Account Takeover using Improper Authorization in “Check Availability” Feature
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内。首先,我得仔细阅读用户提供的文章内容。看起来这篇文章讲的是一个最近解决的报告,提交给了一个私人程序。这个程序是一个应用程序,用于招聘专业人士提供各种服务,比如家政清洁、管道工、油漆工等。 文章中提到用户可以通过电子邮件注册账户,而不需要提供手机号码。这可能是一个安全漏洞,因为没有手机验证的话,账户可能更容易被攻击或滥用。接下来,文章描述了应用程序中专业人员的个人资料功能,包括他们的评分和反馈。用户可以在不经过任何身份验证的情况下查看这些资料,并检查专业人士的可用性。 在“Check Availability”部分,用户可以输入受害者的电子邮件地址,而该账户已经存在。这可能意味着攻击者可以利用已有的账户信息来进行进一步的操作,比如接管账户或者获取敏感信息。 现在我需要把这些信息浓缩到100字以内,并且不需要使用特定的开头语句。我应该突出关键点:应用程序的功能、注册方式、漏洞以及潜在的安全风险。 可能的总结是:文章描述了一个招聘服务平台的应用程序漏洞。用户可通过邮箱注册账户,并查看专业人员资料及可用性。未验证身份即可操作,存在安全隐患。 检查一下字数是否符合要求,并确保内容准确传达了文章的核心信息。 </think> 文章描述了一个招聘服务平台的应用程序漏洞。用户可通过邮箱注册账户,并查看专业人员资料及可用性。未验证身份即可操作,存在安全隐患。 2026-2-11 13:46:55 Author: infosecwriteups.com(查看原文) 阅读量:0 收藏

Ronak Patel

Hello Guys!!!!

Hope you are doing Great.

This article is about recently resolved report, which was submitted to private program. which is application for hiring professionals for different kind of services like House cleaning , carpet cleaning , plumbers, Painters,Contractors.

Press enter or click to view image in full size

Victim Account

As seen above anyone can sign up through email address in application and his account would be created. As seen in above image victim has not supplied his phone number.Account is registered using email only.

Application has profile of the professionals who provides services like plumber, contractors,electricians and more. There is functionality to check availability of such professional unauthenticated.

So any user without any kind of authentication go to any professional’s profile which contains his ratings and feedback,can start the flow to check availability of that professional as seen below

Check Availability

While go through this flow we can supply victim’s email which account already exist as below


文章来源: https://infosecwriteups.com/account-takeover-using-improper-authorization-in-check-availability-feature-4f9f65098853?source=rss----7b722bfd1b8d---4
如有侵权请联系:admin#unsafe.sh