zoukankan      html  css  js  c++  java
  • 某app的安全性分析过程

    交互过程如下,可以发现问题很多

    http://www.ixxxx.com//api/index/app
    图片验证码:
    {"data":{"imgCode":"","loginName":"1371111111"},"code":"user-checkImgeCode"}

    验证手机和验证码:获取到key在注册的时候进行验证,防止恶意注册
    {"data":{"phoneCode":"454336","recommend":"365","loginName":"1371111111","type":1},"code":"auth-checkPhone"}
    {"status":1,"msg":"效验成功","type":0,"data":{"key":"f60b29cefa24ff71cc01c1931040f016"}}


    注册用户 :验证刚刚的key以保证用户手机收过验证码
    {"data":{"loginPwd":"aaaaa111111","secret_key":"f60b29cefa24ff71cc01c1931040f016","parentId":"","loginName":"1371111111","recommend":"365","phoneCode":"454336"},"code":"user-register"}
    {"status":1,"msg":"注册成功","type":0,"data":{"token":"5643777675a4998b1672901.68959906","chu":1,"unique":"474C8E76A4D8F613DABF06807CF6F1B7"}}


    修改密码:需要图片验证码,通过token进行修改
    {"data":{"newpassword1":"aaaaa11111","code":"9587","newpassword":"aaaaa11111","oldpassword":"aaaaa111111"},"code":"user-editPassword"}
    {"status":1,"msg":"修改成功","type":0}

    登录获取token(每次登录补不同):带deviceId: 6AF6B4DB-DF82-F8BA-2495-792465D9607C
    {"data":{"verifyCode":"","loginName":"1371111111","loginPwd":"aaaaa11111"},"code":"user-login"}
    {"status":"1","msg":"登录成功","type":0,"data":{"token":"10899269405a499e09705892.85853445","chu":1,"unique":"474C8E76A4D8F613DABF06807CF6F1B7"}}

    头部
    POST //api/index/app HTTP/1.1
    Host: www.1371111111.com
    Accept: */*
    version: 3.1.0
    Connection: keep-alive
    Accept-Encoding: gzip, deflate
    Accept-Language: zh-Hans-CN;q=1
    token: 5643777675a4998b1672901.68959906
    Content-Type: application/json
    deviceId: 6AF6B4DB-DF82-F8BA-2495-792465D9607C
    version: 3.1.0
    User-Agent: AiXiang/3.1.0 (iPhone; iOS 9.3.4; Scale/3.00)
    Connection: keep-alive
    Content-Length: 33
    device: 3

  • 相关阅读:
    Oracle配置监听
    Oracle创建表空间和分配用户权限
    Dijkstra
    【刷题】【dp】【记忆化搜索】单词游戏
    【刷题】【记忆化搜索】【dp】Longtail Hedgehog
    【刷题】【dp】 Make The Fence Great Again
    【技巧】【卡常】
    【二分】【基础】(跳石头)(合并果子)(蚯蚓)
    【笔记】两种交换元素的方案对比
    【刷题】【单调栈】请客
  • 原文地址:https://www.cnblogs.com/sung/p/8166354.html
Copyright © 2011-2022 走看看