A method and device for detecting logic vulnerabilities in password reset based on verification defects

By installing a vulnerability detection device between the client and server of the platform to be tested, intercepting and modifying the password reset request package, detecting whether there are password reset logic vulnerabilities, solving the problem of difficulty in systematic and comprehensive detection in the existing technology, and achieving efficient vulnerability detection.

CN116319037BActive Publication Date: 2025-06-204399 NETWORK
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310312899.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-28
Publication Date
2025-06-20
Estimated Expiration
2043-03-28

AI Technical Summary

Technical Problem

The existing technology is difficult to systematically detect any password reset vulnerability, and the logical attempts to detect and insufficient detection caused by the uneven level of technical personnel are not considered by the automation program.

Method used

By installing a vulnerability detection device between the client and server of the platform to be tested, intercept the password reset request packet, modify the user's identity information, and determine whether the confirmation response packet that has successfully reset the password can be successfully intercepted, to determine whether there is a password reset logic vulnerability.

Benefits of technology

It realizes systematic and comprehensive detection of whether there are any arbitrary password reset vulnerabilities, solves the problems of limiting the level of automation programs and technicians, and provides a systematic and comprehensive detection method.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116319037B_ABST
    Figure CN116319037B_ABST
Patent Text Reader

Abstract

The present invention provides a method and apparatus for detecting password reset logic vulnerabilities based on verification defects. A vulnerability detection device is installed between the client of the platform to be tested and the server of the platform to be tested. The vulnerability detection device intercepts the password reset request packet sent by the client of the platform to be tested to the server of the platform to be tested, modifies the user identity information in the password reset request packet to the identity information of other users, and sends it to the server of the platform to be tested. It is determined whether an acknowledgement response packet indicating successful password reset returned by the server of the platform to be tested can be intercepted. If so, it is concluded that there is a password reset logic vulnerability in the server of the platform to be tested. The present invention systematically and comprehensively detects whether there are any password reset vulnerability problems, which not only solves the problem of logical attempt detection that is not considered or cannot be performed by automated programs, but also provides a systematic and comprehensive method for detecting any password reset vulnerabilities to technicians with uneven technical levels.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security, and particularly relates to a method and device for detecting password reset logic vulnerabilities based on verification defects. Background Art

[0002] The development of Internet technology has promoted the arrival of the information age. The basis for people to achieve information sharing and communication through the Internet is that users need to register and log in to personal accounts on Internet platforms. Usually, due to various factors, there will be situations where users cannot log in to their personal accounts. Therefore, it is essential that each business platform must have the function of resetting passwords. As a result, the scope of any password reset vulnerability is getting larger and larger.

[0003] Any password reset vulnerability is usually caused by improper software design or verification logic defects. Any password reset vulnerability belongs to a type of business logic vulnerability. An attacker can reset the password of any user without knowing the original password and easily obtain all access rights of that user, which can lead to various serious consequences such as the leakage of sensitive information, account theft, and infringement of user privacy.

[0004] In the prior art, there are generally two ways to detect whether there is any password reset vulnerability on a platform. One is the Chinese patent of Lou Yu and Fan Yuan, "A Method, Device and Medium for Detecting Any Account Password Reset Logic Vulnerability", with the publication number CN112165473A, which discloses a method for automatically judging whether a verification code sending request is initiated in a web page to be detected through a preset program, and further optimizing the method for determining that there is any account password reset logic vulnerability in the web page to be detected in four scenarios related to verification codes. The other is that technicians judge whether there is any password reset vulnerability in the platform to be tested by combining the above-mentioned design steps of resetting passwords in sequence with technical experience. However, the first method is difficult to comprehensively detect any password reset vulnerability systematically due to the logical attempts that are not considered or cannot be carried out by the automated program, and the second method is also difficult to comprehensively detect any password reset vulnerability systematically because of the uneven levels of technicians themselves.

[0005] Therefore, how to comprehensively detect any password reset vulnerability systematically is a technical problem that needs to be solved by those skilled in the art at present. Summary of the Invention

[0006] Aiming at the defects existing in the prior art, the purpose of the present invention is to provide a method for detecting password reset logic vulnerabilities based on verification defects, aiming to systematically solve the problem that it is difficult to comprehensively detect any password reset vulnerability systematically due to the logical attempts that are not considered or cannot be carried out by the automated program and the uneven levels of technicians themselves; another purpose of the present invention is to provide a device and a storage medium for detecting password reset logic vulnerabilities based on verification defects, both of which have the above-mentioned beneficial effects.

[0007] The technical solution adopted by the present invention is as follows:

[0008] The present invention provides a method for detecting password reset logic vulnerabilities based on verification defects, including the following steps:

[0009] Step 1, install a vulnerability detection device between the client of the platform to be tested and the server of the platform to be tested;

[0010] Step 2, the vulnerability detection device detects whether there is a password reset logic vulnerability in the server of the platform to be tested:

[0011] Step 2.1, the vulnerability detection device intercepts the password reset request packet sent by the client of the platform to be tested to the server of the platform to be tested; the password reset request packet carries the user identity information of the user whose password needs to be reset;

[0012] Step 2.2, the vulnerability detection device intercepts the password reset request packet and modifies the user identity information to the identity information of other users to obtain a modified password reset request packet;

[0013] Step 2.3, the vulnerability detection device sends the modified password reset request packet to the server of the platform to be tested;

[0014] Step 2.4, the vulnerability detection device determines whether it can intercept the confirmation response packet indicating successful password reset returned by the server of the platform to be tested. If it can, it indicates that the server of the platform to be tested does not verify the user identity information, and a conclusion that there is a password reset logic vulnerability in the server of the platform to be tested is obtained.

[0015] Preferably, in step 2.1, the user identity information of the user whose password needs to be reset includes user parameters, database user table field parameters, and user identifiers in the current Cookie field.

[0016] Preferably, the user parameters include username, user mobile phone number phone, and user email address email; the database user table field parameters include user id.

[0017] Preferably, it further includes:

[0018] The vulnerability detection device detects whether there is a password reset logic vulnerability in the server of the platform to be tested in the following manner:

[0019] The vulnerability detection device intercepts the request for selecting the email binding verification method sent by the client of the platform to be tested to the server of the platform to be tested, and forwards the request for selecting the email binding verification method to the server of the platform to be tested;

[0020] The vulnerability detection device obtains the password reset link received by the bound email.

[0021] The vulnerability detection device determines whether the password reset link contains the user identity information of the user whose password needs to be reset. If so, it modifies the user identity information of the user whose password needs to be reset to other user identity information, thereby obtaining a modified password reset link.

[0022] The vulnerability detection device determines whether it can successfully access the modified password reset link. If it can, it means that the vulnerability detection device sends a request to reset the password for the other user identity information to the server of the platform to be tested, and determines whether it can intercept the confirmation response packet indicating successful password reset returned by the server of the platform to be tested. If it can, it indicates that the server of the platform to be tested does not perform verification on the user identity information, and a conclusion that there is a password reset logic vulnerability in the server of the platform to be tested is obtained.

[0023] Preferably, it further includes: Step 3, the vulnerability detection device detects whether there is a password reset logic vulnerability in the client of the platform to be tested.

[0024] Preferably, Step 3 is specifically as follows:

[0025] Step 3.1, the vulnerability detection device intercepts the authentication request containing authentication credential information sent by the client of the platform to be tested to the server of the platform to be tested.

[0026] Step 3.2, the vulnerability detection device modifies the authentication credential information in the authentication request to incorrect authentication credential information, obtains a modified authentication request, and sends the modified authentication request to the server of the platform to be tested.

[0027] Step 3.3, the vulnerability detection device intercepts the response packet of the authentication result sent by the server of the platform to be tested.

[0028] Step 3.4, the vulnerability detection device determines whether the intercepted response packet of the authentication result contains an error identification string. If so, it modifies the error identification string to a correct identification string, obtains a modified response packet of the authentication result, and sends the modified response packet of the authentication result to the client of the platform to be tested.

[0029] Step 3.5, the vulnerability detection device determines whether it can intercept the request packet for resetting a new password sent by the client of the platform to be tested. If it can intercept it, it means that the client of the platform to be tested has a password reset logic vulnerability.

[0030] Preferably, the authentication credential information includes mobile phone verification codes, email reset links, and answers to security question.

[0031] The present invention also provides a password reset logic vulnerability detection device based on verification defects. The password reset logic vulnerability detection device based on verification defects is connected to a client of a platform to be tested and a server of the platform to be tested through a network respectively.

[0032] The password reset logic vulnerability detection device based on verification defects includes a web page loading module, a defect detection module for the server of the platform to be tested, and a defect detection module for the client of the platform to be tested.

[0033] The web page loading module is configured to intercept a request packet sent by the client of the platform to be tested to the server of the platform to be tested, and a response packet returned by the server of the platform to be tested to the client of the platform to be tested.

[0034] The defect detection module for the server of the platform to be tested is configured to detect whether there is a password reset logic vulnerability in the server of the platform to be tested according to the request packet or the response packet intercepted by the web page loading module.

[0035] The defect detection module for the client of the platform to be tested is configured to detect whether there is a password reset logic vulnerability in the client of the platform to be tested according to the request packet or the response packet intercepted by the web page loading module.

[0036] The password reset logic vulnerability detection method and device provided by the present invention have the following advantages:

[0037] The password reset logic vulnerability detection method and device provided by the present invention divide the possible verification defects in the three pages implementing the three basic function points of the password reset of a conventional web service platform into two modules: defect detection for the client of the platform to be tested and defect detection for the server of the platform to be tested, and systematically and comprehensively detect whether there are any password reset vulnerability problems. It not only solves the problem of logical attempt detection that cannot be considered or performed by an automated program, but also provides a systematic and comprehensive method for technicians with uneven technical levels to detect any password reset vulnerabilities. Description of the Drawings

[0038] Figure 1 is a schematic flowchart of the password reset logic vulnerability detection method provided by the present invention;

[0039] Figure 2 is a structural diagram of the password reset logic vulnerability detection device provided by an embodiment of the present invention;

[0040] Figure 3It is a composition framework diagram of the page loading module in the password reset logic vulnerability detection device based on verification defects provided by the embodiments of the present invention. Detailed implementation manners

[0041] In order to make the technical problems, technical solutions and beneficial effects solved by the present invention more clear and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0042] A method and device for detecting password reset logic vulnerabilities based on verification defects provided by the present invention divide the possible verification defects in the three pages implementing the three basic function points of password reset in a conventional web service platform into two modules: client defect detection of the platform to be tested and server - side defect detection of the platform to be tested, and systematically and comprehensively detect whether there are any password reset vulnerability problems; it not only solves the logical attempt detection that cannot be considered or carried out by automated programs, but also provides a systematic and comprehensive method for technicians with uneven technical levels to detect any password reset vulnerabilities.

[0043] The present invention provides a method for detecting password reset logic vulnerabilities based on verification defects, including the following steps:

[0044] Step 1, install a vulnerability detection device between the client of the platform to be tested and the server of the platform to be tested;

[0045] Step 2, the vulnerability detection device detects whether there is a password reset logic vulnerability in the server of the platform to be tested:

[0046] Step 2.1, the vulnerability detection device intercepts the password reset request packet sent by the client of the platform to be tested to the server of the platform to be tested; the password reset request packet carries the user identity information of the password to be reset.

[0047] Among them, the user identity information of the password to be reset includes user parameters, database user table field parameters and user identifiers in the current Cookie field. As a specific embodiment, the user parameters include username, user mobile phone number phone and user email address email; the database user table field parameters include user id.

[0048] Step 2.2, the vulnerability detection device intercepts the password reset request packet and modifies the user identity information to other user identity information to obtain a modified password reset request packet;

[0049] Step 2.3, the vulnerability detection device sends the modified password reset request packet to the server of the platform to be tested;

[0050] Step 2.4, the vulnerability detection device determines whether it can intercept the confirmation response packet indicating successful password reset returned by the server of the platform under test. If it can, it indicates that the server of the platform under test does not verify the user identity information, and a conclusion that there is a password reset logic vulnerability in the server of the platform under test is obtained.

[0051] In the present invention, the vulnerability detection device can also detect whether there is a password reset logic vulnerability in the server of the platform under test in the following manner:

[0052] The vulnerability detection device intercepts the request for selecting the bound email verification method sent by the client of the platform under test to the server of the platform under test, and forwards the request for selecting the bound email verification method to the server of the platform under test;

[0053] The vulnerability detection device obtains the password reset link received by the bound email.

[0054] The vulnerability detection device determines whether the password reset link contains the user identity information of the user whose password needs to be reset. If so, it modifies the user identity information of the user whose password needs to be reset to other user identity information, thereby obtaining the modified password reset link.

[0055] The vulnerability detection device determines whether it can successfully access the modified password reset link. If it can, it means that the vulnerability detection device sends a request for resetting the password for the other user identity information to the server of the platform under test, and determines whether it can intercept the confirmation response packet indicating successful password reset returned by the server of the platform under test. If it can, it indicates that the server of the platform under test does not verify the user identity information, and a conclusion that there is a password reset logic vulnerability in the server of the platform under test is obtained.

[0056] It further includes:

[0057] Step 3, the vulnerability detection device detects whether there is a password reset logic vulnerability in the client of the platform under test.

[0058] Step 3 specifically is:

[0059] Step 3.1, the vulnerability detection device intercepts the authentication request containing authentication credential information sent by the client of the platform under test to the server of the platform under test; wherein, the authentication credential information includes mobile phone verification code, email reset link, and answer to security question.

[0060] Step 3.2, the vulnerability detection device modifies the authentication credential information in the authentication request to incorrect authentication credential information, obtains the modified authentication request, and sends the modified authentication request to the server of the platform under test;

[0061] Step 3.3: The vulnerability detection device intercepts the response packet of the authentication result sent by the server of the platform under test.

[0062] Step 3.4: The vulnerability detection device determines whether the response packet of the authentication result intercepted contains an error identification string. If so, it modifies the error identification string to a correct identification string to obtain a modified response packet of the authentication result, and sends the modified response packet of the authentication result to the client of the platform under test.

[0063] Step 3.5: The vulnerability detection device determines whether it can intercept the request packet for resetting a new password sent by the client of the platform under test. If it can be intercepted, it means that there is a password reset logic vulnerability in the client of the platform under test.

[0064] Reference Figure 2 , the present invention also provides a password reset logic vulnerability detection device based on verification defects. The password reset logic vulnerability detection device based on verification defects is connected to the client of the platform under test and the server of the platform under test through a network respectively;

[0065] The password reset logic vulnerability detection device based on verification defects includes a web page loading module, a server defect detection module of the platform under test, and a client defect detection module of the platform under test;

[0066] The web page loading module is used to intercept the request packet sent by the client of the platform under test to the server of the platform under test, and the response packet returned by the server of the platform under test to the client of the platform under test;

[0067] The server defect detection module of the platform under test is used to detect whether there is a password reset logic vulnerability in the server of the platform under test according to the request packet or response packet intercepted by the web page loading module; specifically, it is used to comprehensively detect the consistency verification of user information by the page loading module and the server of the platform under test, where the user information includes but is not limited to mobile phone number, verification code, database user id field, and user identifier. First, it is determined by the page loading module whether the verification step of page 2 can be skipped. If so, it enters the vulnerability determination module; it is determined by the page loading module whether the credential information for key page 2 authentication is directly returned in the response packet of page 2. If so, it enters the vulnerability determination module; further, the page loading module modifies any user information to determine whether the server of the platform under test comprehensively conducts user information consistency verification. If not, it enters the vulnerability determination module;

[0068] Vulnerability determination module: used to determine that there is any password reset logic vulnerability in the client of the platform under test or the server of the platform under test.

[0069] The defect detection module of the client of the platform to be tested is used to detect whether there is a password reset logic vulnerability in the client of the platform to be tested according to the request packet or response packet intercepted by the web page loading module. Specifically, the defect detection module of the client of the platform to be tested: is used to comprehensively detect from two aspects of the page loading module and the client source code; first, judge the credential information for identity verification of the key page 2 through the page loading module, including but not limited to mobile phone verification codes, password reset links for security question email boxes, and security questions, and check whether it is judged by the client. If so, enter the vulnerability determination module, and judge whether the credential information is directly displayed in the source code of the client of the platform to be tested. If so, enter the vulnerability determination module;

[0070] The following introduces specific embodiments:

[0071] The web page loading module is used to capture the request packets and response packets of the following three pages according to the function attack order:

[0072] Page 1, the request message sent by the client of the platform to be tested to the server of the platform to be tested for verifying the account that needs password reset, and the response message returned by the server of the platform to be tested;

[0073] Page 2, the request message sent by the client of the platform to be tested to the server of the platform to be tested for selecting the identity verification method for the account on Page 1; among them, the identity verification methods include the email verification method for binding the email, the verification code verification method for binding the mobile phone, and the security question verification method.

[0074] Page 3, after the identity verification method passes, the client of the platform to be tested sends a request to the server of the platform to be tested to reset the new password, that is: the request to reset the new password for the account determined on Page 1, and the request carries the new password; and the confirmation message returned by the server of the platform to be tested for successfully resetting the new password.

[0075] S10: Judge whether the defect detection module of the client of the platform to be tested detects that there is a password reset logic vulnerability in the client of the platform to be tested:

[0076] Step 1, the client of the platform to be tested sends a request packet for Page 2 to the server of the platform to be tested, that is: the client of the platform to be tested sends the selected identity verification method and the corresponding identity verification credential information to the server of the platform to be tested; the identity verification methods include: mobile phone verification codes, email reset links, and security question answers. The identity verification credential information refers to: if the mobile phone verification code verification method is selected, the identity verification credential information is the mobile phone verification code; if the email reset link verification method is selected, the identity verification credential information is the email reset link; if the security question answer verification method is selected, the identity verification credential information is the security question answer.

[0077] The request packet of page 2 is intercepted by the web page loading module and sent to the defect detection module of the client of the platform under test;

[0078] The defect detection module of the client of the platform under test modifies the authentication credential information in the authentication request to incorrect authentication credential information, obtains the modified authentication request, and sends the modified authentication request to the server of the platform under test;

[0079] Step 2: The defect detection module of the client of the platform under test intercepts the response packet of the authentication result sent by the server of the platform under test;

[0080] Determine whether the response packet of the authentication result intercepted contains an error identification string, for example, one of the error identification strings "0", "false", "no". If so, modify the error identification string to a correct identification string, for example, replace the corresponding "0", "false", "no" with "1", "true", "yes", obtain the modified response packet of the authentication result, and send the modified response packet of the authentication result to the client of the platform under test;

[0081] Step 3: The defect detection module of the client of the platform under test determines whether the client of the platform under test can jump to page 3, that is, determines whether it can intercept the request packet for resetting the new password sent by the client of the platform under test. If it can, it indicates that there is a password reset logic vulnerability in the client of the platform under test.

[0082] On the basis of the above embodiments, this embodiment further explains and optimizes the technical solution. Specifically:

[0083] The client of the platform under test selects one of the three verification methods of mobile phone number, email, and security question verification on page 2. After clicking the requests for sending the mobile phone verification code, sending the email reset link, and filling in the answer to the security question, the defect detection module of the client of the platform under test loads the current page source code of the client of the platform under test through the web page loading module, and determines whether the current page source code of the client of the platform under test contains the correct mobile phone verification code / ^\d{4}|\d{6}$ / , the correct email reset link (https?|ftp|file): / / [-A-Za-z0-9+&@# / %?=~|!:,.;]+[-A-Za-z0-9+&@# / %=

[0084] ~|], and the correct answer to the security question; if so, it means that there is a password reset logic vulnerability in the client of the platform under test.

[0085] That is to say, after the client of the platform to be tested submits the mobile verification code, email reset link, or security question answer to the server of the platform to be tested, the mobile verification code, email reset link, or security question answer should not continue to exist locally on the client of the platform to be tested. If it exists, it indicates that the mobile verification code, email reset link, or security question answer is prone to leakage, and there is a password reset logic vulnerability in the client of the platform to be tested.

[0086] Based on the above embodiments, this embodiment further explains and optimizes the technical solution. Specifically, when the client of the platform to be tested operates on page 1 and page 2, the defect detection module of the client of the platform to be tested uses a script program to match the URL in the page source code of the client of the platform to be tested with the regular expression (https?|ftp|file): / / [-A-Za-z0-9+&@# / %?=~|!:,.;]+[-A-Za-z0-9+&@# / %=~|], and determines whether there is a password reset link for page 3 in the page source code URL of the client of the platform to be tested. If so, it is determined that there is a password reset logic vulnerability in the client of the platform to be tested.

[0087] That is to say, in the case of no password reset logic vulnerability, only when both page 1 and page 2 are successfully executed normally, and after the server of the platform to be tested sends a message indicating that the identity verification has passed, the client of the platform to be tested is allowed to access the password reset link for page 3 through the URL. In the case of this embodiment, the server of the platform to be tested has not sent a message indicating that the identity verification has passed, but the client of the platform to be tested already has the URL to access the password reset link for page 3, indicating that there is a password reset logic vulnerability in the client of the platform to be tested.

[0088] Among them, the defect detection module of the server of the platform to be tested includes:

[0089] S20: Determine whether there is a weak token in the password reset link for the bound email. The specific steps are as follows:

[0090] Step 1: After the client of the platform to be tested selects the email identity verification method through binding by page 2, the bound email will receive a link with a password reset token; the password reset token link is obtained by the defect detection module of the server of the platform to be tested;

[0091] Step 2: The defect detection module of the server of the platform to be tested determines whether the token is a weak token. The weak token includes forms such as those that can easily discover the user ID, email, mobile phone number, tokens that can be predicted by developers using timestamps, certain encryption algorithms such as MD5, or encodings such as base64.

[0092] Step 3: If so, directly modify the user ID, Email, and mobile phone number in the token to other user information, or modify the user ID, Email, and mobile phone number information to other user information after decryption and decoding, and obtain the password reset link of the modified token.

[0093] Step 4: The defect detection module of the server of the platform to be tested determines whether it can successfully access and respond to the password reset link of the modified token. If so, it means that the server of the platform to be tested does not verify the user identity, resets the password of other users, and determines that there is a password reset logic vulnerability in the server of the platform to be tested.

[0094] Based on the above embodiments, this embodiment further explains and optimizes the technical solution. Specifically:

[0095] S30: The defect detection module of the server of the platform to be tested determines whether it can skip the identity verification process on Page 2 and directly send a password reset request. The specific steps are as follows:

[0096] Step 1: After the client of the platform to be tested normally operates Page 1 and Page 2 in sequence, the defect detection module of the server of the platform to be tested intercepts and saves the password reset request packet on Page 3.

[0097] Step 2: The defect detection module of the server of the platform to be tested uniformly modifies the values of the user information-related parameters in the Page 3 request packet, including "username", "email", and "phone", to other user information, obtains the modified Page 3 request packet, and then sends the modified Page 3 request packet to the server of the platform to be tested.

[0098] The defect detection module of the server of the platform to be tested determines whether it can intercept the confirmation message successfully executed by the server of the platform to be tested for the modified Page 3 request packet.

[0099] Step 3: If it can, it means that the server of the platform to be tested resets the password of other users, and determines that there is a password reset logic vulnerability in the server of the platform to be tested.

[0100] Based on the above embodiments, this embodiment further explains and optimizes the technical solution. Specifically:

[0101] Step 1: After the client of the platform to be tested normally operates Page 1 and Page 2 in sequence, the defect detection module of the server of the platform to be tested intercepts and saves the password reset request packet on Page 3.

[0102] Step 2: The client of the platform to be tested operates Page 1 and Page 2 in normal order again. On Page 2, select to obtain a mobile verification code or an email reset link or security question. Before clicking "Next" to send the request packet, that is to say, at this time, the server of the platform to be tested has recorded the mobile phone number, email address or security question sent by the client of the platform to be tested, but has not received the mobile verification code, email reset link or answer to the security question sent by the client of the platform to be tested.

[0103] At this time, the defect detection module of the server of the platform to be tested intercepts the request packet of Page 3 sent by the client of the platform to be tested, and uniformly modifies the values of the user information-related parameters in the request packet of Page 3, including "username", "email", and "phone", to other user information, obtaining the modified request packet of Page 3, and then sends the modified request packet of Page 3 to the server of the platform to be tested;

[0104] The defect detection module of the server of the platform to be tested determines whether it can intercept the confirmation message sent by the server of the platform to be tested for successfully executing the modified request packet of Page 3;

[0105] Step 3: If it can, it means that the server of the platform to be tested resets the password of other users, and it is determined that there is a password reset logic vulnerability in the server of the platform to be tested.

[0106] On the basis of the above embodiments, this embodiment further explains and optimizes the technical solution. Specifically:

[0107] S40: The defect detection module of the server of the platform to be tested determines whether it can reset the password of others by modifying the database id field. The specific steps are as follows:

[0108] Step 1: After the client of the platform to be tested operates Page 1 and Page 2 in normal order, the defect detection module of the server of the platform to be tested intercepts and saves the request packet for resetting the password of Page 3;

[0109] Step 2: The defect detection module of the server of the platform to be tested determines whether the request packet contains the database user table field parameters "id" and "uid";

[0110] Step 3: If so, the defect detection module of the server of the platform to be tested modifies the parameter values of the database user table field parameters "id" and "uid" to other user table field parameters, obtaining the modified request packet of Page 3, and then sends the modified request packet of Page 3 to the server of the platform to be tested;

[0111] The defect detection module of the server of the platform to be tested determines whether it can intercept the confirmation message sent by the server of the platform to be tested for successfully executing the modified request packet of Page 3;

[0112] Step 4: If it can, it means that the server of the platform under test resets the passwords of other users, and it is determined that there is a password reset logic vulnerability in the server of the platform under test.

[0113] Based on the above embodiments, the technical solution is further described and optimized in this embodiment. Specifically:

[0114] S50: The defect detection module of the server of the platform under test determines whether it is possible to reset the passwords of others by replacing the user identification request parameter. The specific steps are as follows:

[0115] Step 1: After the client of the platform under test normally operates Page 1 and Page 2 in sequence, the defect detection module of the server of the platform under test intercepts and saves the password reset request packet of Page 3.

[0116] Step 2: The defect detection module of the server of the platform under test replaces the current user identification in the current Cookie field of the request packet with the identification information of other users to obtain the modified request packet of Page 3, and then sends the modified request packet of Page 3 to the server of the platform under test.

[0117] The defect detection module of the server of the platform under test determines whether it can intercept the confirmation message sent by the server of the platform under test for successfully executing the modified request packet of Page 3.

[0118] Step 3: If it can, it means that the server of the platform under test resets the passwords of other users, and it is determined that there is a password reset logic vulnerability in the server of the platform under test.

[0119] Figure 2 A password reset logic vulnerability detection device based on verification defects provided by an embodiment of the present invention, as Figure 2 shown, a password reset logic vulnerability detection method based on verification defects includes:

[0120] A page loading module 1 is used to capture the request packets and response packets of the following three pages according to the functional attack order: Page 1, a request message sent by the client of the platform under test to the server of the platform under test for verifying the account that needs password reset, and a response message returned by the server of the platform under test; Page 2, a request message sent by the client of the platform under test to the server of the platform under test for selecting the identity verification method for the account on Page 1; wherein, the identity verification methods include email verification method for binding email, verification code verification method for binding mobile phone, and security question verification method. Page 3, after the identity verification method passes, the client of the platform under test sends a request to reset the new password to the server of the platform under test, that is: a request to reset the new password for the account determined on Page 1, and the request carries the new password; and a confirmation message returned by the server of the platform under test indicating that the new password reset is successful.

[0121] The first detection module for defects in the client of the platform to be tested is used to determine the credential information for page 2 authentication through the page loading module, and verify whether the defect detection of the client of the platform to be tested is carried out by the client. If so, the defect detection process of the client of the platform to be tested is carried out; the credential information includes, but is not limited to, mobile phone verification codes, password reset links for security protection email boxes, and security protection questions.

[0122] As a preferred implementation, another password reset logic vulnerability detection device based on verification defects further includes:

[0123] The second detection module for defects in the client of the platform to be tested is used to detect whether the credential information is directly displayed in the source code of the client of the platform to be tested. If so, the defect detection process of the client of the platform to be tested is carried out; the credential information includes, but is not limited to, mobile phone verification codes, password reset links for security protection email boxes, and security protection questions.

[0124] The defect detection module for the server of the platform to be tested is used to determine whether the verification step of page 2 can be skipped through the page loading module. If so, the defect detection process of the server of the platform to be tested is carried out.

[0125] As a preferred implementation, another password reset logic vulnerability detection device based on verification defects further includes:

[0126] The second defect detection module for the server of the platform to be tested is used to determine whether the credential information for the key page 2 authentication is directly returned in the response packet of page 2 through the page loading module. If so, the defect detection process of the server of the platform to be tested is carried out.

[0127] As a preferred implementation, another password reset logic vulnerability detection device based on verification defects further includes:

[0128] The third defect detection module for the server of the platform to be tested is used to modify any user information by the page loading module, and determine whether the server of the platform to be tested comprehensively conducts user information consistency verification. If not, the defect detection process of the server of the platform to be tested is carried out; the user information includes, but is not limited to, mobile phone numbers, verification codes, database user ID fields, and user identifiers.

[0129] The vulnerability determination module is used to determine that there are any password reset logic vulnerabilities in the client of the platform to be tested.

[0130] Figure 3 This is the composition framework diagram of the page loading module in a password reset logic vulnerability detection device based on verification defects provided by the present invention. As Figure 3 shown, the composition framework diagram of the page loading module in a password reset logic vulnerability detection device based on verification defects includes:

[0131] Install the proxy plug-in extension in the browser of the vulnerability detection device and configure it, then install the burpsuite Web attack tool and set up the proxy through the browser proxy plug-in to download the burpsuite certificate, and then install the certificate in the browser of the vulnerability detection device. At this point, the page loading module is built, and then burpsuite can be used normally to capture and modify all request and response information between the client and server of the platform to be tested and test it.

[0132] The present invention can comprehensively detect the reasons for the logical loopholes of password reset based on the verification defects of the client and server of the platform to be tested by modules. The present invention provides a method and device for detecting logical loopholes of password reset based on verification defects, which divides the verification defects that may exist in the three pages implemented by the three basic functional points of password reset of the conventional web business platform into two modules: the defect detection of the client of the platform to be tested and the defect detection of the server of the platform to be tested, and systematically and comprehensively detects whether there is any password reset vulnerability problem; it not only solves the logical attempt detection that is not considered or cannot be performed by the automated program, but also provides a systematic and comprehensive method for detecting any password reset vulnerability to technicians with varying levels.

[0133] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principle of the present invention. These improvements and modifications should also be considered as the scope of protection of the present invention.

Claims

1. A method for detecting logic vulnerabilities in password reset based on verification defects, characterized in that, Including the following steps: Step 1, install a vulnerability detection device between the client of the platform to be tested and the server of the platform to be tested; Step 2, the vulnerability detection device detects whether there is a password reset logic vulnerability in the server of the platform to be tested: Step 2.1, the vulnerability detection device intercepts the password reset request packet sent by the client of the platform to be tested to the server of the platform to be tested; the password reset request packet carries the user identity information of the user whose password needs to be reset; Step 2.2, the vulnerability detection device intercepts the password reset request packet and modifies the user identity information to the identity information of other users to obtain a modified password reset request packet; Step 2.3, the vulnerability detection device sends the modified password reset request packet to the server of the platform to be tested; Step 2.4, the vulnerability detection device determines whether it can intercept the confirmation response packet indicating successful password reset returned by the server of the platform to be tested. If it can, it indicates that the server of the platform to be tested does not verify the user identity information, and a conclusion that there is a password reset logic vulnerability in the server of the platform to be tested is obtained; Step 3, the vulnerability detection device detects whether there is a password reset logic vulnerability in the client of the platform to be tested; The specific content of Step 3 is as follows: Step 3.1, the vulnerability detection device intercepts the authentication request containing authentication credential information sent by the client of the platform to be tested to the server of the platform to be tested; Step 3.2, the vulnerability detection device modifies the authentication credential information in the authentication request to incorrect authentication credential information to obtain a modified authentication request, and sends the modified authentication request to the server of the platform to be tested; Step 3.3, the vulnerability detection device intercepts the response packet of the authentication result sent by the server of the platform to be tested; Step 3.4, the vulnerability detection device determines whether the intercepted response packet of the authentication result contains an error identification string. If so, it modifies the error identification string to a correct identification string to obtain a modified response packet of the authentication result, and sends the modified response packet of the authentication result to the client of the platform to be tested; Step 3.5, the vulnerability detection device determines whether it can intercept the request packet for resetting a new password sent by the client of the platform to be tested. If it can be intercepted, it means that there is a password reset logic vulnerability in the client of the platform to be tested.

2. The method for detecting logic vulnerabilities in password reset based on verification defects according to claim 1, characterized in that, In Step 2.1, the user identity information of the user whose password needs to be reset includes user parameters, database user table field parameters, and the user identifier in the current Cookie field.

3. The method for detecting logic vulnerabilities in password reset based on verification defects according to claim 2, characterized in that, The user parameters include the username, the user's mobile phone number phone, and the user's email address email; the database user table field parameters include the user id.

4. The method for detecting logic vulnerabilities in password reset based on verification defects according to claim 1, characterized in that, It also includes: The vulnerability detection device detects whether there is a password reset logic vulnerability in the server of the platform to be tested in the following way: The vulnerability detection device intercepts a request for selecting the email binding verification method sent by the client of the platform under test to the server of the platform under test, and forwards the request for selecting the email binding verification method to the server of the platform under test; The vulnerability detection device obtains the password reset link received by the bound email; The vulnerability detection device determines whether the password reset link contains the user identity information of the user whose password needs to be reset. If so, it modifies the user identity information of the user whose password needs to be reset to other user identity information, so as to obtain the modified password reset link; The vulnerability detection device determines whether it can successfully access the modified password reset link. If it can, it means that the vulnerability detection device sends a request to reset the password for the other user identity information to the server of the platform under test, and determines whether it can intercept the confirmation response packet indicating successful password reset returned by the server of the platform under test. If it can, it indicates that the server of the platform under test does not perform verification on the user identity information, and a conclusion that there is a password reset logic vulnerability in the server of the platform under test is obtained.

5. The method for detecting logic vulnerabilities in password reset based on verification defects according to claim 1, characterized in that, The authentication credential information includes mobile phone verification codes, email reset links, and answers to security question.

6. A device for detecting logic vulnerabilities in password reset based on verification defects, characterized in that, The password reset logic vulnerability detection device based on verification defects is connected to the client of the platform under test and the server of the platform under test through the network respectively; The password reset logic vulnerability detection device based on verification defects includes a web page loading module, a server defect detection module of the platform under test, and a client defect detection module of the platform under test; The web page loading module is used to intercept the request packet sent by the client of the platform under test to the server of the platform under test, and the response packet returned by the server of the platform under test to the client of the platform under test; The server defect detection module of the platform under test is used to detect whether there is a password reset logic vulnerability in the server of the platform under test according to the request packet or response packet intercepted by the web page loading module; The client defect detection module of the platform under test is used to detect whether there is a password reset logic vulnerability in the client of the platform under test according to the request packet or response packet intercepted by the web page loading module; The specific process of the password reset logic vulnerability detection device based on verification defects detecting whether there is a password reset logic vulnerability in the client of the platform under test is as follows: Intercept the authentication request containing authentication credential information sent by the client of the platform under test to the server of the platform under test; Modify the authentication credential information in the authentication request to incorrect authentication credential information to obtain the modified authentication request, and send the modified authentication request to the server of the platform under test; Intercept the response packet of the authentication result sent by the server of the platform under test; Determine whether the intercepted response packet of the authentication result contains an error identification string. If so, modify the error identification string to a correct identification string to obtain the modified response packet of the authentication result, and send the modified response packet of the authentication result to the client of the platform under test; Determine whether it is possible to intercept the request packet for resetting the new password sent by the client of the platform to be tested. If it can be intercepted, it means that there is a password reset logic vulnerability in the client of the platform to be tested.

Citation Information

Patent Citations

  • Detection method and device for any account password resetting logic vulnerability and medium

    CN112165473A

  • Internet of Vehicles vulnerability analysis method and device based on association analysis, medium and equipment

    CN112311767A