Automated Web Password Reset Logic Vulnerability Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for detecting logic vulnerabilities allowing arbitrary password reset in webpages are inefficient, requiring significant human resources and lacking comprehensive and accurate detection.
Innovation Solution
A method and apparatus that invoke a preset identification program to detect requests for verification codes in webpages, determine the presence of SMS verification codes, and assess the existence of logic vulnerabilities by simulating password reset requests with updated user information or random verification codes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual code checking by technicians is used to detect logic vulnerabilities, then detection accuracy can be maintained, but human resource consumption increases significantly
Solution Approach 1:
The system performs self-detection by automatically invoking identification programs to scan webpage source code, send verification code requests, and analyze response packets for SMS verification codes. The detection system serves itself without requiring manual technician intervention, thereby reducing human resource consumption while maintaining detection accuracy through automated analysis of the password reset logic flow.
Solution Approach 2:
The manual mechanical process of technicians reviewing source code is replaced with an automated electronic system that uses identification programs to programmatically detect verification code requests, parse response packets, and determine the presence of logic vulnerabilities. This substitution of manual inspection with automated computational analysis reduces human resource consumption while maintaining or improving detection precision.
2Productivity
If automated detection methods are used to reduce human resources, then productivity improves, but detection comprehensiveness and accuracy deteriorate
Solution Approach 1:
The system performs preliminary actions by first invoking identification programs to locate verification code request interfaces, then sending test requests to obtain response packets before analyzing for SMS verification codes. This structured preliminary sequence ensures comprehensive detection coverage while maintaining high productivity through automation. The preliminary identification of relevant interfaces guides subsequent automated analysis, preventing missed vulnerabilities.
Solution Approach 2:
The system implements feedback by analyzing response packets from verification code requests to determine whether SMS verification codes are present, then using this information to conclude whether logic vulnerabilities exist. The automated feedback loop continuously refines detection accuracy by comparing expected security behavior against actual system responses, ensuring comprehensive detection while maintaining high throughput and low human resource consumption.
3Measurement precision
If comprehensive automated scanning is performed to detect all vulnerabilities, then detection coverage improves, but detection time increases
Solution Approach 1:
The detection process is segmented into distinct modular stages: (1) invoking identification programs to locate verification code request interfaces, (2) sending test requests to obtain response packets, and (3) analyzing packets for SMS verification codes to determine vulnerability presence. This segmentation allows each stage to be optimized independently and executed efficiently, improving overall detection coverage without proportionally increasing total detection time through parallel processing and targeted analysis.
Data Source
AI summary
Disclosed are a method and apparatus for detecting a logic vulnerability allowing arbitrary password reset for an account, and a computer readable storage medium. The method includes: invoking a preset identification program to determine whether a request for a verification code is initiated in a to-be-detected webpage; obtaining, from a front-end page, a response packet sent in response to the request for a verification code, and determining whether there is a short message service (SMS) verification code in the response packet, on determining that a request for a verification code is initiated in the to-be-detected webpage; and; and determining that the logic vulnerability allowing arbitrary password reset for an account exists in the to-be-detected webpage, on determining that there is an SMS verification code in the response packet.

