当前位置:网站首页>Possible problems with password retrieval function (supplementary)
Possible problems with password retrieval function (supplementary)
2022-06-11 04:05:00 【Sword-heart】
0x00 Background introduction
I have seen a summary of password recovery vulnerabilities before , Now we see some new situations , Write it out to add .
link : Possible problems with password retrieval function
0x01 review
Already in the last article 7 Here's the point :
1 2 3 4 5 6 7 8 |
|
0x02 Add
One . Skip the validation step 、 Ways to retrieve , Go directly to the set new password page
Two . When retrieving the password, the authentication code is sent without verifying whether the user name matches the mailbox on the server
http://www.zhaojin97.cn/read-196.html
3、 ... and . Returned when resetting the password token It is not bound to the account and verification code
Or the above Meizu password reset problem
Four . The server only verifies whether the corresponding verification information exists , Failed to verify whether it matches the account number
WooYun: OPPO The mobile phone resets any account password (3)
WooYun: Second reset OPPO Any account password on the mobile official website ( Second change )
WooYun: OPPO Change any account password
5、 ... and . Verify the server's return information locally , Determine whether to perform password reset , But its return information is controllable , Or what you can get
WooYun: oppo Reset arbitrary user password vulnerability (4)
6、 ... and . Sending SMS and other verification information is carried out locally , It can be controlled by modifying the return package
WooYun: OPPO Change any account password -3
WooYun: OPPO Change any account password -2
7、 ... and . When submitting a new password , Only partially controllable information is verified to match
WooYun: AA Find any password of carpool network 2
8、 ... and . There is an injection vulnerability in retrieving the password
0x03 Repair plan
Retrieving password credentials is complex and unpredictable , Any action is performed on the server side , The transmitted verification parameters shall be encrypted , At the same time, filter the parameters
This article comes from the dark cloud knowledge base , The copyright of this article belongs to Wuyun knowledge base !
边栏推荐
- Market prospect analysis and Research Report of pipe and hose press fitting tools in 2022
- 代码复现CSRF攻击并解决它
- Docker swarm installs redis cluster (bitnami/redis cluster:latest)
- ETH 中继接口
- Radar emitter modulation signal simulation (code)
- Writing shell scripts using vscode
- JMeter piezometric interface programming North
- Lexical analyzer for compiling principle notes
- Matlab reports an error when trying to use * * * as a function problem, and tries to execute script PCA as a function:
- 华生·K的秘密日记
猜你喜欢

强烈推荐这款神器,一行命令将网页转PDF!

How to improve the efficiency of regression testing

Build local source 2.0 for Galaxy Kirin server version

A - Eddy‘s AC难题(C语言)

This artifact is highly recommended. One line command will convert the web page to PDF!

Shopping and retail backstage management system of chain supermarket based on SSM framework

ESP series module burning firmware

2022-06-10:薯队长从北向南穿过一片红薯地(南北长M,东西宽N),红薯地被划分为1x1的方格, 他可以从北边的任何一个格子出发,到达南边的任何一个格子, 但每一步只能走到东南、正南、西南方向的

Source Insight 4.0设置注释与反注释的快捷键

基于SSM的大学生社团管理系统
随机推荐
Guide de migration Maui
VNC remote configuration of Galaxy Kirin server system
Thoughts on the number of threads and CPU caused by the CPU load high alarm
基于SSM的大学生社团管理系统
Interface performance optimization ideas
[interpretable] | axiomatic attribute for deep networks
Run Skynet for the first time
关于重复发包的防护与绕过
Google 有哪些牛逼的开源项目?
【CNN】|How much position information do convolutional neural networks encode?
7. 列表标签
MAUI 遷移指南
如何提高回归测试效率
难忘时刻
After the installation of Damon database is completed, query whether it is case sensitive
app直播源码,平台登录页面实现和修改密码页面实现
MAUI 迁移指南
Student teacher examination management system based on SSM framework
Detailed explanation of network time synchronization (NTP network timing) of video monitoring system
Shell script binary encryption