Automated Web Password Reset Logic Vulnerability Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for detecting logic vulnerabilities allowing arbitrary password reset in webpages are inefficient, requiring significant human resources and lacking comprehensive and accurate detection.

Innovation Solution

A method and apparatus that invoke a preset identification program to detect requests for verification codes in webpages, determine the presence of SMS verification codes, and assess the existence of logic vulnerabilities by simulating password reset requests with updated user information or random verification codes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual code checking by technicians is used to detect logic vulnerabilities, then detection accuracy can be maintained, but human resource consumption increases significantly

Engineering Contradiction:
Improvedetection accuracyVSAvoidhuman resource consumption
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system performs self-detection by automatically invoking identification programs to scan webpage source code, send verification code requests, and analyze response packets for SMS verification codes. The detection system serves itself without requiring manual technician intervention, thereby reducing human resource consumption while maintaining detection accuracy through automated analysis of the password reset logic flow.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual mechanical process of technicians reviewing source code is replaced with an automated electronic system that uses identification programs to programmatically detect verification code requests, parse response packets, and determine the presence of logic vulnerabilities. This substitution of manual inspection with automated computational analysis reduces human resource consumption while maintaining or improving detection precision.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If automated detection methods are used to reduce human resources, then productivity improves, but detection comprehensiveness and accuracy deteriorate

Engineering Contradiction:
Improvehuman resource efficiencyVSAvoiddetection comprehensiveness
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system performs preliminary actions by first invoking identification programs to locate verification code request interfaces, then sending test requests to obtain response packets before analyzing for SMS verification codes. This structured preliminary sequence ensures comprehensive detection coverage while maintaining high productivity through automation. The preliminary identification of relevant interfaces guides subsequent automated analysis, preventing missed vulnerabilities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by analyzing response packets from verification code requests to determine whether SMS verification codes are present, then using this information to conclude whether logic vulnerabilities exist. The automated feedback loop continuously refines detection accuracy by comparing expected security behavior against actual system responses, ensuring comprehensive detection while maintaining high throughput and low human resource consumption.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If comprehensive automated scanning is performed to detect all vulnerabilities, then detection coverage improves, but detection time increases

Engineering Contradiction:
Improvedetection coverageVSAvoiddetection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The detection process is segmented into distinct modular stages: (1) invoking identification programs to locate verification code request interfaces, (2) sending test requests to obtain response packets, and (3) analyzing packets for SMS verification codes to determine vulnerability presence. This segmentation allows each stage to be optimized independently and executed efficiently, improving overall detection coverage without proportionally increasing total detection time through parallel processing and targeted analysis.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12317080B2Method and apparatus for detecting arbitrary account password reset logic vulnerability, and medium
Publication Date: 2025.05.27 DBAPPSECURITY CO LTD
  • US12317080B2 patent drawing
  • US12317080B2 patent drawing

AI summary

Disclosed are a method and apparatus for detecting a logic vulnerability allowing arbitrary password reset for an account, and a computer readable storage medium. The method includes: invoking a preset identification program to determine whether a request for a verification code is initiated in a to-be-detected webpage; obtaining, from a front-end page, a response packet sent in response to the request for a verification code, and determining whether there is a short message service (SMS) verification code in the response packet, on determining that a request for a verification code is initiated in the to-be-detected webpage; and; and determining that the logic vulnerability allowing arbitrary password reset for an account exists in the to-be-detected webpage, on determining that there is an SMS verification code in the response packet.