Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Modification response package for logic vulnerabilities bypassing login verification

Shulou Source: shulou.com Published: 2022-06-01 03:29:06 10月05日 Update

   logic loophole is due to lax or complex logic of the program, which is exploited by people who tamper with relevant data to achieve their own purpose, such as bypassing login verification.

Introduction to the principle of simple operation in practice

   (here is only a brief introduction to the principle of this practice) due to logical defects in checking the login account and password, or again using the relevant parameters returned by the server as the final login credentials, the login restrictions can be bypassed. For example, the server returns a flag parameter as a criterion for whether the login is successful, but the final login success of the code is to obtain this flag parameter as the final verification. Those who cause * * can bypass the login limit by modifying the flag parameter!

Truncate packet

Set up display response package

Modify response package

Login succeeded

The second way to modify the response package

This kind of modification of    is suitable for those that need to be modified later, such as modifying cookie to maintain access!

Repair suggestion

   modifies the verification logic, such as whether the login is successful, the server returns a parameter, but this is the final verification, and there is no need to use the returned parameters as the final basis for judging whether the login is successful or not!

Tags: Login parameters logic success server service authentication principle data practice restrictions vulnerabilities lax complexity code again credentials passwords that is recommendations Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Shulou Technology vpn Apple Microsoft macOS