud knowledge base , The copyright of this article belongs to Wuyun knowledge base !
边栏推荐
- Construction of esp8266/esp32 development environment
- Manual testing cannot be changed to automated testing. What is missing?
- 高考结束,可以干什么事情,专业应该如何选择?-- 来自一个在校大学生的肺腑之言
- Source Insight 4.0设置注释与反注释的快捷键
- Lua removing elements from a loop in a list
- Market prospect analysis and Research Report of denitrification unit in 2022
- 雷达辐射源调制信号仿真(代码)
- Shell script binary encryption
- Docker uses PXC to build a MySQL Cluster (mysql:5.7.24)
- 什么样的人才是幸福的?
猜你喜欢

Guide de migration Maui

WPF of open source project hero alliance

Thoughts on the number of threads and CPU caused by the CPU load high alarm

基于SSM的大学生社团管理系统

Sentence s, paragraph P in VIM text object

强烈推荐这款神器,一行命令将网页转PDF!

大厂外包or自研公司?测试人找工作怎么选?

Student online education and teaching course management system based on SSM framework

SSLStrip 终极版 —— location 劫持

Maui migration guide
随机推荐
Market prospect analysis and Research Report of welding laser in 2022
2022爱分析· 隐私计算厂商全景报告 | 爱分析报告
Radar emitter modulation signal simulation (code)
Optimize your code execution efficiency with completabilefuture
让人感到心灵平静,阳光温暖的图片
代码复现CSRF攻击并解决它
你知道MallBook分账与银行分账的区别吗?
大厂外包or自研公司?测试人找工作怎么选?
Manual testing cannot be changed to automated testing. What is missing?
Large factory outsourcing or self research company? How to choose a job for a tester?
Skynet source code analysis make
什麼樣的人才是幸福的?
Why does the hospital comprehensive security system synchronize the NTP clock of the network server?
Interface performance optimization ideas
手工测试转不了自动化测试,缺的是什么?
Simulation of radar emitter modulated signal
Implementation of one-dimensional convolutional neural network CNN based on FPGA (V) data quantization (with code)
开源项目 英雄联盟 之WPF
Pictures that make people feel calm and warm
雷达辐射源调制信号仿真