文章出處

喜馬拉雅某接口限制不當導致大量撞庫問題

喜馬拉雅FM APP 登陸接口可以撞庫
 

POST /mobile/login HTTP/1.1Host: mobile.ximalaya.comAccept: */*Content-Type: application/x-www-form-urlencodedConnection: closeProxy-Connection: keep-aliveCookie: domain=.ximalaya.com; path=/; channel=ios-b1; 1&_device=iPhone&1DCAA510-BC6C-4C1E-BD41-3E2B9B78E607&4.3.20; impl=com.gemd.iting; SUP=39.996229%2C116.476479%2C1448610697553; XUM=1DCAA510-BC6C-4C1E-BD41-3E2B9B78E607; c-oper=%E6%9C%AA%E7%9F%A5; net-mode=WIFI; res=750%2C1334User-Agent: ting_v4.3.20_c5(CFNetwork, iPhone OS 9.1, iPhone7,2)Accept-Language: zh-cnAccept-Encoding: gzip, deflateContent-Length: 90password=123456&account=18600111147&device=iPhone&XUM=1DCAA510-BC6C-4C1E-BD41-3E2B9B78E607

1.jpg


密碼都是12345
 

1.jpg

 

喜馬拉雅FM APP 登陸接口可以撞庫
 

POST /mobile/login HTTP/1.1Host: mobile.ximalaya.comAccept: */*Content-Type: application/x-www-form-urlencodedConnection: closeProxy-Connection: keep-aliveCookie: domain=.ximalaya.com; path=/; channel=ios-b1; 1&_device=iPhone&1DCAA510-BC6C-4C1E-BD41-3E2B9B78E607&4.3.20; impl=com.gemd.iting; SUP=39.996229%2C116.476479%2C1448610697553; XUM=1DCAA510-BC6C-4C1E-BD41-3E2B9B78E607; c-oper=%E6%9C%AA%E7%9F%A5; net-mode=WIFI; res=750%2C1334User-Agent: ting_v4.3.20_c5(CFNetwork, iPhone OS 9.1, iPhone7,2)Accept-Language: zh-cnAccept-Encoding: gzip, deflateContent-Length: 90password=123456&account=18600111147&device=iPhone&XUM=1DCAA510-BC6C-4C1E-BD41-3E2B9B78E607

 

1.jpg


密碼都是12345
 

1.jpg

解決方案:

 

你們最專業.


就愛閱讀www.92to.com網友整理上傳,為您提供最全的知識大全,期待您的分享,轉載請注明出處。
歡迎轉載:http://www.kanwencang.com/bangong/20161116/56142.html

文章列表


不含病毒。www.avast.com
全站熱搜
創作者介紹
創作者 大師兄 的頭像
大師兄

IT工程師數位筆記本

大師兄 發表在 痞客邦 留言(0) 人氣()