当前位置:网站首页>Remember to get the password of college student account once, from scratch
Remember to get the password of college student account once, from scratch
2022-07-24 06:18:00 【Ant view network security】
Statement : My original intention is to share and popularize network knowledge , If readers do any harm to network security, they will bear the consequences , It has nothing to do with Hetian Wangan laboratory and the original author , This article is the original work of Hutian network security laboratory , If you want to reprint , Please indicate the source !
This record , It is intended to show the strength of information collection and arouse the attention of colleges and universities to network security ..…, See how to get student accounts from scratch …
After understanding the idea , You may be blown away by your masters …
0x01: Look at this window first
Http://xxx.xxx.xxx.xxx/login

If you find your password, you can either retrieve it by email , Or the cell phone is retrieved ….

0x02 Up to now , Probably
1. The mobile phone verification code exploded , Premise : Know the student number + cell-phone number + Resetting the password is to send a verification code, not to connect
2. Mailbox verification code burst , Premise : Know the student number + mailbox + Resetting the password is to send a verification code, not to connect
The above two ideas , Mostly hanging ….
( Because I dug the hole first , Just wrote the article ,
So I know the student number in advance + cell-phone number ….)


The verification code is verified …. The road is blocked ….
0x03: See how to do information gathering
The process of collecting information , Be sure to learn the common excel To clean the data , Find our useful accounts …
Google Dafa …



After half an hour of searching , I found such an announcement , Yes, this is the announcement , Let me have a breakthrough direction …
3、 The email user name is : Student number @xxx.xxx.xxx.cn, The initial password is :xxxx+ Birthday on the ID card 8 position ( Specific date ).Xxxx.xxx..xxx.
4、 The email in the account information of the online service hall has been bound to the student's email account by default

It is not necessary to find the user's password to obtain the account , Changing the password is also a way of thinking , As long as you can log in , Then there is nothing to say …
From seeing this announcement , Our general idea has been established ….

Specific ideas :
Look for sensitive information --- Then reset her password by email --- Finally get the account with unified identity
continue google, Found a sensitive information leak …. Number of leaks 100 Bar or so

Here is a reminder : Many students may change the password of unified identity authentication , But many students will never change the password of their email , Often used to use the mobile phone number to obtain the verification code and change the password …
And we changed her password Use email to change password ….
Find its mailbox , Log in, good guy , Login successful ….

0x04: Unified identity authentication ….





Then we went into unified identity authentication ….
summary :
1. in general , The method is still the original method
2. Don't underestimate the harm of an account , Even low privileged accounts , It can also collect all its hair , Such as this ….
3. There are many ways to change your password , But it is recommended to use the mobile phone number to change the password , Never publish the password rules , Who knows what will happen ?
4. information gathering yyds, From a master, he set up such a view : The process of penetration testing , It's the process of collecting information to fight . Intranet is no exception ! If you collect the account passwords of many hosts , The horizontal process becomes the process of constantly entering the account password … And the movement is very small …
边栏推荐
- Using keras and LSTM to realize time series prediction of long-term trend memory -lstnet
- Flink function (1): rich function
- IA笔记 1
- 什么是单调队列
- Basic knowledge of unity and the use of some basic APIs
- Configure a fixed remote desktop address [intranet penetration, no need for public IP]
- Sort ArrayList < ArrayList < double> >
- Xshell remote access tool
- Unity2d game let characters move - Part 1
- leetcode 不用加减乘除算加法 || 二进制中1的个数
猜你喜欢
随机推荐
什么是单调栈
leetcode剑指offer JZ42 连续子数组的最大和
Opencv reads avi video and reports an error: number < Max_ number in function ‘icvExtractPattern
常见十大漏洞总结(原理、危害、防御)
Dameng database_ Common initialization parameters
How to build a website full of ritual sense and publish it on the public website 2-2
Map the intranet to the public network [no public IP required]
不租服务器,自建个人商业网站(3)
公网访问内网IIS网站服务器【无需公网IP】
Unity2d game let characters move - Part 1
一批面试题及答案_20180403最新整理
Openpose Unity 插件部署教程
++cnt1[s1.charAt(i) - ‘a‘];
IP notes (9)
UE4 reload system 2. Scene capture of reload system
Calculation steps of principal component analysis
IP job (2) rip
初识图形学
将内网映射到公网【无需公网IP】
data normalization








