企业SRC挖洞实战

SRC介绍
SRC: 安全应急响应中心(Security Response Center)通过给企业提交漏洞获取相应的报酬(钱),

SRC的分类大致有以下几种
企业SRC: 阿里SRC 百度SRC 腾讯SRC,BOSS直聘,字节跳动等(还有一部分没有自己的直属SRC平台比如联想之类的)https://www.anquanke.com/src/(SRC导航)
众测平台:补天众测,漏洞盒子 雷神众测 火线 360众测(需要一定的门槛)
还有其他的平台比如:教育SRC,CNVD 公益SRC(目前不挖这个了)

SRC准则
每一个SRC都有自己的挖掘准则,请白帽子们仔细阅准则
https://bsrc.baidu.com/v2/#/announce/127

SRC范围
每一个SRC都有自己的资产范围,确定资产范围是我们的第一步要做就是确定资产目前来说分为两种
1、平台规定的资产和域名,只能从其中挖掘
2、平台没有规定域名,只是某一个应用名或者没有需要采用QCC(企查查)的方法

SRC评级
每个漏洞都有评级,评级不同对应的积分不同,漏洞还分为核心,一般,边缘,白帽们阅读公告。

SRC抓包

image-20241208005901935
image-20241208005939710
image-20241208010019334
image-20241208010404904
image-20241208010443836
image-20241208010656240
image-20241208010819554
image-20241208011019598
image-20241208135354041
image-20241208135521525
image-20241208135727775
image-20241208135821722
image-20241208135944000
image-20241208140531585
image-20241208140652373

信息收集

短信验证码相关逻辑漏洞

验证码爆破漏洞

image-20241208154230445
image-20241208154509185
image-20241208154520258
image-20241208154708248
image-20241208155122710
image-20241208155420324

验证码回显漏洞

image-20241208160238732
image-20241208160401512
image-20241208160528149
image-20241208160634681
image-20241208160718793
image-20241208161316218
image-20241208161404466
image-20241208161532263

验证码与手机未绑定认证关系漏洞

image-20241208161638516
image-20241208161946372
image-20241208162258114

修改返回包绕过验证码漏洞

image-20241208162415813
image-20241208162625167
image-20241208162824876
image-20241208162847234
image-20241208163018420

短信验证码转发漏洞

image-20241208164323329
image-20241208164444556
image-20241208164502024
image-20241208164701444
image-20241208164809729
image-20241208164853375

无效验证任意验证码登录漏洞

image-20241208165100896
image-20241208165256373

验证码为空登录漏洞

image-20241208165329899
image-20241208165613778
image-20241208165846202

固定验证码登录漏洞

image-20241208170145482
image-20241208170327945

手机短信轰炸漏洞

image-20241208170724655
image-20241208171326426
image-20241208171520303
image-20241208171726019
image-20241208171912806
image-20241208172001376
image-20241208172230192
image-20241208172251874
image-20241208172539009
image-20241208172934185
image-20241208173050487
image-20241208173126713
image-20241208173235759

支付相关逻辑漏洞

image-20241208173927083
image-20241208174134201

订单金额任意修改漏洞

image-20241208174542857
image-20241208174752931
image-20241208174830655
image-20241208174900957
image-20241208175251613
image-20241208180455163
image-20241208180626510
image-20241208181243834

负数购买漏洞

image-20241208181356644
image-20241208191041923
image-20241208191110008
image-20241208191244177

越权支付漏洞

image-20241208191640675
image-20241208192144419
image-20241208192550154
image-20241208192649966

优惠卷修改漏洞

image-20241208193033469
image-20241208193216900
image-20241208193230769
image-20241208193316132
image-20241208193622066

修改运费价格漏洞

image-20241208194024274
image-20241208194045911
image-20241208194000764

四舍五入支付漏洞

image-20241208194614582
image-20241208194639905
image-20241208194849651

无限利用优惠漏洞

image-20241208195242881
image-20241208195319264
image-20241208195629350

整数溢出漏洞

image-20241208201050997
image-20241208200929586
image-20241208200936994

权限相关漏洞

image-20241208210958348
image-20241208223551077
image-20241208223658467

并发及相关漏洞

FUZZ技术讲解

JS漏洞挖掘作用

Last updated