当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0148946

漏洞标题:美图网某处设计不当可导致撞库用户(可查看用户地址手机号交易订单等)

相关厂商:美图秀秀

漏洞作者: 路人甲

提交时间:2015-10-23 17:39

修复时间:2015-12-07 17:52

公开时间:2015-12-07 17:52

漏洞类型:设计缺陷/逻辑错误

危害等级:低

自评Rank:3

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-10-23: 细节已通知厂商并且等待厂商处理中
2015-10-23: 厂商已经确认,细节仅向厂商公开
2015-11-02: 细节向核心白帽子及相关领域专家公开
2015-11-12: 细节向普通白帽子公开
2015-11-22: 细节向实习白帽子公开
2015-12-07: 细节向公众公开

简要描述:

美图网某处设计不当可导致撞库用户(可查看用户地址手机号交易订单等)

详细说明:

http://login.meitu.com/这个好像就是主站的登录位置哦,发现没有登录限制,然后抓包用户名和密码都是明文传输的

1.png


2.png


然后测试撞库用户,这里直接给出部分成功帐号证明:
359605603@qq.com long359620 374
wjl440@qq.com 5312900 374
345695328@qq.com xialiu 374
229633534@qq.com 871124 374
124964516@qq.com 7788250 374
313113128@qq.com 8223358520 374
45766047@qq.com wwwwww 374
65839546@qq.com 11998866 374
76567050@qq.com tony1219 374
zjg461274875@qq.com 15991251438 374
331810280@qq.com 3183545 374
cc166@qq.com hahahaha 374
445811257@qq.com 445811257 374
553862222@qq.com 553862222 374
caicai8872@qq.com 19820909 374
hehe767@qq.com 54088d11 374
16540837@qq.com 521124 374
591412238@qq.com cc890923 374
332932078@qq.com fanfan1986 374
550465419@qq.com 123456 374
263131104@qq.com ivan1987 374
182446496@qq.com 80994547 374
361477024@qq.com zhouyuan 374
646995939@qq.com 7127759 374
297157457@qq.com 139603399 374
605080429@qq.com 13282873856 374
nsey@qq.com benjiaming 374
543541998@qq.com 543541998 374
491712201@qq.com 491712201 374
31471588@qq.com 53837370 374
517251189@qq.com 7440017 374
fhqswcan@qq.com fhqswcdx 374
41756477@qq.com 6171679 374
kofcs@qq.com 30122248 374
49013@qq.com 21110011 374
287118254@qq.com wwdk584520 374
549517231@qq.com 549517231 374
264059476@qq.com 264059476 374
vicki657@vip.qq.com 65723511 374
woaini_285174156@qq.com fsq1988 374
114845768@qq.com 75342837 374
393024678@qq.com 2494321 374
zhangnan252398330@qq.com 3612119 374
27133459@qq.com 8103285 374
434445207@qq.com 64776627 374
328536783@qq.com SHADOW 374
61708268@qq.com 5211314ws 374
ripple_bb@qq.com 129500bee 374
371480738@qq.com 1987731 374
24146150@qq.com 200432 374
594187656@qq.com wxy891028 374
279764086@qq.com wh16435287 374
546303719@qq.com woshilvxin 374
43339160@qq.com 198212 374
61574225@qq.com lianyan 374
564096064@qq.com wangjing 374
dingdongbaby@qq.com 198649 374
30646077@qq.com 19861115 374
479514879@qq.com 131417 374
surunxiang@qq.com 7121962 374
42259454@qq.com 2930868 374
473949550@qq.com jiaoxuan 374
505217066@qq.com 3987219 374
304596550@qq.com 364623042 374
253748586@qq.com 9612355623 374
378523041@qq.com 901211 374
539770507@qq.com 12131212 374
276673267@qq.com 276673267 374
250076236@qq.com 104030 374
850299@qq.com zxcv123 374
455238025@qq.com 330196436 374
419410559@qq.com whynotbaby 374
22377201@qq.com 22377201 374
240100641@qq.com 3326419 374
317366820@qq.com chao1209 374
420368736@qq.com cl123456 374
249124401@qq.com 23232323 374
598357178@qq.com 211314 374
391988188@qq.com 123321 374
121517199@qq.com 121517199 374
shy_1988@qq.com shyshy 374
573825409@qq.com 19950607 374
120777576@qq.com 881017 374
lovehebe2@qq.com 1234560 374
tongxin701@qq.com 19890205 374
275931742@qq.com 65206838 374
404717831@qq.com 1091090202 374
1101806@qq.com zxj198378 374
77509333@qq.com 3316588 374
4686919@qq.com 6719903 374
7334536@qq.com 19910513 374
479667962@qq.com 210614 374
yefei_495715706@qq.com yefei19891117 374
154143483@qq.com 9992385260 374
lijinrui_198439@qq.com 75525705 374
55392543@qq.com 118926 374
380639841@qq.com 258258 374
410213535@qq.com woaiwojia77 374
758091129@qq.com 87513214 374
mengyi727@qq.com 900915 374
fengshanyin@vip.qq.com fsy379999 374
725643889@qq.com 1029384756 374
449540564@qq.com 2125843789 374
873326681@qq.com 456421 374
258385031@qq.com 861020 374
liu030211@qq.com 233633 374
522411758@qq.com 19910821 374
353810862@qq.com 8992408 374
22@qq.com 123456 374
386378628@qq.com qw8125733 374
245785145@qq.com a12345 374
535853690@qq.com 13812513872 374
shaung0@qq.com 870519 374
411829537@qq.com 411829537 374
444858666@qq.com 7758521 374
175267231@qq.com 13530387765 374
176941244@qq.com 101419 374
172182219@qq.com 7758521 374
252597140@qq.com 3514926945 374
503728711@qq.com 758521 374
831451@qq.com 198589 374
499086706@qq.com haoya860206 374
137675170@qq.com 19930921 375
454002130@qq.com weiqingy 375
15625074@qq.com 65660250520 375
514804008@qq.com 1989922 415
443501350@qq.com a123456 903
belmont@vip.qq.com asahina 905
主站登录证明(有的可能是没绑定手机号的原因登录之后就会让绑定手机号,但是可以证明成功撞库,因为如果用户名和密码错误的话就会提示帐号或密码错误,如果正确的话没有绑定的就会让绑定,绑定了的就会进去了):

3.png


5.png


6.png

漏洞证明:

3.png


5.png


6.png

修复方案:

加密

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:低

漏洞Rank:5

确认时间:2015-10-23 17:50

厂商回复:

感谢白帽子的提醒!

最新状态:

暂无


漏洞评价:

评价