Universal Web weak password detection method and system
The method uses a headless browser to dynamically load pages, locate login forms, and perform brute-force detection on websites without recognizable fingerprints, addressing the lack of universal weak password detection for complex web pages and improving detection coverage and accuracy.
Patent Information
- Application Number
- CN202510789929.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-13
- Publication Date
- 2025-07-15
AI Technical Summary
The prior art cannot effectively detect weak passwords for custom or complexly designed website login pages. Traditional methods rely on fingerprint feature recognition and have poor versatility, so they cannot adapt to websites that do not store fingerprint features.
Dynamically load the web page through a headless browser, obtain the password input box element, trace the parent element upwards to locate the login form, fill in random strings and simulate submission events, collect HTTP request traffic, and use weak password dictionary for blast detection.
Automatic weak password detection for most websites is realized, improving detection coverage and accuracy, including unknown website systems.
Smart Images

Figure CN120321037A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and particularly to a general Web weak password detection method and system. Background Art
[0002] Weak password vulnerability is one of the most popular and harmful vulnerabilities. Therefore, the detection of weak passwords is extremely important. For protocols with relatively fixed formats, such as ssh, ftp, etc., the authentication processes of these protocols are fixed, so the detection of weak passwords is relatively easy.
[0003] However, for website logins, there is no fixed authentication method. The authentication logic is determined by the website developers. If the login interface cannot be recognized, subsequent weak password detection cannot be performed. Therefore, there is currently no general detection method for weak passwords in website logins. Current security scanning tools can only detect weak passwords of known and common website applications and components. Taking zabbix as an example, when the security scanning tool captures the target web page, it will detect the fingerprint features of the web page. When it finds that the target website title has the fingerprint of zabbix (such as the web page title contains the keyword "Zabbix" which can be used as the fingerprint to identify zabbix), the security scanning tool will use the login interface of zabbix to perform brute force cracking (brute force cracking means that testers use tools to load a weak password dictionary, that is, a common weak password list, and perform login attempts one by one until the login is successful) to detect whether it has a weak password. Therefore, the traditional detection scheme first needs to identify the website application through fingerprint features. Only after successfully identifying the website can it be detected whether it has a weak password. Therefore, for websites without fingerprint features (such as websites developed by users themselves), the traditional scheme cannot detect their weak passwords.
[0004] In recent years, there has emerged a so-called "general" weak password detection technology. The principle is to extract the login interface and its parameter names by matching regular expressions and keywords with the forms in the login web page. This scheme has poor versatility and is only applicable to simple, standard, and static login web pages. For complex, non-standard designed, and login pages rendered by js later, this technology is incompatible. Summary of the Invention
[0005] In view of this, in the first aspect of the present invention, a general Web weak password detection method is provided. The method includes: The main control program sends the target URL to the headless browser to dynamically load the web page; Obtain the password input box element. If the acquisition fails, the process is aborted; Based on the password input box, trace back to the parent element upward to locate the login form; Fill the username box, password box, and / or verification code box in the form with random strings respectively; Simulate triggering the form submission event to collect HTTP request traffic; Mark the positions of the username, password, and / or verification code in the request by matching the random strings; Based on the marked request, use a weak password dictionary for brute-force detection.
[0006] Further, the method of tracing back to the parent element based on the password input box to locate the login form specifically includes: if the element of the password input box cannot be obtained, abort the process; if there is a verification code but the verification code does not support recognition, abort the process.
[0007] Further, the method of tracing back to the parent element based on the password input box to locate the login form specifically includes: tracing back to the parent element based on the password input box until the parent element meets the following conditions, which is regarded as successfully locating the form: The tag name of the parent element is form; Or the parent element has a submit event; Or the child elements of the parent element contain a button with a type attribute of submit; Or the child elements of the parent element contain an element with a tag name of button or span and the text content is login or submit or sign in or login.
[0008] Further, the method of filling the username box, password box, and / or verification code box in the form with random strings respectively specifically includes: generating 2 groups of random strings, requiring the length to be greater than 8 and consisting of letters and numbers. The 2 groups of random strings are the password box string and the text box string; storing the 2 groups of random strings in the first memory; obtaining the element in the form with a tag name of input and a type attribute of passwd, and writing the password box string; obtaining the element in the form with a tag name of input and a type attribute of text, and writing the text box string; the elements of the text box string at least include the text box for entering the username and the text box for entering the verification code, and write the text box string into the text boxes in sequence; the writing method is to input the string into the text box and password box by simulating keyboard input.
[0009] Further, the simulation of triggering the form submission event to collect HTTP request traffic and the marking of the positions of the username, password, and / or verification code in the request by matching the random strings are executed simultaneously.
[0010] Further, the simulation triggers a form submission event to collect HTTP request traffic, specifically including submitting the generated username box, password box, and / or verification code box to the server, that is, sequentially obtaining the submit event of the form, the click event of the login button, and the submit event.
[0011] Further, marking the positions of the username, password, and / or verification code in the request by matching random strings specifically includes detecting whether the request contains the random string of the password box recorded in the first memory. If the match is successful, the request is a login request; finding the string within the password box and replacing it with the unique identifier of the password box; extracting the text box string of the first memory, finding the random string within the text box, and replacing it with the unique identifier of the text box; if there are still unmatched strings in the first memory, extracting the unmatched strings, taking the first 4 digits of the unmatched strings, and performing a match in the request. If found, replacing it with the unique identifier of the unmatched string.
[0012] Further, based on the marked request, using a weak password dictionary for brute-force detection specifically includes, based on the dictionary brute-force method, replacing the unique identifiers of the text box and the password box with different combinations for replay to perform weak password brute-force detection.
[0013] On the other hand, the present invention also provides a general Web weak password detection system, including a headless browser device, a pre-detection device, a login form positioning device, a text box positioning device, an automatic login device, a traffic collection device, and a weak password detection device; The headless browser device is used to dynamically load web pages and perform interactive operations; The pre-detection device is used to obtain the password input box element. If the acquisition fails, the process is aborted; that is, determining whether the loaded web page is a login page and whether it meets the conditions for weak password detection; The login form positioning device is used to trace back the parent element upward based on the password input box to locate the login form; The text box positioning device is used to fill random strings into the username box, password box, and / or verification code box in the form respectively; The traffic collection device is used to simulate triggering a form submission event to collect HTTP request traffic; The automatic login device is used to mark the positions of the username, password, and / or verification code in the request by matching random strings; The weak password detection device is used to perform brute-force detection using a weak password dictionary based on the marked request.
[0014] Further, after the task of the text box positioning device is completed, the automatic login device and the task of the automatic login device are started simultaneously in multiple threads.
[0015] Advantages of the present invention: The present invention does not need to identify the website system, can automatically extract the login interfaces of most websites, including unknown website systems, and perform weak password detection. It improves the coverage and accuracy of weak password detection. Description of the drawings
[0016] Figure 1 Flowchart of a general Web weak password detection method of the present invention; Figure 2 Flowchart of the operation of the pre-detection device of the present invention; Figure 3 Flowchart of the operation of the form positioning device of the present invention; Figure 4 Flowchart of the operation of the text box positioning device of the present invention; Figure 5 Flowchart of the operation of the traffic collection device of the present invention. Detailed implementation manners
[0017] To make the objectives, advantages and features of the present invention more obvious, the following detailed implementation manners further elaborate on the present invention.
[0018] The present invention uses a headless browser to dynamically load the website login page, automatically fills in the user name, password, and verification code (optional) in three fields with random strings, simulates clicking the login button to simulate login, and then extracts the login traffic in the traffic, that is, the login interface, for subsequent weak password detection.
[0019] As Figure 1 shown, an embodiment method of the present invention is: Step 1: The main control program delivers the URL to the headless browser, and the headless browser dynamically loads the URL.
[0020] Step 2: After loading is completed, execute the js, and the js attempts to obtain the element with the tag name input and the type attribute passwd. That is, the password box.
[0021] The role of the pre-detection device is to detect whether the web page meets the requirements before formally entering the recognition logic. If it does not meet the requirements, the process is aborted to avoid consuming unnecessary resources. The execution logic of this device is that if the acquisition in Step 2 fails, it means that the web page has no login function and does not meet the weak password detection conditions, and the process should be aborted. If keywords such as "verification code" exist in the web page and the weak password detection device in Step 9 does not support the recognition of verification codes, then the process should also be aborted.
[0022] Step 4: If the element is successfully obtained in Step 2, use the login form positioning device.
[0023] Step 5: The function of the login form positioning device is to locate the position of the login form in HTML. The execution process is as follows: based on the password box element obtained in Step 2, trace back to its parent element until the parent element meets the following conditions: the tag name of the parent element is form, or the parent element has a submit event, or there is a button with a type attribute of submit among other child elements of the parent element that can be regarded as a login button, or there is an element with a tag name of button or span among other child elements of the parent element and the text content is keywords such as "login", "submit", "sign in", "login", etc. that are also regarded as login buttons. After successfully locating the form, the process enters the "text box positioning device".
[0024] Step 6: The function of the text box positioning device is to fill each text box (such as username, password, verification code) with randomly generated strings to facilitate subsequent positioning of the position of each text box in the login interface. The execution process is as follows: generate two groups of random strings, with the requirement that the length is greater than 8 and consists of letters and numbers. One group of these two groups of strings is marked as the password box string, and the other group is marked as the text box string. Store these two groups of random strings in "Memory A". Obtain the element with a tag name of input and a type attribute of passwd within the form, and write the password box string; obtain the element with a tag name of input and a type attribute of text within the form, which are text box elements. There may be more than one text box element obtained, at least including the text box for entering the username, and may also include the text box for entering the verification code. Write the text box string into these text boxes in sequence. The writing method is to input these strings into the text boxes and password boxes by simulating keyboard input. Then enable two threads to execute the "traffic collection device" and the "automatic login device" simultaneously.
[0025] Step 7: The function of the automatic login device is to automatically submit the username and password filled in Step 6 to the server according to the interface specified by the web developer. The process is as follows: trigger the submit event of the form, the click event and the submit event of the login button obtained by the login form positioning device in Step 5 in sequence.
[0026] Step 8: The function of the traffic collection device is to collect and identify the login traffic of the browser, and mark the positions of the user name, password, and verification code (optional) in the traffic. Its execution process is to detect whether the HTTP request contains the random string in the password box recorded in Memory A. If the match is successful, it indicates that the request is a login request. Find the string in the password box and replace it with a unique identifier, such as {PASSWD}. Extract the string in the text box from Memory A, find the random string in the text box in the request, and replace it with a unique identifier, such as {USERNAME}. If there are still unmatched strings in the memory, extract them, take the first 4 digits of the string, and match them in the request. If found, replace them with the unique identifier {CODE}.
[0027] Step 9: Send the marked login request to the weak password detection device. This device uses the dictionary brute-force method to replace {USERNAME} and {PASSWD} with different combinations for replaying in order to detect weak passwords.
[0028] As Figure 2 shown, the pre-detection device is to judge whether the currently loaded web page is a login page and whether it meets the conditions for weak password detection. The specific steps are as follows: after the web page is loaded, judge whether there is a password box in the web page. If there is no password box, abort the process; if there is a password box but there is a verification code, identify the verification code. If the identification is not supported, abort the process; otherwise, continue with the following process.
[0029] As Figure 3 shown, a form is a concept in HTML, referring to a collection of elements such as text boxes and buttons. In this application, the login form refers to the collection of the user name text box, password input box, verification code text box (optional), and login button. The login form positioning device is used to position the login form. Only when the login form is successfully positioned can the user name text box and login button be located subsequently. That is, keep tracing back to its parent element upward until the outer element including the user name, password box, and login button is found when the conditions are met.
[0030] As Figure 4 shown, the text box positioning device generates 2 groups of random strings with a length of 8, and simulates keyboard input of one group of random strings into the password box. According to the login form positioned in the previous step, the text boxes within the login form must be the user name text box and the verification code text box. Input the second group of random strings into the text box in the way of simulated keyboard input. Generally, the character number limit in the user name text box is relatively loose, while the character number limit in the verification code text box is strict, usually 4. Therefore, for the verification code text box, only the first 4 characters of the random string can be successfully input.
[0031] As Figure 5As shown, the traffic collection device inputs a random string in the text box for login expression, and uses the automatic login device to submit the random string to the server in the format of the login interface. The traffic collection device accesses the interface of the headless browser and can collect all HTTP requests generated by the browser. By matching the above two sets of random strings with the HTTP requests, the positions of the username, password, and verification code (optional) in the HTTP requests can be known.
[0032] The above embodiments have described the technical solutions of the present invention in detail. Obviously, the present invention is not limited to the described embodiments. Based on the embodiments of the present invention, those skilled in the art can also make various changes accordingly, but any changes equivalent or similar to the present invention fall within the scope of protection of the present invention.
[0033] The content not described in detail in this specification belongs to the prior art well-known to those skilled in the art.
Claims
1. A general method for detecting weak passwords on the Web, characterized in that, The method includes: The main control program transports the target URL to a headless browser to dynamically load the web page; Obtain the password input box element, and abort the process if the acquisition fails; Trace back to the parent element based on the password input box to locate the login form; Fill the username box, password box, and / or verification code box in the form with random strings respectively; Simulate triggering the form submission event to collect HTTP request traffic; Mark the positions of the username, password, and / or verification code in the request by matching the random strings; Based on the marked request, use a weak password dictionary for brute force detection.
2. The general Web weak password detection method according to claim 1, wherein The tracing back to the parent element based on the password input box to locate the login form specifically includes: if the acquisition of the password input box element fails, abort the process; If there is a verification code but the verification code does not support recognition, abort the process.
3. The general Web weak password detection method according to claim 2, wherein The tracing back to the parent element based on the password input box to locate the login form specifically includes: tracing back to the parent element based on the password input box until the parent element meets the following conditions, and it is considered that the form is successfully located: The tag name of the parent element is form; Or the parent element has a submit event; Or the child elements of the parent element include a button with a type attribute of submit; Or the child elements of the parent element include an element with a tag name of button or span and the text content is login or submit or log in or login.
4. The general Web weak password detection method according to claim 3, wherein, The filling the username box, password box, and / or verification code box in the form with random strings respectively specifically includes: generating 2 groups of random strings, requiring the length to be greater than 8 and consisting of letters and numbers. The 2 groups of random strings are the password box string and the text box string; store the 2 groups of random strings in the first memory; Obtain the element in the form with a tag name of input and a type attribute of passwd, and write the password box string; Obtain the element in the form with a tag name of input and a type attribute of text, and write the text box string; the elements of the text box string at least include the text box for inputting the username and the text box for inputting the verification code, and write the text box string into the text boxes in sequence; the writing method is to input the string into the text box and password box by simulating keyboard input.
5. The general Web weak password detection method according to claim 4, wherein The simulating triggering the form submission event to collect HTTP request traffic and the marking the positions of the username, password, and / or verification code in the request by matching the random strings are executed simultaneously.
6. The general Web weak password detection method according to claim 5, characterized in that, The simulating triggering the form submission event to collect HTTP request traffic specifically includes: submitting the generated username box, password box, and / or verification code box to the server, that is, sequentially obtaining the submit event of the form, the click event of the login button, and the submit event.
7. The general Web weak password detection method according to claim 6, wherein The method of marking the positions of the username, password, and / or verification code in the request by matching random strings specifically includes detecting whether the random string of the password box recorded in the first memory is included in the request. If the match is successful, the request is a login request. Find the string in the password box and replace it with the unique identifier of the password box. Extract the text box string of the first memory, find the random string in the text box, and replace it with the unique identifier of the text box. If there are still unmatched strings in the first memory, extract the unmatched strings, take the first 4 digits of the unmatched strings, and match them in the request. If found, replace them with the unique identifier of the unmatched strings.
8. The general Web weak password detection method according to claim 7, wherein Based on the marked request, the method of using a weak password dictionary for brute-force detection specifically includes, based on the dictionary brute-force method, replacing the unique identifiers of the text box and the password box with different combinations for replay to perform weak password brute-force detection.
9. A general Web weak password detection system, characterized in that, It includes a headless browser device, a pre-detection device, a login form positioning device, a text box positioning device, an automatic login device, a traffic collection device, and a weak password detection device; The headless browser device is used to dynamically load web pages and perform interactive operations; The pre-detection device is used to obtain the password input box element. If the acquisition fails, the process is aborted. That is, it determines whether the loaded web page is a login page and whether it meets the conditions for weak password detection; The login form positioning device is used to trace back the parent element upward based on the password input box to locate the login form; The text box positioning device is used to fill random strings into the username box, password box, and / or verification code box in the form respectively; The traffic collection device is used to simulate triggering a form submission event to collect HTTP request traffic; The automatic login device is used to mark the positions of the username, password, and / or verification code in the request by matching random strings; The weak password detection device is used to perform brute-force detection using a weak password dictionary based on the marked request.
10. The general Web weak password detection system according to claim 9, characterized in that, After completing the task of the text box positioning device, the automatic login device and the task of the automatic login device are started simultaneously in multiple threads.
Citation Information
Patent Citations
Website login brute force crack method and system capable of identifying verification code
CN105844140A
Method for generating protection configuration for login page and apparatus thereof
CN106685938A
A method and a system for solving the tedious configuration of weak password detection of a web page
CN109241460A
Vulnerability detection method and device, electronic equipment and storage medium
CN114996714A
Weak password detection method and device
CN117811784A